Secure E-mail Exchange
E-mail is a great way to exchange information easily and rapidly. However, it can also be associated with significant risks when sensitive data have to be exchanged. In the standard configuration of usual e-mail programs, the main risks are as follows:
- Sensitive data might be intercepted and subsequently abused. For example, data might fall into the wrong hands, or might even be modified on the way to the legitimate recipient. Note that by default the data pass several servers in unencrypted form, so that they may be intercepted e.g. by someone with administrator rights.
- E-mails with a forged sender identity may be used in various ways. It is easy to send e-mails with a forged sender address, and also easy to imagine in what way this could be exploited for creating damage.
Fortunately, there are ways to basically eliminate these hazards. Being concerned about the security of the customer's data, RP Photonics Consulting GmbH encourages customers to establish secure e-mail exchange and is prepared to assist in this process.
Establishing Secure E-Mail Exchange
The above-mentioned security hazards can be quite securely eliminated in the following way:
- E-mails can be signed with a digital certificate e.g. from Verisign which can be validated by most e-mail programs (without any special measures on the side of the customer). Assuming that the e-mail program will indicate a valid certificate, this ensures the recipient that (1) the received e-mails are really coming from the indicated sender address and (2) that the content of these e-mails has not been modified on the way to the recipient.
- Customers can exchange e-mails with RP Photonics in encrypted form, using the same kind of digital ID. E-mail encryption ensures that nobody else can intercept the information. (Details are given below.)
Unfortunately, the use of digital certificates can also introduce technical problems. In particular, some e-mail clients (e.g. Outlook Express) appear to demand a digital signature for any replies to signed e-mails, and cause an error message in the case that the sender doesn't have a digital ID. This has irritated some customers. Therefore, RP Photonics is currently no more digitally signing outgoing e-mails by default.
How to Obtain an Own Digital Certificate
For exchange of encrypted e-mails and for sending signed e-mails, the customer will need an own digital certificate. It is advisable to get this from one of the well-known certificate authorities, because certificates issued by those are accepted by most software without first installing a certificate of the authority itself. (For example, the Windows operating system comes with a built-in list of trusted authorities.) For example, you can obtain a certificate (valid for one year) for ∼20 USD from VeriSign via the website Digital IDs for Secure Email.
When you got your certificate, just inform RP Photonics Consulting GmbH by e-mail about that. Also, please send your public certificate (never the private one!) by e-mail, or indicate the used certificate authority (e.g. VeriSign). Finally, set your e-mail program so that it will digitally sign all outgoing e-mails, using your certificate.
How to Obtain the Digital Certificate of RP Photonics Consulting GmbH
For the exchange of encrypted e-mails, the customer also has to install the public certificate of R. Paschotta at RP Photonics Consulting GmbH in his or her e-mail program. If customer's e-mail software can handle S/MIME certificates, the easiest way is to download R. Paschotta's S/MIME certificate here in S/MIME Format (Binary PKCS#7). Alternatively, some e-mail programs (e.g. Netscape Communicator) can integrate VeriSign's directory service, making it easy to download and install a foreign certificate. Otherwise, the certificate can be obtained as follows:
- Visit the webpage Search For Digital IDs from VeriSign.
- Enter the e-mail address "Paschotta@rp-photonics.com" to find the certificate.
- Click on "Rüdiger Paschotta" on the found certificate and click on the "Download" button.
- Choose a format which is suitable for your e-mail software and press the button "Download This Digital ID".
- The downloaded certificate file then has to be installed in your e-mail software; the details depend on the used software.
After successful installation, you can set your e-mail software so that messages are sent in encrypted form. As only RP Photonics Consulting GmbH is in possession of the private part of the used key, nobody else will be able to decrypt the data.
A Simple Alternative
Of course, one may exchanging sensitive information simply in the form of attachments which are encrypted with some other kind of software. For example, the program TrueCrypt can be used, which is available for free, simple to handle and rather secure. The key to encrypt and decrypt the information may then be agreed on e.g. on the telephone.
While this method is conceptually simple, its main disadvantage is that each message or file to be transmitted must be manually processed with this encryption software.
Responsibilities
- Of course, RP Photonics Consulting GmbH can not accept any legal responsibility for hazards arising from insecure (not encrypted and signed) e-mail exchange. However, customers are encouraged to establish secure e-mail exchange and will obtain assistance for that as far as possible.
- Customers have to make sure themselves that they understand the workings of secure e-mail exchange (e.g. using the resources given below), and they are responsible themselves for taking appropriate precautions. For example, they must take care not to undermine their security by mistakes (such as making a private certificate accessible by others, or simply sending an e-mail to the wrong address).
- Of course, RP Photonics has no way to prevent that e.g. someone will send unsigned e-mails with a forged sender address of RP Photonics Consulting GmbH (or signed e-mails with a slightly modified address), e.g. with the intention of doing phishing or spreading computer viruses and the like. No technical means can eliminate the need for some level of vigilance on all sides.
Further Information
It is important that customers understand the workings of secure e-mail. Further information on this topic is available via the following links:
- Digital ID – A Brief Overview by VeriSign
- What is a Digital ID? by VeriSign