mavhc Posted May 13, 2018 Posted May 13, 2018 The right thing to do would be assume TLS by default, and if that fails, ask the sending: This email cannot be sent encrypted, please slap the person you're trying to send it to. Also should I send it anyway? Yes/No
Edu-IT Posted May 13, 2018 Posted May 13, 2018 Notes on how you set that up in GMail would be epic - emails leaving us to social services etc. is one thing we're conscious of, as there is no way to avoid them containing personal information, and since we ditched Outlook we can't use things like Egress. Egress has a web interface for sending and receiving emails so can be used without Outlook?
FN-GM Posted May 13, 2018 Posted May 13, 2018 Egress has a web interface for sending and receiving emails so can be used without Outlook? It can yes. You route the email into a relay. The connection between Gmail or OWA is secured via TLS.
markberry Posted May 14, 2018 Posted May 14, 2018 We are looking at implementing Galaxkey which is used by our local Council for sending emails to other schools, LA etc securely and giving us control over how long the document is available to the recipient for and gives us audit capabilities on who has read them etc. It integrates into Exchange and other email platforms. https://www.galaxkey.com/
FN-GM Posted May 14, 2018 Posted May 14, 2018 giving us control over how long the document is available to the recipient for and gives us audit capabilities on who has read them etc. https://www.galaxkey.com/ This is coming to Gmail natively soon.
enjay Posted May 14, 2018 Posted May 14, 2018 This is coming to Gmail natively soon. Only if the recipient has a Google account. You can't set an expiry date on public or anyone-with-link.
Edutech98 Posted May 14, 2018 Posted May 14, 2018 Speaking of Egress I used to work for the local council that supported Egress. The council sold the support contract to another council in the North West and I was sent down for five days to train the new team up with how to support it. It was a new manager and a brand new team and one of the guys kept saying router but in the American way (you know - as in "rau-ter"). The manger kept saying to him stop saying it like that say it properly. Five days in and he said it again on a call so she threw her phone at him and it dinked it him in the face. She walked out and never returned and I was left with 5 new members of staff all looking at me asking what to do now Thank god it was my last day on the job
enjay Posted May 14, 2018 Posted May 14, 2018 It was a new manager and a brand new team and one of the guys kept saying router but in the American way (you know - as in "rau-ter"). I used to work for an Australian company. They also say "rau-ter" but I had to start saying it that way too, because "roo-ter" is a rude word in Australian slang!
Edutech98 Posted May 15, 2018 Posted May 15, 2018 Did anyone see the recent exploit vulnerabilities in the OpenPGP and S/MIME standards today? The attacks break PGP and S/MIME email encryption by coercing clients into sending the full plaintext of the emails to the attacker - just made me think of this thread when I read it. Bruce Schneier blogged about it and he seems to slightly suggest that unless you think the government is trying to hack your emails, then the risk of a random hacker targeting you and getting access to your emails via a MITM attack would be very unlikely. He didn't quite spell it out like that but that's how I took it! Makes me think even more that it seems a bit of a waste of time and money for schools to be buying in encryption to mitigate a risk that is very unlikely to occur and doesn't protect against the more common email attacks/risks.
mavhc Posted May 15, 2018 Posted May 15, 2018 Did anyone see the recent exploit vulnerabilities in the OpenPGP and S/MIME standards today? The attacks break PGP and S/MIME email encryption by coercing clients into sending the full plaintext of the emails to the attacker - just made me think of this thread when I read it. Bruce Schneier blogged about it and he seems to slightly suggest that unless you think the government is trying to hack your emails, then the risk of a random hacker targeting you and getting access to your emails via a MITM attack would be very unlikely. He didn't quite spell it out like that but that's how I took it! Makes me think even more that it seems a bit of a waste of time and money for schools to be buying in encryption to mitigate a risk that is very unlikely to occur and doesn't protect against the more common email attacks/risks. The attacker does need the encrypted email though. Turns out there's 2 attacks: 1. your email client is terrible, 2. the encryption kinda sucks The most common problems are: 1 crap passwords, 2 people who let people find out their passwords, 3 sending to the wrong person, 4 losing a laptop, 5 ransomware, 6 phishing. Sending another pw via a different method helps against 3, and possibly 1,2,4 because the email is kept forever
djrscally Posted May 15, 2018 Posted May 15, 2018 The attacker does need the encrypted email though. Turns out there's 2 attacks: 1. your email client is terrible, 2. the encryption kinda sucks The most common problems are: 1 crap passwords, 2 people who let people find out their passwords, 3 sending to the wrong person, 4 losing a laptop, 5 ransomware, 6 phishing. Sending another pw via a different method helps against 3, and possibly 1,2,4 because the email is kept forever Yeah that report didn't live up the the hype in the original twitter thread. It's also avoidable by not loading remote content, which almost all 'corporate' email setups do anyway as a matter of course.
