TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Thunderbird stored OpenPGP secret keys without master password protection

64 pointsby mritzmannabout 4 years ago

5 comments

akerl_about 4 years ago
Am I reading correctly that ~“GPG private keys were stored unencrypted” and ~“messages could be modified to include non-encrypted chunks, which the client displayed without indicating the distinction” both count as low-severity?
评论 #27231633 未加载
andreasleyabout 4 years ago
This reminds me of the fact that Firefox, by default, allows anyone to view stored credentials – no authentication required, as no master password is set. It boggles my mind.
评论 #27228725 未加载
评论 #27231237 未加载
评论 #27228724 未加载
评论 #27228752 未加载
评论 #27249564 未加载
评论 #27228714 未加载
jokoonabout 4 years ago
Well it&#x27;s not ideal, but it assumes the computer it is stored on is securely protected, so Thunderbird would not be the weakest link here.<p>Protecting this key would require to ask a password to the user.<p>By default there are none, but users who use gpg are aware of security and would generally set a master password.
评论 #27228443 未加载
u801eabout 4 years ago
Would this only affect keys that don&#x27;t have an associated passphrase that&#x27;s used to decrypt them?
评论 #27231050 未加载
treveabout 4 years ago
I&#x27;m a novice at security, but shouldn&#x27;t the correct fix be to force the user to revoke the keys?
评论 #27231304 未加载
评论 #27228091 未加载