Thunderbird 60.0 release
thunderbird.net
thunderbird.net
I still believe it was a poor decision by Mozilla to cut off Thunderbird and float it as a community supported project. It now seems partially blessed by Mozilla, but isn’t how it was before that separation (AFAIK). The main thing I’ve felt as a huge missed opportunity with Thunderbird has been the lack of native Exchange calendar integration (no, none of the extensions, past and present, are close to even the experience of using Outlook web access for this purpose).
I’ll continue using Thunderbird for at least a few more years and will support the project financially, but I feel Outlook web access is slowly chipping away the need to use a desktop client in enterprise environments that are tied to Exchange or Office/Outlook 365.
I was just in the same situation, and simply downloaded the installer from their main webpage [1] (after backing up my data in my profiles folder[2] and closing any running instances of Thunderbird), and it simply worked! I have to say, at least on Windows, the update looks much better, feels quite refreshing! Almost makes me want to actually check all the new emails :)
[1] = https://www.thunderbird.net/en-US/ [2] = https://support.mozilla.org/en-US/kb/profiles-where-thunderb...
It says "currently only offered as direct download", does that mean that it'll be available as an update later on?
Anyone have any idea about this affects Linux? I am using Mint, and in the past the suggestion has always been "update through your repository" not with a download...
Is it different this time for some reason?
This shouldn't affect you if you've been installing/updating from a package manager.
Sweet, although IIRC several of the email providers with 2FA (Gmail and Outlook come to mind) have the option of providing app-passwords instead, which bypass the need for a 2FA token.
For some reason I also thought there was some way of tying the app's identity to the password, such that if an app other than Thunderbird tried to use my Gmail Thunderbird-app password, Gmail would block it. But I'm probably wrong on that point.
Would be a great enhancement, if not.
A false dichotomy. 2FA login is achieved through "web login", where an authentication token is obtained by presenting the service's 2FA interface in a web frame or a simple web browser. See e.g. the initial setup flow in Android 4.x - the Google login and password are a regular form, but if 2FA is enabled, you're shown a web browser.
Whether clients like Thunderbird implement web login remains a quality of implementation issue...
One of the major benefits of TOTP is that you have only a certain time window (usually, 30 seconds) to guess a password before the thing you're trying to guess changes and you have to start over.
With HOTP, you only get one guess before the goalposts move. The downside is that it's more vulnerable to DoS attacks when configured that way.
An app password has no brute-force resistance, so it lowers the security of your otherwise-2FA account overall.
This is, again, wrong. Guessing a 6-digit number will take, on average, 500,000 tries; if the answer changes with each guess, it will take only twice as much (same as when picking random guesses instead of iterating through all possibilities in order).
In fact, you might as well try "000,000" over and over every said 30 seconds, and your guess will eventually be correct after about the above-mentioned 500,000 tries.
If the OTP "000000" is correct with 50% probability after 500,000 attempts, you've just increased the number of attacks necessary to brute-force a password against a live server by (conservatively) 50,000,000%.
You know:
- A username
In order to gain access to this system, you must supply:
- A username - The corresponding password - A TOTP code valid for the time you make the attempt
If any piece of information you give the server is wrong, you get an "auth failed" message which reveals nothing about which part(s) you got wrong. It is an oracle which answers only "yes" or "no".
Assuming you can guess (ask the oracle) once per second, that there are 52^8 possible passwords and 10^6 possible OTPs, and that every thirty seconds the valid OTP shifts to a new totally random value within the valid range, estimate the number of guesses necessary to find (with 50% probability) the correct combination of information. Now repeat the exercise, with the changed situational parameter that you no longer need to supply a correct TOTP.
I think you will find that the estimated time to crack is increased by much, much, much more than a factor of two by having the OTP. I would be interested to see any alternate answer and the reasoning behind the same.
Update: found here - http://forums.mozillazine.org/viewtopic.php?f=29&t=3039509
Syncing with CalDAV/CardDAV or Google Calendar/Contacts has always been problematic and apparently this is the very first version where you can edit single entries of an recurring calendar event. This does not help in building confidence in Thunderbird as a PIM.
But it doesn't support a good chunk of these, which makes it difficult to adopt in my life.
Which is a shame, I much prefer Thunderbird to Kmail UI wise, but when processing thousands of messages (deleting, moving, filtering, etc) it slows to a crawl then freezes. Kmail stays responsive.
This on 16 core 32 GB machine. But it doesn't look like the cores are used very effectively by TB as opposed to Kmail.
For normal usage though it's great. Maybe the next release will focus on performance optimization, in particular multicore.
It's funny, I actually only use Thunderbird for its calendar these days, not for email.
The only thing that it lacks is the native support of Tray, I just use the discontinued extension FireTray.
Anyway, just checked the new version and installed it, it looks fresh and nice, great job!
https://www.mozilla.org/en-US/security/known-vulnerabilities...
I'd advise upgrading Thunderbird and ignoring the features you don't use, or switching to an actively-maintained mail client which is designed to be simpler than Thunderbird.