Home > Security Tips > Web Security Advisor > Implementing e-mail encryption
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

WEB SECURITY ADVISOR

Implementing e-mail encryption


Mike Chapple, CISSP
03.31.2005
Rating: -3.25- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Regulatory requirements and other security issues are forcing many users to demand technical measures that ensure the confidentiality and integrity of their electronic mail messages. Current e-mail encryption mechanisms are still somewhat awkward, but the movement toward pervasive e-mail encryption is gaining steam. In this tip, we'll review a few options for adding security to your e-mail communications.

First, it's important to recognize the fact that e-mail is inherently insecure. The three major protocols used for the vast majority of electronic mail (POP, IMAP and SMTP) are all clear text protocols that were designed without much thought to security. If you use these protocols in their basic form to exchange e-mail, you should have absolutely no expectation of privacy. Your organization's mail is subject to interception, alteration and counterfeiting by anyone on the virtual path between the sender and the recipient.

What's a security-conscious e-mailer to do?
You need to examine the e-mail security issue from two points of view. You need to protect account data (especially usernames and passwords) from disclosure and you need to protect the confidentiality and integrity of the messages sent.

Data defense
Protecting account data isn't that hard. If you're using a desktop e-mail client like Outlook, Eudora or Thunderbird with the standard POP/SMTP or IMAP/SMTP protocol pairings, use a Secure Sockets Layer (SSL) connection to encrypt exchanges with the server. This requires some reconfiguration and can only be done if your ISP supports SSL connections. You'll probably need to change the ports you use for each protocol to their SSL counterparts. SMTPS typically runs on port 465 instead of the standard SMTP port 25. IMAPS uses port 993, and POP3S uses 995.

Encrypting the session with the local server is usually easier for Web-based e-mail. Most Web-based e-mail services support SSL for at least the authentication process. Simply use the same address you normally use for Web-based mail but change the "http://" to "https://." Some services, including Google's Gmail, keep this SSL connection for your entire session while others will revert to standard HTTP after you've authenticated.

It's critical to note here that both of the SSL mechanisms described only protect communication with your local server. SSL will protect you against someone sniffing the connection between you and your server with a tool like tcpdump or ethereal, but it doesn't provide any protection beyond the local server.

Confidentiality complexity
If you'd like to protect the confidentiality and integrity of your organization's e-mail messages from source to destination, you have a slightly more complex problem on your hands. There really isn't a standardized method for exchanging cryptographic keys and encrypted e-mail messages. You must collaborate with the recipient of your messages and agree on the technology that will be used. Programs like Microsoft Outlook and Mozilla Thunderbird support S/MIME, the closest thing we have to a standard. To take advantage of this functionality, you'll need to obtain a digital certificate that contains a signed version of your public key. You can obtain such a certificate from firms like Verisign and Thawte. Thawte even offers a limited functionality personal certificate for free.

The alternative to S/MIME is Phil Zimmerman's Pretty Good Privacy (PGP). This model, based upon a "Web of trust," is also available as a plug-in for Microsoft Outlook. It's not currently available for Thunderbird users, but Mozilla says it plans to introduce PGP support in a future release. You can try PGP for free by signing up for a Web-based e-mail account with Hushmail.

Once you have it up and running, e-mail encryption promises to add a great deal of security to your electronic communications. Stay attuned to the industry as we watch the development of S/MIME and PGP toward a single standard.

About the author
Mike Chapple, CISSP is an IT Security Professional with the University of Notre Dame. He previously served as an information security researcher with the National Security Agency and the U.S. Air Force. Mike is a frequent contributor to SearchSecurity, a technical editor for
Information Security magazine and the author of several information security titles including the CISSP Prep Guide and Information Security Illuminated.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Web Security Advisor,   Application and Platform Security,   Email Protection,   Email Security Guidelines, Encryption and Appliances,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Web Security Advisor
DNS rebinding defenses still necessary, thanks to Web 2.0
New defenses for automated SQL injection attacks
PCI compliance and Web applications: Code review or firewalls?
Worst practices: Bad security incidents to avoid
Web scanning and reporting best practices
Social networking Web site threats manageable with good enterprise policy
Enterprise security in 2008: Building trust into the application development process
PCI DSS Section 6: A plan for tackling application security
Making the case for Web application vulnerability scanners
Preparing for uniform resource identifier (URI) exploits

Email Security Guidelines, Encryption and Appliances
How to confirm the receipt of an email with security protocols
Best Email Security Products
Can an IP spoofing tool be used to spam SPF servers?
WatchGuard acquires email and Web security vendor BorderWare
McAfee to acquire email SaaS vendor MX Logic
What does 'invoked by uid 78' mean?
How to configure firewall ports for webmail system implementation
Fierce competition prompted new Cisco email security options
Cisco brings email security appliances closer to SaaS
Cisco offers more email security choices, but lacks vision

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
asymmetric cryptography  (SearchSecurity.com)
challenge-response system  (SearchSecurity.com)
cryptographic checksum  (SearchSecurity.com)
data encryption/decryption IC  (SearchSecurity.com)
elliptical curve cryptography  (SearchSecurity.com)
Escrowed Encryption Standard  (SearchSecurity.com)
MPPE  (SearchSecurity.com)
Quiz: Cryptography  (SearchSecurity.com)
session key  (SearchSecurity.com)
Twofish  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts