News: 1600405439

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Thunderbird implements PGP crypto feature first requested 21 years ago

(2020/09/18)


Mozilla’s mail reader, Thunderbird, has implemented a feature first requested 21 years ago.

The request was for “a plugin for PGP to ede and encrypt PGP crypted” and it appears to have gone un-implemented due to concerns about US laws that bar export of encryption, debate about whether PGP was the right way to do crypto and other matters besides.

Thunderbird eventually chose to use Enigmail and its implementation of OpenPGP public key e-mail encryption, however it is an add-on rather than integrated.

Commenters in the [1]Bugzilla thread stemming from the request therefore kept the dream alive.

Then in October 2019, The Thunderbird Blog [2]announced that Thunderbird 78 “will add built-in functionality for email encryption and digital signatures using the OpenPGP standard.”

Thunderbird 78 emerged in July 2020 and late in August Thunderbird contributor Kai Engert (:KaiE:) posted: “We have released support for OpenPGP email in Thunderbird version 78.2.1. Marking fixed.”

Also at Mozilla

In other Mozillan news, the outfit has announced it is killing off a couple of products.

One, the encrypted file-sharing tool “Firefox Send”, “garnered good reach, a loyal audience, and real signs of value throughout its life” according to a Mozilla [3]blog post . Unfortunately among those who perceived value were “some abusive users were beginning to use Send to ship malware and conduct spear phishing attacks.”

Mozilla therefore took Send offline and has decided not to re-launch it in line with recent [4]strategic review that saw the organisation shed a quarter of its staff.

Firefox Notes, an encrypted data sharing tool, has also been shown the door and will cease operations as of November 2020. ®

Get our [5]Tech Resources



[1] https://bugzilla.mozilla.org/show_bug.cgi?id=22687

[2] https://blog.thunderbird.net/2019/10/thunderbird-enigmail-and-openpgp/

[3] https://blog.mozilla.org/blog/2020/09/17/update-on-firefox-send-and-firefox-notes/

[4] https://www.theregister.com/2020/08/14/mozilla_google_search/

[5] https://whitepapers.theregister.com/

Encryption should be automatic

Anonymous Coward

PGP never took off, because it requires a public key server to verify identity and identity simply has nothing to do with encryption. Those third party servers are just honeypots of 'who is sending encrypted emails to whom and when' and places to attack if you want to substitute a key. They are the Symantec's of the world*.

https://news.softpedia.com/news/three-symantec-employees-fired-for-issuing-fake-google-com-ssl-certificates-492190.shtml

Revoke key is not a good thing either. You let a third party say a key is cancelled because you trust that third party more than the actual email services you're talking too??? No.

Thunderbird should sent a public key with every email in the meta data. Mozilla should automatically collect public keys from the meta data and use them. It should have a setting "Automatically upgrade to encrypted", when it receives an encrypt key, it should use the key when emailing that address, and keep track of which keys were provided.

If you trust an email address enough to talk to them as if they were fred.bloggs@ then you trust their key to encrypt that message. You do not need a third party to verify fred.bloggs is fred.bloggs. If you didn't care enough for other purposes, then you don't care enough for the encryption.

Collect the keys, confirm the key remains constant, if ever the key changes, flash a big alert up "fred.bloggs's encrypt key has changed, is this still him?"

No third party keyholder, not 'trusted' third party. No Symantec's injected into private conversations. There is nothing special about wanting a private conversation in a communication system that is supposed to be private!

* And also notice that Google monitors its public keys, which is how they spotted Symantec issuing fake certificates, but you do not. You would not be aware if the 'trusted' keyholder starts issuing a different public key. PGP was never adopted because it is flawed.

"Maintain an awareness for contribution -- to your schedule, your project,
our company."
-- A Group of Employees