> Only the body of the message. Please note that, as with all OpenPGP
> messages, the email subject line and list of recipients remain
> unencrypted.
Hopefully attachments are considered part of the body? > Only the body of the message. Please note that, as with all OpenPGP
> messages, the email subject line and list of recipients remain
> unencrypted.
Hopefully attachments are considered part of the body?[0] http://www.w3.org/Protocols/rfc1341/7_2_Multipart.html
[1] http://msdn.microsoft.com/en-us/library/ms526560(v=exchg.10)...
I'm not saying that End-To-End does this, just that it is perfectly possible (and common) to encrypt the whole message.
H
This could work, but the web service would have to support it as well as the extension.
Then there is also the issue of how does the receiver read the message? The extension would need to be able to parse MIME, and allow access to the separate parts.
Encrypt them before uploading them, and send the decrypting key in the body.
But Gmail itself may handle attachments differently.
AFAIK, Gmail handles attachments the same.
Because if you look at the low-level structure of email, "attachments" are just parts of a body that is in multipart/mixed MIME type.
Answering the GP, that varies from one implementation to another. Most clients encrypt attachments, but it looks like this one extension only encrypts the textarea contents.