Menu

#250 Enigmail leaks too much metadata

invalid
nobody
None
1.6.0
Minor
All
---
nobody
2014-02-06
2014-02-06
No

When I use enigmail, it adds some extra headers and comments by default to my outgoing emails that are not required but reveal information about the software and the version numbers in use.
This makes it easier to launch targeted attacks against me.
I can disable all these headers manually, but as a security software, Enigmail should be more secure/less revealing by default.

a) The "X-Enigmail-Version:" mail header
b) for GPG signatures, the comment line: "Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/"
c) Enigmail should suppress the GPG Version line by default

Discussion

  • Ludwig Hügelschäfer

    • status: open --> invalid
     
  • Ludwig Hügelschäfer

    This is a duplicate of bug 216 (https://sourceforge.net/p/enigmail/bugs/216/). Please join the discussion there.

     

Log in to post a comment.