Why You Should Encrypt Your Email

Author Topic: Why You Should Encrypt Your Email  (Read 2449 times)

Offline kazi shahin

  • Hero Member
  • *****
  • Posts: 607
  • Fear is not real
    • View Profile
    • Personal website of kazi shahin
Why You Should Encrypt Your Email
« on: August 30, 2010, 12:01:21 AM »

Security is mostly hype, right? You don't really need to bother with all those complicated passwords, antivirus software, firewalls and such. Its all just security software vendors and security consultants trying to scare everyone so they can sell their products and services.
I don't actually disagree with those statements at times. There are common sense steps everyone should take to secure their computers and networks, but there is certainly no shortage of hype in the news. Like the latest hot mutual fund- by the time it makes it into a newspaper or magazine it is old news and most likely too late for you to react to anyway.

However, as one of the common sense measures that aren't pure hype you should consider encrypting your email communications. If you are on vacation you might send a picture postcard to a friend or family member with a quick "wish you were here" sort of message. But, if you are writing a personal letter to that same friend or family member you would be more inclined to seal it in an envelope.

If you are mailing a check to pay a bill or perhaps a letter telling a friend or family member that the extra key to your house is hidden under the large rock to the left of the back porch you might use a security envelope with hatched lines to obfuscate or hide the contents of the envelope even better. The post office offers a number of other means of tracking messages- sending the letter certified, asking for a return receipt, insuring the contents of a package, etc.

Why then would you send personal or confidential information in an unprotected email? Sending information like the location of your extra house key under the large rock to the left of the back porch in an unencrypted email is the equivalent of writing it on a postcard for all to see.

Encrypting your email will keep all but the most dedicated hackers from intercepting and reading your private communications. Using a personal email certificate like the one freely available from Thawte you can digitally sign your email so that recipients can verify that its really from you as well as encrypt your messages so that only the intended recipients can view it. Comodo is another company offering free digital certificates for personal use. You can obtain your free certificate by filling out a very short and simple registration form.

That actually introduces an added benefit. By obtaining and using a personal email certificate to digitally sign your messages you can help to stem the tide of spam and malware being distributed in your name. If your friends and family are conditioned to know that messages from you will contain your digital signature, when they receive an unsigned message with your email address spoofed as the source they will realize that its not really from you and delete it.

The way typical email encryption works is that you have a public key and a private key (this sort of encryption is also known as Public Key Infrastructure or PKI). You, and only you, will have and use your private key. Your public key is handed out to anyone you choose or even made publicly available.

If someone wants to send you a message that is meant only for you to see, they would encrypt it using your public key. Your private key is required to decrypt such a message, so even if someone intercepted the email it would be useless gibberish to them. When you send an email to someone else you can use your private key to digitally "sign" the message so that the recipient can be sure it is from you.

It is important to note that you should sign or encrypt all of your messages, not just the confidential or sensitive ones. If you only encrypt a single email message because it contains your credit card information and an attacker is intercepting your email traffic they will see that 99% of your email is unencrypted plain-text, and one message is encrypted. That is like attaching a bright red neon sign that says "Hack Me" to the message.

If you encrypt all of your messages it would be a much more daunting task for even a dedicated attacker to sift through. After investing the time and effort into decrypting 50 messages that just say "Happy Birthday" or "Do you want to golf this weekend?" or "Yes, I agree" the attacker will most likely not waste any more time on your email.
Kazi Shahin                   
092-15-795
Department of CSE   
Cell : 01718 699 590
Blood Group: O+
Google + :  https://plus.google.com/u/0/101741817431143727344/about?hl=en
Facebook : http://www.facebook.com/kazishahin.rahman
Web : http://www.kazishahin.com/

Offline kazi shahin

  • Hero Member
  • *****
  • Posts: 607
  • Fear is not real
    • View Profile
    • Personal website of kazi shahin
Encrypt e-mail messages
« Reply #1 on: August 30, 2010, 12:10:32 AM »
Sometimes you want additional protection for your e-mail communication to keep it from unwanted eyes. Encrypting an e-mail message in Microsoft Office Outlook 2007 protects the privacy of the message by converting it from (readable) plaintext into (scrambled) ciphertext. Only the recipient who has the private key that matches the public key used to encrypt the message can decipher the message for reading. Any recipient without the corresponding private key would see only garbled text.
Kazi Shahin                   
092-15-795
Department of CSE   
Cell : 01718 699 590
Blood Group: O+
Google + :  https://plus.google.com/u/0/101741817431143727344/about?hl=en
Facebook : http://www.facebook.com/kazishahin.rahman
Web : http://www.kazishahin.com/

Offline kazi shahin

  • Hero Member
  • *****
  • Posts: 607
  • Fear is not real
    • View Profile
    • Personal website of kazi shahin
Encrypt a single message
« Reply #2 on: August 30, 2010, 12:11:44 AM »
1.In the message, on the Message tab, in the Options group on the ribbon, click the Encrypt Message Contents and Attachments button.
 NOTE   If you don't see this button, click the Options Dialog Box Launcher in the lower right corner of the group to open the Message Options dialog box. Click the Security Settings button and in the Security Properties dialog box, select Encrypt message contents and attachments. Click OK and then close the Message Options dialog box.

2.Compose your message and send it.
Kazi Shahin                   
092-15-795
Department of CSE   
Cell : 01718 699 590
Blood Group: O+
Google + :  https://plus.google.com/u/0/101741817431143727344/about?hl=en
Facebook : http://www.facebook.com/kazishahin.rahman
Web : http://www.kazishahin.com/

Offline kazi shahin

  • Hero Member
  • *****
  • Posts: 607
  • Fear is not real
    • View Profile
    • Personal website of kazi shahin
Encrypt all outgoing messages
« Reply #3 on: August 30, 2010, 12:13:26 AM »
Choosing to encrypt all outgoing messages means, in effect, your e-mail is encrypted by default. You can write and send messages the same as with any other e-mail messages, but all potential recipients must have your digital ID to decode your messages.

On the Tools menu, click Trust Center, and then click E-mail Security.
Under Encrypted e-mail, select the Encrypt contents and attachments for outgoing messages check box.
To change additional settings, such as choosing a specific certificate to use, click Settings.
Click OK twice.
 NOTE   3DES is the default encryption algorithm used in Outlook 2007. For more information, see the Overview of certificates and cryptographic e-mail messaging in Outlook.
Kazi Shahin                   
092-15-795
Department of CSE   
Cell : 01718 699 590
Blood Group: O+
Google + :  https://plus.google.com/u/0/101741817431143727344/about?hl=en
Facebook : http://www.facebook.com/kazishahin.rahman
Web : http://www.kazishahin.com/