Don't Trust GnuPG Encrypted and Signed E-Mail

By Lisa Vaas
Excerpt:
“Core Security Technologies has discovered a flaw in GNU Privacy Guard - the open-source cryptographic software system that's part of the GNU software project and at the heart of third-party e-mail that's signed, encrypted and trusted - that allows attackers to reach into e-mail and add whatever content they dream up.”
Source: eWeek











