thanks very much Magnus. Are you saying that TB also sends via SMTP encrypted text that was encrypted using the sender's public key, merely so that it can be read in the sender's Sent Mail, which is (likely) written via IMAP. What's the point of sending that to the recipient via SMTP? [Note that the sender did not Cc themselves] Wouldn't that also mean that if the sender is careless with their own private key, the message can be intercepted and read, even without my (recipient) private key? That seems like a slight lessening of security? And I only see one encrypted.asc attachment in the email; that can't be encrypted using both public keys, surely, otherwise I'd not be able to read it? And I'd still argue that the final box in Message Security is confusing, and needs adjustment, even if just to add "also" :)
Bug 1941457 Comment 3 Edit History
Note: The actual edited comment in the bug view page will always show the original commenter’s name and original timestamp.
thanks very much Magnus. Are you saying that TB also sends via SMTP encrypted text that was encrypted using the sender's public key, merely so that it can be read in the sender's Sent Mail, which is (likely) written via IMAP. What's the point of sending that to the recipient via SMTP? [Note that the sender did not Cc themselves] Wouldn't that also mean that if the sender is careless with their own private key, the message can be intercepted and read, even without my (recipient) private key? That seems like a slight lessening of security? And I'd still argue that the final box in Message Security is confusing, and needs adjustment, even if just to add "also" :)