On any given day we all likely communicate with others in both an official and unofficial capacity using email. Many of us have multiple email accounts that we might use. It’s certainly not uncommon for people to have separate work and personal email accounts, and some people maintain separate throw away accounts for use with online media or other potentially spam generating websites.
Here are the four places where such a compromise could happen:
Your, or your email recipient’s, devices are a very likely target. We go through a lot to protect these devices. They should all be password protected and encrypted, but is that really the case? Does everyone use a lock screen or password? If device storage is not encrypted then anyone with access to the hard drive or other storage (i.e. a memory card) can easily copy the unencrypted data, including any email or associated attachments.
You might think that a person needs to gain physical access to your laptop, desktop, tablet or smartphone in order to search through it. Unfortunately, with the advent of web or cloud based email services a bad actor only needs your username and password to access your email because it is not actually stored on your local device. Instead, all they need is a browser to remotely access your account. The most likely way that your email will be compromised is as the result of malware installed as part of a phishing attack or through a seemingly valid website. Accessing your email is one of the most common malware purposes.
Sending email is not like making an old fashion telephone call. It doesn’t establish a direct, secure, connection between the sender and the receiver. Instead, it kicks off a process where your email gets forwarded from your local and/or cloud email server to other email servers. In some ways it’s like the Pony Express with your message bouncing from point to point (server to server) along the way until it finally reaches its destination. And, at any point along the way, that email could potentially be read by anyone with the right level of access or with the correct technical tools. This means that when you send email there are many places where your email could be compromised. First, there is your, and your email recipient’s, connection to your respective email services. Second, there are the connections between email service provider servers. Let’s take a look at both.
First, it is highly likely that everyone’s connection to their email service is encrypted. You should always check to ensure that you are accessing web based email clients over a secure internet connection. When using a browser simply verify that there is a lock (SSL/TLS) icon displayed on the address bar or that the address shows “https://” at the beginning. If you have a piece of client software it’s a little more difficult to check. In most cases there will be a setting where you indicate that you want to secure the connection between your client software and email server. At SUNY SA this is part of the default security baked into all our systems. You should also note that servers at your email provider or ISP physically store all your email. If someone guesses or steals your password they probably don’t need your device in order to log directly into your email provider. Remember, your email is stored on those servers in regular unencrypted text format. Providers do this to avoid associated costly overhead and because they want to scan your message traffic for key words to sell advertising.
In the second case mentioned above, in order for your email to move through the internet to its destination it must traverse many different network devices (routers and switches) likely owned and operated by different companies. There is no guarantee that all the communications involved in the sequence of connections between the source (you) and destination (your recipient’s) email servers are secure. While we would like to assume the entire chain of email transmission is secure the truth is that there is no way to really know. As a result, your email could be easily read directly off the wire using readily available, free, network tools (i.e. Wireshark) and you would have no way of knowing this is happening.
The best approach is to accept that email is NOT secure and to take appropriate steps to safeguard your sensitive personal or business information. This will introduce additional layers of complexity, but without them there is really no way of protecting data sent via email. Here are some steps you can take today to provide better email security:
As always, if you have any questions regarding whether or not you should send specific information in an email, err on the side of caution. It’s amazing what people will send via email. Below is a short listing of sensitive data that has been sent via O365 email over the last year:
This is a recurring issue and is not limited to any given individual or functional office.
If you have already reviewed the Data Risk Classification Policy and still have questions please contact the CISO, Ken Runyon, at ken.runyon@suny.edu or via phone at 518-320-1368.
[i] PII – Personally Identifiable Information (PII). The National Institute for Standards and Technology (NIST) document 800-122, "Guide to Protecting the Confidentiality of Personally Identifiable Information (PII)", defines PII as the following: "Any information about an individual maintained by an agency, including (1) any information that can be used to distinguish or trace an individual's identity, such as name, social security number, date and place of birth, mother's maiden name, or biometric records; and (2) any other information that is linked or linkable to an individual, such as medical, educational, financial, and employment information.", pg. ES-1.