My thoughts on eFail “vulnerability” with “PGP” s/mime etcetera…

This has to do with improper handling of HTML emails.  And is said that it could “expose plain text”.  The “attacker” needs to compose a message, which contains a malformed multi-part mime message, which they then encrypt, and they can then expose the plaintext of that message with some browsers which improperly handle these messages. […]

