Who would read my e-mail?
E-mail today, without comparison, is the most common and easiest way to communicate.
There are close to 300 million e-mail user, and it's growing more with 2 million each
week. You don't know who is reading your e-mail, nor their motive or if they can read
your e-mails without your knowledge. To send an e-mail is generally compared
with, as
if you send someone a postcard.
That's wrong, it is even worth, due to the fact that e-mail can be intercepted with
high sophisticated computer technology, while postcards-scanning or taping would need a
huge number of individuals who read them manually.
This information is provided to you with the intention to give you the
knowledge and the tools to do it right and do it safe.
Who has the interest to read your E-mail?
"I have nothing to hide, so I don't care if someone can read my e-mail".
This is the most common statement you will find around you, and most likely your own way
to look at it. But with such view, the statement is only based on the philosophy that
everyone only has good intentions. Unfortunately, this is very wrong.
Read the following argumentation and you will soon see that you both are
putting your self in dangerous as well as the fact that you might also but others in
dangerous.
Criminals
The rapid development within IT, also create new innovations within
the field of criminals, especially in the so-called organised crime. But also the
"small" guy's might get new ideas on how to use IT to accelerate their crimes.
Just as one example, In Stockholm a number of wealthy individuals
have been caused large crime. No one knows any thing about the perpetrator. The truth is
that the one who has made the crime, seems to be very well informed. Most likely they have
conducted e-mail scanning and after they have gained a clear picture of there victims,
they have conducted the crime. The police force, who just have learnt to use a muse, has
no clue and stand in front of this crimes as a living question mark.
The goal for tap into e-mail and gain access to information about you might have
different explanations, here is a few thoughts:
Preparation of burglary, Background information to prepare and plan a theft or
burglary. By tap into your e-mail, they might know when you will be away or when you plan
to go on holiday.
Blackmail , to conduct blackmail based on information from e-mail, there maybe
you just have looked for a new work, this can be used against you or be a ground for
blackmail, or just things which happens within the family or a mystery affair.
Sell information , the information in all of its forms has always a value. The
right information to the right buyer always has a price tag.
Strategic preparations . Most crime is prepared and includes preinvestigations of
the victim. The perpetrator may plan a crime or he might plan a racial outrage. Especially
the workforce of journalists, it is not only criminals who do crime or step over the
boarder to gain access to information.
Fraud , there the knowledge gained from e-mail later on are used in a crime.
Thefts . Business ideas, innovations, drawings, names, scripts and all other type
of valuable information can be a target for thefts. Internet can in other words be stolen.
Patent applications arrive to the registration office from someone else or a domain name
is registered just before you self was suppose to register such name.
Rowdy & just "fun"
The knowledge on how you can "hack" into others e-mail is
today a common knowledge and even if there is not planed to do a crime, the temptations
from enthusiasts may cause large damages. The one who have successfully done it may
calibrate there victory, but the one who was the victim, my not be as happy.
Errors & blunders
It is easy to send someone a e-mail, and we start to do it very
quick. Anyone, who has used e-mail also, knows how easy it might be to send it to the
wrong recipient. More often, it dos not cusses you any damages, but it can cause you
problem, devastation consequences.
Business Intelligence
Some business intelligence is legal some business intelligence are
not legal. Where to draw the border difference among and within each company and their
rules for ethics. This view difference also between countries and between the difference
in cultures.
All companies should have the fundamental rule that any other company would do what
ever it takes to gain access to the right information at the right time. The value to gain
access to such information can only be appraisals in the view from the competitor and
there need or benefits of such information.
Information can most commonly be ordered from criminals.
To send e-mail and allow the staff to communicate with e-mail, without a very good
encryption software is the same as leaving the door to the office open and let the
computers be accessed without passwords.
Just ask yourself the question, what
intact it would have o your business if the competitors has access to the information,
within the company?
Business development
Recruitment of new staff
Financial information
Name on business partners
Details of activities like advertisement etc...
Uncle "Sam" can see you!
