-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On 14.09.13 17:32, Tom Ritter wrote:
> While Thunderbird is open, but not being used,  just downloading 
> messages in folders in the background (constantly) - Enigmail will 
> pop up the passphrase dialog.  I didn't try and open  an encrypted 
> mail, I didn't receive an encrypted mail into the folder I had
> open, my best guess is that TB downloaded an encrypted mail in the 
> background, prompting Enigmail to pop the dialog.
> 
> I've enabled debug logging, and there is no indication in the logs 
> about what message triggers the dialog.  I've long been suspicious
> of someone using the Enigmail prompt as a phishing scheme to
> extract passphrases. So I have a few questions/suggestions:
> 
> 1) Is this a known bug/behavior? Does anyone know why this might
> be happening?

Yes, that's bug 138 (https://sourceforge.net/p/enigmail/bugs/138/),
which is fixed for the next release. It will require Thunderbird 24 to
work, that is it cannot be fixed with Thunderbird 17.

> 2) Would it be possible to have the subject and a unique
> identifier of the message be written to the logfile to identify
> which message threw the dialog? 3) Would you consider adding UI to
> the passphrase dialog?  I envision this:

The passphrase dialog displayed by Enigmail (and any passphrase
handling related to it) is only relevant for GnuPG 1.4.x. For GnuPG
2.x, the passphrase dialog is triggered via gpg -> gpg-agent ->
pinentry and is out of the control of Enigmail. The passphrase
management is entirely delegated to gpg-agent.

GnuPG 1.4.x is considered legacy, and the authors of GnuPG start to
have plans for dropping GnuPG 1.4.x one day. Therefore I won't work on
improving passphrase handling and related dialogs in Enigmail at all.

- -Patrick
-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.20 (Darwin)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQEVAwUBUjSFpsk25cDiHiw+AQi43AgAkkDaJ2/Z0IWpJoguIfMv32XQ/8Oh0nFI
eOAr3iF8mbtixMUzZV3cfU7W0Nn8JdLder3JW11tqV4tPJCzrqM5Q6B91TpTW5C/
HHykEFR9Azm5GtxtQphJLN8YXcI197MKXIY8nqJtU0dQ2lTufYRWQuZn+25spJKc
/F3DniWqncLYDn9eKcYh4XFX+OpzLwv20THtL7OuAe/0sMFm/o5lV9nFZeM+S/0O
oTklzHYiSDqJ1KQSukBC0k0Lt+Zty3y3wQnlgONPLmHwmM0mSZHVozfOKNtKfHYG
doHc7923pZSf9zDcM8DYvXrlpCsTgm46Tbykht7H9hreszzVFTkgpw==
=EuGH
-----END PGP SIGNATURE-----

_______________________________________________
enigmail-users mailing list
[email protected]
https://admin.hostpoint.ch/mailman/listinfo/enigmail-users_enigmail.net

Reply via email to