[Enigmail] Usability issues

Tobias Rapp t.rapp at noa-audio_no-spam_.com
Wed Dec 12 06:39:14 PST 2007


Robert J. Hansen wrote:
> A bad signature on a message does not necessarily mean the semantic
> content (which is what we care about) was tampered with.  It only means
> that we cannot guarantee it was not tampered with--not that it actually was.

That's a good thought. Indeed if there is a bad signature on a message
it just tells you that the man-in-the-middle was too dumb to remove the
whole signature if he changed it.

I fully agree that the trust value of a message with bad signature, a
message with "untrusted good signature" and a message without signature
are equal.

/Tobias


More information about the Enigmail mailing list