Each country has its own rules and practices on how to handle
policies for TAP or monitor information and listen in on conversations. In Sweden, any
taping made by a governmental body, need approvals from curt, but such decision is
confidential. In cases taping has been used to prove a crime, in such cases the curt can
make such decision after that the factual taping has been conducted.
During 1998 it there was 1,000 officially registered cases or curt approvals for
taping. Only 1 (one) case was dismissed due to the fact that the application was filled in
wrong. Most likely the true figure is 10 or 100, times bigger.
Since all the decisions in curt is confidential, no one knows if and how the case has
been properly conducted.
The basis for taping is to secure evidence and identify crime.
Just in Sweden, there is four (4) official bodies who conduct tapping, the police
force, Säpo = secret service, Tullkrim = the custom and the Military. Most likely there
is also an exchange of information in between international organisations and these
Swedish organisations.
Each and every telephone number in Sweden has its own contact specialist within the
public operator Telia, Governmental owned. Each number has one extra extension to be used
for taping on request from one governmental body.
Who has access to this, is not an information available for the public.
In UK, the government is starting to scan and tap all e-mail traffic from the fall of
2000. They have described that all e-mails will pass through a few special computers to
find, investigate and protect for crime.
Others country within the European Community are following this debate and this
integration with large interest. You can read more about it, if you follow this link:
The fact is, the government and individuals within these organisations has and can
access also the e-mail, there is no guaranties what so ever that it is not used and there
is not any clear rules on how, when or whom you can tap in to. In Sweden there is to day
well known that SÄPO, the secret service has registered people's opinion and taped
telephone conversations without prior decision from the curt.
In several cases there is also publicly known that the
police are working together wit the criminals to be able to buy back theft gods. If this
is the case, how difficult would it be for a criminal to buy an officials, when they
normally just have small salaries. Or if the criminals have some information about those
officials, who could put him or her in "hot water", than blackmail to get
information wouldn't be so far away?
By summarise the different arguments related to Swedish conditions, there is no
guaranties, what so ever that governmental officials following the law and regulations.
I my self (L-O-Känngård) would be the first witness of such case, I have bitterly
experienced how governmental officials has been proven guilty to violate a large umber of
laws, but there "friends" higher up cover such act up, instead that the law
should be equal for all. If you are a Swedish speaking and reading person, who is
reading this text, then you can, if you have time, visit one of my other Internet sites http://www.myndighetsmissbruk.com and see it
by your self. These swedish words "myndighetsmissbruk" means governmental
misuse.
Foreigner governments and embassies
Organised and non-organised mapping and tapping are well known that
embassies are conducting. The official explanation is to protect and safeguard for
terrorists and safeguard for crime or to avoid threats to such country. But in reality and
most likely, a lot of such taping aren't any thing else than industrial espionage.
The most famous and the largest system known as of today is the US based system Echelon,
administrated by NSA (National Security Agency). In popular languish its called Data-FBI,
and by its own definitions clarify its purpose.
The Echelon system can tap in and gather information from any telephone, fax, telex or
e-mail system in the world and thy do it to a large extend. There has been told that this
agency has around 40,000 people working with such tasks. Even if most of its activities is
highly classified one of the stories who came to public knowledge was the transcript of
conversations made by Princess Diana.
Just recently it has been brought up several cases, their Echelon has been accused for
industrial espionage. One of the reports talks about that a price bid came to be known for
Boing so Airbus loosed an order on $1 billion. Boing received the contract and USA/NSA
denies that the system was involved.
If you would like to read more about NSA and Echelon, you then can visit this site:
xxxx.
The European Commission has also criticised US and there is a number of reports
available about this topic.
Is just this a political game or fictions, nobody knows. The only once who might have
the right answer is that small group who might control it, some voices is saying that NSA
are directly linked into the US industry and also partly financed that way other voices
says that NSA in practice is in the control for the democracy.
Even if US today has the most advanced system other countries also has huge resources,
and who knows what they do, Japan is known to be able of taping in to memory's of
facsimile machines and Russia has also sophisticated systems to tap in to electronic
e-mail system etc.
In a general you cant know if you are under special surveillance or not, maybe you
just have received a mail from wrong person?
