Menu

#501 mail.identity.id1.pgpkeyId should be a full fingerprint

fixed
nobody
None
1.8.2
Minor
All
1.9.0
nobody
2015-12-17
2015-05-28
No

enigmail's per-account configuration includes mail.identity.idX.pgpkeyId (en_US account preferences pane text: "Use specific OpenPGP key ID (0x1234ABCD)"), which is populated with a short (32-bit) key ID.

forging a 32-bit keyId is trivial. If the account is configured in this way, and an attacker manages to inject a new subkey in the user's keyring, it's conceivable that the attacker's subkey could be used to encrypt the message instead of the user's subkey.

Discussion

  • Patrick Brunschwig

    Changed on master for editing in Account selection. Key creation and setup wizard to follow.

     
  • Patrick Brunschwig

    • Fixed in version: --- --> 1.9.0
     
  • Patrick Brunschwig

    Fixed on master. Existing settings are not touched though.

     
  • Patrick Brunschwig

    • status: open --> fixed
     

Log in to post a comment.