No one wants their emails to be monitored by third parties. Unfortunately, the recently discovered vulnerability “Efail” could make this threat a reality.
On Monday morning, the Electronic Frontier Foundation (EFF) reported that Efail is able to expose HTML emails encrypted with PGP and S/MIME — even those sent years ago. These tools are commonly used by journalists, politicians, and other users who want secure communication.
“In short, Efail abuses the active content of HTML emails, for example images loaded from external sources, to secretly retrieve their content in plaintext format, via the required URLs,” the researchers write.
“The attacker alters an encrypted email in such a way that when the victim's email client receives it, it decrypts the email message and loads any external content, thereby exposing the content to the attacker in plaintext.”.
In other words, once hackers gain access to your emails, they can use HTML tags in emails to trick mail clients into incorrectly decrypting those messages in a way that allows hackers access.
What can we do?
The EFF recommendation suggests that if you use PGP or S/MIME, disable them and uninstall the tools that decrypt them.
Other sources, however, claimed that these measures were not necessary.
ProtonMail, for example, claims that many data encryption and decryption services have already patched the vulnerability that allows Efail. ProtonMail itself has verified that it is not vulnerable to Efail.
Dan Guido, CEO of security firm Trail of Bits, claims that Efail is very easy for users to detect.
But if you're still concerned, you can always opt for plaintext over HTML emails – or just use Signal.
