BBC 'vague' reporting again!

Roland Perry ukcrypto at chiark.greenend.org.uk
Tue, 2 Dec 2008 04:42:41 +0000


In article <493404C4.8000007@pmsommer.com>, Peter Sommer 
<peter@pmsommer.com> writes
>I do recognise, though,  there'd be an interesting case to be made in 
>respect of an email delivered to the PC but not yet read by the owner - 
>a fact which could be established by looking at the flags within the 
>email archive.

How many different email clients would a typical trojan be able to 
extract individual messages from?

For example: a relatively well known, but low volume client such as 
Turnpike. I am led to believe that the messagebase itself is encrypted, 
and would be surprised if the algorithms required to unpack and examine 
individual emails were 'in the wild', even if the encryption key could 
be discovered/broken.

Therefore, the only way to read the emails might be to intercept (sic) 
them as they arrived.
-- 
Roland Perry