fiza Posted June 20, 2018 Posted June 20, 2018 Does anyone who uses MDM to enforce encryption and passwords on personal mobile devices have an AUP document they would be willing to share? Don't want to write one from scratch if there are good ones out there already.
mthomas08 Posted June 21, 2018 Posted June 21, 2018 Do we *need* to do so? No. Simple really. If you have taken precautions in training staff on password/security. You do not *need* encrypted emails. Nothing stops you from using it, it's extra security but at the end of the day.. you don't *need* it.
mavhc Posted June 21, 2018 Posted June 21, 2018 I was looking for info about how to deploy S/MIME in a corporation yesterday, there's hardly any details online, I guess you'd need to buy a certificate that lets you create S/MIME certs for your domain, but no idea how much that is.
djrscally Posted June 21, 2018 Posted June 21, 2018 I was looking for info about how to deploy S/MIME in a corporation yesterday, there's hardly any details online, I guess you'd need to buy a certificate that lets you create S/MIME certs for your domain, but no idea how much that is. It's pointless anyway - it's the recipient that needs to have an S/MIME cert in order for you to send them an encrypted email so buying them yourself just lets other people who use s/mime send you one, it doesn't let you send them to anyone else. And few people would know how to fetch your cert in order to send you an encrypted mail anyway.
mavhc Posted June 21, 2018 Posted June 21, 2018 It's pointless anyway - it's the recipient that needs to have an S/MIME cert in order for you to send them an encrypted email so buying them yourself just lets other people who use s/mime send you one, it doesn't let you send them to anyone else. And few people would know how to fetch your cert in order to send you an encrypted mail anyway. Well, it lets you sign your outgoing email, to prove it's a) from you and b) not altered, but yeah, until it's free and automatic it's pointless, obviously so few people do it that there's no information out there about how to do it.
mjk Posted June 25, 2018 Posted June 25, 2018 I was looking for info about how to deploy S/MIME in a corporation yesterday, there's hardly any details online, I guess you'd need to buy a certificate that lets you create S/MIME certs for your domain, but no idea how much that is. @rogerdnixon has done a pretty good job of documenting how to enable S/MIME https://wpsit.blogspot.com/2018/06/smime-email-signature-and-encryption.html
gshaw Posted June 25, 2018 Posted June 25, 2018 No. Simple really. If you have taken precautions in training staff on password/security. You do not *need* encrypted emails. Nothing stops you from using it, it's extra security but at the end of the day.. you don't *need* it.Some public bodies will only accept data transferred via some form of encryption, be it Egress Switch or in our case Office 365 Message Encryption... that's been our experience anyway
mavhc Posted June 26, 2018 Posted June 26, 2018 Some public bodies will only accept data transferred via some form of encryption, be it Egress Switch or in our case Office 365 Message Encryption... that's been our experience anyway But will they set up s/mime? hah - - - Updated - - - @rogerdnixon has done a pretty good job of documenting how to enable S/MIME https://wpsit.blogspot.com/2018/06/smime-email-signature-and-encryption.html Right, but the main issue is how to create the certs, for everyone, automatically, without a per user cost
mjk Posted June 26, 2018 Posted June 26, 2018 I don't think you'd need to setup certificates for everyone, just some key people in safeguarding, pastoral and leadership teams. I think it's one of those things that will start to build up momentum. As soon as a few schools start using it and setting up rules so that certain email get encrypted automatically it will snowball because the recipients will be asking their IT teams to implement it too.
FN-GM Posted June 26, 2018 Posted June 26, 2018 Does using SMIME have any real benefit over using TLS?
mavhc Posted June 26, 2018 Posted June 26, 2018 It's encrypted on the server (well, except everyone uses webmail), it's per user encryption, not per site, and it also adds authentication, so you can prove an email was sent by you, and wasn't altered.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now