The flaws affect S/MIME and OpenPGP, two technologies that e-mail programs often use to protect data.
The news: Ars Technica reports that security researchers in Germany have uncovered a way to decrypt e-mails that rely on the above techniques. They released their findings under the banner “Efail” in a paper published today.
The hacks: These essentially work by inserting manipulated text into an e-mail that’s been intercepted by hackers, and then sending it on to the unsuspecting recipient. Once the victim opens it, the malicious code tricks the program into sending a plain-text version back to the hacker. The researchers say new and archived e-mails are vulnerable.
The response: Some security executives say the risk exists only in e-mail programs that don’t check for decryption errors, so it’s worth verifying whether yours does. If you’re particularly paranoid, you might choose to decrypt messages in applications that are separate from your e-mail program—a step the German researchers recommend. They’ve disclosed the vulnerability to the companies providing e-mail programs, so watch out for software patches.
Why this matters: This hardly needs spelling out, but it’s worth noting that it’s not just an issue for companies and governments; many journalists and activists rely on encrypted e-mail to keep in touch with their sources.
A chip design that changes everything: 10 Breakthrough Technologies 2023
Computer chip designs are expensive and hard to license. That’s all about to change thanks to the popular open standard known as RISC-V.
Modern data architectures fuel innovation
More diverse data estates require a new strategy—and the infrastructure to support it.
Chinese chips will keep powering your everyday life
The war over advanced semiconductor technology continues, but China will likely take a more important role in manufacturing legacy chips for common devices.
The computer scientist who hunts for costly bugs in crypto code
Programming errors on the blockchain can mean $100 million lost in the blink of an eye. Ronghui Gu and his company CertiK are trying to help.
Get the latest updates from
MIT Technology Review
Discover special offers, top stories, upcoming events, and more.