enigma plugin: gpg redressing attack#10007
enigma plugin: gpg redressing attack#10007JohnRDOrazio wants to merge 3 commits intoroundcube:masterfrom
Conversation
|
The point was that this place is not safe. Maybe in the dark mode (with white HTML content) you see separation, but normally you don't and the attacker could made the content look the same. So, I don't know if we can consider this a fix. Also, a message can consist multiple parts, all or some encrypted/signed. How do you know which box is to which part? |
|
That's not much different than #6450 (comment) |
|
I guess that makes sense. Whether you set a custom background pattern on the whole mail preview with a clear separation between the enigma message boxes and the message body, or you set a custom background image on the enigma message boxes themselves, either approach pretty much solves the issue of any redress attacks. Perhaps the only advantage to setting a custom background pattern on the whole mail preview, with a clear separation between the enigma message boxes and the message body, would be to further "sandbox" the message body. But one way or the other both solutions help address the issue. |


Fixes #6450
status_messagecallback now only sets the private class arraystatus_messages, rather than modify the message body.message_outputcallback if the private class arraystatus_messagesis not empty.