email encryption

34
• Email Encryption https://store.theartofservice.com/the-email-encryption- toolkit.html

Upload: theodore-simpson

Post on 04-Jan-2016

226 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Email Encryption

• Email Encryption

https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 2: Email Encryption

Email - Operation overview

1 Email messages are not secure if email encryption is not used

correctly.

https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 3: Email Encryption

Gmail - Privacy

1 Any (web mail or other) mail system which stores and retains user's email

contents is an attractive target for such attacks, but Gmail is popular

with security-conscious users because of its early HTTPS secure

(Email encryption|encrypted) connection support, and its more-recent HTTPS-only default setting..

Gmail Help Center.https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 4: Email Encryption

E-mail - Operation overview

1 * Email messages are not secure if email encryption is

not used correctly.

https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 5: Email Encryption

GNU Privacy Guard - History

1 Because GnuPG is an OpenPGP standard compliant system, the

history of OpenPGP is of importance. It was designed to interoperate with Pretty Good Privacy|PGP, the email

encryption program initially designed and developed by Phil Zimmermann.

https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 6: Email Encryption

Secure transmission

1 In computer science, 'secure transmission' refers to the transfer of

data such as confidential or proprietary information over a secure channel. Many secure transmission methods require a type of encryption. The most common email encryption is called public key

infrastructure|PKI. In order to open the encrypted file an exchange of Key

(cryptography)|keys is done.

https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 7: Email Encryption

Operations security

1 Protecting this critical information is through the use of email encryption

software, being careful of who may be listening to you (like in a hotel bar), paying close attention to a picture you have taken

(back ground), or not talking openly on social media sites about information on the

unit's critical information list (military deployments, shortages of equipment or

movement of VIPs).

https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 8: Email Encryption

Philip Zimmermann

1 'Philip R. Phil Zimmermann, Jr.' (born February 12, 1954) is the creator of Pretty Good Privacy (PGP), the most

widely used email encryption software in the world. He is also known for his work

in VoIP encryption protocols, notably ZRTP and Zfone. Zimmermann is

currently the president and co-founder of the global encrypted communications

firm, Silent Circle (software)|Silent Circle.

https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 9: Email Encryption

WatchGuard - History

1 In 2009, WatchGuard acquired Toronto-based BorderWare

Technologies for its products including email and web content

security, data loss prevention, and email encryption.

https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 10: Email Encryption

E-mail client - Encryption

1 With no encryption, much like for postcards, email activity is plainly visible by any

occasional eavesdropper. Email encryption enables privacy to be safeguarded by

encrypting the mail sessions, the body of the message, or both. Without it, anyone with

network access and the right tools can monitor email and obtain login passwords. Examples

of concern include the government censorship and surveillance and fellow wireless network

users such as at an Internet cafe.

https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 11: Email Encryption

Comodo Group - Consumer Products

1 Comodo SecureEmail is an email encryption program that allows

S/MIME email users to send emails to any email user without exchanging

keys beforehand.

https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 12: Email Encryption

Mobile business intelligence - Device Security

1 As such, there is no local copy to lose if the mobile device is stolen and the data can reside on servers within the data center with access permitted only

over the network.[http://www.cio.com/article/40360/Mobile_S

ecurity_Definition_and_Solutions?page=1taxonomyId=3061 Mobile Security Definition and Solutions] Most smartphone

manufacturers provide a complete set of security features including full-disk encryption, email

encryption, as well as remote management which includes the ability to wipe contents if device is lost

or stolenhttps://store.theartofservice.com/the-email-encryption-toolkit.html

Page 13: Email Encryption

Kolab - Main features

1 * Full support for client-side PGP and S/MIME email encryption (officially Sphinx-

interoperable)

https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 14: Email Encryption

Exchange ActiveSync - Exchange ActiveSync 2.5

1 Tasks syncing was added as was SMIME|S/MIME email encryption and the

following policies were added:

https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 15: Email Encryption

Email encryption

1 'Email encryption' refers to encryption, and often authentication,

of email messages, to protect the content from being read by any but

the intended recipients.

https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 16: Email Encryption

Email encryption

1 Email encryption can rely on public-key cryptography, in which users can each publish a public key that others

can use to encrypt messages to them, while keeping secret a Public-key cryptography|private key they

can use to decrypt such messages or to digitally encrypt and sign

messages they send.

https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 17: Email Encryption

Email encryption - Encryption protocols

1 Communications protocol|Protocols for

email encryption include:

https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 18: Email Encryption

Edward Snowden - Release of documents

1 Snowden communicated using Email encryption|encrypted email, using

the codename :wikt:verax|Verax. He asked not to be quoted at length for fear of identification by stylometry.

https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 19: Email Encryption

Identity certificate

1 Certificates are an important component of Transport Layer

Security (TLS, sometimes called by its older name SSL), where they

prevent an attacker from impersonating a secure website or other server. They are also used in

other important applications, such as email encryption and code signing.

https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 20: Email Encryption

CipherCloud - Platform

1 Encryption keys are stored locally, never leave the user’s site and are not shared with the cloud provider.[http://safegov.org/2012/11/9/is-cloud-data-encryption-the-answer-to-patriot-act-fears Is Cloud Data Encryption the Answer to Patriot Act Fears? SafeGov.org, November 9, 2012]

[http://www.washingtontimes.com/news/2013/aug/18/email-encryption-services-suddenly-

close-over-us-s/?page=all#pagebreak Shaun Waterman, Email Encryption Services Suddenly

Close Over U.S

https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 21: Email Encryption

ProtonMail - Crowdfunding

1 The PayPal account of Protonmail was frozen on 30 June 2014. A representative of PayPal stated that the company froze

the account over the doubts of the legality of the encryption.O'Neill, Patrick Howell. [http://www.dailydot.com/politics/paypal-protonmail-freeze/ PayPal freezes account

of email encryption startup ProtonMail [Update. The Daily Dot. July 1, 2014.

