• [^] # Re: Surface d'attaque OpenPGP.js & GnuPG

    Posté par . En réponse à la dépêche GnuPG, OpenPGP.js & cie : quoi de neuf ?. Évalué à 3.

    La recommandation dans l'audit pour Thunderbird: Mettre a jour et désactiver toutes les extensions. Ne pas utiliser de flux RSS dans Thunderbird.

    Pour Enigmail: Mettre a jour vers 1.9.9 et n'utiliser que l'extension Enigmail.

    Ce sont des failles spécifiques a thunderbird qui sont différentes de celles récemment commentées. Ci-dessous la version originale.

    For all Thunderbird users:

    • Update Thunderbird to the latest versions as soon as they are available. The new versions will remove several of the vulnerabilities that were revealed in this audit.
    • Use Thunderbird preferably without or at least with verified add-ons until the architecture of Thunderbird has been rebuilt.
    • Do not use RSS feeds in Thunderbird for now. There are critical security problems threatening your entire communication.
    • Do not accidentally install add-ons through phishing, since rogue add-ons can be used to attack you.

    If you follow these security recommendations, your communication will be notedly more secure.

    For Enigmail users:

    • Update Enigmail immediately to the new version 1.9.9. This update removes all vulnerabilities identified in this audit.
    • Update Thunderbird to the latest versions as soon as they are available. The new versions will remove several of the vulnerabilities that were revealed in this audit.
    • Do not install any other add-on except for Enigmail until the add-on architecture of Thunderbird has been rebuilt.
    • Do not use RSS feeds in Thunderbird for now. There are critical security problems threatening your entire communication.
    • Do not accidentally install add-ons through phishing, since rogue add-ons can be used to attack you.

    If you follow these security recommendations, your communication is notedly more secure.