Menu

#893 Efail: don't block decryption of mixed content entirely

fixed
nobody
None
2.0.5
Major
All
2.0.8
nobody
2018-08-05
2018-08-05
No

In order to prevent against the Efail attack, Enigmail does simply not decrypt mixed (encrypted & unencrypted) content anymore. An ideal solution would be to ensure that mixed content cannot blend into each other.

That's not possible with Thunderbird, as everything goes into a single HTML document. However, the following workaround is feasible:

  1. pretend that a PGP/MIME part of a mixed-content message is an attachment.
  2. if mixed content is displayed, don't decrypt the message, but display a placeholder message instead
  3. if encrypted message is part opened in a separate window (and just that bit, without anything else before or after), then decrypt the message.

Related

Forum: Enigmail 2.0.5 available - full protection against Efail

Discussion


Log in to post a comment.

MongoDB Logo MongoDB