maniac Posted July 20, 2011 Posted July 20, 2011 Would people consider a passworded ZIP file, with the password being given verbally to the recepient over the phone, adequate security for sending data offsite by e-mail?
X-13 Posted July 20, 2011 Posted July 20, 2011 Seems adequate to me. But it ultimately depends of what is in the ZIP file. I would have a word with whoever is in charge though and see what they say.
FN-GM Posted July 20, 2011 Posted July 20, 2011 I wouldn't, you can get past password zipped files with software from the net. I would create an encrypted truecrypt container (file), that would be allot more secure.
Sam_Brown Posted July 20, 2011 Posted July 20, 2011 Like FN-GM says zipped files aren't the most difficult things to break into. The most secure way is, as FN-GM says, full encryption using something like truecrypt or axcrypt which is what we use here (personally find axcrypt easier myself). If you dont want to use those then even using WINRAR instead of a ZIP file is more secure way but would definately recommend truecrypt or axcrypt.
maniac Posted July 20, 2011 Author Posted July 20, 2011 Seems adequate to me. But it ultimately depends of what is in the ZIP file. I would have a word with whoever is in charge though and see what they say. I'm in charge, it's my call. This data has been requested in this format by an external company we use for a service. It will contain names, addresses, DOB and other data on new year 7 students, and I'm not really 100% happy with this security, but I've been informed by them that 'no one else has raised this as an issue' so I thought I'd see what the general opinion was on here. Mike.
X-13 Posted July 20, 2011 Posted July 20, 2011 I'm in charge, it's my call. This data has been requested in this format by an external company we use for a service. It will contain names, addresses, DOB and other data on new year 7 students, and I'm not really 100% happy with this security, but I've been informed by them that 'no one else has raised this as an issue' so I thought I'd see what the general opinion was on here. Mike. Ah, personal information. Disregard my previous statement. +1 for TrueCrypt
Domino Posted July 20, 2011 Posted July 20, 2011 Truecrypt, or use openPGP and encrypt the whole email.
sonofsanta Posted July 20, 2011 Posted July 20, 2011 I'm in charge, it's my call. This data has been requested in this format by an external company we use for a service. It will contain names, addresses, DOB and other data on new year 7 students, and I'm not really 100% happy with this security, but I've been informed by them that 'no one else has raised this as an issue' so I thought I'd see what the general opinion was on here. Mike. No-one raised an issue about Sony's security issues, and their complete failure to understand the role of randomised seeds in the generation of signed certificates to prevent pirated software, right up until the point when it went wrong. Just because no-one's had a problem before, doesn't mean there isn't a problem there. For personal data of students - particularly those of a young age - I'd use TrueCrypt as the only way to secure it. If they're a company handling personal data and they're not familiar with TrueCrypt, they need to think long and hard about the market they're in and whether they're really up to the job.
theriver Posted July 20, 2011 Posted July 20, 2011 @maniac, it's YOUR data, so you're in the driving seat. If they were halfway decent they should be asking you what *your* standards are, and how they can accommodate *you*. Shoddy. Just because none of their other customers have raised this as an issue (they say!) doesn't mean that it isn't one, just means that you're ahead of the game. If you're feeling uncomfortable about it now, imagine how you'd feel if it all goes pear shaped and you find yourself having to answer questions about what happened in the aftermath. At this moment in time all you're having to do is explain to your boss why a supplier is ****, if the worst happens you're potentially explaining why you went against your better judgement . . . . .
laserblazer Posted July 20, 2011 Posted July 20, 2011 I take it there's a reason for an outside company having this information? I'd use Safehouse but that's just a personal thing. It needs to be encrypted along with some sort of disclaimer saying the data should not be removed or transmitted from their site in an unencrypted format.
maniac Posted July 20, 2011 Author Posted July 20, 2011 There's every chance quite a few of you reading this will deal with the same company, and have had the data requested from you in the same format. Mike.
Pete10141748 Posted July 20, 2011 Posted July 20, 2011 TrueCrypt all the way, no data should leave site in something as relatively weak as a passworded ZIP folder, let alone sensitive personal information about pupils!
pete Posted July 20, 2011 Posted July 20, 2011 Are we talking a decent Zip program with AES-256 encryption and a strong password? With regard to the "no-one else has raised this as an issue" problem, guess how many local goverment-related organisations / companies / quangos in Lincolnshire think it's acceptable to require a) default simple password for use with every encrypted file sent to them b) use the first line of their postal address as that password? c) Send pupil data in the clear? More than you'd think, even in this cynical forum. Guess how many schools have said GTFO sonny-jim, you get it securely or not at all? Apparently, we were the first. And the reason? "Different passwords are too tricky to handle". Nobody with the clout to enforce it seems willing to: a) teach them how to do it properly b) make them do it properly and prosecute when they don't. c) give them access to (say) securedatatransfer.teachernet.gov.uk* so it's easier to do it properly than not. *I am aware S2S has been unavailable for much of this week. My point is that existing methods that are sufficiently secure are readily available - there's no need for each little quango/org to dream up their own half-baked system.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now