Refine
Year
Publication Type
- Part of a Book (119)
- Lecture (83)
- Article (68)
- Conference Proceeding (42)
- Book (20)
- Participation in a Norm (DIN, RFC etc.) (13)
- Master's Thesis (4)
- Course Material (3)
- Report (2)
- Bachelor Thesis (1)
Language
- English (197)
- German (131)
- Multiple languages (27)
Keywords
- Photovoltaik, Solarstrom, Speicher (5)
- Cyber Security (4)
- Elektrotechnik (3)
- Photovoltaik (3)
- QUIC (3)
- Outdoor-EL (2)
- Photovoltaics (2)
- Solarstrom (2)
- Transport Protocol (2)
- Ack Ratio (1)
Faculty
- Elektrotechnik und Informatik (ETI) (355) (remove)
OpenPGP and S/MIME are the two major standards to en-crypt and digitally sign emails. Digital signatures are sup-posed to guarantee authenticity and integrity of messages. Inthis work we show practical forgery attacks against variousimplementations of OpenPGP and S/MIME email signatureverification in five attack classes: (1) We analyze edge casesin S/MIME’s container format. (2) We exploit in-band sig-naling in the GnuPG API, the most widely used OpenPGPimplementation. (3) We apply MIME wrapping attacks thatabuse the email clients’ handling of partially signed mes-sages. (4) We analyze weaknesses in the binding of signedmessages to the sender identity. (5) We systematically testemail clients for UI redressing attacks.Our attacks allow the spoofing of digital signatures for ar-bitrary messages in 14 out of 20 tested OpenPGP-capableemail clients and 15 out of 22 email clients supportingS/MIME signatures. While the attacks do not target the un-derlying cryptographic primitives of digital signatures, theyraise concerns about the actual security of OpenPGP andS/MIME email applications. Finally, we propose mitigationstrategies to counter these attacks.