Join the Mozilla’s Test Days event from Dec 2–8 to test the new Firefox address bar on Firefox Beta 134 and get a chance to win Mozilla swag vouchers! 🎁

搜索 | 用户支持

防范以用户支持为名的诈骗。我们绝对不会要求您拨打电话或发送短信,及提供任何个人信息。请使用“举报滥用”选项报告涉及违规的行为。

详细了解

话题已关闭并存档。 如果需要帮助请提出新问题。

Encryption - email account with no key can access encrypted email?

  • 10 个回答
  • 1 人有此问题
  • 1 次查看
  • 最后回复者为 Matt

more options

I've set up 3 email accounts on Thunderbird on a single computer.

I've set up 2 of them with each other's keys to send and receive encrypted emails.

However, the third email account has no key at all but can still read encrypted emails by pressing the "Repair Message" button.

Thunderbird won't let you encrypt a message unless at least one of the recipients of an email has a key. However, if another recipient doesn't have a key, that recipient will still receive the encrypted message but can open it as explained above.

Have I done something wrong? I thought the receiver without the key should not be able to open the encrypted email. If they can open it, does that mean anyone at any hop along the path of the email can open it?

TIA John

I've set up 3 email accounts on Thunderbird on a single computer. I've set up 2 of them with each other's keys to send and receive encrypted emails. However, the third email account has no key at all but can still read encrypted emails by pressing the "Repair Message" button. Thunderbird won't let you encrypt a message unless at least one of the recipients of an email has a key. However, if another recipient doesn't have a key, that recipient will still receive the encrypted message but can open it as explained above. Have I done something wrong? I thought the receiver without the key should not be able to open the encrypted email. If they can open it, does that mean anyone at any hop along the path of the email can open it? TIA John

所有回复 (10)

more options

Is this using s/mime or PGP and enigmail?

more options

Hi Matt,

I'm using PGP and enigmail.

more options

Well I assume it's using PGP and Enigmail. I downloaded the PGP package and added the Enigmail extension to Thunderbird.

more options

I think the problem was that I was trying to test it all on the same machine. When I tested an email to a different host they were not able to decrypt the message.

Thanks.

more options

one instance of Thunderbird with three email accounts will certainly have access to the encryption keys for all accounts. They are not doled out per account.

more options

Yes, Thanks Matt!

more options

Matt said

one instance of Thunderbird with three email accounts will certainly have access to the encryption keys for all accounts. They are not doled out per account.

If this is true, it is a really, really faulty design.

more options

r_avital said

Matt said
one instance of Thunderbird with three email accounts will certainly have access to the encryption keys for all accounts. They are not doled out per account.

If this is true, it is a really, really faulty design.

It is true and personally I see no fault in the design. You might, but really it is not relevant in the context of this question what you think is faulty.

more options

And here I was under the impression, apparently mistaken, that as long as the language is kept clean and courteous, criticism, including of the design of TB, was allowed and legitimate. Respectfully, what is relevant to you is not relevant to me. Whatever, me wrong you right have a nice day.

more options

Locking this spam generating topic.