What am I missing here? Is the latter mode on by default and MUA are widely known to correctly deal with the error code in a secure way?
What am I missing here? Is the latter mode on by default and MUA are widely known to correctly deal with the error code in a secure way?
I've always used plaintext when using PGP, same with others who have used it with me... I thought it was standard practice. I don't see the point in using HTML for one-on-one encrypted conversations. HTML is for newsletters and similar content. Although I assume this means "don't use HTML at all in your client, not just for encrypted email".
In a context where pgp is used, which is not me receiving promotional material or forwards from Grandma, why do you consider it unlikely that mail is to be sent as plaintext and not as html?
But everyone adds transclusion (in-line rendering of linked content, which leaks data and opens up the door to bugs), fonts (ie: programs), images (historically not a great idea), and some even Javascript!
And that's not even all the muas that runs in the browser, and try to expose some safe subset of itself to be used for rendering the mail body.
So, html Email is insecure, when contrasted with plain text email.
Using pgp as "code signing" for hypertext applications ("html emails") isn't nearly enough.
Sadly, afaik there's no agreed "safe" rich text format for mail. Absurdly rtf would probably be better than html mail.
Anyway, I don't see how anyone could expect html mail to be safe in the first place.
If I'm expecting encrypted email, I don't expect it formatted as HTML, so I can just disable its rendering. At which point the attacker can send it any format they want, my mail client just won't render it.
The parent to my comment says this is unlikely, and I don't understand why. Hence my asking (and now I see I phrased it the opposite way).