<<

Efail: Breaking S/MIME and OpenPGP using Exfiltration Channels

Damian Poddebniak1, Christian Dresen1, Jens Müller2, 1 Münster University of Applied Sciences Fabian Ising1, Sebastian Schinzel1, Simon Friedberger3, 2 Ruhr University Bochum Juraj Somorovsky2, Jörg Schwenk2 3 NXP Semiconductors

Damian Poddebniak1, Christian Dresen1, Jens Müller2, Fabian Ising1, Sebastian Schinzel1, Simon Friedberger3, Juraj Somorovsky2, Jörg Schwenk2 Motivation for using end-to-end encryption

Nation state attackers • Massive collection of • Snowden’s global surveillance disclosure Breach of email provider / email account • Single point of failure • Aren’t they reading/analyzing my emails anyway? Insecure Transport • TLS might be used – we don’t know!

2 Two competing standards

OpenPGP (RFC 4880) • Favored by privacy advocates • Web-of-trust (no authorities)

S/MIME (RFC 5751) • Favored by organizations • Multi-root trust-hierarchies

3 History of secure email Mostly usability studies

4 Both standards use old crypto Both standards use old crypto

Ciphertext C = Enc(M)

C1 valid/invalid

C2 valid/invalid … M = Dec(C) (repeated several times)

5 Old crypto has no negative impact

CBC / CFB modes of operation used, but their usage is not exploitable

Old crypto has no negative impact Assumption: Email is non-interactive

6 Backchannel

• Any functionality that forces the to interact with the network

• HTML/CSS • JavaScript XSSDisposition