Published August 15, 2018 | Version v1

Efail: Breaking S/MIME and OpenPGP Email Encryption using Exfiltration Channels

  • 1. Münster University of Applied Sciences
  • 2. Ruhr University Bochum
  • 3. NXP Semiconductors

Description

OpenPGP and S/MIME are the two prime standards for providing end-to-end security for emails. We describe novel attacks built upon a technique we call malleability gadgets to reveal the plaintext of encrypted emails. We use CBC/CFB gadgets to inject malicious plaintext snippets into encrypted emails. These snippets abuse existing and standard conforming backchannels to exfiltrate the full plaintext after decryption. We describe malleability gadgets for emails using HTML, CSS, and X.509 functionality. The attack works for emails even if they were collected long ago, and it is triggered as soon as the recipient decrypts a single maliciously crafted email from the attacker. We devise working attacks for both OpenPGP and S/MIME encryption, and show that exfiltration channels exist for 23 of the 35 tested S/MIME email clients and 10 of the 28 tested OpenPGP email clients. While it is advisable to update the OpenPGP and S/MIME standards to fix these vulnerabilities, some clients had even more severe implementation flaws a

Files

sec18-poddebniak.pdf

Files (772.0 kB)

Name Size
md5:1ce2a3a2911b12ec1945b93fe6705e6c
772.0 kB Preview Download

Additional details

Funding

European Commission
ECRYPT-NET - European Integrated Research Training Network on Advanced Cryptographic Technologies for the Internet of Things and the Cloud 643161