It is currently Wed Jun 19, 2013 9:13 pm

All times are UTC - 8 hours




Post new topic Reply to topic  [ 12 posts ] 
Author Message
 Post subject: Mozilla Thunderbird Portable privacy issue [resolved]
PostPosted: Mon Nov 15, 2010 3:04 pm 
Offline
User avatar

Joined: Wed Apr 11, 2007 8:06 pm
Posts: 3534
Location: US, Texas
I noticed a privacy problem with a SeaMonkey test and Thunderbird (v3.1.6) appears to exhibit the same behavior (unsurprising since its based on the same code). It creates "HKCU\Software\Microsoft\Windows\CurrentVersion\UnreadMail\username@domain.com" in the registry. This is a privacy issue because if you're checking your email on a public terminal, you obviously don't want your email address left behind.

Oddly, I have multiple email addresses setup under my copy of Thunderbird and it seems to only list one of them. I guess it only stores the default address? I tried manually removing the registry entry and restarting and it came right back.

Can someone verify this is happening on more than just my machine? I have several plugins running that may be polluting my test results. I also have not checked to see if X-Thunderbird has this issue.


Setup/Software:

_________________
Supporting the Electronic Frontier Foundation | DuckDuckGo user | My GPG key | Projects donated to: VLC, CubicExplorer, Ditto, Greenshot, TrueCrypt, WinSplit


Last edited by webfork on Thu Apr 28, 2011 8:31 am, edited 3 times in total.
(minor edits for clarity/grammar)


Top
 Profile  
 
 Post subject: Re: Mozilla Thunderbird Portable privacy issue
PostPosted: Mon Nov 15, 2010 9:48 pm 
Offline
User avatar

Joined: Sat Mar 31, 2007 2:38 am
Posts: 906
Location: Kce,PL
Not confirmed, XP x64.

_________________
Image


Top
 Profile  
 
 Post subject: Re: Mozilla Thunderbird Portable privacy issue
PostPosted: Wed Nov 17, 2010 11:15 am 
Offline
User avatar

Joined: Wed Apr 11, 2007 8:06 pm
Posts: 3534
Location: US, Texas
Tested on a clean WinXP install and it showed up. I guess its just a 32-bit issue.

_________________
Supporting the Electronic Frontier Foundation | DuckDuckGo user | My GPG key | Projects donated to: VLC, CubicExplorer, Ditto, Greenshot, TrueCrypt, WinSplit


Top
 Profile  
 
 Post subject: Re: Mozilla Thunderbird Portable privacy issue
PostPosted: Wed Nov 17, 2010 3:34 pm 
Offline

Joined: Sat Aug 22, 2009 12:26 pm
Posts: 31
i confirm that.
webfork wrote:
Oddly, I have multiple email addresses setup under my copy of Thunderbird and it seems to only list one of them. I guess it only stores the default address? I tried manually removing the registry entry and restarting and it came right back.

Setup/Software:
i also removed it and can confirm that it came back. it's only one address, even if i did not open the account the address belongs to.
under the mentioned key there is an entry "Application" with value " "D:\...\App\thunderbird\thunderbird.exe" -profile "D:\...\Data\profile" -mail ".


Top
 Profile  
 
 Post subject: Re: Mozilla Thunderbird Portable privacy issue
PostPosted: Wed Nov 17, 2010 4:41 pm 
Offline
User avatar

Joined: Wed Apr 11, 2007 8:06 pm
Posts: 3534
Location: US, Texas
Thanks fang. I'll post a note on the entry.

_________________
Supporting the Electronic Frontier Foundation | DuckDuckGo user | My GPG key | Projects donated to: VLC, CubicExplorer, Ditto, Greenshot, TrueCrypt, WinSplit


Top
 Profile  
 
 Post subject: Re: Mozilla Thunderbird Portable privacy issue
PostPosted: Wed Nov 17, 2010 5:46 pm 
Offline

Joined: Sat Aug 22, 2009 12:26 pm
Posts: 31
maybe other versions don't have this issue.


Top
 Profile  
 
 Post subject: Re: Mozilla Thunderbird Portable privacy issue
PostPosted: Wed Nov 17, 2010 6:46 pm 
Offline
User avatar

Joined: Wed Feb 10, 2010 4:44 pm
Posts: 407
Location: New York, NY
Current version should not have this issue. It was an old bug around some Windows versions not having the registry key already in existence (although it should exist) and the launcher not interpreting that properly. TBP 3.1.6 should not have this issue and has code specifically to test and correct for this case (see lines 398-402 and 435-436 in ThunderbirdPortable.nsi). TBP 2.0.0.24 is no longer supported so any bugs in it won't be addressed and should not be seen as confirmation of a bug in a current release.

If you are able to get the bug to re-appear with a current release, please post the steps you did to reproduce it and I'll go about trying to reproduce and address the specific condition.

In the meantime, I have updated the bug to detail the issue as it definitely does not occur on any PC where HKCU\Software\Microsoft\Windows\CurrentVersion\UnreadMail already exists and doesn't appear to occur for most users where it doesn't. If there is a regression and it does occur on some versions of Windows, it would leave your account name there (which some users may inadvertently set to their email address).

Last I checked, this bug existed in all unlicensed versions of TB done portably but does not exist in ours. At least it didn't about 2 point releases ago. I'll check to see if there is a regression in that code and if there is, do a revision of both TBP and SMP tomorrow morning (NY time).

