• Deutsch
Internal Login

Open Access

  • Home
  • Search
  • Browse
  • Publish
  • FAQ

Refine

Author

  • Brinkmann, Marcus (1)
  • Böck, Hanno (1)
  • Müller, Jens (1)
  • Poddebniak, Damian (1)
  • Schinzel, Sebastian (1)
  • Schwenk, Jörg (1)
  • Smomrosvsky, Juraj (1)

Year of publication

  • 2019 (1)

Document Type

  • Article in Conference Proceedings (1)

Language

  • German (1) (remove)

Has Fulltext

  • no (1)

Is part of the Bibliography

  • no (1)

Institute

  • Elektrotechnik und Informatik (ETI) (1)

1 search hit

  • 1 to 1
  • BibTeX
  • CSV
  • RIS
  • 10
  • 20
  • 50
  • 100
“Johnny, you are fired!” – Spoofing OpenPGP and S/MIME Signatures in Emails (2019)
Müller, Jens ; Brinkmann, Marcus ; Poddebniak, Damian ; Böck, Hanno ; Schinzel, Sebastian ; Smomrosvsky, Juraj ; Schwenk, Jörg
OpenPGP and S/MIME are the two major standards to en-crypt and digitally sign emails. Digital signatures are sup-posed to guarantee authenticity and integrity of messages. Inthis work we show practical forgery attacks against variousimplementations of OpenPGP and S/MIME email signatureverification in five attack classes: (1) We analyze edge casesin S/MIME’s container format. (2) We exploit in-band sig-naling in the GnuPG API, the most widely used OpenPGPimplementation. (3) We apply MIME wrapping attacks thatabuse the email clients’ handling of partially signed mes-sages. (4) We analyze weaknesses in the binding of signedmessages to the sender identity. (5) We systematically testemail clients for UI redressing attacks.Our attacks allow the spoofing of digital signatures for ar-bitrary messages in 14 out of 20 tested OpenPGP-capableemail clients and 15 out of 22 email clients supportingS/MIME signatures. While the attacks do not target the un-derlying cryptographic primitives of digital signatures, theyraise concerns about the actual security of OpenPGP andS/MIME email applications. Finally, we propose mitigationstrategies to counter these attacks.
  • 1 to 1

OPUS4 Logo

  • Contact
  • Imprint
  • Sitelinks