Thursday, 27 September 2012

Electronic Mail Security Issues

Brief Note
There are a number of issues that need to be addressed when it comes to electronic mail usage. In the old days, it was easy to detect that some one opened your (mail) letter in an envelop because it would be easy to konw. At this current "(dot).com" information age, it is quite difficult with the availability of sophiscated tools to hide traces/marks/evidence of tampering/unauthorized access. There are certain personal issues and organizational issues concerning e-mail usage. These issues can affect both the security and privacy of the e-mail owners, and the organization at alarge. The organisation says we have to monitor your email usage to ensure security of the organization and see to it that you are ony in the working limitations; nothing else, BUT the worker/email owner is looking at privacy for his/her emails. It is therefore important to note and think about issues related to that. Below are some of the issues for discussions. Please give in your comments and ideas.

Electronic Mail Issues

Personal mail: (issues of confidentiality and integrity)—Password sharing with boy/girl friends or wives/husbands etc… is it an issue in families? What if you are a secret government agent e.g. CID, FBI, etc.? What is your take on such issue? Is this an issue for the e-mail service provider or an issue for the email owner.

Email and the Business World: If you are in the business world, how do you manage and secure your mail? What if someone unauthorized got to access your work mail. What can happen to Organization trade secrets, financial data, organization trademarks etc.? How would you advise workers and organization managers?

Viruses: Sent via mail in some sort of nice attachment, your system will not be affected unless you download the attachment. How many times have you been a victim? What would you advise email users on this issue? how about protection? is it the service provider's poor security, the organization's bad security or the individual's lack of awareness and poor mail management skills?

Spam: This can really be a problem if not avoided? Have you been a culprit before? What can you do to reduce on the spam mail? How easy is it to design spam mail? Is it easy anyway? What does it take? is it something to fear? or you can do away with it.

Keystroke Loggers: Different organizations have their email etiquette. One of the common one is to monitor email usage by worker, where by there are some new software now days that monitor every key stroke an employee makes on the key board regardless of whether or not the data is saved. Do you think this is good? What could be good in this and what is the bad side of this? It seems to be an issue of management and making sure that you only focus on your work while in the organization. Is that fair enough or?

How about email storage? Are you comfortable with how the mails are stored? Do you any way know how emails are stored? Say for example organization mail servers, or the common Gmail, yahoo, Hotmail etc.? Do you think it secure enough? What makes you feel so? Does your mail still remain private even when it is stored by a third party company? so who is the sole person(entity) in charge of the security of the stored mails?
Your comments and ideas are welcome.

By
Fred Kaggwa

52 comments:

  1. good practices on how we can Maintain our emails.
    . avoid using obvious passwords such as your names, ur birth date
    . periodic changing of your password is emphasized
    . the longer the password, the harder it is for the hacker to crack
    . always deactivate cookies
    . your password should contain both characters and numbers
    . do not share your password with anyone however much you are close

    ReplyDelete
  2. I think the challenge in security of any electrical/digital service lies in the ever evolving technology which renders today's secure technology tomorrow's less secure or insecure technology.As one wise man once said any security made by man can be broken by man.

    Atwiine Herbert

    ReplyDelete
  3. This comment has been removed by the author.

    ReplyDelete
  4. The emerging technologies in ict are the causes of the higher insecurities in as far as the email insecurities are concerned. so the question stands on the kind of technology to be trusted and followed so as to be secure. otherwise the more the technology the more the insecurity.

    ReplyDelete
  5. Internet has gone as far as sending SMS to mobile phones using a computer, even to more than one person at the same time, such as using bulk SMS.
    . Because SMS are limited in size and the more the number of characters the higher the cost. but with Emails, they don't limit you on the number of characters, may be on the server.
    . Sometimes you don't need an internet connection to send an SMS using a mobile phone but with Emails, you need an Internet connection.
    . lastly, you can attach a document on an E mail which you cannot with an SMS.

    ReplyDelete
  6. This comment has been removed by the author.

    ReplyDelete
  7. Mail insecurity is a common issue today. Some people are just careless in such a way that one can even trust a friend to check for him or her their new messages or send their messages. This is a risk because you may not be friends forever. One can use such weaknesses to make an attack on you e.g of a scenario was where a guy forgot his password of an ATM account and the password was sent to his account which he made his room mate to download for him since he was not well conversant with internet, few weeks later he found out that he was missing 100,000/= from his account and yet the money had been sent. There is a possibility that his friend could have used his pin number to make withdrawals using his ATM card since he knew the pin number.
    It's always good to be very selfish such details since once one can use your weakness to gain from you.
    Denis Angor

    ReplyDelete
  8. Sharing personal information online can be both dangerous and of value; it especially puts an individual under the threat of being attacked by hacker, crackers and also makes them prone to fraud though it is useful to service providers since it helps them to monitor their subscribers. Athen Ayebare.

