Hi, nice catch!

I played with this a bit and wasn't able to reproduce it immediately.
In my sent folder they looked like your screenshot, but for the  
friend I sent them to they were obviously broken because, 
as far I can tell, thunderbird changed some things before sending
it out. However, I crafted them by hand and scripted it and
now it works for me like you described. Its possible to hide this 
(in the view) to some extend but for a realistic attack 
the receiving email server must be badly configured e.g don't
do a reverse lookup of the senders IP to fake the sender.


- INLINE PGP must be used and an inline signature is needed
  a detached signature can't be used

- Its not possible to advert thunderbird displaying the attached 
  email. The Content-Type must be either text/ or message/ for
  enigmail to pick it up. 

Its been too long for me that I worked on the enigmail code base, but we 
already 
have a 'MIME Iterator' in place. As the bug report states, after we fixed this
INLINE/MIME case, it'd be good to have a better way to display which parts were 
signed.

Maybe we're able to somehow influence the style of the divider that is 
displayed between
two mime container. Or even add information there. Knowing Thunderbirds code 
base that 
either will be impossible or involve lots and lots of tears.

Another idea would be to slightly change the background correlating to their 
signature
status, if that would be possible people would start sending out html emails 
with 
these background colors. 

Surely there have been discussions on this before?

-- gnoxter

Ps: Patrick please forgive me :o
_______________________________________________
enigmail-users mailing list
[email protected]
To unsubscribe or make changes to your subscription click here:
https://admin.hostpoint.ch/mailman/listinfo/enigmail-users_enigmail.net































Attachment: signatur.asc
Description: message/unknown

_______________________________________________
enigmail-users mailing list
[email protected]
To unsubscribe or make changes to your subscription click here:
https://admin.hostpoint.ch/mailman/listinfo/enigmail-users_enigmail.net

Reply via email to