If an attacker creates a HTML mail containing a signed inline-PGP message part, then Enigmail would display a "good signature" instead of saying that the message is only partially signed. Example attached.
Log in to post a comment.