Security 10745 Published by

Despite settings to the contrary, plaintext messages stored on IMAP servers.



From ArsTechnica:
On Thursday, independent privacy and security researcher Ashkan Soltani was shocked to make the same discovery after finding that GPG-protected e-mails he received from others were stored unencrypted in the drafts folder of his Gmail account. The messages had been automatically saved immediately after he hit the reply button, just below where he would type his response. Like other Mavericks users, he had specifically configured his system not to save such messages when using the Internet Message Access Protocol (IMAP) in Gmail. Without warning, the unchecked checkmarks inexplicably reappeared.

"This is an example of things falling apart at the seams at the integration points," Soltani told Ars. "A lot of people don't use the Gmail browser. They just use Gmail for IMAP. I just happened to have Gmail in the browser opened. Most people wouldn't know about it. I was really shocked."
  SecOps failure: GPG+Gmail on OSX Mavericks may store unencrypted drafts