Email Security

Email security

On any given day we all likely communicate with others in both an official and unofficial capacity using email. Many of us have multiple email accounts that we might use. It’s certainly not uncommon for people to have separate work and personal email accounts, and some people maintain separate throw away accounts for use with online media or other potentially spam generating websites.

Here are the four places where such a compromise could happen:

  1. On your device (Laptop, desktop, smartphone, tablet, etc…)
  2. On your destination/recipient device
  3. On your network/internet connection
  4. On the email servers

Your, or your email recipient’s, devices are a very likely target.  We go through a lot to protect these devices.  They should all be password protected and encrypted, but is that really the case?  Does everyone use a lock screen or password?  If device storage is not encrypted then anyone with access to the hard drive or other storage (i.e. a memory card) can easily copy the unencrypted data, including any email or associated attachments.

You might think that a person needs to gain physical access to your laptop, desktop, tablet or smartphone in order to search through it. Unfortunately, with the advent of web or cloud based email services a bad actor only needs your username and password to access your email because it is not actually stored on your local device.  Instead, all they need is a browser to remotely access your account.  The most likely way that your email will be compromised is as the result of malware installed as part of a phishing attack or through a seemingly valid website.  Accessing your email is one of the most common malware purposes.

Sending email is not like making an old fashion telephone call.  It doesn’t establish a direct, secure, connection between the sender and the receiver.  Instead, it kicks off a process where your email gets forwarded from your local and/or cloud email server to other email servers.  In some ways it’s like the Pony Express with your message bouncing from point to point (server to server) along the way until it finally reaches its destination.  And, at any point along the way, that email could potentially be read by anyone with the right level of access or with the correct technical tools.  This means that when you send email there are many places where your email could be compromised. First, there is your, and your email recipient’s, connection to your respective email services.  Second, there are the connections between email service provider servers. Let’s take a look at both.

First, it is highly likely that everyone’s connection to their email service is encrypted.  You should always check to ensure that you are accessing web based email clients over a secure internet connection.  When using a browser simply verify that there is a lock (SSL/TLS) icon displayed on the address bar or that the address shows “https://” at the beginning.  If you have a piece of client software it’s a little more difficult to check.  In most cases there will be a setting where you indicate that you want to secure the connection between your client software and email server.  At SUNY SA this is part of the default security baked into all our systems.  You should also note that servers at your email provider or ISP physically store all your email.  If someone guesses or steals your password they probably don’t need your device in order to log directly into your email provider.  Remember, your email is stored on those servers in regular unencrypted text format.  Providers do this to avoid associated costly overhead and because they want to scan your message traffic for key words to sell advertising.

In the second case mentioned above, in order for your email to move through the internet to its destination it must traverse many different network devices (routers and switches) likely owned and operated by different companies.  There is no guarantee that all the communications involved in the sequence of connections between the source (you) and destination (your recipient’s) email servers are secure.  While we would like to assume the entire chain of email transmission is secure the truth is that there is no way to really know.  As a result, your email could be easily read directly off the wire using readily available, free, network tools (i.e. Wireshark) and you would have no way of knowing this is happening.

The best approach is to accept that email is NOT secure and to take appropriate steps to safeguard your sensitive personal or business information. This will introduce additional layers of complexity, but without them there is really no way of protecting data sent via email. Here are some steps you can take today to provide better email security:

  1. Secure Outlook – SA has implemented secure email functionality in our O365 Outlook email service. When you are using the client application on your desktop/laptop or are using the web client, you can now secure your email communication. To secure your email do the following:
    1. Identify that there is data that you want to protect at a higher level. When in doubt check the SUNY SA Data Risk Classification Policy for guidance
    2. Add !SUNYEmailEncryption! to the body of your email. For more details, visit the Technology Solutions Center on SUNY Blue. 
  2. Encrypt Attachments – If you are sending an email that contains data that you want protected or which should be protected (i.e. is deemed Private or Restricted) based on the SA Data Risk Classification Policy then the best option is to encrypt the information.

Email security methods:

  1. Microsoft Word and Excel – Microsoft includes the ability to encrypt both MS Word documents and Excel spreadsheets. The functionality is found by going to "File" > "Protect Document (or Spreadsheet, as the case may be)"> "Encrypt with Password." By default Office 2016/O365 uses AES 256 encryption which is considered the de facto industry standard.
    1. Be sure to create a password that is a minimum of 10 characters and which includes numbers, letters (both upper and lower case), and special characters. Often a phrase is easier to remember and provides better security due to its length.
    2. Never send the password in the same or another email. The best solution is to contact the intended recipient and provide the password/passphrase either over the phone (best) or via a text message (less secure).
  2. Windows 7 and Windows 10 – Do not use the built-in encryption functionality provided by the OS.  It is not designed to create portable encrypted files.
  3. 3rd Party Software – There are several programs that provide easy to implement encryption. Two of the most popular (and free) solutions are 7-Zip and WinZip. Follow the directions supplied by these 3rd party tools to encrypt your sensitive documents. Follow the same instructions provided above regarding password length and complexity. 

As always, if you have any questions regarding whether or not you should send specific information in an email, err on the side of caution.  It’s amazing what people will send via email. Below is a short listing of sensitive data that has been sent via O365 email over the last year:

  1. Personal Tax Forms
  2. Personal Loan Forms
  3. Personal Medical Information
  4. Foreign Visa Applications
  5. Credit Card Information – with security codes
  6. Credit Card Applications
  7. Student FERPA and PII[i] Data
  8. Employee PIIi Data
  9. Sensitive legal documents
  10. Birth/Death Certificates

This is a recurring issue and is not limited to any given individual or functional office.

If you have already reviewed the Data Risk Classification Policy and still have questions please contact the CISO, Ken Runyon, at ken.runyon@suny.edu or via phone at 518-320-1368.


 

[i] PII – Personally Identifiable Information (PII). The National Institute for Standards and Technology (NIST) document 800-122, "Guide to Protecting the Confidentiality of Personally Identifiable Information (PII)", defines PII as the following: "Any information about an individual maintained by an agency, including (1) any information that can be used to distinguish or trace an individual's identity, such as name, social security number, date and place of birth, mother's maiden name, or biometric records; and (2) any other information that is linked or linkable to an individual, such as medical, educational, financial, and employment information.", pg. ES-1.

Information Security