TY - CONF A1 - Müller, Jens A1 - Brinkmann, Marcus A1 - Poddebniak, Damian A1 - Schinzel, Sebastian A1 - Schwenk, Jörg T1 - What's up John­ny? – Co­vert Con­tent At­tacks on Email End-to-End En­cryp­ti­on T2 - 17th In­ter­na­tio­nal Con­fe­rence on Ap­p­lied Cryp­to­gra­phy and Net­work Se­cu­ri­ty (ACNS 2019) N2 - We show practical attacks against OpenPGP and S/MIMEencryption and digital signatures in the context of email. Instead of tar-geting the underlying cryptographic primitives, our attacks abuse legiti-mate features of the MIME standard and HTML, as supported by emailclients, to deceive the user regarding the actual message content. Wedemonstrate how the attacker can unknowingly abuse the user as a de-cryption oracle by replying to an unsuspicious looking email. Using thistechnique, the plaintext of hundreds of encrypted emails can be leakedat once. Furthermore, we show how users could be tricked into signingarbitrary text by replying to emails containing CSS conditional rules.An evaluation shows that "out of" OpenPGP-capable email clients,as well as "out of" clients supporting S/MIME, are vulnerable to atleast one attack. We provide different countermeasures and discuss theiradvantages and disadvantages. Y1 - 2019 UR - https://www.hb.fh-muenster.de/opus4/frontdoor/index/index/docId/10665 SP - 1 EP - 18 ER -