There are no guaranties and as long as you do not safeguard your self, you would
never know.
How can e-mail be taped.
The exact technique to tap into others e-mails aren't to be learnt
here, but for you to understand some of the different possibilities, we here will describe
some potential ways for you. These descriptions are done with the aim to get you to
understand how open your e-mails are and how vulnerable you are.
Most of the e-mails you are sending are "official" due to the fact that each
e-mail specifically carries the information on from which server this was send with the
domain name and the correct IP number, address and who this server belonging to.
Most common is also that you use your full name, nicely your family name as well as
your first given name, so there isn't so difficult to see from who a specific e-mail comes
from.
In Sweden, the biggest and state owned Telia uses as e-mail addresses:
first -name.last-name@mail.comunity name.telia.com.
Then if you request information through the directory service you
most likely would find the telephone number and the street address to such sender.
Here are now some other sources of information and misuse:
Insider
If an employee, working at an operator or ISP Internet Service
Provider, leeks out or sells information, user data, passwords or actually copies of
e-mails, thats a insider crime.
Insider can do this by them self or in organised ways or as a mission from someone who
pays them to do so.
Every day there are a large number of safety backups made, who has access to them,
nobody knows.
Insiders can be any one in a governmental body, or operator or service provider or as
the service technician who install new software and gets access to your system. The risk
that an insider would be caught is small, du to the fact the he knows how to protect him
self. The potentially insiders is most likely a relatively low paid worker, who most
likely aren't too difficult to buy.
Taping at the street
In Sweden the telephone system are built around a huge network of
small connection boxes and equipment stations. Most consumers and companies are connected
via small or larger connection points, some of them visible on the street, built in to the
staircase in the house etc. The risk that someone open one of this boxes and cable/weir a
taping device and should be caught, are small, and he can remotely monitor any traffic on
such line.
Access to the telephone network
The one who has access to the right equipment can easily monitor
all traffic passing through the network cables. There is also available equipment so that
all traffic easily can be copied.
In the past, the military used equipment so they just could clime up to the telephone
pole and attach their equipment to both monitor traffic and make calls.
Today, the cables are most likely buried in the ground. But unfortunate the system
such in Sweden give out free of charge any information on the exact position of cables in
the street or at a property. The reason is that they do not want people to cut cables so,
companies like Telia even on a request, goes out to such property and will mark out the
exact position.
All of this is done, bluntly to protect the cables, it never strokes their mind that
someone might plan a crime.
Encroachment to Servers
All the servers on the net have special gateways designed for
services. In a large number of cases this gateways or "back doors" aren't even
secured with a password or in some cases only safeguarded with such password as
"admin".
Even if your service provider gives you guaranties for that they have a high security,
with all the finesses available. The e-mail you will send will pass other servers who
might have no security at all.
User identity thefts
Each time you will log on and should pull down your e-mail, you
then fully open are sending your identity and password across the net. This can be
compared with that a manager of a supermarket calls out the code to the safety box there
they keep the money.
It is not difficult at all to scan IP umber and catch all or specific data from a
service provider. It is like fishing, some one may take all and some one would just
collect the salmon.
Theft of e-mail
There are today, available technical solutions for making copies of
e-mail flying around in the cyber sphere. If they might have an access point to scan such
a server, then it is possible via so called robot-software to pin point a specific mail or
mail send from or to a specific user.
Broad Band
"Broad Band" Is, as you probably know the latest
"gadget" within the high-tech industry. It is also market as highly secured and
much better then standard communication. There is two simple ways to tap in to broad band
networks. The simplest is just to curve the cable and it will leek out the information or
just to cut it, put in a small device who make a copy and then put it back.
From some sources it has also been told that you with a special type of radar scanning
devise can tap information, if you just are close to such network.
Airborne traffic
All traffic connected via air is possible to bug, as long as you
have the right equipment. Today, it is more common to tie networks together in the cities
via so called radio or city links. Quite often, such traffic has some type of encryption
protection, but not so advanced and the key might be in the wrong hands.
