USENIX Security2018Top-tier venue
Efail: Breaking S/MIME and OpenPGP Email Encryption using Exfiltration Channels
Damian Poddebniak, Christian Dresen, Jens Müller, Fabian Ising, Sebastian Schinzel, Simon Friedberger, Juraj Somorovsky, Jörg Schwenk
Abstract
OpenPGP and S/MIME are the two prime standards for providing end-to-end security for emails. We describe novel attacks built upon a technique we call malleability gadgets to reveal the plaintext of encrypted emails. We use CBC/CFB gadgets to inject malicious plaintext snippets into encrypted emails. These snippets abuse existing and standard conforming backchannels to exfiltrate the full plaintext after decryption. We describe malleability gadgets for emails using HTML, CSS, and X.509 functionality. The attack works for emails even if they were collected long ago, and it is triggered as soon as the recipient decrypts a single maliciously crafted email from the attacker.
We devise working attacks for both OpenPGP and S/MIME encryption, and show that exfiltration channels exist for 23 of the 35 tested S/MIME email clients and 10 of the 28 tested OpenPGP email clients. While it is advisable to update the OpenPGP and S/MIME standards to fix these vulnerabilities, some clients had even more severe implementation flaws allowing straightforward exfiltration of the plaintext.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext cf38a9d9-3f7d-43f1-a3dd-e3c975fd087fCited by top-tier papers19
- If This Then What?: Controlling Flows in IoT AppsIulia Bastys, Musard Balliu, Andrei SabelfeldCCS 2018 · 119 citations
- Weak Links in Authentication Chains: A Large-scale Analysis of Email Sender Spoofing AttacksKaiwen Shen, Chuhan Wang, Minglei Guo, Xiaofeng Zheng et al.USENIX Security 2021 · 49 citations
- "Johnny, you are fired!" - Spoofing OpenPGP and S/MIME Signatures in EmailsJens Müller, Marcus Brinkmann, Damian Poddebniak, Hanno Böck et al.USENIX Security 2019 · 34 citations
- Practical Decryption exFiltration: Breaking PDF EncryptionJens Müller, Fabian Ising, Vladislav Mladenov, Christian Mainka et al.CCS 2019 · 18 citations
- The Challenges of Bringing Cryptography from Research Papers to Products: Results from an Interview Study with ExpertsKonstantin Fischer, Ivana Trummová, Phillip Gajland, Yasemin Acar et al.USENIX Security 2024 · 9 citations
Builds on3
- Data Breaches, Phishing, or Malware?: Understanding the Risks of Stolen CredentialsKurt Thomas, Frank Li, Ali Zand, Jacob Barrett et al.CCS 2017 · 248 citations
- Systematic Fuzzing and Testing of TLS LibrariesJuraj SomorovskyCCS 2016 · 136 citations
- A Surfeit of SSH Cipher SuitesMartin R. Albrecht, Jean Paul Degabriele, Torben Brandt Hansen, Kenneth G. PatersonCCS 2016 · 36 citations
Related papers
- Mitigation of Attacks on Email End-to-End EncryptionJörg Schwenk, Marcus Brinkmann, Damian Poddebniak, Jens Müller et al.CCS 2020 · 10 citations
- Content-Type: multipart/oracle - Tapping into Format Oracles in Email End-to-End EncryptionFabian Ising, Damian Poddebniak, Tobias Kappert, Christoph Saatjohann et al.USENIX Security 2023
- Styled to Steal: The Overlooked Attack Surface in Email ClientsLeon Trampert, Daniel Weber, Christian Rossow, Michael SchwarzCCS 2025
- 27 Years and 81 Million Opportunities Later: Investigating the Use of Email Encryption for an Entire UniversityChristian Stransky, Oliver Wiese, Volker Roth, Yasemin Acar et al.S&P 2022 · 27 citations
- On the (In)Security of ElGamal in OpenPGPLuca De Feo, Bertram Poettering, Alessandro SorniottiCCS 2021 · 7 citations
