Re: [Enigmail] [BUG] Character encoding mix-up when encrypting Inline.

2016-03-06 Thread Daniel Kahn Gillmor
On Wed 2016-03-02 04:27:28 -0500, Lachezar Dobrev wrote: > My outgoing e-mail is set to send in UTF-8. > The 'use default encoding' option has a common negative effect: there are > numerous encodings that support Cyrillic, and not all mail agents (quite a > few web-mail agents) support MBCS pro

Re: [Enigmail] Able to impersonate by attaching a signed PGP/MIME E-mail

2016-03-06 Thread Gnoxter
I did some digging. We're dealing with two cases, both ugly (yay). Case 1: multipart/mixed with INLINE PGP This is was my previous email exploited. The part that looks and parses INLINE messages iterates over an DOM Tree which leads to the case were the first two mime parts are skipped but it t

Re: [Enigmail] Able to impersonate by attaching a signed PGP/MIME E-mail

2016-03-06 Thread gnoxter
Hi, nice catch! I played with this a bit and wasn't able to reproduce it immediately. In my sent folder they looked like your screenshot, but for the friend I sent them to they were obviously broken because, as far I can tell, thunderbird changed some things before sending it out. However, I cr

[Enigmail] [ANN] Enigmail v1.9.1 available

2016-03-06 Thread Patrick Brunschwig
I'm happy to announce the availability of Enigmail v1.9.1 for Thunderbird 38 and newer, and SeaMonkey 2.35 and newer. Changes === This is a bugfix release addressing some regressions introduced in the last release. Important Note == This version requires GnuPG 2.0.7 or newer. Gn

Re: [Enigmail] Able to impersonate by attaching a signed PGP/MIME E-mail

2016-03-06 Thread Ludwig Hügelschäfer
Hi, On 06.03.16 14:20, Vincent Canfield wrote: > > Indeed, the message seems to have been munged somehow. You can see a > screenshot of this in action here: > > https://vc.gg/7NXkF0NP > > This is pretty easy to reproduce, but if you need any help reproducing > it let me know and I can send you a t

Re: [Enigmail] Able to impersonate by attaching a signed PGP/MIME E-mail

2016-03-06 Thread Vincent Canfield
Indeed, the message seems to have been munged somehow. You can see a screenshot of this in action here: https://vc.gg/7NXkF0NP This is pretty easy to reproduce, but if you need any help reproducing it let me know and I can send you a test off this list. On 03/06/2016 03:17 PM, Vincent Canfield w

[Enigmail] Able to impersonate by attaching a signed PGP/MIME E-mail

2016-03-06 Thread Vincent Canfield
Hi, I found recently that when someone sends me an E-mail signed by another, the entire E-mail is treated as signed by that user. To recreate this issue, you can do the following in Mozilla Thunderbird: - Take an E-mail signed with PGP/MIME and save it as whatever.eml - Optionally, open the .eml

Re: [Enigmail] Truncated email

2016-03-06 Thread Olav Seyfarth
Hi DIL23 I tested Enigmail with Adele and get: "Your email is truncated" I suspect Adele not functioning - unfortunately we have no influence on that. To test, please send email(s) to me and I'll reply. Olav -- The Enigmail Project - OpenPGP Email Securi