{"id":25882,"date":"2014-09-10T13:40:44","date_gmt":"2014-09-10T17:40:44","guid":{"rendered":"http:\/\/www.opensource.im\/?p=25882"},"modified":"2014-09-10T13:40:44","modified_gmt":"2014-09-10T17:40:44","slug":"encryption-failures-fixed-in-popular-pgp-email-security-tool-enigmail","status":"publish","type":"post","link":"https:\/\/euvolution.com\/open-source-convergence\/encryption\/encryption-failures-fixed-in-popular-pgp-email-security-tool-enigmail.php","title":{"rendered":"Encryption failures fixed in popular PGP email security tool Enigmail"},"content":{"rendered":"<p><p>    Developers of the popular Enigmail email security extension    for Thunderbird have fixed several issues that could have    exposed messages users believed to be encrypted.  <\/p>\n<p>    Enigmail provides a graphical user interface in the Mozilla    Thunderbird and SeaMonkey programs that allows users to    digitally sign and encrypt email messages using the OpenPGP    standard.  <\/p>\n<p>    The    Enigmail Project released version 1.7.2 of the extension on    Aug. 29 and briefly noted that the release fixes several    important bugs. The changelog    did not contain additional details about the impact of the    fixed issues, but included a link to the projects external bug    tracker.  <\/p>\n<p>    In    addition to several non-security issues, the bug tracker lists    a number of addressed bugs that could have serious security    implications for users of the older Enigmail 1.7 version.    One of    them causes emails to be sent in unencrypted form when only    BCC (blind carbon copy) recipients are specified.  <\/p>\n<p>    Another    issue causes drafts to be saved in plain text when writing a    new email even when the email is marked for encryption    automatically. If the IMAP protocol is used, the unencrypted    drafts can be synchronized with the email server, exposing    potentially sensitive information.  <\/p>\n<p>    This    behavior only happens when the system selects an email for    encryption automatically based on an existing per-recipient    rule or when the recipients public key exists in the local key    store. If the email is manually marked to be encrypted (e.g.    by clicking the yellow key symbol on the bottom-right) the    drafts are correctly encrypted before being sent to the IMAP    server, the bug entry    notes.  <\/p>\n<p>    Another    bug can cause an incorrect encryption or signing status message    to be displayed when composing a reply. This especially    happens if the compose window is not opened for the first    time, another entry on    the bug tracker notes.  <\/p>\n<p>    A    fourth issue that has been addressed can cause an upgrade from    Enigmail 1.6 to 1.7 to break encryption. Email messages wont    be encrypted if the per recipient setting is disabled under    Key Selection, despite other key selection mechanisms like by    email and manual if missing being enabled.  <\/p>\n<p>    When    confirmation dialog is enabled you can even see that Enigmail    wants to send an email unsigned\/unencrypted despite having    selected forced encryption, the corresponding bug    entry says. Otherwise it is silently sent    unencrypted.  <\/p>\n<p>    An    Enigmail user who reported one of the encryption failures in    version 1.7 on the projects support forum     described the situation as the biggest imaginable    catastrophe.  <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>See original here:<br \/>\n<a target=\"_blank\" href=\"http:\/\/www.pcworld.com\/article\/2604880\/encryption-failures-fixed-in-popular-pgp-email-security-tool-enigmail.html\/RK=0\/RS=KFJsqMCNKhpDV9kLT.hkxTrqWc0-\" title=\"Encryption failures fixed in popular PGP email security tool Enigmail\">Encryption failures fixed in popular PGP email security tool Enigmail<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Developers of the popular Enigmail email security extension for Thunderbird have fixed several issues that could have exposed messages users believed to be encrypted. Enigmail provides a graphical user interface in the Mozilla Thunderbird and SeaMonkey programs that allows users to digitally sign and encrypt email messages using the OpenPGP standard<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[45],"tags":[],"class_list":["post-25882","post","type-post","status-publish","format-standard","hentry","category-encryption"],"_links":{"self":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/25882"}],"collection":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/comments?post=25882"}],"version-history":[{"count":0,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/25882\/revisions"}],"wp:attachment":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/media?parent=25882"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/categories?post=25882"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/tags?post=25882"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}