# Who uses enigmail? Why don't banks use it?

**URL:** https://boards.straightdope.com/t/who-uses-enigmail-why-dont-banks-use-it/627185
**Category:** Factual Questions
**Created:** [July 4, 2012, 5:50am UTC](https://boards.straightdope.com/t/who-uses-enigmail-why-dont-banks-use-it/627185 "2012-07-04T05:50:39Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Measure\_for\_Measure](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/measure_for_measure/32/557_2.png) [@Measure\_for\_Measure](https://boards.straightdope.com/u/Measure_for_Measure)
#### Post date: [July 4, 2012, 5:50am UTC](https://boards.straightdope.com/t/who-uses-enigmail-why-dont-banks-use-it/627185/1 "2012-07-04T05:50:39Z")

</div>

Enigmail is a utility that permits email encryption: it is an addon to the [Mozilla Thunderbird](http://www.mozilla.org/en-US/thunderbird/) email program.

Who uses enigmail? Is it mostly used within a single business or between friends and family? Or is it used between businesses? AFAIK, banks don’t publish their public key (if they have one) and they don’t ask their customers for one.

Obviously, few financial institutions want to get involved with configuring their customers’ computers. But why is there so little interest in creating secure email? I suppose there’s a chicken and egg problem.

Relevant thread: [Encrypting email](http://boards.straightdope.com/sdmb/showthread.php?p=15215259) from a few days ago.  
Message board: [Enigmail forum](http://www.mozilla-enigmail.org/forum/index.php).

---

<div class="post-metadata">

### Author: ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)
#### Post date: [July 4, 2012, 6:06am UTC](https://boards.straightdope.com/t/who-uses-enigmail-why-dont-banks-use-it/627185/2 "2012-07-04T06:06:08Z")

</div>

Businesses generally don’t use Thunderbird, and when there’s a requirement for large busineases to do mail encryption, it would be done uniformly across their whole estate, imposed by the mail server and policies, and using certificates rather than individual keys.

Sounds like enigmail is a good solution for individuals though.

---

<div class="post-metadata">

### Author: ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)
#### Post date: [July 4, 2012, 12:42pm UTC](https://boards.straightdope.com/t/who-uses-enigmail-why-dont-banks-use-it/627185/3 "2012-07-04T12:42:11Z")

</div>

Also, there’s still something of a perception (slowly improving) in big businesses that open-source software is risky or unreliable, or that getting properly organised support could be a problem - case in point: the documentation and support links in that forum don’t seem to work - if I were to suggest today to my Operations team that this product was worth considering, my request would be summarily thrown out on the basis of these dead links.

---

<div class="post-metadata">

### Author: ![Derleth](https://avatars.discourse-cdn.com/v4/letter/d/b9e5f3/32.png) [@Derleth](https://boards.straightdope.com/u/Derleth)
#### Post date: [July 5, 2012, 4:43am UTC](https://boards.straightdope.com/t/who-uses-enigmail-why-dont-banks-use-it/627185/4 "2012-07-05T04:43:26Z")

</div>

> [@Mangetout](#):
>
> Also, there’s still something of a perception (slowly improving) in big businesses that open-source software is risky or unreliable

Except a _lot_ of web servers run Apache. A _lot_.

I don’t doubt your general statement, but there do seem to be exceptions.
