See attachment for another example of a signature spoofing attack with PGP inline. I use plaintext wrapping of a proper inline signature (this causes a "Part of the message signed" message in the info box). I hide the signed plaintext with whitespace (this causes a scrollbar to appear that could be noticed by the victim). The prepended message at the top uses UI redressing to spoof the "BEGIN ENCRYPTED or SIGNED PART" part. The "part of the message signed" is correct, because I also add a "non-signed part" to the spoofed section. I avoid the extra warning that occurs with > 10 newlines by using Unicode 0x0085 NEXT LINE characters (there are also many other whitespace options).
Forum: Enigmail no longer displays unencrypted part of message
Diff:
Proof of concept.
This doesn't happen anymore with the fix for bug [#984].
May I ask you to use the build linked below, as it doesn't make sense to report more variations of what has already been addressed:
https://enigmail.net/download/nightly/enigmail-nightly-enigmail-2.0-branch-all.xpi
Related
Bugs:
#984