In Apple Mail, there is no protecting PGP-encrypted messages. Even with disabling remote content, GPGTools is vulnerable to EFAIL, and the only mitigation for now is to switch to Thunderbird/Enigmail, and disable viewing HTML emails
https://theintercept.com/2018/05/25/in-apple-mail-theres-no-protecting-pgp-encrypted-messages/
Here's a proof-of-concept exploit that I developed (Hanno Bรถck deserves much of the credit too) that demonstrates the attack:
@micahflee Thank you for your continuing work on this. Clear videos that show just how easy the social engineering really put things in the right context, IMO.
Hopefully "next time" we have a drama like this you'll be able to recommend Mailpile as an alternative as well. Hopefully! ๐
@HerraBRE It's been a long time since I last tried Mailpile, I should try it out again
@HerraBRE @micahflee dito! ;)
@mastor @HerraBRE @micahflee fun fact, Mailpile is the only e-mail client I know that completely blocks HTML in encrypted e-mails.
@micahflee @rysiek @HerraBRE What about Mutt?
@HerraBRE @micahflee @rysiek \รถ/ (-:
So, perhaps, the hard work setting it up (for me as a medium talented user) pays.
I also use it via #Termux in #CopperheadOS, by the way. Mutt in Copperhead, Neomutt in Qubes.
#Mutt #Neomutt