Page MenuHome GnuPG

GPGOl silently leaves messages decrypted on Outlook 2007
Closed, ResolvedPublic

Description

After at least a day of operation (leaving Outlook 2007 open), after receiving
and decrypting--and then closing--an encrypted message, GPGOl writes the
decrypted message without asking to disk. This causes the message to be
synchronized unencrypted back to Exchange. This does not always occur but is
pretty easy to replicate if you leave Outlook open for a day or more. It also
happens often upon replying to decrypted messages.

This is a significant issue as we are trying to prevent our Exchange
administrators from reading messages between management members.

Please help. Thanks!

Event Timeline

I found another case where this invisible decryption occurs. I received a
message with some encrypted attachments. I clicked the decrypt button in
Outlook, and GPGOl prompted me to ask if it should decrypt and save the
attachments. When I clicked 'No,' it decrypted the message on disk (I could see
it change in the preview pane in the background) as well as in the message
window. I confirmed that viewing this message via OWA that it was in fact
decrypted on disk.

marcus added a project: gpgol.
marcus added a subscriber: werner.
bernhard added a subscriber: aheinecke.
bernhard added a subscriber: bernhard.

Hi Arthur,
sorry for the late reply:

Outlook 2010 has new code for supporting OpenPGP and S/MIME,
we will tackling the problem differently there.
I think that the last code for GPgOL for Outlook 2007 uses
encryption.

If this is still relevant for you: Can you retest?

bernhard renamed this task from GPGOl silently leaves messages decrypted to GPGOl silently leaves messages decrypted on Outlook 2007.Mar 2 2016, 2:17 PM
bernhard reassigned this task from werner to aheinecke.
bernhard added a project: Info Needed.