rad Posted September 21, 2012 Posted September 21, 2012 Our child protection officer received an email from a borough contact saying... Please note we now have a secure E-mail address as follows: Please note this will only be usable from secure E-mail accounts. We use email provided by LGfL, what is classed as a secure email? I did ask that they send a test email but I am not sure what they are referring to as a secure email. Thanks
glennda Posted September 21, 2012 Posted September 21, 2012 Perhaps one that connects via TLS? Or as with my old LEA (WSCC) they would only send stuff to the email addresses provided by them (i.e @wsgfl addresses) 1
jmak Posted September 21, 2012 Posted September 21, 2012 Our LA provides an MS Exchange based email for all employees and governors, which we were instructed to use as it's "secure". It might have been until people started downloading them to the mail client on their smartphones. When asked, how many governors or staff do you think were using the free apps to remotely wipe their data in the event of losing their phone? They can also use gmail and similar as a client reader for MS Exchnage accounts on their PCs. So Google get to analyse them too. Remote access to data or cloud computing is being resisted on security grounds here, so let's just send round attachments to phones without password protection or take unencrypted USB sticks everywhere. Rant over........ 1
FN-GM Posted September 21, 2012 Posted September 21, 2012 Cant emails be intercepted if you have the right kit? 1
MatthewL Posted September 21, 2012 Posted September 21, 2012 I think the only emails systems designated as secure as GSCX, NHS.net and Police. There are a number of others that come under GSCX but I cannot find the document with it on at the moment. 1
Cache Posted September 21, 2012 Posted September 21, 2012 (edited) It's funny, I've had 3 people ask me this week about whether we have a secure email system and I've just assumed no because of the reasons above but it's made me wonder, is it something, like everything else, I should be looking in to it and how would I even start to look at going about it? Edited September 21, 2012 by Cache 1
jmak Posted September 21, 2012 Posted September 21, 2012 I don't think email will ever be secure (possibly with the exceptions mentioned above). It's more like sending a postcard than a letter - most of them won't be read by anyone other than the intended recipient but there's not much to stop someone reading it if they want to. IMHO the best solution for ease of use / security compromise is to send emails with hyperlinks to a secure document storage system. 1
FN-GM Posted September 21, 2012 Posted September 21, 2012 encrypted attachments is one way to secure data sent via email 1
MatthewL Posted September 21, 2012 Posted September 21, 2012 Our LA use 7Zip and secure them that way and apparently that meets the requirements of CoC and GSCX. 1
Guest Guest Posted September 21, 2012 Posted September 21, 2012 encrypted attachments is one way to secure data sent via email But how do you tell them the password? Obviously the only secure way is by a different form of communication but most people will then send a second email with the password... Same goes for bank cards, how does sending the card and PIN in 2 letters make it secure?
FN-GM Posted September 21, 2012 Posted September 21, 2012 But how do you tell them the password? Obviously the only secure way is by a different form of communication but most people will then send a second email with the password... Same goes for bank cards, how does sending the card and PIN in 2 letters make it secure? Over the Phone. 1
SYNACK Posted September 22, 2012 Posted September 22, 2012 Over the Phone. Smoke signals or even better http://www.rfc-editor.org/rfc/rfc1149.txt 1
rad Posted September 22, 2012 Author Posted September 22, 2012 Our LA use 7Zip and secure them that way and apparently that meets the requirements of CoC and GSCX. Thanks @MatthewL the email did contain GSCx but wasn't sure what it meant. It therefore would mean we don't have a secure email system! Thanks all
mavhc Posted September 22, 2012 Posted September 22, 2012 If only someone had, say 20 years ago, invented encrypted public key email
Michael Posted September 22, 2012 Posted September 22, 2012 I think there are several answers to this question - Live@Edu for example uses the following: POP - Encryption method: SSL IMAP - Encryption method: SSL SMTP - Encryption method: TLS This makes it pretty secure between your application or browser, connecting to your e-mail server. The only problem is between your e-mail server and the recipient of the e-mail. There are many different e-mail platforms out there, the majority unsecure. Banks for example may send part of the communication via e-mail and the other part via SMS. Two communication methods does improve security, but then again, Smartphones can receive e-mail and SMS so it isn't that secure. People store their life on Smartphones these days! The alternative is to use digital certificates, however it means all your recipients need your digital signature. This is great for regular e-mails/contacts, but if you randomly e-mail someone you've never e-mailed before, a 5 minute job is no longer a 5 minute job. I suspect in future with 3G/4G and fibre broadband speeds, bandwidth will no longer be an issue, so in theory all webpages, e-mail and other services would use SSL or similar.
SYNACK Posted September 22, 2012 Posted September 22, 2012 I suspect in future with 3G/4G and fibre broadband speeds, bandwidth will no longer be an issue, so in theory all webpages, e-mail and other services would use SSL or similar. SSL does not add that much overhead on bandwidth it is much heavier on CPU, that's why there was and probably still is a market for SSL accelerators for large sites.
Arthur Posted September 22, 2012 Posted September 22, 2012 it is much heavier on CPU Google doesn't use any SSL accelerators for GMail. The overhead is minimal. HTTPS isn't (that) expensive any more Yes, in the hoary old days of the 1999 web, HTTPS was quite computationally expensive. But thanks to 13 years of Moore's Law, that's no longer the case. It's still more work to set up, yes, but consider the real world case of GMail: "In January this year (2010), Gmail switched to using HTTPS for everything by default. Previously it had been introduced as an option, but now all of our users use HTTPS to secure their email between their browsers and Google, all the time. In order to do this we had to deploy no additional machines and no special hardware. On our production frontend machines, SSL/TLS accounts for less than 1% of the CPU load, less than 10KB of memory per connection and less than 2% of network overhead. Many people believe that SSL takes a lot of CPU time and we hope the above numbers (public for the first time) will help to dispel that." (Source) 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now