ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Sending Secure E-Mail?

    Scheduled Pinned Locked Moved IT Discussion
    55 Posts 12 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      JasGot
      last edited by JasGot

      I have a customer that needs to send e-mail to a company.
      This customer does not want ANYONE other than the intended recipient to view the contents.

      What are the options to do this, and what complexities do they impose?

      I am aware of these methods and their problems:

      1. send the info in an encrypted document that is attached
        1a) Some anti virus software will block encrypted attachments.
        1b) You still have to communicate the decryption password to the end user who is only available via e-mail.

      2. Sites that allow you to send a document into their service/system and then the recipient has to go there to retrieve it
        2a) Recipient may refuse to go to a web site to retrieve an e-mail.
        2b) Recipient may not have web access with a browser.

      Any other options? The key elements are 1) E-mail based and 2) cannot be read by anyone other than the recipient.

      JaredBuschJ ObsolesceO 2 Replies Last reply Reply Quote 1
      • gjacobseG
        gjacobse
        last edited by

        What is your current email system?

        1 Reply Last reply Reply Quote 0
        • JaredBuschJ
          JaredBusch @JasGot
          last edited by

          @JasGot Flat not possible because of

          1 would work except for 1b.
          If the encrypted document and the password are both in email, it is not possible to not let anyone else (System Administrators) potentially have access to it.

          2 would never work because the link and how to access it all come to the same email and (System Administrators) potentially have access to it.

          1 Reply Last reply Reply Quote 0
          • JaredBuschJ
            JaredBusch
            last edited by

            Once you get that told to them, you can then to get to the reason for such a stupid request. Likely a misunderstanding of some compliance need.

            J 1 Reply Last reply Reply Quote 1
            • J
              JasGot @JaredBusch
              last edited by

              @JaredBusch said in Sending Secure E-Mail?:

              Once you get that told to them, you can then to get to the reason for such a stupid request. Likely a misunderstanding of some compliance need.

              Here's the request from the customer. It makes sense. But is also difficult to overcome. Especially with state workers who will likely say "Not our process, FU"

              <snip>

              I’m looking for options for secure email transmissions of sensitive data.

              The dept is engaged in a grant program with the State Department of Environment…, which requires us to include our banking information on every reimbursement application.

              Because the Governor has closed the State offices, forcing the staff to work from home, The Grant Office has directed us to submit our applications via email or take the risk of having our applications sit unreviewed for a month, since the staff only go to the office once each month to pick up their mail. Even then, they are scanning the documents and emailing them, via unsecured email, to other staff members.

              I have refused to include the banking information on documentation submitted via email, opting instead to email “incomplete” documentation to the staff and mailing the “complete” documentation to State’s office.

              Is there a relatively inexpensive option for secure email transmission available to protect our banking info?

              scottalanmillerS 1 2 Replies Last reply Reply Quote 0
              • DustinB3403D
                DustinB3403
                last edited by

                Additional to what Jared said, what if the recipient left their computer unlocked or prints the email and leaves it about.

                This sounds like a misunderstanding of the technology.

                1 Reply Last reply Reply Quote 0
                • JaredBuschJ
                  JaredBusch
                  last edited by

                  So yeah, this ANYONE requirement is invalid. That is not how anything works.

                  Your client simply needs to force encryption on outbound email to the domain that these emails are sent to. End of story, everything secured. This is simple to do in O365 and not super hard with Exchange on prem. GSuite is also not hard to set this up.

                  They have zero control over how the government handles their data after it is delivered. They never did and sending it over email does not change this. In the past, the dropped off forms were likely scanned and then emailed around aslo.

                  scottalanmillerS J 3 Replies Last reply Reply Quote 2
                  • scottalanmillerS
                    scottalanmiller @JasGot
                    last edited by

                    @JasGot said in Sending Secure E-Mail?:

                    Is there a relatively inexpensive option for secure email transmission available to protect our banking info?

                    Check if the government is using TLS. If not, nothing is going to make that org secure, nothing. If it is, you are already secure.

                    This is really simple. Don't read too much into it. It's just communications between two people.