Retrieved on July 1, 2014.

https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 22: Email Encryption

Echoworx

1 'Echoworx', an email encryption software company, is based in Toronto, Canada, with offices in Atlanta and

London.[http://www.echoworx.com/contact/ Echoworx Corporate Offices] As a certificate authority,[https://cert.webtrust.org/SealFile?

seal=548file=pdf Echoworx Web Trust Certificate] Echoworx is a member of both the Microsoft Root Certificate Program

[http://social.technet.microsoft.com/wiki/contents/articles/14217.windows-and-windows-phone-8-ssl-root-certificate-program-april-2012-e-g.aspx Windows and Windows Phone 8 SSL Root Certificate Program]

and Apple Root Certificate Program.[http://support.apple.com/kb/HT5012 iOS: List of available trusted root certificates] Echoworx operates several data centers,

including locations in the United States[http://iprodeveloper.com/security/echoworx-announces-secure-

data-center Echoworx announces secure data center] and Europe.[http://www.thewhir.com/web-hosting-news/echoworx-plans-european-

data-center Echoworx Plans European Data Center]

https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 23: Email Encryption

Echoworx - Products

1 Echoworx offers several products in the area of email encryption. Its

products are offered both through Direct selling|direct sales and as a white-label product|white-labelled

product[http://www.clipper.com/research/TCG2005079.pdf Echoworx builds

opportunity into its secure mail solution] through several partners.

Major offerings include:https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 24: Email Encryption

Echoworx - Products

1 *OneWorld - A policy-based email encryption solution designed to work with

multiple platforms. OneWorld supports Pretty Good Privacy|PGP, S/MIME and

Transport Layer Security|TLS, in addition to encrypted Portable Document Format|PDF

E-mail attachment|attachments and a secure web

portal.[http://mcafee.ulitzer.com/node/2394116 Echoworx oneWorld-Email Encryption

Without Boundaries]https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 25: Email Encryption

Echoworx - Products

1 *Encrypted Message Exchange - A fully hosted secure web-based email portal[http://mosaicsecurity.com/categories/102-hosted-email-encryption Hosted Email Encryption Products

Comparison]

https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 26: Email Encryption

Echoworx - Products

1 *mobilEncrypt - On-device email encryption for iOS, Android (operating system)|Android and Blackberry (company)|BlackBerry products.

[http://www.scmagazine.com/echoworx-mobilencrypt-endpoint/review/3679/ SC

Magazine mobilEncrypt Review] mobilEncrypt was response to a growing trend of BYOD

policies in businesses[http://www.itworldcanada.com/article/echoworx-extends-e-mail-device-encryption-to-ipad-iphone/44422 Echoworx extends e-mail

device encryption to iPad, iPhone]

https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 27: Email Encryption

DataMotion, Inc.

1 DataMotion provides secure information transport services and products to businesses, including

email encryption, SSH File Transfer Protocol|secure file transfer and

secure electronic form delivery.Stephenson, Peter,

[http://www.scmagazine.com/datamotion-securemail-gateway/review/3732

/ Review: DataMotion SecureMail Gateway]

https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 28: Email Encryption

DataMotion, Inc. - Patents

1 The patent was granted in 2004.http://patft.uspto.gov/netacgi/n

ph-Parser?Sect1=PTO2Sect2=HITOFFp=1u=%2Fnetahtml%2FPTO%2Fsearch-

bool.htmlr=48f=Gl=50co1=ANDd=PTXTs1=6,684,248OS=6,684,248RS=6,684,248 This patent was the basis for the company’s first product, self-

provisioning email encryption.https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 29: Email Encryption

DataMotion, Inc. - Products

1 The company first introduced SaaS-based email encryption in 1999. An

updated version of this product is still offered today as SecureMail Desktop. Several products have been added since that time. Other products sold

include:

https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 30: Email Encryption

DataMotion, Inc. - Products

1 SecureMail Gateway– an email

encryption filter

https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 31: Email Encryption

DataMotion, Inc. - Products

1 SecureContact– inbound-initiated email encryption

https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 32: Email Encryption

Forward secrecy - Use

1 Since November 2013, Twitter has provided forward secrecy with TLS to users of its

service. All wikis hosted by the Wikimedia Foundation use PFS from July 1, 2014.

Facebook reported as part of an investigation into email encryption that as of May 2014 74% of hosts that support STARTTLS also

provide Perfect Forward Secrecy. , 13.8% of TLS-enabled websites are configured to use cipher suites that provide forward secrecy to

web browsers.As of October 3, 2014.

https://store.theartofservice.com/the-email-encryption-toolkit.html

Page 33: Email Encryption

Taher ElGamal - Biography

1 Elgamal currently serves as the CTO, Security at Salesforce.com. He serves as a

director of Vindicia, Inc., which provides online payment services, and Zix Corporation, which provides email

encryption services. He has served as an advisor to Onset Ventures, Glenbrook

Partners, PGP corporation, Arcot Systems, Finjan, Actiance, Symplified, and Zetta. He served as Chief Security Officer of Axway,

Inc. He is vice chairman of SecureMisr.https://store.theartofservice.com/the-email-encryption-toolkit.html