In the mobile network like NMT, GSM 900 - 1800, MPS and ETACS it has been stated that
the security level is high. Test has shown that it took just a second to tap in on such
network.
Web e-mail
The term web e-mail is defined as a public web based
service. Web based e-mail services like Hotmail allowed during the fall of 1999 users to
gain access to a mailbox even without passwords, from certain web pages.
The password are unsecured stored in the computer you access the mail from. It is in
an office environment easy for others to just use your private log in details.
Some of the web based e-mail system such as Hotmail also provides the convenient
service that you can route other mail boxes in to your e.g. Hotmail account, then all your
personal passwords are stored in such database.
In general all the risks described with e-mail also applies on web e-mail.
Access to someone else's computer
To gain access to someone else's computer can be done either
physical or via a network.
Many new networks are now days build in house complexes there the residents are given
access to a "in house" network as well as Internet. In most cases, with our
without there knowledge it is possible to access your neighbour computer. One example,
Stjärn TV in Stockholm (local cable network operator), gave their viewers Internet access
and network access with no security at all, to start with.
The one who might gain access to your computer and know what he is looking for can
easily gain access to the file continuing all the security information he or she needs.
The Virus syndrome
There exist viruses who works like the principle of for example
"Happy99" and "I LOVE YOU", who gain and distribute valuable
information about your contacts. But different from this once who create damages, there is
also the one flying around who dos not make damages, they just exist and fulfil their
tasks.
There are other samples of programs like Netbus and Backdoor. They will
allow strangers to gain access or fully control your computer.
Most likely, after the attack of "I LOVE YOU" and the widely
spread knowledge on the source code, for such virus, we soon well see new very innovative
versions of such virus and likelihood also see versions who make huge damages.
Its easy to safeguard your self from this
type of viruses, dont EVER open an attachment, if you do not now what it is and who
its comes from. If you receive an attachment from a friend, send him or she a mail and ask
what file it is, then you will never have a problem, as long as you can trust this
"friend".
How do you safeguard your self?
To safeguard your self you must use encryption. The down side of
using encryption's, when you need to communicate with others is that they need to have
exactly the same equipment or software.
The one who sends the information will encrypt the information and the one who
receives the information needs to decrypt the information.
If you think that encryption is an overkill for your purposes and needs, then you at
least can safeguard you by sending the e-mail as an "anonymous" mail, which
means that you do not use your own name at all.
("Anonymous" e-mail is when you register your self on a web based e-mail
system like Hotmail, and using information, which can be tracked back to you as
individual.)
If you would be targeting for a theft, that might then safeguard you at this stage and
the thief may chose another target.
Up to now, most users who has considering using encryption solutions has been
sceptical since most of the solutions derives from the US, and whiteout knowing
connections in between NSA, they might skip such choice.
RSA
Is the far most known algorithm for encryption's, the choice of
name is not far away from NSA, the three founders of RSA are also former NSA
employee. RSA is the largest used algorithm RSA- algorithm.
Within the society of crypto-people in the world, there is a saying that the
RSA-algorithm can be opened by simple PC software. NSA, and others has made it clear that
they have such access. RSA denies that, but what is quite strange is that RSA introduced
new algorithms shortly after such information came out.
The mathematics behind the RSA-algorithm is that the one who has the sum of two large
prim-numbers (extreme large numbers) cant figure out the first key.
P x Q = N
there P and Q is two prim-numbers.
The one who has N can't calculate P or Q (maybe?).
Roomers state that a prim-number based on 4096 bits can be calculated with less then 2
million calculations, by starting at the far end, the last digit, and then with 40
different associated numbers and assumptions build up the prim number with the technique
of doing the last digit first, the second one etc..
If this would be true, then such encryption key could be solved within seconds.
Even if there is just roomers, it should be considered as possibilities. The
connection between RSA and NSA and other aspects might be useful and valuable for you to
look at other available systems.
One of the most reputed experts within the field of crypt technologies, Bruce
Schneier, is according to sayings, having a close relation with NSA. If this is correct
then you ought to be careful with other algorithms like Blowfish and Twofish.
