Hi!
I investigated carefully, but found no related topic elsewhere. This is the issue:
The sender sends a PGP/Mime-signed, unencrypted email to the recipient at web.de or GMX. The recipient uses the respective Android app or web interface of the two United Internet brands.
I performed the following steps with GMX, and also conducted some random tests with web.de, finding no difference. To simulate the most realistic handling of the received, signed emails, I used MS Edge with a completely new browser profile in a virtual machine.
The first oddity appeared as soon as the signed email was read:
»Verschlüsselte Kommunikation wird von Ihrem aktuellen Browser nicht unterstützt! Um verschlüsselte Kommunikation auf diesem Computer verwenden zu können, nutzen Sie bitte Mozilla Firefox oder Google Chrome. (Encrypted communication is not supported by your current browser! To use encrypted communication on this computer, please use Mozilla Firefox or Google Chrome.)«
Aha. I didn’t understand why this should concern me, a hypothetical average GMX customer who’d never heard of Mailvelope or any other such fancy stuff, and ignored the message. So I cheerfully clicked the »Antworten (Reply)« button and found myself on the email composition settings page, with no mention of encryption. Back to the composition page, now next to the »Von (From)« address in GMX, it says »Verschlüsselt senden (Send encrypted)«. The wonders never end, but hey, fortune favors the bold! So I confidently clicked the button again, but now the disappointment is immense, and the error message reads:
»Ihre E-Mail konnte nicht versandt werden. (Your email could not be sent).«
What a pity! I’ve already written half an encyclopedia as a reply to the original sender and I don’t want to lose it. Since I’ve become quite used to miracles, I bravely clicked the »Verschlüsselt speichern (Save encrypted)« button, but oh dear, now the error message reads:
»Fehler beim Verarbeiten Ihres PGP Entwurfs. Möchten Sie den Entwurf verwerfen? (Error processing your PGP draft. Do you want to discard the draft?)«
Not really, since I spent quite some time writing the reply. And what’s PGP anyway? At this point, the average GMX customer should be desperately abandoning this magical email thing and only want to communicate with the sender via SMS or WhatsApp.
The whole dilemma
-
was no different with the GMX Mail app, only the error message was less specific,
-
regardless of the key type used to create the signature, i.e., ECC or RSA,
-
regardless of enabled or disabled autocrypt
-
and regardless of the sender domain used
When using a generic mail user agent such as Thunderbird, FairEmail or Kmail to connect with GMX, the error was not reproducible; the signatures were treated like any other attachment, and a »Re:« to the signed email showed no abnormalities.
Now I’m wondering if I’m really the first person to notice this behavior, if I’ve overlooked an RFC that forces recipients of signed emails to set up PGP, or if I’ve simply made an embarrassing logical error.
I would appreciate any clarification or confirmation of my bug report.