Omit Autocrypt header for encrypted mail [feature request]
OpenPGP addon for Mozilla Thunderbird
Brought to you by:
pbrunschwig
I'd like to suggest to omit the Autocrypt header in messages that are already encrypted for the recipient. If "Attach my public key to messages" is enabled, the 2nd public key in the Autocrypt header seems to be especially confusing. But my understanding is that even without "my public key" attached, Autocrypt is futile in cases where encryption is apparently already set up.
That's clearly against the Autocrypt spec. Being the sender, I can't know if the recipient does have my key or not - the recipient may have multiple devices (mobile phones etc). In addition, there is a timing component in the specification concerning outdating the key. If you want to be Autocrypt-compliant, the key is part of every outgoing message.
Again, that's against the spec. Autocrypt intends to make automatic processing of keys easier. An attached key is ignored in terms of Autocrypt.
If you want Autocrypt then your key is part of every sent message. Otherwise you're not compliant with the standard.
I didn't know. Thanks a lot for clarifying this!
As Patrick pointed out this is against the specs. But even if it wasn't it would be quite dangerous to omit the header if my public key was already attached as it gives away information about potentially large parts of the contents of the encrypted message. (Note: Enigmail with "Attach my public key to messages" enabled encrypts the text body plus the key.)