                    1 Reply Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller @JaredBusch
                      last edited by

                      @JaredBusch said in Sending Secure E-Mail?:

                      In the past, the dropped off forms were likely scanned and then emailed around aslo.

                      Or faxed, much like sticking on a bulletin board somewhere.

                      1 Reply Last reply Reply Quote 0
                      • scottalanmillerS
                        scottalanmiller @JaredBusch
                        last edited by

                        @JaredBusch said in Sending Secure E-Mail?:

                        Your client simply needs to force encryption on outbound email to the domain that these emails are sent to. End of story, everything secured. This is simple to do in O365 and not super hard with Exchange on prem. GSuite is also not hard to set this up.

                        Yup, simply decide to not send unencrypted and voila, done. Email is incredibly secure by default these days.

                        brandon220B 1 Reply Last reply Reply Quote 0
                        • brandon220B
                          brandon220 @scottalanmiller
                          last edited by

                          @scottalanmiller Try telling that to the auditors. Dealing with those folks make me want to drink.

                          scottalanmillerS 1 Reply Last reply Reply Quote 1
                          • jt1001001J
                            jt1001001
                            last edited by

                            What about PGP? Just did this for one of our users. Basic instructions here for PGP on Outlook.
                            https://www.comparitech.com/blog/information-security/pgp-encryption-with-outlook/

                            JaredBuschJ scottalanmillerS 2 Replies Last reply Reply Quote 0
                            • JaredBuschJ
                              JaredBusch @jt1001001
                              last edited by

                              @jt1001001 said in Sending Secure E-Mail?:

                              What about PGP?

                              The only communication method is email. so the key will be in email too. SO an admin will have access.

                              1 Reply Last reply Reply Quote 1
                              • scottalanmillerS
                                scottalanmiller @brandon220
                                last edited by

                                @brandon220 said in Sending Secure E-Mail?:

                                @scottalanmiller Try telling that to the auditors. Dealing with those folks make me want to drink.

                                If your auditors aren't competent, they aren't auditors, they are security breaches getting paid.

                                1 Reply Last reply Reply Quote 2
                                • scottalanmillerS
                                  scottalanmiller @jt1001001
                                  last edited by

                                  @jt1001001 said in Sending Secure E-Mail?:

                                  What about PGP? Just did this for one of our users. Basic instructions here for PGP on Outlook.
                                  https://www.comparitech.com/blog/information-security/pgp-encryption-with-outlook/

                                  PGP is a great tool, but doesn't add anything beyond the existing TLS.

                                  1 Reply Last reply Reply Quote 0
                                  • DashrenderD
                                    Dashrender
                                    last edited by

                                    If you were allowed a one time phone call with the receiving person beforehand, you could provide the password to them. Or you could mail the password to them.

                                    1 Reply Last reply Reply Quote 0
                                    • ObsolesceO
                                      Obsolesce @JasGot
                                      last edited by

                                      @JasGot said in Sending Secure E-Mail?:

                                      I have a customer that needs to send e-mail to a company.
                                      This customer does not want ANYONE other than the intended recipient to view the contents.

                                      What are the options to do this, and what complexities do they impose?

                                      I am aware of these methods and their problems:

                                      1. send the info in an encrypted document that is attached
                                        1a) Some anti virus software will block encrypted attachments.
                                        1b) You still have to communicate the decryption password to the end user who is only available via e-mail.

                                      2. Sites that allow you to send a document into their service/system and then the recipient has to go there to retrieve it
                                        2a) Recipient may refuse to go to a web site to retrieve an e-mail.
                                        2b) Recipient may not have web access with a browser.

                                      Any other options? The key elements are 1) E-mail based and 2) cannot be read by anyone other than the recipient.

                                      Tell the recipients not to let anyone else have access to their email or their username and password. Tell recipients to enable MFA on their email. Tell recipients to secure the devices that have access to their email.

                                      Then only they can see their email.

