Live data from Hacker News

Thunderbird 60.0 release

thunderbird.net

11–20 of 57 posts

Re: Thunderbird 60.0 release

#11

> FIDO U2F support Sweet, although IIRC several of the email providers with 2FA (Gmail and Outlook come to mind) have the option of providing app-passwords instead, which bypass the need for a 2FA token.

Just so you know, an app password downgrades the security of your 2FA+Password pairing, and I never use app paswords because of that. If it was somehow possible to intercept the password used in the IMAP handshake, then that means access to your inbox without 2FA. This is why I am a huge fan of web-based clients and not things like Thunderbird.

> This is why I am a huge fan of web-based clients and not things like Thunderbird.

A false dichotomy. 2FA login is achieved through "web login", where an authentication token is obtained by presenting the service's 2FA interface in a web frame or a simple web browser. See e.g. the initial setup flow in Android 4.x - the Google login and password are a regular form, but if 2FA is enabled, you're shown a web browser.

Whether clients like Thunderbird implement web login remains a quality of implementation issue...

Re: Thunderbird 60.0 release

#12

> FIDO U2F support Sweet, although IIRC several of the email providers with 2FA (Gmail and Outlook come to mind) have the option of providing app-passwords instead, which bypass the need for a 2FA token.

Just so you know, an app password downgrades the security of your 2FA+Password pairing, and I never use app paswords because of that. If it was somehow possible to intercept the password used in the IMAP handshake, then that means access to your inbox without 2FA. This is why I am a huge fan of web-based clients and not things like Thunderbird.

IMAP authentication is done within SSL, so you'd have to start with an SSL MITM to be able to access the password login anyways. If you're scared about people having access to that, there are quite a few password authentication schemes baked into IMAP that don't leak your password over the network (SCRAM-SHA-256, anybody?). That said, all IMAP servers in practice implement only plaintext auth, or maybe NTLM and Kerberos.

Re: Thunderbird 60.0 release

#13
I currently have Thunderbird installed from apt but pinned to an ancient version that allows Lightning (the calendar tool) to work. (Newer versions broke Lightning on Linux, although I can't recall the failure mode.) Maybe I'll try out Thunderbird 60 on my work computer to see if it works better now...

It's funny, I actually only use Thunderbird for its calendar these days, not for email.

Re: Thunderbird 60.0 release

#14

Earlier quoted context omitted.

Just so you know, an app password downgrades the security of your 2FA+Password pairing, and I never use app paswords because of that. If it was somehow possible to intercept the password used in the IMAP handshake, then that means access to your inbox without 2FA. This is why I am a huge fan of web-based clients and not things like Thunderbird.

I could've sworn you had some granular level of control as far as what the apps are allowed to do when they access your Gmail account, e.g. Reading emails only versus read/reply/compose, etc. Maybe I'm thinking of OAuth. For some reason I also thought there was some way of tying the app's identity to the password, such that if an app other than Thunderbird tried to use my Gmail Thunderbird-app password, Gmail would b…

If you enable IMAP access, the only granularity of control you get is "total access" versus "no access."

Re: Thunderbird 60.0 release

#15
post #10

Gee I'm still on version 11. I tried updating once, got a ton of useless crap like calendars and shit and reverted back. Email is one of the few things that I want something very basic and crude.

If you're using Thunderbird 11, you are using a mail client full of security issues.

https://www.mozilla.org/en-US/security/known-vulnerabilities...

Re: Thunderbird 60.0 release

#16
The list of additions, changes and fixes look impressive! But I’m still worried about Thunderbird’s future and the planned rewrite. It’s a tough position to be in, (as if) attached at the hip to Firefox and to deal with the obsolescence of XUL extensions and other things that come part and parcel of using a good amount of code from Firefox.

I still believe it was a poor decision by Mozilla to cut off Thunderbird and float it as a community supported project. It now seems partially blessed by Mozilla, but isn’t how it was before that separation (AFAIK). The main thing I’ve felt as a huge missed opportunity with Thunderbird has been the lack of native Exchange calendar integration (no, none of the extensions, past and present, are close to even the experience of using Outlook web access for this purpose).

I’ll continue using Thunderbird for at least a few more years and will support the project financially, but I feel Outlook web access is slowly chipping away the need to use a desktop client in enterprise environments that are tied to Exchange or Office/Outlook 365.

Re: Thunderbird 60.0 release

#17

I downloaded this while it was in beta to see whether they'd fixed the scaling issues with mixed DPI setups in XWayland, or better yet, moved to native Wayland. Alas, this is not the case.

Firefox hasn't been ported to wayland, yet. So I wouldn't hold my breath for thunderbird

Re: Thunderbird 60.0 release

#18
post #10

Gee I'm still on version 11. I tried updating once, got a ton of useless crap like calendars and shit and reverted back. Email is one of the few things that I want something very basic and crude.

In that case may I recommend mutt or claws mail? Basic, unlikely to change significantly, and still getting security patches.

Re: Thunderbird 60.0 release

#19
post #10

Gee I'm still on version 11. I tried updating once, got a ton of useless crap like calendars and shit and reverted back. Email is one of the few things that I want something very basic and crude.

Careful. Old versions of internet-facing applications like email clients are dangerous and put you at risk. They often have widely known security issues which can allow malware to access your PC.

I'd advise upgrading Thunderbird and ignoring the features you don't use, or switching to an actively-maintained mail client which is designed to be simpler than Thunderbird.

Post reply on HN