When this happened last time (quite a while ago as I recall), I wrote a utility to fix the counts and remove the additional entries in the registry and reset the mail counts:
http://johnhaller.com/jh/useful_stuff/r ... il_counts/

(it may give an error about not installing properly on Vista/7 but that error can be ignored)

_________________
PortableApps.com - The open standard for portable software


Top
 Profile  
 
 Post subject: Re: Mozilla Thunderbird Portable privacy issue
PostPosted: Wed Nov 17, 2010 9:43 pm 
Offline

Joined: Wed Jul 18, 2007 5:45 pm
Posts: 618
@johnhaller - I couldn't find TB portable 2.0.0.24 on the portableapps.com site. As judging from this thread - http://portableapps.com/node/23080 - some people (including me) would prefer to see it as well.

_________________
is it stealth? ;)


Top
 Profile  
 
 Post subject: Re: Mozilla Thunderbird Portable privacy issue
PostPosted: Wed Nov 17, 2010 11:30 pm 
Offline
User avatar

Joined: Sat Jul 31, 2010 1:19 am
Posts: 825
Location: Helsinki, Finland
freakazoid wrote:
@johnhaller - I couldn't find TB portable 2.0.0.24 on the portableapps.com site. As judging from this thread - http://portableapps.com/node/23080 - some people (including me) would prefer to see it as well.


http://sourceforge.net/projects/portableapps/files/Mozilla%20Thunderbird%2C%20P.E./Mozilla%20Thunderbird%2C%20Portable%20Edition%202.0.0.24/ ;)

_________________
My YouTube channel | Release date of my fourth playlist: April 11, 2013


Top
 Profile  
 
 Post subject: Re: Mozilla Thunderbird Portable privacy issue
PostPosted: Thu Nov 18, 2010 7:26 am 
Offline
User avatar

Joined: Wed Feb 10, 2010 4:44 pm
Posts: 407
Location: New York, NY
freakazoid wrote:
@johnhaller - I couldn't find TB portable 2.0.0.24 on the portableapps.com site. As judging from this thread - http://portableapps.com/node/23080 - some people (including me) would prefer to see it as well.


You're welcome to grab it from SourceForge but you absolutely should not be using it anymore. Thunderbird 2.x has been discontinued and is no longer supported. With things like email clients and browsers, this is a HUGE deal as security issues won't be patched. So, all it takes is someone with your address to get infected and have their malware send an email to you that exploits a bug in an old email client and your PC is infected. Or one of the botnets to send it to you (and if you have ever gotten a single piece of spam, the spammers/scammers have your address).

I would highly suggest you either switch to a supported version or switch to another email client. You're at risk now (and putting every PC you use the client on at risk) and that will only get worse with time.

_________________
PortableApps.com - The open standard for portable software


Top
 Profile  
 
 Post subject: Re: Mozilla Thunderbird Portable privacy issue
PostPosted: Thu Nov 18, 2010 7:46 am 
Offline
User avatar

Joined: Wed Apr 11, 2007 8:06 pm
Posts: 3534
Location: US, Texas
Here's a full bug report. I'm aware I should do this on the official site rather than here so I can move it if needed.

Setup: Clean copy of WinXP SP3 32-bit under VMware so I have the 'snapshots' feature I can go back to.

Steps:

  1. Start Settings Explorer and use its snapshot (not the same as the VMware one) feature to track the registry before and after
  2. Download and start up Thunderbird
  3. Setup an IMAP mail account (I don't actually download any mail but I can run that test if needed)
  4. Close the program
  5. Run snapshot again and compare

Defect: Email address present in registry

Workaround (if you don't know the Windows registry well, use with caution): Open regedit (may require admin privileges) and do a search for the email address. Right click the registry entry and delete.

If more detail is needed on any of these steps including logs, I can provide.

fang-face wrote:
maybe other versions don't have this issue.

I added a note to that thread to sort of address this. Even if they don't, I'd probably rather stick with a more-official version for other reasons.

Edit: That's WinXP SP2, not SP3.

_________________
Supporting the Electronic Frontier Foundation | DuckDuckGo user | My GPG key | Projects donated to: VLC, CubicExplorer, Ditto, Greenshot, TrueCrypt, WinSplit


Last edited by webfork on Thu Jan 13, 2011 6:02 pm, edited 3 times in total.
(added workaround, fang response)


Top
 Profile  
 
 Post subject: Re: Mozilla Thunderbird Portable privacy issue
PostPosted: Thu Dec 09, 2010 7:24 pm 
Offline
User avatar

Joined: Wed Feb 10, 2010 4:44 pm
Posts: 407
Location: New York, NY
I added an additional fix to the 3.1.7 release that makes doubly sure that this key is not left behind. It's been tested on clean-install PCs with no mail count that are missing this key (which seems to be a factor in the issue for some people). If you have left this key behind on any PC, I have a utility that fixes it from a while back here:
http://johnhaller.com/jh/useful_stuff/r ... il_counts/

The same patch was applied to SeaMonkey 2.0.11.

_________________
PortableApps.com - The open standard for portable software


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 12 posts ] 

All times are UTC - 8 hours


Who is online

Users browsing this forum: No registered users and 13 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  

Protected by Anti-Spam ACP Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group