Author Topic: Scanning of e-mail with PGP Key attached  (Read 4626 times)

0 Members and 1 Guest are viewing this topic.

epp

  • Guest
Scanning of e-mail with PGP Key attached
« on: July 23, 2008, 05:31:22 PM »
A friend uses a Linux system and his e-mails have his PGP Key attached to them.

When I retrieve the e-mail (via the standard port 110 with my ISP), these particular e-mails do not have the message appended that the inbound message is clean, but the e-mail headers have this indication.

Is this normal scanning behavior for Avast when there is a PGP key involved?  Not a big deal, just curious.  :)



Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89210
  • No support PMs thanks
Re: Scanning of e-mail with PGP Key attached
« Reply #1 on: July 23, 2008, 05:48:28 PM »
It won't that is the whole point of the PGP security, the email is encrypted until opened with the corresponding key and avast doesn't have that key. The email headers are obviously still available and accessible.

Personally I feel it a waste of processing effort in so marking inbound email, a) I wouldn't trust any such signature it could be forged b) if the email is infected all hell will break lose and you will know.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

epp

  • Guest
Re: Scanning of e-mail with PGP Key attached
« Reply #2 on: July 23, 2008, 06:40:35 PM »
On my K6-2, I have not noticed any unusual slowness when it is scanning inbound and outbound mail. 

Personally, I like having the messages appended like that, it provides peace of mind.  :)
 

Offline alanrf

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3870
  • Just an avast user
Re: Scanning of e-mail with PGP Key attached
« Reply #3 on: July 23, 2008, 06:53:41 PM »
as DavidR says avast needs to be able to inspect the way the body of the email is made up in order to be able to insert the "clean message" in the correct place in the message body. There are rules that must be followed for how to put the parts of an email together.   Since the body is encrypted avast cannot see the format of the message body and has to pass on inserting the "clean message".

By the way, it also means that avast cannot scan any attachments included in the message so extra care is appropriate in dealing with them.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89210
  • No support PMs thanks
Re: Scanning of e-mail with PGP Key attached
« Reply #4 on: July 23, 2008, 07:25:37 PM »
Personally, I like having the messages appended like that, it provides peace of mind.  :)

Fine up to the point it bites you in the a**, trust and peace of mind are something that require a little more than a couple of sentences tagged at the bottom of an email.

There are a number of malicious emails that have used the same sort of 'This email has been scanned by [Insert your AV of choice here] and is clean.' Great up to the point they open the attachment.

As I continue to say, your system, your choice.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

epp

  • Guest
Re: Scanning of e-mail with PGP Key attached
« Reply #5 on: July 23, 2008, 07:33:40 PM »
By the way, it also means that avast cannot scan any attachments included in the message so extra care is appropriate in dealing with them.

Understood.  :)


epp

  • Guest
Re: Scanning of e-mail with PGP Key attached
« Reply #6 on: July 23, 2008, 07:36:14 PM »
Personally, I like having the messages appended like that, it provides peace of mind.  :)

Fine up to the point it bites you in the a**, trust and peace of mind are something that require a little more than a couple of sentences tagged at the bottom of an email.

There are a number of malicious emails that have used the same sort of 'This email has been scanned by [Insert your AV of choice here] and is clean.' Great up to the point they open the attachment.

As I continue to say, your system, your choice.

The thing I like about this, is that it includes an original timestamp, along with the date and database information.  This is certainly a big plus, in my opinion.  It has more complete information, as opposed to a generic statement (your example above).  Plus where the e-mail headers also have the database information listed, once scanned, it can be matched to any statement.




epp

  • Guest
Re: Scanning of e-mail with PGP Key attached
« Reply #7 on: August 05, 2008, 06:45:28 PM »
I've since learned that he was using Claws (Claws Mail) to send the e-mail. 

But when he uses Thunderbird on the same system to send e-mail, avast! will append the text to a message sent using Thunderbird.  Thunderbird does not directly support PGP, an extension has to be installed.  Once that is installed, avast! will probably behave in the same manner as e-mail sent using Claws.



« Last Edit: August 05, 2008, 06:50:48 PM by epp »