# Is Ciphermail save against "Efail"?

**URL:** <https://community.ciphermail.com/t/is-ciphermail-save-against-efail/618>\
**Category:** Gateway\
**Created:** [May 14, 2018, 10:53am UTC](https://community.ciphermail.com/t/is-ciphermail-save-against-efail/618 "2018-05-14T10:53:34Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![lst\_hoe021](https://avatars.discourse-cdn.com/v4/letter/l/58956e/32.png) [@lst\_hoe021](https://community.ciphermail.com/u/lst_hoe021)\
**Post date:** [May 14, 2018, 10:53am UTC](https://community.ciphermail.com/t/is-ciphermail-save-against-efail/618/1 "2018-05-14T10:53:34Z")

</div>

Hello,

today a new threat againts encrypted e-mail (PGP and S/MIME) is in the news:

[https://www.eff.org/deeplinks/2018/05/attention-pgp-users-new-vulnerabilities-require-you-take-action-now](https://www.eff.org/deeplinks/2018/05/attention-pgp-users-new-vulnerabilities-require-you-take-action-now)

From what i understand the basic problem is that it is possible to  
inject special data in already encrypted e-mail, which than will be  
reported back after decryption with HTML URLs to the attacker and can  
be used to derive the key used for encryption.

So i guess one would need the following conditions to be true for the  
attack to succeed

- The MUA access external URLs to load content in HTML e-mail (automatically)

- The e-mail will be decode despite the altered content (not vaild  
signed at least)

- Probably many e-mails are needed to get the oracle attack to work?

So for Ciphermail there should be no direct problem because it does  
not "read" the e-mail or obey URLs in the e-mail? But the question  
remains if there is a possibilty to prevent the "vulnerable" clients  
againts attack e-mail passing Ciphermail by not decrypting them or  
something like that?

Maybe i'm totaly wrong, but thanks for any feedback on this

Regards

Andreas

---

<div class="post-metadata">

**Author:** ![martijn](https://dub1.discourse-cdn.com/flex017/user_avatar/community.ciphermail.com/martijn/32/127_2.png) [@martijn](https://community.ciphermail.com/u/martijn)\
**Post date:** [May 14, 2018, 11:17am UTC](https://community.ciphermail.com/t/is-ciphermail-save-against-efail/618/2 "2018-05-14T11:17:10Z")

</div>

I'm still investigating the actual vulnerability but from what I have  
read I would say it's more a vulnerability in email clients which can be  
exploited to get parts of the plain text from a previously sent email.

To be vulnerable, the mail client should automatically retrieve remote  
information (for example images or CSS files). Allowing your mail client  
to automatically retrieve information from remote sources is strongly  
discouraged anyway because it can also be used by trackers (1 pixel images).

The vulnerability is that an attacker can create an email containing  
previously encrypted content which is then decrypted. The decrypted  
content however is embedded into a link (image, css etc.). If the mail  
client then tries to retrieve the remote link, it sends the URL (which  
contains part of the email). The attacked then retrieves the link and  
can extract the text.

To mitigate this, the first step would be to disallow your mail client  
to retrieve remote content (so block loading remote content).

I will do some further analysis and see whether a server side fix can  
work around the issue.

Kind regards,

Martijn Brinkers

> **···**
>
> On 14-05-18 12:53, Andi via Users wrote:
> 
> > Hello,
> > 
> > today a new threat againts encrypted e-mail (PGP and S/MIME) is in the  
> > news:
> > 
> > [Attention PGP Users: New Vulnerabilities Require You To Take Action Now | Electronic Frontier Foundation](https://www.eff.org/deeplinks/2018/05/attention-pgp-users-new-vulnerabilities-require-you-take-action-now)
> > 
> > From what i understand the basic problem is that it is possible to  
> > inject special data in already encrypted e-mail, which than will be  
> > reported back after decryption with HTML URLs to the attacker and can be  
> > used to derive the key used for encryption.
> > 
> > So i guess one would need the following conditions to be true for the  
> > attack to succeed
> > 
> > - The MUA access external URLs to load content in HTML e-mail  
> > (automatically)
> > 
> > - The e-mail will be decode despite the altered content (not vaild  
> > signed at least)
> > 
> > - Probably many e-mails are needed to get the oracle attack to work?
> > 
> > So for Ciphermail there should be no direct problem because it does not  
> > "read" the e-mail or obey URLs in the e-mail? But the question remains  
> > if there is a possibilty to prevent the "vulnerable" clients againts  
> > attack e-mail passing Ciphermail by not decrypting them or something  
> > like that?
> > 
> > Maybe i'm totaly wrong, but thanks for any feedback on this
> 
> --  
> CipherMail email encryption
> 
> Email encryption with support for S/MIME, OpenPGP, PDF encryption and  
> secure webmail pull.
> 
> > **[CipherMail email encryption and digital signatures](https://www.ciphermail.com)**
> >
> > Easy to use server-side email encryption for automatic encryption and digital signing of email.
> 
> Twitter: [http://twitter.com/CipherMail](http://twitter.com/CipherMail)

---

<div class="post-metadata">

**Author:** ![lst\_hoe021](https://avatars.discourse-cdn.com/v4/letter/l/58956e/32.png) [@lst\_hoe021](https://community.ciphermail.com/u/lst_hoe021)\
**Post date:** [May 14, 2018, 12:16pm UTC](https://community.ciphermail.com/t/is-ciphermail-save-against-efail/618/3 "2018-05-14T12:16:54Z")

</div>

Zitat von Martijn Brinkers via Users \<users(a)lists.djigzo.com\>:

> The vulnerability is that an attacker can create an email containing  
> previously encrypted content which is then decrypted. The decrypted  
> content however is embedded into a link (image, css etc.). If the  
> mail client then tries to retrieve the remote link, it sends the URL  
> (which contains part of the email). The attacked then retrieves the  
> link and can extract the text.

Hm, ok. This will be an even more bogus attack i guess. I was  
suspecting something like a advanced padding oracle attack used to  
decrypt the message, but they simply trick the client to decrypt AND  
send back the content.

HTML e-mail is a security nightmare, automatically loading external  
content is even worse and encrypting the whole shit does not solved  
the problem at all. So nothing really new in this case.

As stated here : [https://www.efail.de/](https://www.efail.de/)

What are the EFAIL attacks?

The EFAIL attacks break PGP and S/MIME email encryption by coercing  
clients into sending the full plaintext of the emails to the attacker.

But at least for Thunderbird one have to alter the default setting to  
automatically load external content.
