DEF CON 27 - Jens Muller - Re Whats up Johnny Covert Content Attacks on Email End-to-End Encryption @HackersOnBoard
DEF CON 27 - Jens Muller - Re Whats up Johnny Covert Content Attacks on Email End-to-End Encryption  @HackersOnBoard
Uploaded December 2019 | Updated September 2026, 5 days ago
We show practical attacks against OpenPGP and S/MIME encryption and digital signatures in the context of email. Instead of targeting the underlying cryptographic primitives, our attacks abuse legitimate features of the MIME standard and HTML, as supported by email clients, to deceive the user regarding the actual message content. We demonstrate how the attacker can unknowingly abuse the user as a decryption oracle by replying to an unsuspicious looking email. Using this technique, the plaintext of hundreds of encrypted emails can be leaked at once. Furthermore, we show how users could be tricked into signing arbitrary text by replying to emails containing CSS conditional rules. An evaluation shows that 17 out of 19 OpenPGP-capable email clients, as well as 21 out of 22 clients supporting S/MIME, are vulnerable to at least one attack. We provide different countermeasures and discuss their advantages and disadvantages


Presenters:
Jens Müller - Ruhr University Bochum
Jens Müller is a PhD student at the Chair for Network and Data Security, Ruhr University Bochum, Germany. His research interests are legacy protocols and data formats, for which he loves to investigate what could possibly go wrong in a modern world. He has experience as a speaker on international security conferences (BlackHat, IEEE S&P, OWASP) and as a freelancer in network penetration testing and security auditing. Besides breaking thinks, he develops free open source software, for example, tools related to network printer exploit^H^H^H^H^H^H^H, um, "debugging". Twitter: @jensvoid Websites: nds.ruhr-uni-bochum.de/chair/people/jmueller hacking-printers.net
DEF CON 27 - Jens Muller - Re Whats up Johnny Covert Content Attacks on Email End-to-End EncryptionBlack Hat USA 2018 - Mainframe [z/OS] Reverse Engineering and Exploit DevelopmentDetecting Malicious Cloud Account Behavior A Look at the New Native Platform CapabilitiesDEF CON 27 - Zombie Ant Farm Practical Tips for Playing Hide and Seek with Linux EDRsDEF CON 27 - State of DNS Rebinding Attack & Prevention Techniques and the Singularity of OriginDEF CON 27 - droogie - Go NULL Yourself or How I Learned to Start Worrying While Getting FinedDEF CON 27 - XiaoHuiHui - All the 4G Modules Could Be HackedDEF CON 27 - Leon Jacobs - Meticulously Modern Mobile ManipulationsDEF CON 27 - Backdooring Hardware Devices By Injecting Malicious Payloads On MicrocontrollersDEF CON 27 - Patrick Wardle - Harnessing Weapons of Mac DestructionDEF CON 27 - How You Can Buy ATandT T-Mobile and Sprint Real-Time Location Data on the Black MarketDEF CON 27 - Pedro Cabrera Camara - SDR Against Smart TVs URL and Channel Injection Attacks
HackersOnBoard |

DEF CON 27 - Jens Muller - Re What's up Johnny Covert Content Attacks on Email End-to-End Encryption

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER