Hey Patrick, should we schedule a phone call?
Current plan is for coordinated disclosure at 17th of April. Attached the redacted paper submitted to USENIX Security. Please treat this confidential!
Sounds great. Thanks Patrick!
Patrick, can we please coordinate the amount of information that you make public for the patches? We are not yet ready for public disclosure of the different bugs. In parallel, we are talking to gnupg and Thunderbird as well as several others. You were among the very first that we disclosed the issues to and we would appreciate if we can coordinate this with the other vendors. Ok?
Can we talk about how and when we disclose these bugs? What is the current state for patches/mitigations? Should we have a call to start discussions?
Could you please add Jens Müller (jens.a.mueller@rub.de) to this bug. He is the original author of this finding.
Efail: Full Plaintext Recovery in PGP via Chosen-Ciphertext Attack