[tor-dev] Torbirdy - IMAP issue

Nima Fatemi nima at redteam.io
Fri Dec 6 05:10:24 UTC 2013


It doesn't have anything to do with TorBirdy. All you really have to do,
is to have Encryption on by default in Enigmail.

Your drafts are now going to be encrypted. Problem solved!

Bests,
-- 
Nima
0XC009DB191C92A77B | mrphs - https://anarchy.io

"I disapprove of what you say, but I will defend to the death your right
to say it" --Evelyn Beatrice Hall

arkmd:
> Accessing an email server via IMAP may leak data by saving a draft on
> the remote server.
> 
> 
> Using Thunderbird+Enigmail+Torbirdy.
> 
> While writing a message on Thunderbird, it is automatically saved as a
> draft, which by default is sent to the IMAP server. So the server will
> be able to read that message.
> 
> That's a big problem when the message should be encrypted before sent.
> So the email provider will be able to read sensitive data on those
> drafts in cleartext and the user probably won't notice.
> 
> 
> To solve this the user need to manually set the account drafts
> settings (in Copies & Folders) to keep drafts on Local Folders.
> 
> I think Torbirdy should do it by default.
> 
> This info should be added to known issues on Torbirdy wiki.
> 
> 
> I know Torbirdy developers recommend POP over IMAP, but as a
> mailtor.net user I don't have any other option.
> 


-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 801 bytes
Desc: OpenPGP digital signature
URL: <http://lists.torproject.org/pipermail/tor-dev/attachments/20131206/f10181b7/attachment.sig>


More information about the tor-dev mailing list