-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

On 03.09.14 15:44, Simon wrote:
> Hi,
> 
> I finally decided to switch to Thunderbird and start taking PGP
> seriously.

Good decision :-)

> Everyone is talking about enigmail but when I configured my new 
> Thunderbird install earlier today I noticed there is a “Security” 
> section in the “Account” settings which has a feature to add 
> certificates out-of-the-box.

The builtin "Security" function in Thunderbird is using the S/MIME
standard. This is one of the two big standards for asymmetric
cryptography regarding email encryption. The other one is OpenPGP.

S/MIME uses a centralized certificate chain infrastructure by which it
ensures trust. It is practically impossible to work with S/MIME
without obtain a certificate from one of the big suppliers. These
certificates have a limited lifetime, usually valid for 2 years. After
this period you have to obtain a new one. Whats also important: your
cryptographic key is generated by this supplier. You have to trust him
completely.

> Now, obvious n00b question is why does one need enigmail and
> should I simply go with the default Thunderbird options or are
> there good reasons to skip those and use enigmail?

Enigmail provides the GUI for the OpenPGP standard. OpenPGP usually
uses a distributed trust model called "web-of-trust", where
certificates are generated by yourself and trust is assured by
personal action (key exchange and personal legitimation). You can
decide completely whom you trust.

OpenPGP can also use the centralized trust model similar to S/MIME,
but this usually used in big companies only.

There is no cryptographic difference between both standards, both use
the same algorithms.

You can use both standards in Thunderbird alternatively. S/MIME is
builtin and OpenPGP is supplied by Enigmail (and GnuPG in the background).

> Can’t find anything in the enigmail FAQ.

Then we should add a paragraph for this. Robert?

HTH

Ludwig

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCgAGBQJUB2b6AAoJEA52XAUJWdLjqN8H/1UvDHMG8uM7mhBBgks6ezgJ
Gr/JCy6ckbhHpDXPjG3xY1ETLsf+QexCFZlq921hObJTrNvotKMUHUJLuzsZ5xTm
xKlWUugYK0M0uDy3Dqr/8QmDohByiigCHW8X3gAa47bRNEbvLfuzCorW89vbX18o
ii7Hu5iK3QjpvGvGKWsAEyz49OWsG/vXQG18J67RIePCYPthe2wEQ3+uHUYUMlG1
dmA4hLHH9kcQb+oHwryEWcl/NsLfUbvBfgiUpN6fxSbHEyDtQTXeAZUVyLlLxmg5
wn8rUGHcddsRQ25FmyqcakG0dCL0yhjG9HV8+geMiZn/WEdlbOkGG2fYf713F8Q=
=+gXx
-----END PGP SIGNATURE-----

_______________________________________________
enigmail-users mailing list
[email protected]
To unsubscribe or make changes to your subscription click here:
https://admin.hostpoint.ch/mailman/listinfo/enigmail-users_enigmail.net

Reply via email to