Can you trust what you decrypt? In this article, we look at S/MIME-encrypted emails and exploit them to take the recipients into alternate versions of reality.

https://lutrasecurity.com/en/articles/salamander-mime/

#SalamanderMIME #SMIME #KeyCommitment

Salamander/MIME – Lutra Security

If you remember kobold letters, you already know not to blindly trust emails. But it’s not just HTML emails that can be deceiving. In this article, we’ll take a look at S/MIME and how we can use the concept of invisible salamanders to craft messages that tell each recipient a different story. Let’s talk about Salamander/MIME.