Thursday, 27 September 2012

Electronic Mail Security Issues

Brief Note
There are a number of issues that need to be addressed when it comes to electronic mail usage. In the old days, it was easy to detect that some one opened your (mail) letter in an envelop because it would be easy to konw. At this current "(dot).com" information age, it is quite difficult with the availability of sophiscated tools to hide traces/marks/evidence of tampering/unauthorized access. There are certain personal issues and organizational issues concerning e-mail usage. These issues can affect both the security and privacy of the e-mail owners, and the organization at alarge. The organisation says we have to monitor your email usage to ensure security of the organization and see to it that you are ony in the working limitations; nothing else, BUT the worker/email owner is looking at privacy for his/her emails. It is therefore important to note and think about issues related to that. Below are some of the issues for discussions. Please give in your comments and ideas.

Electronic Mail Issues

Personal mail: (issues of confidentiality and integrity)—Password sharing with boy/girl friends or wives/husbands etc… is it an issue in families? What if you are a secret government agent e.g. CID, FBI, etc.? What is your take on such issue? Is this an issue for the e-mail service provider or an issue for the email owner.

Email and the Business World: If you are in the business world, how do you manage and secure your mail? What if someone unauthorized got to access your work mail. What can happen to Organization trade secrets, financial data, organization trademarks etc.? How would you advise workers and organization managers?

Viruses: Sent via mail in some sort of nice attachment, your system will not be affected unless you download the attachment. How many times have you been a victim? What would you advise email users on this issue? how about protection? is it the service provider's poor security, the organization's bad security or the individual's lack of awareness and poor mail management skills?

Spam: This can really be a problem if not avoided? Have you been a culprit before? What can you do to reduce on the spam mail? How easy is it to design spam mail? Is it easy anyway? What does it take? is it something to fear? or you can do away with it.

Keystroke Loggers: Different organizations have their email etiquette. One of the common one is to monitor email usage by worker, where by there are some new software now days that monitor every key stroke an employee makes on the key board regardless of whether or not the data is saved. Do you think this is good? What could be good in this and what is the bad side of this? It seems to be an issue of management and making sure that you only focus on your work while in the organization. Is that fair enough or?

How about email storage? Are you comfortable with how the mails are stored? Do you any way know how emails are stored? Say for example organization mail servers, or the common Gmail, yahoo, Hotmail etc.? Do you think it secure enough? What makes you feel so? Does your mail still remain private even when it is stored by a third party company? so who is the sole person(entity) in charge of the security of the stored mails?
Your comments and ideas are welcome.

By
Fred Kaggwa

Friday, 21 September 2012

Implications of Auto Email Replies on an Individual's Privacy (e.g, Out of office auto reply, summer holiday auto reply)

A number of times email users have complained about hacking into their email accounts and having their privacy infringed. By privacy being infringed, i mean, for example, it is possible to know from an auto summer holiday reply that a certain email user is away for holiday. It is also possible to know that some one is out of office for a certain journey and for how long. This itself can lure the "bad guys" into launching certain attacks since they can easily plan for their time well based on the duration of the vacation or holiday as mentioned in the auto reply. Not only attacks to systems, but also physical robbery, or theft at the users home can easily be launched.
 
In this blog we would want to assess and see if this is a realistic privacy concern and if so, what other consequenses can come along with it. Imagine if the netwrok administrator is having a vacation to china for 1 month, what possible attacks can be anticipated that could easily and successfuly be launched based on the time schedule?
You can mention a number of other issues that  you think are privacy and security related in terms of auto reply technologies. And any way, is privacy really a concern in this scenario or it is an "i dont care" aspect?
 
Your ideas are welcome

By
Fred Kaggwa
Lecturer/Head, Computer Security Research Group
Institute of Computer Science,
Mbarara University of Science and Technology, Uganda
EMAIL: kaggwa_fred@must.ac.ug or fred.kaggwa@gmail.com