"Enigmail" appears in signed message bodies when the body is left empty
OpenPGP addon for Mozilla Thunderbird
Brought to you by:
pbrunschwig
"Enigmail" appears in message bodies when the message is signed with the body left empty. Ideally the body would be left empty to avoid disclosing the agent and encryption software involved.
Maybe there could be an option to auto-fill empty bodies with the subject to prevent the signature from being reused by an attacker. Some folks use e-mail like an asynchronous chat by only populating subjects. For example, a subject may read "Thanks for meeting today. EOM" while the body is empty.
This is an inline-PGP issue only. I fixed this such that an empty message is now signed (creating a non-empty message body with the signature for no text).
Thanks or taking the time to respond. Can you provide an example of the non-empty body produced?
At present the PGP signature is already included. Do you mean to say you're using the Thunderbird account's signature (such as "--\nJohn Doe\nSupport Team")? If so I don't think that'd help since it is not dynamic. Therefore someone with a signed body could resend that body with a different subject to impersonate a user.
Wait a moment: You're saying that resending such a message would impersonate a user? What would the message be, what it's meaning? In this case: empty, no meaning of course. Even if not empty: Resending a signed message is always possible. It doesn't say anything different than the original message. The OpenPGP signature can never ("Cryptographically impossible") impersonate another user - the message and it's signature is always linked to only one private key.
What problem are you trying to solve?
Subjects are not part of the signature!
The body will be something like this: