Questions tagged [thunderbird]

Thunderbird is an email client from Mozilla.

13 questions
9
votes
0 answers

PGP security with Thunderbird 78 email client

I have a query regarding best practice of using PGP to sign emails with Thunderbird 78. Thunderbird 78 took an existing system by Enigmail and brought it "in-house" to be built into the email client program. This results in some notable changes…
Martin
  • 1,057
  • 1
  • 11
  • 18
6
votes
1 answer

How are the PGP keys that Thunderbird 78+ uses encrypted?

With Thunderbird 78, a new PGP subsystem has been introduced which handles PGP keys internally. In previous versions, the add-on Enigmail has handled PGP-related stuff, by letting do GnuPG the work behind the scenes. I currently know only that the…
Binarus
  • 557
  • 5
  • 16
2
votes
2 answers

How to get PGP key passphrase out of Thunderbird?

I set up Thunderbird to use PGP a while ago, so I can sign and decrypt messages now. But I have forgotten my private passphrase for my private key, but since Thunderbird can do it anyway, it has it stored somewhere. How can I get it? I already…
2
votes
3 answers

Reading locally-stored emails sent encrypted

As far as I know, when Alice sends an encrypted email using PGP to Bob then the email will be encrypted using Bob's public key. Only Bob can decrypt it (as long as no one else has Bob's private key). As far as I know, Thunderbird implements exactly…
anion
  • 1,013
  • 8
  • 10
1
vote
0 answers

avoiding plaintext on the hard drive

If you decrypt ciphertext to the terminal like this: gpg --output - --armor --encrypt --recipient 23642351 message.txt.pgp ..does it touch the hard drive / ssd or only live in RAM? What about when Thunderbird decrypts a message - does the plaintext…
cardamom
  • 359
  • 2
  • 9
1
vote
1 answer

Thunderbird uses AWS: Secure?

In their Privacy Note, Mozilla writes the following: Amazon Web Services: Thunderbird uses Amazon Web Services (AWS) to host its servers and as a content delivery network. Your device’s IP address is collected as part of AWS’s server logs. (i) If…
0
votes
1 answer

Forward messages without tracking pixels using thunderbird

Thunderbird does not load remote content by default, preventing pixel-tracking. However, if I forward an email, the links to remote content is still included in the forwarded email. Is there an option in Thunderbird to strip remote content when…
Clément
  • 103
  • 3
0
votes
0 answers

PubKey decrypted differences when Sending an encrypted email via a bash script and when sending it via Thunderbird

This is a 2-part question. When GnuPG is used externally in Thunderbird 91.7.x, i tested email encryption from Account A to Account A, the message was received perfectly encrypted and in the "Message Security - OpenPGP" view pane of the message, it…
0
votes
1 answer

I am noticing a malicious DNS query in Thunderbird

My Suricata IDS is generating this alert when starting Thunderbird: ET INFO Observed DNS Query to .cloud TLD You can analyze a json log: { "_index": "suricata-1.1.0-2022.02.11", "_type": "_doc", "_id": "Uvxd6X4Bz6KASDsJzj8a", "_score": 1, …
0
votes
1 answer

How can a Microsoft "unsuccessful sign-in" trigger a 2FA request?

I was certain I'd find a question asking this, but a search didn't return any results. I have 2FA enabled on my Microsoft account, which requires me to approve all sign-ins using the Microsoft Authenticator app. My understanding is, after you supply…
user218666
0
votes
0 answers

Security of Third Party Plugins in Thunderbird

In Thunderbird (a popular open source email client), there is an extension store similar to Mozilla Firefox which adds further functionality to the client. Mozilla has an article detailing the security and safety of Firefox extensions (see Tips for…
0
votes
1 answer

Link test differs from link location in plaintext view is not visible in Thunderbird

Today I noticed something strange. I got an email containing a link that links to another site than the text says. In (Simple) HTML, the review is visible when hovering over the link. However, in plaintext, in 3 out of 4 mails only the a.com was…
kaiya
  • 422
  • 1
  • 3
  • 11
0
votes
1 answer

How to workaround Thunderbird 78's lack of support for encrypted mailing lists?

As of Thunderbird 78, the support for PGP plugins such as Enigmail has been dropped in favour of a native implementation of pgp in Thunderbird's core. But some features of Enigmail are still missing. One of those features is to create something akin…
bitmask
  • 585
  • 1
  • 5
  • 12