Some OpenPGP, S/MIME-capable email clients vulnerable to attack Open-source 64-ish-bit serial number gen snafu sparks TLS security cert revoke runaround
Boffins testing the security of OpenPGP and S/MIME, two end-to-end encryption schemes for email, recently found multiple vulnerabilities in the way email client software deals with certificates and key exchange mechanisms. They found that five out of 18 OpenPGP-capable email clients and six out of 18 S/MIME-capable clients are vulnerable to at least one attack. These flaws are not due to cryptographic weaknesses. Rather they arise from the complexity of email infrastructure, based on dozens of s...