Welcome to the mailbox user forum
 

Beware - Guard isn't signing out properly

Maximus shared this problem 21 hours ago
Published

To reproduce:

1. Sign in to mailbox with your username, main password, and Guard password (if prompted to do so when opening an encrypted email or document)

2. Sign out of mailbox (either via the top right sign out icon OR by clicking the my account icon and selecting the third option to "sign out"). Do NOT click "sign out mailbox Guard." Signing out of your account is supposed to also sign you out of Guard.

3. Sign back into mailbox. Click my account icon at the top right. You should not see the option to "Sign out mailbox guard" because you when signed out of your account, it should have also automatically signed you out of Guard simultaneously. So far everything looks good, but it's not.

4. You think you were signed out of Guard, but you really weren't. Try opening an encrypted email or file and voila! Easy access, just like that. No Guard password needed. Turns out it was STILL ACTIVE the whole time. What kind of security risk or broken promises are we dealing with here? Now navigate back up to your my account icon and you'll see "Sign out mailbox guard" now appears, even though YOU NEVER SIGNED IN WITH YOUR GUARD PASSWORD.

What does work: signing out of your Guard password first, then signing out of your account.

What troubles me: If this behavior is isolated to me, that means its a targeted attack, which means any one of you could be next and mailbox absolutely cannot be trusted with your keys. If this behavior is not isolated to me, it means we're all dealing with anything from poor programming and/or design choices yet again (best case) to a larger scale security risk for the entire mailbox community (worst case).

Please try reproducing and post your results here so we can help each other. In the meantime, I will be reaching out to support. Wait times are very long so it may be weeks before I get a response.

Replies (1)

photo
1

I don't use the guard service, so i have no way of testing it right now.

Which option did you select in the guard settings: “Remember password default setting”?

photo
1

Thanks for your response! Good question. Mailbox Guard "remember password default" is set to "Session", per my usual settings. I have had it set to "Session" for years and it's never remained signed in when I sign out until recently.

Nothing more dangerous than the illusion of privacy and security.

photo
Leave a Comment
 
Attach a file
You can't vote. Please authorize!