Tempests email guide -> Whonix wiki

Here’s a more sane take: Errata Security: Some notes on eFail

Summary
It only works if attackers have already captured your emails (though, that’s why you use PGP/SMIME in the first place, to guard against that).

It only works if you’ve enabled your email client to automatically grab external/remote content.

It seems to not be easily reproducible in all cases.

Instead of disabling PGP/SMIME, you should make sure your email client hast remote/external content disabled – that’s a huge privacy violation even without this bug.