    ReplyDelete
  9. it is a very good thing that you have come up with such a blog that addresses these security issues.
    In this age it is imperative that we know about all these security concerns and how to prevent them. Recently, i receive about 120 spam messages per day but am considerably immune to most of these online scams. I don't fall for them thanks to sites like these.
    However the great tech of today may not be the great tech of tomorow so we keep our eyes open

    ReplyDelete
  10. ah thank you so much for putting in the efforts upon teaching us what really spamming is and on how to protect our emails against spamming.i have really learnt alot about cookies and how to activate and deactivate them,password protection from my friends and spouses.thank you

    ReplyDelete
  11. Its not a bright idea to share your password with your loved one because in case of a misunderstanding they can decide to destroy you using your password.
    storing very important documents on your email is not a safe way to keep them reason being one can easily hack into the system and destroy one's work.
    TIBENDA SARAH 2010/BIT/198/PS

    ReplyDelete
  12. Well, well well..
    Now about the keyboard strokes issue, its really a good idea only for the company's security and confidentiality.
    The employers will be less likely to let out any company secrets such as accounts passwords to the outside parties. this will prevent such issues of external attacks as for the URA CASE maybe.
    However, it deprives the employees of their privacy rights since what ever they do is monitored.
    KASANA AGASTON 2010 BIT 104 PS

    ReplyDelete
  13. In most cases are not convinced with the way e-mails are stored.just because mails are stored on servers and these servers are being monitored by human beings who may be attempted to read these mails at a later time.
    And for the case of passwords its better to keep them confidential.

    ReplyDelete
  14. Fred,on the email storage,I think these big companies like Google or Yahoo have virtual backup storage mail servers.when you create an account on their mail server,it is automatically cloned onto the virtual backup mail server.such that when the mail server you created an account with is destroyed or gets any physical damage/problem,you are automatically redirected to the backup mail server.And you as the user will not know.this secures users' accounts from physical damage like fire and others.

    ReplyDelete
  15. Spam has increasingly become a problem on the Internet. While every Internet user receives some spam, email addresses posted to web sites or in newsgroups and chat rooms attract the most spam.

    To reduce the amount of spam you receive, i think one should do the following.

    1.Filter your email
    2.Don't reply to spam
    3.Be careful releasing your email address, and know how it will be used
    4.Use a secondary email account
    5.Be proactive

    ReplyDelete

  16. the highly increasing technologies in the ICT are highly affecting email security and this comes up in the sense where many people have insecure policies of protecting there email accounts like using short email passwords, sharing passwords with family and friends, using obvious passwords like using girlfriends names etc, all these lead to insecure email accounts and many people have been victimized by such incidences. these are my views..........

    ReplyDelete
  17. keylogger is a more sophisticated way of network security breach....confidential information can easily be gathered and stolen from an author by just striking the keyboard where a device is placed to read the keystrokes...bank details,personal data,account details,private information are all at stake

    ReplyDelete
  18. Thanks so much for the lecture,i like it that you wrote about email security, mostly when it comes to our personal emails.most of us have just been logging out without clearing all the Web history and cookies. thank you it was really great.

    ReplyDelete
  19. am not 100% comfortable with how my mail is stored because i think its not really safe but it can be improved by maybe using a long digited password.

    ReplyDelete
  20. Possession of a strong email password composed of a combination of figures, letters and characters and addition not sharing it with anyone irrespective of your relationship is the best way to protect one's privacy....

    In relation to spam and viruses, it's best not to open unknown messages from unknown parties..

    Monitoring employee usage of organization computers isn't a bad idea for the organization since its meant to monitor organizational security however, privacy greatly necessary for employees to carryout there duties comfortably

    ReplyDelete
  21. It is not easy to secure our passwords because we are not the administrators of the sites we use and how sure are we that our information is safe...they always ask us about us for every site we are to create an account on, such as our names,date of birth,places of origin and more so how sure can we be that they don't use it to hack in our accounts and use them for what ever they want...Nyesiga Doreen.

    ReplyDelete
  22. Actually my concern is on the keystroke loggers: From the companies side of view, it could mean no harm since they need to monitor how the workers use the companies recourses. Are they focused on their duties or they are simply creating junk email to the outside world? or even the company itself?

