Re: Server side S/MIME EFail (partial) Mitigation

2018-07-02 Thread Dr. Rolf Jansen
Well, I did not expect that writing an after-queue filter for Postfix which could possibly mitigate an actual attack to postfix-users would be off-topic. However, so it is. Please excuse my ignorance, and I will leave the list. In case I decide to finish the project, I will publish it on my GitH

Re: Server side S/MIME EFail (partial) Mitigation

2018-07-02 Thread Dr. Rolf Jansen
> Am 02.07.2018 um 03:33 schrieb martijn.list : > > On 02-07-18 01:15, Dr. Rolf Jansen wrote: >> Hello, >> >> I read carefully the technical paper about the exfiltration attack >> (efail) on decrypted S/MIME or PGP content. >> >> https://efail.de >> https://efail.de/efail-attack-paper.pdf >> >>

Re: Server side S/MIME EFail (partial) Mitigation

2018-07-01 Thread martijn.list
On 02-07-18 01:15, Dr. Rolf Jansen wrote: > Hello, > > I read carefully the technical paper about the exfiltration attack > (efail) on decrypted S/MIME or PGP content. > > https://efail.de > https://efail.de/efail-attack-paper.pdf > > According to my understanding, sanitizing text/html content t

Server side S/MIME EFail (partial) Mitigation

2018-07-01 Thread Dr. Rolf Jansen
Hello, I read carefully the technical paper about the exfiltration attack (efail) on decrypted S/MIME or PGP content. https://efail.de https://efail.de/efail-attack-paper.pdf According to my understanding, sanitizing text/html conte