Closed Bug 1118724 Opened 11 years ago Closed 11 years ago

Private comments on public bugs are sent unencrypted by email

Categories

(bugzilla.mozilla.org :: Extensions, defect)

Production
defect
Not set
major

Tracking

()

RESOLVED FIXED

People

(Reporter: nbp, Assigned: dkl)

References

Details

(Keywords: sec-want)

Attachments

(2 files)

I made a Private comment in Bug 1118469 comment 3, this comment was sent back to me in a plain text (html) email. I would expect such emails to be ciphered before being sent to anybody, as it is done for security sensitive issues.
Email notifications are only encrypted if the bug they are for are marked as private to a security sensitive group. Bug 1118469 is not marked private to any of those groups. Private comments are just filtered out of emails and the UI for people not in the 'insidergroup' and are not normally encrypted. dkl
Status: NEW → RESOLVED
Closed: 11 years ago
Resolution: --- → INVALID
Group: bugzilla-security
(In reply to David Lawrence [:dkl] from comment #1) > Email notifications are only encrypted if the bug they are for are marked as > private to a security sensitive group. Bug 1118469 is not marked private to > any of those groups. Private comments are just filtered out of emails and > the UI for people not in the 'insidergroup' and are not normally encrypted. So the "Private" flag is not even making any private email, and anybody who is rooting such email can see the content which was supposed to be "Private", right?
(In reply to Nicolas B. Pierron [:nbp] from comment #2) > (In reply to David Lawrence [:dkl] from comment #1) > > Email notifications are only encrypted if the bug they are for are marked as > > private to a security sensitive group. Bug 1118469 is not marked private to > > any of those groups. Private comments are just filtered out of emails and > > the UI for people not in the 'insidergroup' and are not normally encrypted. > > So the "Private" flag is not even making any private email, and anybody who > is rooting such email can see the content which was supposed to be > "Private", right? Private in the context of comments just means that the comment will be filtered out and not visible to everyone except privileged accounts. It does not mean private in the it makes the email encrypted to those who can see the comment. Marking a bug as private to a group that has encryption enable will only do that. dkl
Reopening because I agree with Nicolas this is not what we expect to happen. Private comments are only available to core-security (insidergroup) people and bugs filed in that group are sent encrypted. One common use for such comments is to note that a particular bug has security implications when we don't want to hide the entire bug because the general issue is already public. Why wouldn't that comment need the same protection we would give had we hidden the entire bug? I guess this isn't a "bug" if securemail wasn't designed that way, but it's at least a perfectly valid feature request.
Status: RESOLVED → REOPENED
Component: General → Extensions: SecureMail
Keywords: sec-want
Resolution: INVALID → ---
(In reply to Daniel Veditz [:dveditz] from comment #4) > Reopening because I agree with Nicolas this is not what we expect to happen. > Private comments are only available to core-security (insidergroup) people > and bugs filed in that group are sent encrypted. One common use for such > comments is to note that a particular bug has security implications when we > don't want to hide the entire bug because the general issue is already > public. Why wouldn't that comment need the same protection we would give had > we hidden the entire bug? > > I guess this isn't a "bug" if securemail wasn't designed that way, but it's > at least a perfectly valid feature request. Ok. After reading the code more closely, I realize now that the body of the email containing the private comments (if not filtered out) should be encrypted. I initially did not put it together that the insidergroup was set to core-security which is indeed a SecureMail enabled group. I will investigate this further. Nicolas, do you still have the email and can you attach it making sure to include the headers. Remove the private comment which I don't need anyway. Thanks dkl
Assignee: nobody → dkl
Severity: normal → major
Status: REOPENED → ASSIGNED
Flags: needinfo?(nicolas.b.pierron)
Attached file email
Flags: needinfo?(nicolas.b.pierron)
Attached patch 1118724_1.patchSplinter Review
Ok found this issue. It was an issue with not properly taking multi-part emails into account when looking for a private comment in the text. Putting fix up for review. dkl
Attachment #8546123 - Flags: review?(glob)
Comment on attachment 8546123 [details] [diff] [review] 1118724_1.patch Review of attachment 8546123 [details] [diff] [review]: ----------------------------------------------------------------- r=glob
Attachment #8546123 - Flags: review?(glob) → review+
To ssh://gitolite3@git.mozilla.org/webtools/bmo/bugzilla.git 0b5e63f..2bf5ed2 master -> master
Status: ASSIGNED → RESOLVED
Closed: 11 years ago11 years ago
Resolution: --- → FIXED
This is live now.
Component: Extensions: SecureMail → Extensions
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: