Encryption failures fixed in popular PGP email security tool Enigmail

Users of Enigmail 1.7 are advised to upgrade to version 1.7.2 as soon as possible

Developers of the popular Enigmail email security extension for Thunderbird have fixed several issues that could have exposed messages users believed to be encrypted.

Enigmail provides a graphical user interface in the Mozilla Thunderbird and SeaMonkey programs that allows users to digitally sign and encrypt email messages using the OpenPGP standard.

The Enigmail Project released version 1.7.2 of the extension on Aug. 29 and briefly noted that the release fixes "several important bugs." The changelog did not contain additional details about the impact of the fixed issues, but included a link to the project's external bug tracker.

In addition to several non-security issues, the bug tracker lists a number of addressed bugs that could have serious security implications for users of the older Enigmail 1.7 version. One of them causes emails to be sent in unencrypted form when only BCC (blind carbon copy) recipients are specified.

Another issue causes drafts to be saved in plain text when writing a new email even when the email is marked for encryption automatically. If the IMAP protocol is used, the unencrypted drafts can be synchronized with the email server, exposing potentially sensitive information.

This behavior only happens when the system selects an email for encryption automatically based on an existing per-recipient rule or when the recipient's public key exists in the local key store. "If the email is manually marked to be encrypted (e.g. by clicking the yellow key symbol on the bottom-right) the drafts are correctly encrypted before being sent to the IMAP server," the bug entry notes.

Another bug can cause an incorrect encryption or signing status message to be displayed when composing a reply. "This especially happens if the compose window is not opened for the first time," another entry on the bug tracker notes.

A fourth issue that has been addressed can cause an upgrade from Enigmail 1.6 to 1.7 to break encryption. Email messages won't be encrypted if the "per recipient" setting is disabled under Key Selection, despite other key selection mechanisms like "by email" and "manual if missing" being enabled.

"When confirmation dialog is enabled you can even see that Enigmail wants to send an email unsigned/unencrypted despite having selected forced encryption," the corresponding bug entry says. "Otherwise it is silently sent unencrypted."

An Enigmail user who reported one of the encryption failures in version 1.7 on the project's support forum described the situation as "the biggest imaginable catastrophe."

"I am currently preparing a crypto class for journalists next week to teach them how to use safe email," the user wrote. "HOW am I going to explain that? A system tells the user in a separate window as well as in a menu line that everything will be encrypted but then it simply FORGOT to ENCRYPT and, ooops, their report will be intercepted and their source will be tortured?"

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags securityprivacydata protectionencryptionThe Enigmail Project

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Lucian Constantin

IDG News Service
Show Comments

Brand Post

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Luke Hill

MSI GT75 TITAN

I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Laura Johnston

MSI GS65 Stealth Thin

If you can afford the price tag, it is well worth the money. It out performs any other laptop I have tried for gaming, and the transportable design and incredible display also make it ideal for work.

Andrew Teoh

Brother MFC-L9570CDW Multifunction Printer

Touch screen visibility and operation was great and easy to navigate. Each menu and sub-menu was in an understandable order and category

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?