Home > Ask the Security Experts > Application Security Questions & Answers > Are Internet cafe users' email credentials at risk?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Are Internet cafe users' email credentials at risk?

Michael Cobb, featured expert EXPERT RESPONSE FROM: Michael Cobb, featured expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 13 February 2008
When checking email in a public place, is it possible for a user's message information to be stored in an Internet cache? Can it be easily retrieved? I've heard specifically about Gmail credentials being at risk, but is it an issue for corporate webmail accounts as well, and if so, how can it be avoided?

>
There are many different ways of checking email in a public place, but let's start with the Internet café scenario where you are using a Web browser on the coffee shop's personal computer. The default setting for most Web browsers is to store all Web pages, including a user's message and other information, in a cache from which it is retrievable with relative ease, whether the email account is with Gmail, Yahoo, Hotmail or a corporate webmail server.

Fortunately, it is also relatively easy to clean out this cache and other information related to your Internet café session, including cookies, after your session. You can use the browser menu (Tools/Internet Options in IE and Tools/Options in Firefox). In fact, this should be second nature to anyone who uses a public terminal to check email. A responsible Internet café will remind you of this; some even provide an automated end-of-session cleanup process. To be safe, however, make sure to do it yourself. You can also set a browser not to cache any pages, but this setting can slow performance, and it may not be available on a public terminal.

Some readers will be aware that Web pages themselves can be created with a "no-cache" setting. You can verify such restrictions when you view the page source of a message in Yahoo Mail, for example. The "no-cache" instruction is generally respected by the browser cache and caching servers used by ISPs. The latter are another place from which your email could be illicitly retrieved by someone with sufficient SRM: skills, resources and motivation. Anyone checking email in public places should have an "SRM index" in mind. Is the email so sensitive that someone would apply a serious amount of skills, resources and motivation to obtain it?

The specific vulnerability involving Gmail and Microsoft Internet Explorer, recently publicized by application security vendor Cenzic, requires serious SRM. Other attacks could be easier, like putting a keystroke logger on a public computer or "shoulder-surfing" to capture messages as a user types them.

If you are accessing email wirelessly in a public place, someone could be sniffing the airwaves. Therefore, your precautions and countermeasures should be appropriate to the sensitivity of the data that is potentially exposed. For example, if you have internal sales data that must be transferred securely, encrypt the information and send it as an attachment to a message that says something innocuous like "Here is the data you requested."

In other words, risk is relative. A good rule of thumb is not to send or receive mission-critical data from a public place via webmail unless your company has put some serious rules and safeguards in place and cleared you to do so.

More information:

  • Visit SearchSecurity.com's Messaging Security School.
  • Learn about the webmail flaws found by researchers at Black Hat Conference 2007.


  • BROWSE BY TAG
    Application Security,   Application and Platform Security,   Email Protection,   Email Security Guidelines, Encryption and Appliances,   Enterprise Data Protection,   Identity Theft and Data Security Breaches,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Application Security
    Do Facebook URL security concerns justify blocking social networks?
    Is there a way to block iPhone widgets that bypass Web filters?
    Should enterprises be concerned with Twitter in the workplace?
    Are there still Google Desktop security problems?
    Can an IP spoofing tool be used to spam SPF servers?
    Will an application usage policy best control network bandwidth?
    How can URL-shortening services be manipulated?
    Is my security program ready for Web application firewall deployment?
    How to ensure the security of a shopping cart application
    When to use the service features of the Metasploit hacking tool

    Email Security Guidelines, Encryption and Appliances
    How to confirm the receipt of an email with security protocols
    Best Email Security Products
    Can an IP spoofing tool be used to spam SPF servers?
    WatchGuard acquires email and Web security vendor BorderWare
    McAfee to acquire email SaaS vendor MX Logic
    What does 'invoked by uid 78' mean?
    How to configure firewall ports for webmail system implementation
    Fierce competition prompted new Cisco email security options
    Cisco brings email security appliances closer to SaaS
    Cisco offers more email security choices, but lacks vision

    Identity Theft and Data Security Breaches
    Chip and PIN adoption serves lesson for U.S. payment industry
    Group to shed light on secure identity management threats
    Heartland CIO is critical of First Data's credit card tokenization plan
    Heartland CIO on end-to-end encryption, credit card tokenization
    Heartland CIO on PCI, E3 project
    Visa probes tokens, encryption for PCI card data protection
    University data breach exposes 163,000 women to identity theft
    TJX thrives following breach, bucks sour economy
    Security expert's PCI analysis misguided, says PCI Council GM
    External attacks start with unintentional mistakes, survey finds

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    asymmetric cryptography  (SearchSecurity.com)
    challenge-response system  (SearchSecurity.com)
    cryptographic checksum  (SearchSecurity.com)
    data encryption/decryption IC  (SearchSecurity.com)
    elliptical curve cryptography  (SearchSecurity.com)
    Escrowed Encryption Standard  (SearchSecurity.com)
    MPPE  (SearchSecurity.com)
    Quiz: Cryptography  (SearchSecurity.com)
    session key  (SearchSecurity.com)
    Twofish  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts