The man who invented PGP has teamed up with some developers of other keys to assure users that the popular encryption program is not insecure, despite conflicting reports earlier this month.

Some institutions such as the EFF (Electronic Frontier Foundation) misreported the findings of the new research they conducted, described new "vulnerabilities" in the program, and recommended that users disable the service.
A report late last week states:
“These statements are misleading and dangerous. PGP is not broken. The vulnerabilities identified by eFail are not flaws in the OpenPGP protocol itself but in its implementations, including Apple Mail, Mozilla Thunderbird, and Microsoft Outlook. Many other well-known software that relies on PGP are not affected in any way by the eFail vulnerability, as the researchers themselves point out in their paper.”
The developers of Enigmail, Mailvelope, and ProtonMail recommended that users switch to PGP implementations that are not affected by eFail or update their existing software to the latest version.
“Make sure everyone you communicate with is also using unaffected apps or has updated their software,” they added. “Make sure you get verified confirmation from your contacts before sending out your sensitive information.”
Of course, the EFF's advice to users to disable PGP plugins or stop using PGP altogether does not solve the problem, but it is like saying that "because some locks may break, we should remove all the doors.".