                                      DashrenderD 1 Reply Last reply Reply Quote 0
                                      • DashrenderD
                                        Dashrender @Obsolesce
                                        last edited by

                                        @Obsolesce said in Sending Secure E-Mail?:

                                        @JasGot said in Sending Secure E-Mail?:

                                        I have a customer that needs to send e-mail to a company.
                                        This customer does not want ANYONE other than the intended recipient to view the contents.

                                        What are the options to do this, and what complexities do they impose?

                                        I am aware of these methods and their problems:

                                        1. send the info in an encrypted document that is attached
                                          1a) Some anti virus software will block encrypted attachments.
                                          1b) You still have to communicate the decryption password to the end user who is only available via e-mail.

                                        2. Sites that allow you to send a document into their service/system and then the recipient has to go there to retrieve it
                                          2a) Recipient may refuse to go to a web site to retrieve an e-mail.
                                          2b) Recipient may not have web access with a browser.

                                        Any other options? The key elements are 1) E-mail based and 2) cannot be read by anyone other than the recipient.

                                        Tell the recipients not to let anyone else have access to their email or their username and password. Tell recipients to enable MFA on their email. Tell recipients to secure the devices that have access to their email.

                                        Then only they can see their email.

                                        How does this keep the admin on the system from seeing the email?

                                        ObsolesceO 1 Reply Last reply Reply Quote 0
                                        • ObsolesceO
                                          Obsolesce @Dashrender
                                          last edited by

                                          @Dashrender said in Sending Secure E-Mail?:

                                          @Obsolesce said in Sending Secure E-Mail?:

                                          @JasGot said in Sending Secure E-Mail?:

                                          I have a customer that needs to send e-mail to a company.
                                          This customer does not want ANYONE other than the intended recipient to view the contents.

                                          What are the options to do this, and what complexities do they impose?

                                          I am aware of these methods and their problems:

                                          1. send the info in an encrypted document that is attached
                                            1a) Some anti virus software will block encrypted attachments.
                                            1b) You still have to communicate the decryption password to the end user who is only available via e-mail.

                                          2. Sites that allow you to send a document into their service/system and then the recipient has to go there to retrieve it
                                            2a) Recipient may refuse to go to a web site to retrieve an e-mail.
                                            2b) Recipient may not have web access with a browser.

                                          Any other options? The key elements are 1) E-mail based and 2) cannot be read by anyone other than the recipient.

                                          Tell the recipients not to let anyone else have access to their email or their username and password. Tell recipients to enable MFA on their email. Tell recipients to secure the devices that have access to their email.

                                          Then only they can see their email.

                                          How does this keep the admin on the system from seeing the email?

                                          Why would anyone other than the user have admin privileges on the system?

                                          DashrenderD 1 Reply Last reply Reply Quote 0
                                          • DashrenderD
                                            Dashrender @Obsolesce
                                            last edited by

                                            @Obsolesce said in Sending Secure E-Mail?:

                                            @Dashrender said in Sending Secure E-Mail?:

                                            @Obsolesce said in Sending Secure E-Mail?:

                                            @JasGot said in Sending Secure E-Mail?:

                                            I have a customer that needs to send e-mail to a company.
                                            This customer does not want ANYONE other than the intended recipient to view the contents.

                                            What are the options to do this, and what complexities do they impose?

                                            I am aware of these methods and their problems:

                                            1. send the info in an encrypted document that is attached
                                              1a) Some anti virus software will block encrypted attachments.
                                              1b) You still have to communicate the decryption password to the end user who is only available via e-mail.

                                            2. Sites that allow you to send a document into their service/system and then the recipient has to go there to retrieve it
                                              2a) Recipient may refuse to go to a web site to retrieve an e-mail.
                                              2b) Recipient may not have web access with a browser.

                                            Any other options? The key elements are 1) E-mail based and 2) cannot be read by anyone other than the recipient.

                                            Tell the recipients not to let anyone else have access to their email or their username and password. Tell recipients to enable MFA on their email. Tell recipients to secure the devices that have access to their email.

                                            Then only they can see their email.

                                            How does this keep the admin on the system from seeing the email?

                                            Why would anyone other than the user have admin privileges on the system?

                                            the email admin.

                                            ObsolesceO 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 1 / 3
                                            • First post
                                              Last post