Jump to content

Recommended Posts

Posted
The right thing to do would be assume TLS by default, and if that fails, ask the sending: This email cannot be sent encrypted, please slap the person you're trying to send it to. Also should I send it anyway? Yes/No
Posted
Notes on how you set that up in GMail would be epic - emails leaving us to social services etc. is one thing we're conscious of, as there is no way to avoid them containing personal information, and since we ditched Outlook we can't use things like Egress.

Egress has a web interface for sending and receiving emails so can be used without Outlook?

Posted
Egress has a web interface for sending and receiving emails so can be used without Outlook?

 

It can yes. You route the email into a relay. The connection between Gmail or OWA is secured via TLS.

Posted
We are looking at implementing Galaxkey which is used by our local Council for sending emails to other schools, LA etc securely and giving us control over how long the document is available to the recipient for and gives us audit capabilities on who has read them etc. It integrates into Exchange and other email platforms. https://www.galaxkey.com/
Posted
This is coming to Gmail natively soon.

 

Only if the recipient has a Google account. You can't set an expiry date on public or anyone-with-link.

Posted

Speaking of Egress I used to work for the local council that supported Egress. The council sold the support contract to another council in the North West and I was sent down for five days to train the new team up with how to support it.

 

It was a new manager and a brand new team and one of the guys kept saying router but in the American way (you know - as in "rau-ter"). The manger kept saying to him stop saying it like that say it properly. Five days in and he said it again on a call so she threw her phone at him and it dinked it him in the face. She walked out and never returned and I was left with 5 new members of staff all looking at me asking what to do now :D

 

Thank god it was my last day on the job

Posted
It was a new manager and a brand new team and one of the guys kept saying router but in the American way (you know - as in "rau-ter").

 

I used to work for an Australian company. They also say "rau-ter" but I had to start saying it that way too, because "roo-ter" is a rude word in Australian slang!

Posted

Did anyone see the recent exploit vulnerabilities in the OpenPGP and S/MIME standards today? The attacks break PGP and S/MIME email encryption by coercing clients into sending the full plaintext of the emails to the attacker - just made me think of this thread when I read it.

 

Bruce Schneier blogged about it and he seems to slightly suggest that unless you think the government is trying to hack your emails, then the risk of a random hacker targeting you and getting access to your emails via a MITM attack would be very unlikely. He didn't quite spell it out like that but that's how I took it! Makes me think even more that it seems a bit of a waste of time and money for schools to be buying in encryption to mitigate a risk that is very unlikely to occur and doesn't protect against the more common email attacks/risks.

Posted
Did anyone see the recent exploit vulnerabilities in the OpenPGP and S/MIME standards today? The attacks break PGP and S/MIME email encryption by coercing clients into sending the full plaintext of the emails to the attacker - just made me think of this thread when I read it.

 

Bruce Schneier blogged about it and he seems to slightly suggest that unless you think the government is trying to hack your emails, then the risk of a random hacker targeting you and getting access to your emails via a MITM attack would be very unlikely. He didn't quite spell it out like that but that's how I took it! Makes me think even more that it seems a bit of a waste of time and money for schools to be buying in encryption to mitigate a risk that is very unlikely to occur and doesn't protect against the more common email attacks/risks.

 

The attacker does need the encrypted email though. Turns out there's 2 attacks: 1. your email client is terrible, 2. the encryption kinda sucks

 

The most common problems are: 1 crap passwords, 2 people who let people find out their passwords, 3 sending to the wrong person, 4 losing a laptop, 5 ransomware, 6 phishing.

 

Sending another pw via a different method helps against 3, and possibly 1,2,4 because the email is kept forever

Posted
The attacker does need the encrypted email though. Turns out there's 2 attacks: 1. your email client is terrible, 2. the encryption kinda sucks

 

The most common problems are: 1 crap passwords, 2 people who let people find out their passwords, 3 sending to the wrong person, 4 losing a laptop, 5 ransomware, 6 phishing.

 

Sending another pw via a different method helps against 3, and possibly 1,2,4 because the email is kept forever

 

Yeah that report didn't live up the the hype in the original twitter thread. It's also avoidable by not loading remote content, which almost all 'corporate' email setups do anyway as a matter of course.

  • 1 month later...
Posted
Does anyone who uses MDM to enforce encryption and passwords on personal mobile devices have an AUP document they would be willing to share? Don't want to write one from scratch if there are good ones out there already.
Posted

Do we *need* to do so?

 

No.

 

Simple really. If you have taken precautions in training staff on password/security. You do not *need* encrypted emails.

 

Nothing stops you from using it, it's extra security but at the end of the day.. you don't *need* it.

Posted
I was looking for info about how to deploy S/MIME in a corporation yesterday, there's hardly any details online, I guess you'd need to buy a certificate that lets you create S/MIME certs for your domain, but no idea how much that is.
Posted
I was looking for info about how to deploy S/MIME in a corporation yesterday, there's hardly any details online, I guess you'd need to buy a certificate that lets you create S/MIME certs for your domain, but no idea how much that is.

 

It's pointless anyway - it's the recipient that needs to have an S/MIME cert in order for you to send them an encrypted email so buying them yourself just lets other people who use s/mime send you one, it doesn't let you send them to anyone else. And few people would know how to fetch your cert in order to send you an encrypted mail anyway.

Posted
It's pointless anyway - it's the recipient that needs to have an S/MIME cert in order for you to send them an encrypted email so buying them yourself just lets other people who use s/mime send you one, it doesn't let you send them to anyone else. And few people would know how to fetch your cert in order to send you an encrypted mail anyway.

 

Well, it lets you sign your outgoing email, to prove it's a) from you and b) not altered, but yeah, until it's free and automatic it's pointless, obviously so few people do it that there's no information out there about how to do it.

Posted
No.

 

Simple really. If you have taken precautions in training staff on password/security. You do not *need* encrypted emails.

 

Nothing stops you from using it, it's extra security but at the end of the day.. you don't *need* it.

Some public bodies will only accept data transferred via some form of encryption, be it Egress Switch or in our case Office 365 Message Encryption... that's been our experience anyway
Posted
Some public bodies will only accept data transferred via some form of encryption, be it Egress Switch or in our case Office 365 Message Encryption... that's been our experience anyway

 

But will they set up s/mime? hah

 

- - - Updated - - -

 

@rogerdnixon has done a pretty good job of documenting how to enable S/MIME

 

https://wpsit.blogspot.com/2018/06/smime-email-signature-and-encryption.html

 

 

Right, but the main issue is how to create the certs, for everyone, automatically, without a per user cost

Posted

I don't think you'd need to setup certificates for everyone, just some key people in safeguarding, pastoral and leadership teams.

I think it's one of those things that will start to build up momentum. As soon as a few schools start using it and setting up rules so that certain email get encrypted automatically it will snowball because the recipients will be asking their IT teams to implement it too.

Posted
It's encrypted on the server (well, except everyone uses webmail), it's per user encryption, not per site, and it also adds authentication, so you can prove an email was sent by you, and wasn't altered.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...