Home > Security Channel Tips > Application Security > Email encryption mechanisms
Security Channel Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

APPLICATION SECURITY

Email encryption mechanisms


Mike Chapple
11.03.2006
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Value-added resellers (VARs) and security consultants can use this tip, originally from SearchSecurity.com, to get advice on how to add security to email communications through encryption.

Email Security Project Guide
Find more tips and strategies for securing your customer's email systems in our Email Security Project Guide, designed specifically for channel professionals. 

Regulatory requirements and other security issues are forcing many users to demand technical measures that ensure the confidentiality and integrity of their electronic mail messages. Current email encryption mechanisms are still somewhat awkward, but the movement toward pervasive email encryption is gaining steam. In this tip, we'll review a few options for adding security to your email communications.

First, it's important to recognize the fact that email is inherently insecure. The three major protocols used for the vast majority of electronic mail (POP, IMAP and SMTP) are all clear text protocols that were designed without much thought to security. If you use these protocols in their basic form to exchange email, you should have absolutely no expectation of privacy. Your organization's mail is subject to interception, alteration and counterfeiting by anyone on the virtual path between the sender and the recipient.

What's a security-conscious emailer to do?

You need to examine the email security issue from two points of view. You need to protect account data (especially usernames and passwords) from disclosure and you need to protect the confidentiality and integrity of the messages sent.

Data defense

Protecting account data isn't that hard. If you're using a desktop email client like Outlook, Eudora or Thunderbird with the standard POP/SMTP or IMAP/SMTP protocol pairings, use a Secure Sockets Layer (SSL) connection to encrypt exchanges with the server. This requires some reconfiguration and can only be done if your ISP supports SSL connections. You'll probably need to change the ports you use for each protocol to their SSL counterparts. SMTPS typically runs on port 465 instead of the standard SMTP port 25. IMAPS uses port 993, and POP3S uses 995.

Encrypting the session with the local server is usually easier for Web-based email. Most Web-based email services support SSL for at least the authentication process. Simply use the same address you normally use for Web-based mail but change the "http://" to "https://." Some services, including Google's Gmail, keep this SSL connection for your entire session while others will revert to standard HTTP after you've authenticated.

It's critical to note here that both of the SSL mechanisms described only protect communication with your local server. SSL will protect you against someone sniffing the connection between you and your server with a tool like tcpdump or ethereal, but it doesn't provide any protection beyond the local server.

Confidentiality complexity

If you'd like to protect the confidentiality and integrity of your organization's email messages from source to destination, you have a slightly more complex problem on your hands. There really isn't a standardized method for exchanging cryptographic keys and encrypted email messages. You must collaborate with the recipient of your messages and agree on the technology that will be used. Programs like Microsoft Outlook and Mozilla Thunderbird support S/MIME, the closest thing we have to a standard. To take advantage of this functionality, you'll need to obtain a digital certificate that contains a signed version of your public key. You can obtain such a certificate from firms like Verisign and Thawte. Thawte even offers a limited functionality personal certificate for free.

The alternative to S/MIME is Phil Zimmerman's Pretty Good Privacy (PGP). This model, based upon a "Web of trust," is also available as a plug-in for Microsoft Outlook. It's not currently available for Thunderbird users, but Mozilla says it plans to introduce PGP support in a future release. You can try PGP for free by signing up for a Web-based email account with Hushmail.

Once you have it up and running, email encryption promises to add a great deal of security to your electronic communications. Stay attuned to the industry as we watch the development of S/MIME and PGP toward a single standard.

About the author
Mike Chapple, CISSP is an IT Security Professional with the University of Notre Dame. He previously served as an information security researcher with the National Security Agency and the U.S. Air Force. Mike is a frequent contributor to SearchSecurity, a technical editor for
Information Security magazine and the author of several information security titles including the CISSP Prep Guide and Information Security Illuminated.

This tip originally appeared on SearchSecurity.com.


Rate this Tip
To rate tips, you must be a member of SearchSecurityChannel.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Instant messaging and collaboration application security
Social media security policies: Helping customers understand the threats
Compliance, Web threats change email security market, opportunities
Sophos integrates encryption into endpoint, email security
Email security vendor Sendio unveils new partner program
Netgear primes VARs for SMB email and Web security appliance sales
Outlook Web Access security: Helping channel customers stay safe
Channel Explained: Email security
What security settings best apply to the client?
Can we offer managed security services to the client for this server?
Should we offer periodic security audits of the email server?

Email Encryption Mechanisms
Can we offer managed security services to the client for this server?
A review of Voltage Security's Voltage SecureMail Desktop
Demystifying email encryption
Securing your customer's email with digital signatures
Add DKIM to your customer's email security solution
Securing email with S/MIME
Transport Layer Security encryption: Five steps to get you started

Webmail Security
Can we offer managed security services to the client for this server?

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

HomeNewsTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogsEvents
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2006 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts