# 'EFAIL' Is Why We Can't Have Golden Keys

DevFeed: ['EFAIL' Is Why We Can't Have Golden Keys](<https://devfeed.tech/articles/efail-is-why-we-can-t-have-golden-keys-36769.md>)

Original publisher: [Read original article](<https://shostack.org/blog/efail-is-why-we-cant-have-golden-keys/>)

Author: Adam

Published: 2018-06-11T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Encryption](<https://devfeed.tech/topics/encryption.md>), [Security](<https://devfeed.tech/topics/security.md>), [systems](<https://devfeed.tech/topics/systems.md>), [HTML](<https://devfeed.tech/topics/html.md>)

Tags: [encryption](<https://devfeed.tech/tags/encryption.md>), [essay](<https://devfeed.tech/tags/essay.md>), [html](<https://devfeed.tech/tags/html.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

This commentary presents EFAIL as evidence against creating golden keys. It says the issues reduce the security of PGP and S/MIME email through problems involving HTML email parsing and CBC encryption, illustrating the difficulty of securing systems made from components with disparate design goals.

## Source excerpt

[no description provided]