PGP Encryption and MIAB?

Continuing the discussion from Undelivered Mail Returned to Sender:

> To protect emails from prying eyes that might intercept them, set up PGP. PGP, or Pretty Good Privacy, allows you to send a message that is encrypted in a way that can only be decrypted by the intended recipient.

  • However, that means this only works if the other party is set up to use PGP as well—and many people are not.
  • Only the content of your email will be encrypted. The sender and recipient information, along with the subject line, are not.

The question is whether or not it is possible to include PGP Encryption with MIAB. I would have thought that, the title, of this post, which states “PGP Encryption and MIAB?” made the question obvious. In either case, the title is an abbreviated way of asking how or whether or not it is possible to combine the two.

Some more information:

Do you have a specific question?

JoshData commented on May 19, 2016
Closing because it was a fun idea but it seems like no one will get around to this any time soon.

martindale commented on May 20, 2016
Please re-open this issue, as it remains a requirement for the project. Move it to another milestone if you must (propose: “Backlog”), but definitely do not close it just because someone isn’t getting to it soon.

JoshData commented on May 20, 2016
as it remains a requirement for the project
I don’t know what that even means. If it’s a requirement you have for a mail server, then this project won’t meet your needs.

martindale commented on May 20, 2016
Then close the issue as “out of scope”, and be clear about that to your community so they can find solutions that meet their needs. “no one will get around to this” is a poor explanation that you do not view this as an important feature and are removing it from the list of things other contributors can do for you.

As for the context of the issue itself, deploying a mail server without end-to-end encryption is irresponsible in the post-Snowden era. You would be doing a serious disservice to your users by even allowing unencrypted configurations, let alone explicitly removing them from your product backlog.

@JoshData I suspect this issue of end-to-end encryption will continue to crop up until a compromise is found.

Take it easy. We’re all trying to help. If it appears otherwise, it’s a misunderstanding. There are a lot of threads here and on github and it is hard to keep track of what everything is about.

Mail-in-a-Box doesn’t support PGP encryption out of the box and modifying the box is discouraged because it makes getting help much harder. No one is currently working on adding PGP encryption.

It’s of course possible, if you build the PGP integration yourself – but again that’s discouraged. Unless you’re prepared to walk through the process of adding a new feature to Mail-in-a-Box for everyone.

Thank you for your response, @JoshData

What are the steps for adding a new feature? I am not so technically minded, but I do enjoy learning about how to build new products.

Some work was done here. That is work on implementing the enigma plugin in round cube. That works looks stalled because of php7 support. Which might change if we implement nextcloud 12.

Working towards universal PGP support where the server encrypts and decrypts (so the box holds the keys) wouldn’t be my favourite way of implementing this.

To be quite honest, I wouldn’t use the enigma plugin either. I think PGP should be a client side tool because you don’t trust the transport layer. But that just depends on your threat level I guess. I sign my email using s/mime. Which works by default in most clients. As @joshdata mentions in the PR/Issue I referenced he is willing to accept a well tested PR.

Let’s continue the discussion in whichever issue or pull request on github is closest to this topic.

Hi, new to MIAB - thanks for the contribution. I’m wondering if it has PGP support now?

You can use PGP encryption with your mail client, like Outlook or Thunderbird, but I don’t think there’s anything bundled with Roundcube in MIAB as it stands (so nothing for the web portal).

Thanks for the info, I use enigmail for Thunderbird and k9 on m Droid. Sad to hear that years later MIAB still didn’t add support