GMX/web.de Apps force the setup of PGP

Hi!

I investigated carefully, but found no related topic elsewhere. This is the issue:

The sender sends a PGP/Mime-signed, unencrypted email to the recipient at web.de or GMX. The recipient uses the respective Android app or web interface of the two United Internet brands.

I performed the following steps with GMX, and also conducted some random tests with web.de, finding no difference. To simulate the most realistic handling of the received, signed emails, I used MS Edge with a completely new browser profile in a virtual machine.

The first oddity appeared as soon as the signed email was read:

»Verschlüsselte Kommunikation wird von Ihrem aktuellen Browser nicht unterstützt! Um verschlüsselte Kommunikation auf diesem Computer verwenden zu können, nutzen Sie bitte Mozilla Firefox oder Google Chrome. (Encrypted communication is not supported by your current browser! To use encrypted communication on this computer, please use Mozilla Firefox or Google Chrome.)«

Aha. I didn’t understand why this should concern me, a hypothetical average GMX customer who’d never heard of Mailvelope or any other such fancy stuff, and ignored the message. So I cheerfully clicked the »Antworten (Reply)« button and found myself on the email composition settings page, with no mention of encryption. Back to the composition page, now next to the »Von (From)« address in GMX, it says »Verschlüsselt senden (Send encrypted)«. The wonders never end, but hey, fortune favors the bold! So I confidently clicked the button again, but now the disappointment is immense, and the error message reads:

»Ihre E-Mail konnte nicht versandt werden. (Your email could not be sent).«

What a pity! I’ve already written half an encyclopedia as a reply to the original sender and I don’t want to lose it. Since I’ve become quite used to miracles, I bravely clicked the »Verschlüsselt speichern (Save encrypted)« button, but oh dear, now the error message reads:

»Fehler beim Verarbeiten Ihres PGP Entwurfs. Möchten Sie den Entwurf verwerfen? (Error processing your PGP draft. Do you want to discard the draft?)«

Not really, since I spent quite some time writing the reply. And what’s PGP anyway? At this point, the average GMX customer should be desperately abandoning this magical email thing and only want to communicate with the sender via SMS or WhatsApp.

The whole dilemma

  • was no different with the GMX Mail app, only the error message was less specific,

  • regardless of the key type used to create the signature, i.e., ECC or RSA,

  • regardless of enabled or disabled autocrypt

  • and regardless of the sender domain used

When using a generic mail user agent such as Thunderbird, FairEmail or Kmail to connect with GMX, the error was not reproducible; the signatures were treated like any other attachment, and a »Re:« to the signed email showed no abnormalities.

Now I’m wondering if I’m really the first person to notice this behavior, if I’ve overlooked an RFC that forces recipients of signed emails to set up PGP, or if I’ve simply made an embarrassing logical error.

I would appreciate any clarification or confirmation of my bug report.

Hi, and welcome to the forum @Grokenberger!

You haven’t made a logical error, but this isn’t a GnuPG/OpenPGP bug.
I appears you’ve run into a quirk in GMX’s/web.de’s own webmail frontend. The bug is not related to the OpenPGP standard or to any GnuPG/Gpg4win component.

GMX and web.de (both are brands by United Internet, and use similar or the same software) have a built-in “encrypted communication” feature in their webmail that works with the Mailvelope browser extension in Firefox or Chrome. And Mailvelope itself uses OpenPGP.js as its cryptography backend. This is what the error message said when you used Microsoft Edge.

In particular, when their webmail software detects that an incoming e-mail has a PGP/MIME structure, it appears to assume that the response must be sent encrypted.

This is a bug at GMX/web.de worth reporting directly to their support

Hi swagner,

do you agree to call it rather a major bug than a quirk? And is it really possible that I’m the first one who detected?

Anyway, web.de/GMX are not companies that handle bugs transparently. Calling support could be a challenge.

In my opinion, this is an outright bug. It prevents users of United Internet from responding to signed e-mails.
The bug is also consistently reproducible, I see it myself as well.

As this is completely out of scope for GnuPG and OpenPGP, I’m afraid we cannot offer any more help to you and other affected parties. It’s your service provider’s responsibility to correct this behavior.

Thanks deeply @swagner for clarification! I hope, you and the community behind GPG never felt accused in any kind! I was just wondering that one of the biggest email providers in Germany failed so miserably managing a decades-old, well documented and established procedure.

But please do not close this thread to early or mark it as solved, maybe anyone else has an idea, how to put pressure on United Internet to do their homework.

Note that many users do not demand good crypto handling and probably are not willing to pay for it. So there is little incentive for a company to spend much time optimizing their interfaces. In addition advanced users are more likely to switch to a more native IMAP/SMTP email client.

You could respectfully approach the Mailvelope folks.

If you are a paying customer of web.de or gmx, you could send a written problem report.
(And if you have the time, publicity might help your cause.)

Mmm. The companies do not expend energy on enabling their customers — who are not particularly tech-savvy — to reply to specific, yet standards-compliant, emails in the first place. That’s a difference.

Maybe the first post wasn’t that clear: I’m running my own MX successfully a couple of years. All the research I made was for testing purpose, nor as a regular customer of United Internet. And not primary to blame the company, but to enable a close relative to communicate with me.

Mmm². Why I should bother a project for an issue NOT using their software?

I totally agree! But where to start?

This is just general advise from my personal experience, what I would consider doing:

Help the person that is a customer of United internet to write a good problem report
and send it to them. That is good custom. Wait a few days to see their reaction.

If the reaction is good, you are fine.

If there is no reaction or an inadequate one, you can publish the report in a way that many people understand the issue. Use whatever publication platform you have, e.g. a blog or the fediverse. Help people find this report of yours. A next step could be to gather more users of their services that ask United internet about this defect.

The Mailvelope people also have an interest that crypto mails works fine and they could have a better relation to the United Internet people, because they are using Mailvelope for the web based products.

All those ideas cost time and they are little steps, so do not expect them to change much or quickly. However, you never know. A well documented case of a usability defect might at some time get more attention and be fixed.

Regards,
Bernhard

Resounding success looks different, but I’ll stay tuned anyway. Thanks for your tip.

Thanks for the report to mailvelope.

Do have screenshots?
More details about which revisions behave badly?

Regards,
Bernhard