Encrypt and sign Gmail messages with FireGPG

Posted by: Anonymous [ip:] on January 15, 2008 09:23 PM
I am actually wondering if I've stumbled upon a vulnerability with the firegpg plugin for firefox using gmail. If you are inputing your plain text message into the javascript field in gmail, and lets say your message is a few lines or more, then gmail is automatically going to save a draft of your email - the one you want to encrypt - in plain text. It then saves this copy on its servers thereby circumventing the whole security process! SO what's the point?