    However, workers also need their privacy. Its logical one wont be glued to office work all day! one may want to email ones spouse! should this be monitored?. No! If this software only detected junk or spam emails, then it could be the best

    conclusion: Honesty is the key both to the workers and the management group ie the ICT guys.

    ReplyDelete
  23. 2010/bit/132/ps
    the highly increasing technologies in the ICT are highly affecting email security and this comes up in the sense where many people have insecure policies of protecting there email accounts like using short email passwords, sharing passwords with family and friends, using obvious passwords like using girlfriends names etc, all these lead to insecure email accounts and many people have been victimized by such incidences. these are my views..........

    ReplyDelete
  24. password sharing is dangerous so one should not share their passwords even with their loved ones.Creation of strong passwords is very important and it ensures extra security for ones email.
    files to be downloaded should be scanned before downloading to avoid viruses
    monitoring of emails by organist ion's is a great ideal for the organization's security though it violates individual privacy.

    ReplyDelete
  25. About the mail storage i think its a good topic because to i think they are not ahundred percent safe in that i dont understand where the deleted mails go for example on a person computer after they go to the recycle bin and you go a head to delete them so on line where do they go so thats what makes think that they are not safe

    ReplyDelete
  26. Irabizi Deborah
    spam is a big threat to electronic mail, because if some one is able to hack into the organisation's server then it's easy for a hacker to get into one's privacy and do destructive things.

    ReplyDelete
  27. iam really so grateful about today's lecture, thank you for the great job you are doing foe us.first of all i have learnt about spams and how to our emails safe from being hacked into.
    i also learnt how to create strong passwords thus by changing them frequently. the other thing is that its not always good to share personal information with the public thus confidentiality must be considered.thank you, akidi harriet

    ReplyDelete
  28. given the current trend that the so called technology is taking it really makes me wonder whether it(technology) is developing for our own good or it's causing us more harm than good,ranging from site restrictions to spyware not to mention the keyloggers.This makes me believe that we are getting(if we are not yet there) to a point when we can no longer control our own lives.And this really make me feel like going back to our "traditional days" of "letter writing", for they were atleast secure to a certain extent.

    ReplyDelete
  29. I strongly believe that security should be some sort of secret that should be kept to the user alone. However, there has been a security bleach caused by people trusting their close friends and families in a way that they tell them their passwords and can easily access their information and even modify it. A situation comes when these friends were just used by bad people who want to hack into your account for their benefit. In that context i want to advise people to keep their passwords to themselves for security reasons.

    ReplyDelete
  30. 2010bcs026/PS
    really these are good points to note as far as social engineering is concerned and surely many internet users fall victims of this since the internet is open to a wide audience. My advice could be that internet users get some knowledge and training on the various security tools and applications in network security e.g. spam blockers, popup blockers, firewalls, software patches and updates, e.t.c…..

    ReplyDelete
  31. well with the use of email addresses and their a compliments, like passwords, my friends at times allow me to access their accounts in order to help them sent certain emails, so the next time if they don't change their passwords they will be vulnerable to these threats.but however the dot com world has made life easier.

    ReplyDelete
  32. Birungi mary 2010/bit/231/ps
    I don't actually think that our emails are any secure or private because of the way we disclose our personal information and this allows for hacking by even those administrators themselves hence theft of information or altering of information.

    ReplyDelete
  33. Agaba Walter 2010 bit 033ps
    YES.NO Kind of but not sure. i think its not any secure if there is a third party of the company.me but it can be hacked into if some one gets to know of my password guesses it right or if i dont sign out my mail.

    ReplyDelete
  34. Its very important to keep passwords private because sharing them would make easy for one to access your email account without your knowledge.
    Spam messages are from unknown people and thus one should avoid opening spam.
    2010/bit/282

    ReplyDelete
  35. ABIGABA DUNCAN 2010/BIT/031/PS
    I really dont known how emails are stored I think my email is secure because i always mind about my password by making it difficult to guess. i advice to always sign out after using you Email.

    ReplyDelete
  36. Its both the personal email and the provider. Because the providers should not accept the password with out digits or spaces.
    more to that people creating Emails should not include family names, boy/girl friend's names for security Issues.
    Mukonyezi Chillion.

