Show the Sender header in the message pane
Carsten N. from JonDos suggested that we set mailnews.headers.showSender
to true
; doing this will show the Sender
header in the message pane.
In a nutshell: setting this to true
can help enhance X509 certificate validation where an attacker may use a fake From
header. This is not a complete solution but it may help attacks described in the article http://heise.de/-2044405.
It was also suggested to make this a default option in Thunderbird. https://bugzilla.mozilla.org/show_bug.cgi?id=332639