Can we also please talk about the need to MITM the encrypted message first before one can launch any #efail attack? Thanks to ubiquitous TLS, this seems to be the much more difficult feat to pull off these days (unless you have considerable resources). The cost of targeting and MITMing a given user is gigantic.
Telling the general public to uninstall GPG extensions is really silly, they should do the opposite. And install updates and disable html, ffs. Everything else is just FUD 😩