The attack requires the victim to encrypt/decrypt many chosen messages, no? Configure your laptop to only encrypt or decrypt messages when you want it to.
Not if the attacker doesn't control the contents. They would need to send you the email, and then you would need to open/decrypt it while they're listening. afaik.
Comments
The attack requires the victim to encrypt/decrypt many chosen messages, no? Configure your laptop to only encrypt or decrypt messages when you want it to.
Some people have GPG configured to sign every email they send. Would that be enough activity to compromise the key?
Not if the attacker doesn't control the contents. They would need to send you the email, and then you would need to open/decrypt it while they're listening. afaik.