<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Securing your own email in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/Securing-your-own-email/m-p/33108#M2382</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/136236425"&gt;@ericgeater&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Since my Gmail account isn't secure, and my employer doesn't have a legitimate necessity for doing server level mail encryption, if I wanted to create my own secure email system, what all is required?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With PGP, it's fairly easy -- as long as the other party you're communicating with uses PGP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I understand that with PKI, anyone can exchange messages with you -- provided they know the protocol.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I go the PKI route, I would probably use a domain I own.&amp;nbsp; That way I can look at the whole thing in-house, except for the CA/RA part.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What experiences do y'all have with personal or "roll-your-own professional" secure email?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Eric,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I have not used it, but &lt;STRONG&gt;&lt;A href="https://protonmail.com" target="_blank" rel="noopener"&gt;ProtonMail&lt;/A&gt;&lt;/STRONG&gt; looks interesting. Have you investigated it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 25 Feb 2020 21:52:41 GMT</pubDate>
    <dc:creator>CraginS</dc:creator>
    <dc:date>2020-02-25T21:52:41Z</dc:date>
    <item>
      <title>Securing your own email</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Securing-your-own-email/m-p/33053#M2375</link>
      <description>&lt;P&gt;Since my Gmail account isn't secure, and my employer doesn't have a legitimate necessity for doing server level mail encryption, if I wanted to create my own secure email system, what all is required?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With PGP, it's fairly easy -- as long as the other party you're communicating with uses PGP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I understand that with PKI, anyone can exchange messages with you -- provided they know the protocol.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I go the PKI route, I would probably use a domain I own.&amp;nbsp; That way I can look at the whole thing in-house, except for the CA/RA part.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What experiences do y'all have with personal or "roll-your-own professional" secure email?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2020 01:37:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Securing-your-own-email/m-p/33053#M2375</guid>
      <dc:creator>ericgeater</dc:creator>
      <dc:date>2020-02-25T01:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: Securing your own email</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Securing-your-own-email/m-p/33065#M2376</link>
      <description>&lt;P&gt;I wouldn't do it. The question is would there be enough use for it to be worth the time? If you only have a few people that would sent you encrypted messages then it would not pay to setup a whole infrastructure to support it. What about a simple plug in on the mail client? It would shift things from server to client side but still allow for messages to be encrypted and decrypted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just my .02&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;John-&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2020 13:47:51 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Securing-your-own-email/m-p/33065#M2376</guid>
      <dc:creator>JKWiniger</dc:creator>
      <dc:date>2020-02-25T13:47:51Z</dc:date>
    </item>
    <item>
      <title>Re: Securing your own email</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Securing-your-own-email/m-p/33074#M2377</link>
      <description>&amp;gt; ericgeater (Contributor I) posted a new topic in Tech Talk on 02-24-2020 08:37&lt;BR /&gt;&lt;BR /&gt;&amp;gt; &amp;nbsp; But I understand&lt;BR /&gt;&amp;gt; that with PKI, anyone can exchange messages with you -- provided they know the&lt;BR /&gt;&amp;gt; protocol. &amp;nbsp; If I go the PKI route, I would probably use a domain I own.&amp;nbsp; That&lt;BR /&gt;&amp;gt; way I can look at the whole thing in-house, except for the CA/RA part. &amp;nbsp; What&lt;BR /&gt;&amp;gt; experiences do y'all have with personal or "roll-your-own professional" secure&lt;BR /&gt;&amp;gt; email?&lt;BR /&gt;&lt;BR /&gt;Ah, yes. I remember the days when people would say "I want five pounds of&lt;BR /&gt;PKI." PKI is not a "thing." It's a whole bunch of things, and you need to get each&lt;BR /&gt;and every one of them right. It's no harder than trying to creeate your own&lt;BR /&gt;crypto algorithm. (In other words, it's really, really hard.)&lt;BR /&gt;&lt;BR /&gt;As it happens, I'm (sort of) working with a guy who is trying this "universal secure&lt;BR /&gt;email the easy way" right now, and he's got a system that is both secure and easy&lt;BR /&gt;to use. It's a bit clunky, and relies on the sending party having a smartphone&lt;BR /&gt;(which I also think is the main weakness of the system), but it's quite clever.&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;A ship in port is safe, but that is not what ships are built for.&lt;BR /&gt;- (John A.?/William?) Shedd&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
      <pubDate>Tue, 25 Feb 2020 16:55:53 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Securing-your-own-email/m-p/33074#M2377</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2020-02-25T16:55:53Z</dc:date>
    </item>
    <item>
      <title>Re: Securing your own email</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Securing-your-own-email/m-p/33086#M2378</link>
      <description>&lt;P&gt;Glad you pointed out the difficulty attached to the payoff.&amp;nbsp; In my personal case, there's not enough requirement for it yet.&amp;nbsp; I suppose the message could be encrypted in a file, then attached to a message.&amp;nbsp; Poor man's secrecy good in a pinch.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2020 18:00:39 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Securing-your-own-email/m-p/33086#M2378</guid>
