Skip to main content

Email encryption flaw gives hackers full access to your secret messages

Researchers at the Munster University of Applied Sciences discovered vulnerabilities in the Pretty Good Protection (PGP) and S/MIME technologies used to encrypt email. The problem resides in how email clients use these plug-ins to decrypt HTML-based emails. Individuals and companies are encouraged to disable PGP and/or S/MIME in their email clients for now and use a separate application for message encryption. 

Called EFAIL, the vulnerability abuses “active” content rendered within HTML-based emails, such as images, page styles, and other non-text content stored on a remote server. To successfully carry out an attack, the hacker must first have the encrypted email in possession, whether it’s through eavesdropping, hacking into an email server, and so on. 

The first attack method is called “Direct Exfiltration” and abuses vulnerabilities in Apple Mail, iOS Mail, and Mozilla Thunderbird. An attacker creates an HTML-based email comprising of three parts: the start of an image request tag, the “stolen” PGP or S/MIME ciphertext, and the end of an image request tag. The attacker then sends this revised email to the victim. 

On the victim’s end, the email client first decrypts the second part and then combines all three into one email. It then converts everything into an URL form starting with the hacker’s address and sends a request to that URL to retrieve the nonexistent image. The hacker receives the image request, which contains the entire decrypted message. 

The second method is called the “CBC/CFB Gadget Attack,” which resides within the PGP and S/MIME specifications, affecting all email clients. In this case, the attacker locates the first block of encrypted plaintext in the stolen email and adds a fake block filled with zeroes. The attacker then injects image tags into the encrypted plaintext, creating a single encrypted body part. When the victim’s client opens the message, the plaintext is exposed to the hacker. 

Ultimately, if you don’t use PGP or S/MIME for email encryption, then there’s nothing to worry about. But individuals, companies, and corporations who use these technologies on a daily basis are advised to disable related plugins and use a third-party client to encrypt emails, such as Signal (iOS, Android). And because EFAIL relies on HTML-based emails, disabling HTML rendering is also advised for now. 

“This vulnerability might be used to decrypt the contents of encrypted emails sent in the past. Having used PGP since 1993, this sounds baaad (sic),” F-Secure’s Mikko Hypponen wrote in a tweet. He later said that people use encryption for a reason: Business secrets, confidential information, and more.  

According to the researchers, “some” email client developers are already working on patches that either eliminates EFAIL altogether or makes the exploits harder to accomplish. They say the PGP and S/MIME standards need an update, but that “will take some time.” The full technical paper can be read here. 

The problem was first leaked by the Süddeutschen Zeitun newspaper prior to the scheduled news embargo. After the EFF contacted the researchers to confirm the vulnerabilities, the researchers were forced to release the technical paper prematurely.

Editors' Recommendations

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
This HP laser printer deal cuts over 50% off the price for a limited time
The HP LaserJet Tank MFP 2604sdw laser printer on a white background.

There's no shortage of printer deals out there, which will make it hard to narrow down your options. If you want a recommendation, here's an offer that you'd probably find attractive -- the HP LaserJet Tank MFP 2604sdw laser printer for an affordable $200, as it's less than half its original price of $420 following a 52% discount. The $220 in savings is only available for a limited time though, so there should be some sense of urgency on your end if you want to take advantage of this bargain. Buy it now if you don't want to miss out.

Why you should buy the HP LaserJet Tank MFP 2604sdw laser printer
Among the advantages of laser printers versus inkjet printers is their ability to print documents quickly and efficiently. You'll enjoy these benefits with the HP LaserJet Tank MFP 2604sdw laser printer, which offers print speeds of up to 23 pages per minute, with the option for automatic two-sided printing while maintaining sharp text and bold black levels. With a full tank of HP toner, the printer can print up to 5,000 monochrome pages, and once the toner needs replacing, the process will only take seconds so you can resume printing with barely any interruption.

Read more
Dell has some major discounts on XPS laptops and desktops today
The Dell XPS desktop on a table.

The Dell XPS brand of laptops and desktop computers is one of the most trusted names in the computing industry today, whether you're looking for a device for personal or professional use. We've found a pair of offers that you wouldn't want to miss -- the previous-generation Dell XPS 13 for $799, following a $300 discount on its original price of $1,099, and the Dell XPS Desktop for $1,100, for savings of $450 on its sticker price of $1,550. Either way, you're going to have to be quick in completing your purchase because we're not sure how much time is remaining before these bargains disappear. If you want to get a Dell XPS laptop or desktop PC for cheaper than usual, push through with your transaction as soon as you can.
Dell XPS 13 (9315) -- $799, was $1,099

Even with the arrival of the new Dell XPS 13, the previous-generation Dell XPS 13 is still a highly recommended machine when it appears with a discount in laptop deals. It all starts with its gorgeous design, with the narrow bezels surrounding its 13.4-inch screen with Full HD+ resolution, and a slim profile that makes it extremely portable. However, it's also capable of providing decent performance for your everyday activities with its 12th-generation Intel Core i7 processor, Intel Iris Xe Graphics, and 16GB of RAM. The Dell XPS 13 also comes with a 512GB SSD, which ships with Windows 11 Home pre-installed, and a comfortable keyboard that will help in further boosting your productivity.

Read more
The Samsung Galaxy Book4 Pro has a rare $590 price cut today
The Samsung Galaxy Book4 Pro 360 2-in-1 laptop on a white background.

If you're looking for premium 2-in-1 laptop deals, we highly recommend going for the Samsung Galaxy Book4 Pro 360, especially now that it's available from Samsung with a $590 discount. Instead of its original price of $2,185, you'll only have to pay a more reasonable $1,595 for this device. However, if you want to pocket the savings, you're going to have to hurry in completing your purchase because we're not sure how long its lowered price will hold -- it may be back to normal as soon as tomorrow, so buy the 2-in-1 laptop today.

Why you should buy the Samsung Galaxy Book4 Pro 360 2-in-1 laptop
A 2-in-1 laptop offers the convenience of a tablet's touchscreen and the utility of a laptop's keyboard, according to our laptop buying guide, and the Samsung Galaxy Book4 Pro 360 certainly fits the bill. The 360-degree hinges that attach its 16-inch Dynamic AMOLED 2X touchscreen to its body allows you to switch from laptop mode to tablet mode by folding it all the way back. This gives you various options on how to use the display, which is sharp and bright with its 3K resolution.

Read more