Showing posts with label efail. Show all posts
Showing posts with label efail. Show all posts

01 June 2018

Encryptomatic OpenPGP Add-in for MS Outlook is Updated

Encryptomatic OpenPGP add-in for Microsoft Outlook 2010/2013/2016 has been updated.  Version 2.5.2 is now available for download from the product homepage.

This is a recommended update for all users.  It addresses concerns around the widely reported eFail exfiltration technique.  While our analysis did not confirm the success of eFail with Encryptomatic OpenPGP and MS Outlook, we have implemented further precautions. 

This new release includes security enhancements that will warn users for emails without MDC validation and signature verification. We have also provided more control to you to be informed and receive security warnings. 



Changelog:
EPGP-191    eFail security enhancement    Implemented
EPGP-180    Error message is displaying without any message    Fixed
EPGP-187    Review labels and instructions in new EFAIL related security feature    Adjusted
EPGP-177    GUI improvements    Implemented


14 May 2018

Statement about eFail email encryption vulnerability.

Today we learned through Electronic Frontier Foundation (EFF) of an exploit known as efail that can compromise the text of OpenPGP encrypted messages through a combination of factors.

Developers at Encryptomatic LLC will be studying this issue in the hours and days ahead and will respond with software updates to Encryptomatic OpenPGP for MS Outlook if mitigation is necessary.

EFF is advising all PGP users to pause in their use of OpenPGP email encryption tools and seek other modes of secure end-to-end communication for now. This would include halting the use of Enigmail in Thunderbird, GPG for Outlook, and Encryptomatic OpenPGP for Outlook.