Key Information

  • In June 2022, the Sonar Research team discovered critical code vulnerabilities in multiple encrypted email solutions, including Proton Mail, Skiff, and Tutanota.

  • These privacy-oriented webmail services provide end-to-end encryption, making communications safe in transit and at rest. Our findings affect their web clients, where the messages are decrypted, mobile clients were not affected.

  • The vulnerabilities would have allowed attackers to steal emails and impersonate victims if they interacted with malicious messages. Nearly 70 million users were at risk on Proton Mail alone.

  • The issue has been fixed and there are no signs of in-the-wild exploitation.

  • Objects in Space@infosec.pub
    link
    fedilink
    English
    arrow-up
    28
    ·
    10 months ago

    Discovered, reported and fixed shortly after. The headline is catchy but the article is more about the process of how it all went down last year.

    Also found this noteworthy:

    “We would like to thank the Proton Mail team for their fast and professional handling of our report. They also awarded us with a $750 USD bug bounty, which we happily donated to charity.”

    • d_cent@lemm.ee
      cake
      link
      fedilink
      arrow-up
      11
      ·
      10 months ago

      Well said. Not to mention the article title calls out Proton but it’s basically all the noteworthy e2ee email products. Very click baity

    • H2207@lemmy.world
      link
      fedilink
      arrow-up
      10
      ·
      10 months ago

      Now this, this is how you know a company really cares about it’s users. Sure $750 probably isn’t going to affect their bottom line much but still, it’s $750 just handed to some people for securing their customers.