ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Security mindsets of very small businesses and residential clients

    IT Discussion
    8
    45
    6.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • alexntgA
      alexntg @technobabble
      last edited by

      @technobabble said:

      @alexntg I am using Office 365.

      That uses opportunistic TLS. If your receiving party does the same (or forces TLS) you'll be good to go for transmission encryption.

      JaredBuschJ 1 Reply Last reply Reply Quote 0
      • JaredBuschJ
        JaredBusch @alexntg
        last edited by

        @alexntg said:

        @technobabble said:

        @alexntg I am using Office 365.

        That uses opportunistic TLS. If your receiving party does the same (or forces TLS) you'll be good to go for transmission encryption.

        I recently had this argument with the owner of our company. He always refused to send passwords in email. Even internally. I repeatedly stated how much time he was wasting on a non-issue. Internal email is never on the public internet unencrypted for gods sake. We had an SBS server and are now Office 365. Everything is encrypted to the devices.

        C 1 Reply Last reply Reply Quote 1
        • T
          technobabble
          last edited by

          Now I have to check my Zendesk ticketing system's encryption.

          1 Reply Last reply Reply Quote 0
          • C
            Carnival Boy @JaredBusch
            last edited by

            @JaredBusch said:

            I repeatedly stated how much time he was wasting on a non-issue. Internal email is never on the public internet unencrypted for gods sake.

            Depends on what the password is for, but other users may have been granted access to that user's e-mail. By using e-mail you may still be compromising security. It's about internal security as well as external security.

            JaredBuschJ scottalanmillerS 2 Replies Last reply Reply Quote 0
            • JaredBuschJ
              JaredBusch @Carnival Boy
              last edited by

              @Carnival-Boy you are taking security to the point of interfering with running a business IMO. IT is a business expense, but there is a balance to it just like any other business expense.

              1 Reply Last reply Reply Quote 0
              • C
                Carnival Boy
                last edited by

                Possibly. I really don't know what best practice is and to be honest, I haven't thought about it all that much. E-mailing passwords just feels wrong to me.

                I normally send them by SMS, which is possibly even less secure (but like I say, I haven't thought about it much until today).

                alexntgA scottalanmillerS 2 Replies Last reply Reply Quote 0
                • alexntgA
                  alexntg @Carnival Boy
                  last edited by

                  @Carnival-Boy said:

                  Possibly. I really don't know what best practice is and to be honest, I haven't thought about it all that much. E-mailing passwords just feels wrong to me.

                  I normally send them by SMS, which is possibly even less secure (but like I say, I haven't thought about it much until today).

                  If you know how SMS works, your pants would be brown right about now.

                  1 Reply Last reply Reply Quote 0
                  • C
                    Carnival Boy
                    last edited by

                    Not sure. Google et al's two-factor verification is based on SMS, so how bad can it be? What's the worst that can happen?

                    alexntgA scottalanmillerS 2 Replies Last reply Reply Quote 0
                    • alexntgA
                      alexntg @Carnival Boy
                      last edited by

                      @Carnival-Boy said:

                      Not sure. Google et al's two-factor verification is based on SMS, so how bad can it be? What's the worst that can happen?

                      Well, you know, their password being broadcast on-air to everyone within a few miles of your user is up there in risk. Two-factor verification isn't quite the same as a password.

                      1 Reply Last reply Reply Quote 0
                      • C
                        Carnival Boy
                        last edited by

                        So they're at risk from attackers physically located within a few miles of them, who know what to do with a random password, and know exactly when the SMS is being sent? This seems very low risk or am I missing something? I only send the password, there is no other information with it. It's not quite the same as two-factor verification, but I think it's similar.

                        alexntgA 1 Reply Last reply Reply Quote 0
                        • alexntgA
                          alexntg @Carnival Boy
                          last edited by

                          @Carnival-Boy said:

                          So they're at risk from attackers physically located within a few miles of them, who know what to do with a random password, and know exactly when the SMS is being sent? This seems very low risk or am I missing something? I only send the password, there is no other information with it. It's not quite the same as two-factor verification, but I think it's similar.

                          There's still some risk. If someone's phone's being monitored, the person monitoring the phone would have some idea of who's it is. If someone's just absorbing all SMS traffic in a given area, it wouldn't have any particular meaning or value.

                          1 Reply Last reply Reply Quote 0
                          • scottalanmillerS
                            scottalanmiller @Carnival Boy
                            last edited by

                            @Carnival-Boy said:

                            @JaredBusch said:

                            I repeatedly stated how much time he was wasting on a non-issue. Internal email is never on the public internet unencrypted for gods sake.

