Jump to content

Recommended Posts

Posted

Hi all,

 

Thoughts please?

 

We use Office 365, and I set up email encryption for if the subject contains the word encrypt/confidential/encryption, so far so good. Now, as others have pointed out, many Governmental organisations are not allowing password protected encrypted emails. By default Office 365 uses TLS 1.2, therefore encrypting emails by default between other organisations that also use TLS. Using the following website: https://www.checktls.com/TestReceiver, we can check whether a potential recipient of an email is using TLS and therefore emails are encrypted by default end to end. My question, do people think this is sufficient for GDPR purposes?

 

Cheers

 

Nick

Posted

GDPR doesn't set out specific security measures, so there is no general "sufficient for GDPR" and this has to be considered by data controllers on a case by case basis.

 

What GDPR requires is that the measures that you take should be appropriate to the perceived risk.

 

You can examine risk and record your decision with a Data Protection Impact Assessment, which you should then review with your DPO and keep on record. Consider what data you are sending, whether it is all essential for the purpose (could it be reduced, pseudonymised, anonymised, aggregated?), what risk transmission of that data carries and how best to mitigate that risk. It sounds like you're talking about sending personal data outside your organisation, so ensure also that you've recorded the basis on which you do this, whether it's a controller to controller transfer or a controller to processor transfer, and, for the latter, how you've established that the processor will handle the data securely.

Posted

Thanks for the reply,

 

I appreciate the wording of GDPR, so let me change "sufficient for GDPR" to "would you be comfortable relying on TLS 1.2 for encryption of personal data being sent to governmental organisations."

 

I personally, at the moment, can't see an issue if we're both using TLS, as it would be encrypted end-to-end, but wanted to see if there's anything obvious I've missed, or not considered, as this is something that is affecting a of people as it is referred to in another couple of threads.

 

Nick

Posted (edited)

I think that the adequacy of TLS itself is well established (and all Office 365 / GalaxKey / Egress do is host a page that displays the message to which the recipient connects via TLS), but there are operational problems associated with relying on the standard TLS mail transmission that mean I wouldn't be comfortable with that. You cannot rely on your staff to use that site to check a recipient is safe. They are highly unlikely to do it imo, and even if they do if it reports that it's not safe they'll likely just send the mail anyway. If a recipient is safe, that doesn't mean their server is set up to send mails over TLS so you might receive replies sent in the clear. There are a ton of problems with relying on TLS mail imo.

 

Now, as others have pointed out, many Governmental organisations are not allowing password protected encrypted emails.

 

It is my firm opinion that this is the problem of those organisations, not our problem. We shouldn't downgrade our security to accommodate their crappy practices.

 

EDIT: although I appreciate that isn't helpful when you need to send something to them and can't!!

Edited by djrscally
Posted

Hi DJ,

 

I don't intend for staff to check whether TLS is enabled on recipient's addresses I would still expect them to try to encrypt the email using Office 365 encryption. However for our local councils with whom we are in regular contact who are refusing to accept our encryption, if they pass the test, I can let people know they can send the email. If an external sender is sending a totally un-encrypted email without checking, the onus is on them, not us and so I'm not going to worry about that (I can add something in our disclaimer at the bottom of our email placing the liability on them). if we do receive a reply to an email we've sent, I can check whether it's encrypted and if not, I can let them know that they have been 'naughty'!

Posted
Hi DJ,

 

I don't intend for staff to check whether TLS is enabled on recipient's addresses I would still expect them to try to encrypt the email using Office 365 encryption.

 

Ah cool, sorry I misunderstood.

 

However for our local councils with whom we are in regular contact who are refusing to accept our encryption, if they pass the test, I can let people know they can send the email. If an external sender is sending a totally un-encrypted email without checking, the onus is on them, not us and so I'm not going to worry about that (I can add something in our disclaimer at the bottom of our email placing the liability on them). if we do receive a reply to an email we've sent, I can check whether it's encrypted and if not, I can let them know that they have been 'naughty'!

 

Fair enough I suppose. Why are the council's refusing to accept them out of interest?

Posted

Sorry, I didn't make clear, DJ.

 

I believe their problem is that, if an email is encrypted it could potentially be hiding a virus or other nasty, we've been denied by the MOD also along the same lines in the last couple of weeks, so in that instance resorted to snail mail.

 

Cheers

Posted
I believe their problem is that, if an email is encrypted it could potentially be hiding a virus or other nasty, we've been denied by the MOD also along the same lines in the last couple of weeks, so in that instance resorted to snail mail.

 

Oh good grief.

Posted
Reading this thread, I feel like I'm missing something. Isn't TLS just used to encrypt email in transit, with emails stored in plaintext once safely arrived at the receiving system? End-to-end encryption being something else (i.e. where the body of the email is stored encrypted on the receiving system, prohibiting things like virus scanning which some organisations might be required to do).
  • Thanks 1
Posted

There's quite a large rise of phishing attacks emulating these exact secure emails, we've certainly had a few and there's a thread here opened today IIRC with the same. It would be therefore wise to educate staff to only ever open those emails when expecting them, i.e. with a prior email saying "I'll send a secure email following this one with the confidential details" and should be taught to do the same.

I've seen phishing attacks emulating egress switch too, so there's certainly people having a go at educational institutions.

Posted
No, you're not missing anything. For our purposes, we use OWA, so with TLS and OWA as far as we are concerned emails will be encrypted all the way at our end. On the receiving end, we'll probably have to check how they are accessing their emails, I'm working through how this is all working at the moment.
Posted
Ah, okay, I get what you're wanting to do now (encrypt the body of certain messages automatically, to guarantee their encryption in case the receiving system doesn't support TLS).

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...