Efail - Possible Measures?

Lukas Pitschl | GPGTools lukele at gpgtools.org
Sat May 19 19:40:32 CEST 2018

> I would consider the following "regular" MIME structures:
> 1. top-level MIME part is multipart/encrypted.
> 2. an attached email (Content-Type = message/rfc822) containing a
> multipart/encrypted MIME part as direct child.

We have been doing this in the past but changed it especially for
Exchanges servers if I remember correctly, since they tend to wrap
the multipart/encrypted mime part into other mime parts.
Also I think it was at the Dreieich conference when I brought this
issue up and was told that it is perfectly alright to have a
multipart/encrypted part as a child part of other parts.

It would however certainly fix this issue for PGP/MIME.

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 268 bytes
Desc: Message signed with OpenPGP using GPGMail
URL: <https://lists.gnupg.org/pipermail/gnupg-users/attachments/20180519/44b65fa0/attachment-0001.sig>

More information about the Gnupg-users mailing list