      <dc:creator>ericgeater</dc:creator>
      <dc:date>2020-02-25T18:00:39Z</dc:date>
    </item>
    <item>
      <title>Re: Securing your own email</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Securing-your-own-email/m-p/33108#M2382</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/136236425"&gt;@ericgeater&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Since my Gmail account isn't secure, and my employer doesn't have a legitimate necessity for doing server level mail encryption, if I wanted to create my own secure email system, what all is required?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With PGP, it's fairly easy -- as long as the other party you're communicating with uses PGP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I understand that with PKI, anyone can exchange messages with you -- provided they know the protocol.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I go the PKI route, I would probably use a domain I own.&amp;nbsp; That way I can look at the whole thing in-house, except for the CA/RA part.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What experiences do y'all have with personal or "roll-your-own professional" secure email?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Eric,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I have not used it, but &lt;STRONG&gt;&lt;A href="https://protonmail.com" target="_blank" rel="noopener"&gt;ProtonMail&lt;/A&gt;&lt;/STRONG&gt; looks interesting. Have you investigated it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2020 21:52:41 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Securing-your-own-email/m-p/33108#M2382</guid>
      <dc:creator>CraginS</dc:creator>
      <dc:date>2020-02-25T21:52:41Z</dc:date>
    </item>
    <item>
      <title>Re: Securing your own email</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Securing-your-own-email/m-p/33226#M2394</link>
      <description>&lt;P&gt;I have not!&amp;nbsp; It does look like a useful solution, however!&amp;nbsp; Thanks for the link!&lt;/P&gt;</description>
      <pubDate>Sun, 01 Mar 2020 15:45:36 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Securing-your-own-email/m-p/33226#M2394</guid>
      <dc:creator>ericgeater</dc:creator>
      <dc:date>2020-03-01T15:45:36Z</dc:date>
    </item>
    <item>
      <title>Re: Securing your own email</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Securing-your-own-email/m-p/33227#M2395</link>
      <description>&lt;P&gt;I realize that a claim is only as good as its veracity, but I did notice this on the &lt;A href="https://protonmail.com/pricing" target="_blank" rel="noopener"&gt;ProtonMail website&lt;/A&gt;:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;Revenue from paid accounts is used to further develop ProtonMail and support free users such as democracy activists and dissidents who need privacy but can't necessarily afford it.&lt;/SPAN&gt;"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am aware that some ransomware thugs use ProtonMail too... but it's nice to see this type of declaration.&amp;nbsp; Pretty awesome.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Mar 2020 16:05:59 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Securing-your-own-email/m-p/33227#M2395</guid>
      <dc:creator>ericgeater</dc:creator>
      <dc:date>2020-03-01T16:05:59Z</dc:date>
    </item>
    <item>
      <title>Re: Securing your own email</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Securing-your-own-email/m-p/33236#M2396</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/136236425"&gt;@ericgeater&lt;/a&gt;&amp;nbsp;&amp;nbsp; What concerns you?&amp;nbsp; Your privacy in terms of exchanging messages between trusted parties or reducing the opportunity for Federal Authorities accessing the contents of your messages?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We all know G-mail is insecure and probably the contents end up in one of Google Datasets by default.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has I have stated previously to &lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/780103681"&gt;@CraginS&lt;/a&gt; various countries around the world, have the authority by law to intercept all and any traffic passing through ISPs.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You effectively make yourself a target, because if the authorities cannot immediately decrypt on mass and look for key words, or defined parameters makes you a target of interest.&amp;nbsp; Especially if you use a cryptographic algorithm, which is not fully defined or customised to meet a particular need.&amp;nbsp;&amp;nbsp; In fact encryption in the USA is seen as a Munition:&amp;nbsp; &lt;A href="https://law.stackexchange.com/questions/3705/what-exactly-makes-encryption-a-weapon" target="_blank"&gt;https://law.stackexchange.com/questions/3705/what-exactly-makes-encryption-a-weapon&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other countries have similar definitions and export rules.&amp;nbsp;&amp;nbsp; I should know I have to go through such a process every time I define a solution, service for a client etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Mar 2020 23:19:53 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Securing-your-own-email/m-p/33236#M2396</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2020-03-01T23:19:53Z</dc:date>
    </item>
    <item>
      <title>Re: Securing your own email</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Securing-your-own-email/m-p/33455#M2437</link>
      <description>&lt;P&gt;My inquiry was based on the usefulness of having a secure solution available for message exchange.&amp;nbsp; But it definitely sounds like there's a whole lot of trouble to go through, for a very limiting payoff.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Mar 2020 04:26:26 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Securing-your-own-email/m-p/33455#M2437</guid>
      <dc:creator>ericgeater</dc:creator>
      <dc:date>2020-03-08T04:26:26Z</dc:date>
    </item>
  </channel>
</rss>