                            Depends on what the password is for, but other users may have been granted access to that user's e-mail. By using e-mail you may still be compromising security. It's about internal security as well as external security.

                            That is the case with any secure system though. If you have a compromise it doesn't matter if you used email, secure download, KeePass, etc. That doesn't make email any better or worse.

                            1 Reply Last reply Reply Quote 0
                            • scottalanmillerS
                              scottalanmiller @Carnival Boy
                              last edited by

                              @Carnival-Boy said:

                              Possibly. I really don't know what best practice is and to be honest, I haven't thought about it all that much. E-mailing passwords just feels wrong to me.

                              I normally send them by SMS, which is possibly even less secure (but like I say, I haven't thought about it much until today).

                              Very insecure. SMS I would definitely avoid. That's worse than sending it to their personal email.

                              1 Reply Last reply Reply Quote 0
                              • scottalanmillerS
                                scottalanmiller @Carnival Boy
                                last edited by

                                @Carnival-Boy said:

                                Not sure. Google et al's two-factor verification is based on SMS, so how bad can it be? What's the worst that can happen?

                                That's the second factor only. That's purely "extra" security above and beyond existing security. The point there is to send a one time code side band. It's only useful if you can combine the two bands and only for a moment. It could be announced openly on the radio and not be any risk.

                                That Google uses it that way doesn't imply anything about it being safe.

                                1 Reply Last reply Reply Quote 0
                                • scottalanmillerS
                                  scottalanmiller
                                  last edited by

                                  The worst that can happen is that a password is compromised because of not following minimum security practices (by using internal email.). Using SMS would move the risk from "acceptable low security for ease of use" via email to "unacceptably low security that takes more effort" potentially.

                                  And are you sending to locked down end points? My SMS messages display even when my phone is locked.

                                  1 Reply Last reply Reply Quote 0
                                  • scottalanmillerS
                                    scottalanmiller
                                    last edited by

                                    I've written a bit on the evils of SMS. Keep in mind that email is "user" security. SMS is "device" security. You are deciding to send that password to the physical holder of a device rather than to the account of a user. Changes a lot if things fundamentally beyond the security gap.

                                    1 Reply Last reply Reply Quote 0
                                    • C
                                      Carnival Boy
                                      last edited by

                                      @scottalanmiller said:

                                      I've written a bit on the evils of SMS.

                                      Link? I definitely don't understand the risks.

                                      Another problem I have with using e-mail for confidential communication is the annoying habit of some users to set-up rules to forward all of their work e-mail to their personal e-mail. That's usually their personal Hotmail e-mail that uses the password "password".

                                      scottalanmillerS alexntgA 2 Replies Last reply Reply Quote 0
                                      • scottalanmillerS
                                        scottalanmiller @Carnival Boy
                                        last edited by

                                        @Carnival-Boy said:

                                        @scottalanmiller said:

                                        I've written a bit on the evils of SMS.

                                        Link? I definitely don't understand the risks.

                                        Another problem I have with using e-mail for confidential communication is the annoying habit of some users to set-up rules to forward all of their work e-mail to their personal e-mail. That's usually their personal Hotmail e-mail that uses the password "password".

                                        What do you fear in email that you don't fear in SMS? SMS has no security either. All of the bad things in email exist in SMS.

                                        C 1 Reply Last reply Reply Quote 0
                                        • C
                                          Carnival Boy @scottalanmiller
                                          last edited by

                                          @scottalanmiller said:

                                          What do you fear in email that you don't fear in SMS? SMS has no security either. All of the bad things in email exist in SMS.

                                          Off the top of my head, e-mail is easier to spread around, more likely to be read by other users or forwarded to unsecure locations, as I've already mentioned and more likely to be printed out and pinned on a noticeboard.

                                          I generally send username and other account details by e-mail and passwords by SMS. One is useless without the other, and the probability of both being hacked is massively lower than the probability of one. That's the two-factor bit.

                                          Let me ask you, what do you fear in SMS that you don't fear in e-mail? I certainly don't understand what is "evil" about SMS.

                                          scottalanmillerS 1 Reply Last reply Reply Quote 0
                                          • C
                                            Carnival Boy
                                            last edited by

                                            And just to clarify, I didn't start this thread and have no dog in this fight. I don't fear e-mail. I'm just saying what I do, and am interested to hear what others do, and why.

                                            1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 2 / 3
                                            • First post
                                              Last post