Home > Security Tips > Web Security Advisor > Implementing e-mail encryption
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

WEB SECURITY ADVISOR

Implementing e-mail encryption


Mike Chapple, CISSP
03.31.2005
Rating: -3.25- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Regulatory requirements and other security issues are forcing many users to demand technical measures that ensure the confidentiality and integrity of their electronic mail messages. Current e-mail encryption mechanisms are still somewhat awkward, but the movement toward pervasive e-mail encryption is gaining steam. In this tip, we'll review a few options for adding security to your e-mail communications.

First, it's important to recognize the fact that e-mail is inherently insecure. The three major protocols used for the vast majority of electronic mail (POP, IMAP and SMTP) are all clear text protocols that were designed without much thought to security. If you use these protocols in their basic form to exchange e-mail, you should have absolutely no expectation of privacy. Your organization's mail is subject to interception, alteration and counterfeiting by anyone on the virtual path between the sender and the recipient.

What's a security-conscious e-mailer to do?
You need to examine the e-mail security issue from two points of view. You need to protect account data (especially usernames and passwords) from disclosure and you need to protect the confidentiality and integrity of the messages sent.

Data defense
Protecting account data isn't that hard. If you're using a desktop e-mail client like Outlook, Eudora or Thunderbird with the standard POP/SMTP or IMAP/SMTP protocol pairings, use a Secure Sockets Layer (SSL) connection to encrypt exchanges with the server. This requires some reconfiguration and can only be done if your ISP supports SSL connections. You'll probably need to change the ports you use for each protocol to their SSL counterparts. SMTPS typically runs on port 465 instead of the standard SMTP port 25. IMAPS uses port 993, and POP3S uses 995.

Encrypting the session with the local server is usually easier for Web-based e-mail. Most Web-based e-mail services support SSL for at least the authentication process. Simply use the same address you normally use for Web-based mail but change the "http://" to "https://." Some services, including Google's Gmail, keep this SSL connection for your entire session while others will revert to standard HTTP after you've authenticated.

It's critical to note here that both of the SSL mechanisms described only protect communication with your local server. SSL will protect you against someone sniffing the connection between you and your server with a tool like tcpdump or ethereal, but it doesn't provide any protection beyond the local server.

Confidentiality complexity
If you'd like to protect the confidentiality and integrity of your organization's e-mail messages from source to destination, you have a slightly more complex problem on your hands. There really isn't a standardized method for exchanging cryptographic keys and encrypted e-mail messages. You must collaborate with the recipient of your messages and agree on the technology that will be used. Programs like Microsoft Outlook and Mozilla Thunderbird support S/MIME, the closest thing we have to a standard. To take advantage of this functionality, you'll need to obtain a digital certificate that contains a signed version of your public key. You can obtain such a certificate from firms like Verisign and Thawte. Thawte even offers a limited functionality personal certificate for free.

The alternative to S/MIME is Phil Zimmerman's Pretty Good Privacy (PGP). This model, based upon a "Web of trust," is also available as a plug-in for Microsoft Outlook. It's not currently available for Thunderbird users, but Mozilla says it plans to introduce PGP support in a future release. You can try PGP for free by signing up for a Web-based e-mail account with Hushmail.

Once you have it up and running, e-mail encryption promises to add a great deal of security to your electronic communications. Stay attuned to the industry as we watch the development of S/MIME and PGP toward a single standard.

About the author
Mike Chapple, CISSP is an IT Security Professional with the University of Notre Dame. He previously served as an information security researcher with the National Security Agency and the U.S. Air Force. Mike is a frequent contributor to SearchSecurity, a technical editor for
Information Security magazine and the author of several information security titles including the CISSP Prep Guide and Information Security Illuminated.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Managing Technology
SMTP policies help reduce the risk of unauthorized mail servers
How to secure e-mail with S/MIME
Symantec glitch could expose user names, passwords
HELP!
The methodology of software creation/distribution
Creating an antispam cocktail: Best spam detection and filtering techniques
Using TLS encryption
Experts predict new path for malicious code, antivirus products
When it comes to e-mail security, it's still 'sit, hope and pray'
Seven steps to safeguard enterprise e-mail

Web Security Advisor
DNS rebinding defenses still necessary, thanks to Web 2.0
New defenses for automated SQL injection attacks
PCI compliance and Web applications: Code review or firewalls?
Worst practices: Bad security incidents to avoid
Web scanning and reporting best practices
Social networking Web site threats manageable with good enterprise policy
Enterprise security in 2008: Building trust into the application development process
PCI DSS Section 6: A plan for tackling application security
Making the case for Web application vulnerability scanners
Preparing for uniform resource identifier (URI) exploits

Email Encryption (SMIME & PGP)
Tumbleweed merger seen as a negative for email security customers
Secure messaging complications result in limited protection
Information security book excerpts and reviews
ING hopes to cut phishing attacks with encryption software
Companies still monitoring email manually, survey finds
Should iPhone email be sent without SSL encryption?
Can the symmetric encryption algorithm for S/MIME messages be changed?
Security vendor Postini acquired by Google
Which email encryption products can be released internationally?
What are the pros and cons of using an email encryption gateway?
Email Encryption (SMIME & PGP) Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
asymmetric cryptography  (SearchSecurity.com)
cryptographic checksum  (SearchSecurity.com)
data encryption/decryption IC  (SearchSecurity.com)
deniable encryption  (SearchSecurity.com)
elliptical curve cryptography  (SearchSecurity.com)
Escrowed Encryption Standard  (SearchSecurity.com)
MPPE  (SearchSecurity.com)
Quiz: Cryptography  (SearchSecurity.com)
session key  (SearchSecurity.com)
Twofish  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
More Security Resources for Resellers, VARs and OEMs
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts