cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
FMorschel
Strollin' around
Status: New idea

Problem you are trying to solve

I'd like to keep my email more secure.
I live in a country where stolen phones are really common. There is a trend of phones being stolen while the owner has them unlocked, and they try not to click on the power button to keep the screen on so they can access the data.

Suggested solution

I'd like to propose that the Thunderbird Android app has a security feature similar to the one on the desktop app, where there is a need for a password.

My actual request would be to have a password to lock the email app and possibly allow biometrics to unlock it.

There could be a timer to lock it again similar to what WhatsApp already has.

Screenshots / Drawings / Technical details

Options available on WhatsApp as a reference below.

We could also have an option to ommit the data on the notifications with the unlocked phone  as well as the option we already have for the locked screen.

Both ideas were first described at:
- https://github.com/thunderbird/thunderbird-android/issues/7529

- https://github.com/thunderbird/thunderbird-android/issues/7530

 

19 Comments
Teun
New member

There are various apps called applock, spelled in various ways and with addition like Pro. Which one do you use? I prefer to follow your advice rather than try them all myself...

NightOwl17
Strollin' around

It's only on f-droid or github. It's just called app lock. The developper is Pranav Purwar. It's free, open source and no ads, no accounts.

 

There is only one feature it doesn't have that the ones with adds on google play store have is that it doesn't take a picture of someone that tries and fails to unlock 5 times in a row. But then I realized it's not that useful as your phone already has its own locker. This is just for apps so if someone has access to your apps, you would already know who it is because you would already have given your phone to someone. If your phone is stolen they still can't open your phone and you can have a picture taken there.

 

https://f-droid.org/packages/dev.pranav.applock

nathanael
Strollin' around

a biometric lock option for thunderbird mobile would be great. almost any other app on my device with sensitive information has this today

bayraktarozcan
New member

I strongly support this feature request, and I believe it should be considered a security and privacy control rather than merely a convenience feature.

Thunderbird for Android provides access to highly sensitive information, including private correspondence, attachments, personal data, password-reset messages, account-recovery links, authentication codes, and potentially confidential business information. Once an Android device is unlocked, the device-level authentication boundary no longer protects the Thunderbird application itself.

This creates a practical security gap in scenarios where a device is lost, stolen, temporarily handed to another person, or otherwise accessed while it is already unlocked. Protecting the device alone is therefore not always sufficient to protect the confidentiality of the information stored and displayed by an email client.

A dedicated application-level authentication mechanism would provide an additional security boundary for Thunderbird.

From a secure-development perspective, this is also consistent with established mobile application security practices. OWASP MASVS explicitly addresses secure local authentication and additional authentication for sensitive functionality (MASVS-AUTH-2 and MASVS-AUTH-3). Android itself provides platform-supported mechanisms such as BiometricPrompt, hardware-backed Android Keystore and authentication-bound cryptographic keys for implementing this securely.

I would therefore suggest that the implementation should ideally provide:

  • An optional application lock for Thunderbird.

  • Strong biometric authentication where supported by the device.

  • Secure fallback to the device credential (PIN, pattern or password), where appropriate.

  • Automatic re-locking after a configurable period of inactivity.

  • Re-authentication after the application returns from the background, based on the user's selected timeout.

  • Protection of the actual sensitive application data or cryptographic keys, rather than relying solely on a UI-level authentication check.

  • Proper invalidation and re-provisioning of authentication-bound keys when biometric enrollment changes.

  • Protection against bypass through activities, deep links, notifications, background tasks or other application entry points.

  • No exposure of sensitive message content on the lock screen or in notifications when the application is locked.

  • A clear security model explaining what remains protected while Thunderbird is locked and what information may still be exposed through Android system components.

The Android security architecture already provides the necessary building blocks for this approach. BiometricPrompt can be combined with Android Keystore and authentication-bound cryptographic operations, allowing access to protected secrets to depend on successful user authentication rather than merely on a client-side boolean or UI event.

This is also consistent with broader industry practice. Security standards and frameworks across mobile, payment and enterprise environments increasingly treat strong authentication, least privilege and protection of sensitive data as layered controls. PCI Security Standards Council and EMVCo provide examples of the broader industry adoption of strong authentication and consumer-device verification mechanisms, while Android and OWASP provide directly applicable technical guidance for mobile applications.

I therefore believe that application-level authentication for Thunderbird Android deserves consideration as a genuine security and privacy capability, not simply as a user-interface enhancement.

The existing request has been open for a considerable period, and the underlying requirement remains relevant. I would appreciate it if this feature could be reassessed against the current Thunderbird Android security architecture and current Android security capabilities.