Re: Repo with test cases for covert content attacks

2019-08-12 Thread Sebastian Schinzel
Am 12.08.19 um 17:47 schrieb Stefan Claas via Gnupg-users: > Sebastian Schinzel wrote: > >> Dear all, >> >> Jens Müller just gave a talk at DEFCON about Covert Content Attacks >> against S/MIME and OpenPGP encryption and digital signatures in the >> email conte

Repo with test cases for covert content attacks

2019-08-12 Thread Sebastian Schinzel
Dear all, Jens Müller just gave a talk at DEFCON about Covert Content Attacks against S/MIME and OpenPGP encryption and digital signatures in the email context. He just published the PoC emails that he used in the talk and they might be useful for further testing.

Backchannels via OCSP and CRL in S/MIME (Was: efail is imho only a html rendering bug)

2018-06-07 Thread Sebastian Schinzel
Am 06.06.2018 um 20:19 schrieb Werner Koch: > Thanks for responding. However, my question was related to the claims > in the paper about using CRL and OCSP as back channels. This created the > impression that, for example, the certificates included in an encrypted > CMS object could be modified