    ReplyDelete
  37. email users should be more conscious about the attachments they download and also keenly look at the source of such messages.viruses are embedded in some attachment which we find in our messages in the inbox.
    one should ensure he/she has an anti virus installed on his/her machine so that such files are always scanned and viruses deleted automatically.
    anti virus is supposed to be updated frequently for effective results.
    i don't think its the service provider security faulty because nowadays executable files can not be sent or attached however much try hard and since most viruses are executable.i think it is individual ignorance.
    2010/BIT/192/PS SUNDAY BRENDA

    ReplyDelete
  38. Since spammers get addresses of people randomly from social networks, it would be great that you change it to a new address or use good spam detector software to detect and delete spam

    ReplyDelete
  39. BAKUNDA YOWERI 2010BIT076PS
    Indeed its a good practice to change email passwords periodically and keeping them to our selves alone.Again companies should monitor company mails for security of the company data and leave out personal emails like yahoo,g mail for their employees' non official duties.

    ReplyDelete
  40. Thank you so much i highly appreciate you effort to every student of must community understand and learn more about security issues by coming up with such idea of teaching people through blog.
    I also learnt with email security every one should be vigilante enough to keep confidentiality and privacy of his or her emails by always signing out after using your email.

    ReplyDelete
  41. Ivan Himbisa Mukama 2010/bit/265/ps
    No really i don't know how about the emails are stored. just i know.but i know organization email are controlled by the administrators for the security bit of it was like they set they own settings for the security. email administrators set the changes the security concerns.

    ReplyDelete
  42. Perhaps the greatest tool to protect one's computer from security related issues like spam and viruses is to use well updated anti virus

    ReplyDelete
  43. Mugiizi muhamudu 2010/bit/134/ps
    its important to make strong passwords and secure them from other people.The hackers are ready to tap any information on internet unless we keep our systems very well protected from both hackers and viruses.

    ReplyDelete
  44. This is scaring! our emails are not secure at all. it means people access our information online, so lets try to protect ourselves and our information from being altered or lost.
    NSUBUGA DAVID
    2010/BIT/172/PS

    ReplyDelete
  45. It is true that lack of adequate email security measures can result in unauthorized access of resources, intrusion of viruses and theft of data.
    A personal mail is personal so no sharing even if it is my Girlfriend, for workers, that should be their secret never to go to the public,email users should avoid pop up windows in their emails to avoid attacks inform of spams,trojan horses etc
    For Keystroke Loggers, I think this is good idea, this emphasizes serious business when at work,though it looks being so strict on workers.
    Emails are servers which enable storage though i am not sure who is responsible. Thanks
    2010/bcs/057/ps

    ReplyDelete
  46. I personally think password sharing should not be done no matter how close you are to an individual not forgetting one common mistake where people fail to log out hence making it easy for them to fall prey.For workers in an organization should follow company policy not to share information with the outsiders,then passwords should have characters and integers making it hard for a hacker to crack it.

    For viruses via emails i think people should not read mails from unknown location.Then activation of firewall to block pop ups,and other attacks.

    Generally i think emails are secure for third party companies like yahoo g mail etc operate under guidelines of the w3c company.
    2010bit275ps

    ReplyDelete
  47. with all the security measures employed to see that personal information remains confidential, data security has been put at stake as technology advances. this brings us to a notice that counting on these measures for our data protection not enough but we also ought to play our role e.g activating our anti viruses, setting and keeping passwords as private by not giving it to other people, using spam blockers, setting timeouts such that when we dont logout, we are automatically logged out.
    however with all this put in action we can never guarantee 100% the security of our data. Julian Nabaggala

    ReplyDelete
  48. To ensure that our information is protected on the Internet,confidentiality and integrity issues as it regards to security should emphasized by internet users.
    -Email account passwords should be held secretly.
    -strong passwords should be used ie a password of more than 8 characters of both numbers and digits.This makes it had for hackers.

    ReplyDelete
  49. No really i don't know how about the emails are stored and i don't that they are secure.

    ReplyDelete
  50. i really get some security concepts although i need more elaboration

    ReplyDelete
  51. ASABA BOAZ
    sharing of email account passwords is insecure in families and work place in that some one may misuse your account to achieve his personal needs in case there is a need to do so which may inconvenience some ones privacy either in the family affairs or at work place.
    it is also a good behavior to always sign out and clear the cookies before moving away from a cafe because bad guys may take advantage of your account being open and they tap into your private plans.

    ReplyDelete
  52. TAREMWA SSEBUGWAWO

    I think it is the administrators who determine the safety of our email adresses.
    B i think we should use strong passwords for the saftey of our adressses.

    ReplyDelete