If this is just bad rumours or if there is any truth in it, that's for others to judge.
One little reflection, you might ask your self is how it can be that RSA, Blowfish,
and Twofish algorithm are free to any one. With exception from RSA, their algorithm is
free from August of this year. The question would be, way are trying to get it out
free, for what purpose, has it a connection back to NSA?
Up to just recently, there has been not been allowed to export crypt program from US.
From December of 1999 it is allowed as long as the product is approved.
So in general terms, you ought to be careful with products who comes from the US.
Hushmail
http://www.hushmail.com
The company, was first in the world to launch a software for making web based e-mail
encrypted. The downside is that it has a few large gap. The mail aren't secure nor
encrypted between there server and your computer and you cant send any other included
information. Then it is also slow and the receiver of such mail needs also to be a user at
Hushmail.
The positive side of the service is that it is free.
This service is better then no security at all.
PGP
This is today maybe the most frequent used software in the market. Its free for
private user and has a an user fee less then $50 per corporate users.
The software is available in a large numbers of versions and it is produced in the US.
The constructor Zimmerman, was sued by the US Government and after 3 years then the
Government called back their summon. How the case ended and how the settlement was worded
is a national secrecy.
Shortly after that the case vas settled, Zimmerman sold his program PGP to companies
like Norton.
Since the program exist in a variety of versions, it is difficult for the user to
coupe up with what version you might have. One serious question is therefore needed, is
there any backdoors available?
If you have a good version of PGP then there is stated that it is very safe. In the
cases of breaking the key, then this is due to usage errors or a manipulated version. A
correct version, correct used will give high security.
The most common comments from users are that the software is difficult to use.
One big advantage is that PGP can be used on different operating systems.
SafeIT ()
This is the latest global launch of
new software for encryption of e-mail and the software which will give you
total privacy!
The software is built on earlier experiences for sending encrypted telex traffic.
The software is only distributed via Internet, and you receive it directly and can
start to use it simply after a few minutes.
The full package of SafeIT Secure Office 2003 cost $250.00 and
gives you three different program and security modules, or you select and
buy the SafeIT program module suitable for your needs.
The full SafeIT™ Security
Office 2003 package include, the following components, and
each of those can be purchased individually:
- SafeIT E-Mail Encryption 2003.
- SafeIT File Encryption System.
- SafeIT File Shredding System.
The software is truly user-friendly and is working automatically in the background
when you use your normal e-mail program. If you read their Quick-guide, then you learn how
to use it within two minutes.
The level of safety is very high in compared with any other available encryption
software, and with the use of a secure connection and 2,048 bits asymmetric start and the
use of Diffie-Hellman key system. The next step in the process goes in to a 480 bit
symmetric key and the property key of SafeIT's algorithm. The key, by itself, is changed
fully automatically. This solution is unique and SafeIT is the only one who has it on the
market.
In general terms the level of security is very high and the user friendliness make it
to stand out from any comparatively of other systems.
It is most likely that this technique and its solution will become a de-facto
standard across the globe to secure e-mail.
In fact, the software is very fast and its actually speeds up your sending our
receiving of secure e-mail, which in all other cases of encryption is the opposite.
The only negative thing is that Safit only today support PC with Windows 95/98,
Windows XP and NT
as well as 2000. You also need to use the e-mail protocol SMTP/POP3. According to the
company, there will be solutions also available later for other systems.
Certificate
To use the type of security, known as Certificate,
is actually a asymmetric algorithm. There you have a "public key" as your
identification and provided from a third party. Mail or messages send to you, can
be encrypted with this public key, but only be decrypted by the one who has the decryption
key.
In both Netscape and Outlook you have built in certificate
functions, but few users are using them and trust these methods. The length of the key is
also very short which limit the security. During the fall of 99 it was discovered that the
Certificate function provided by Netscape, only was empty air and did not give you any
security at all.
The European Commission is today a spokesman for public
keys and certificate, have you ask yourself the question, why?
Not difficult to understand at all, this would then allow
the governments to fully control and access any message send with a so-called pubic key
and certificate.
So there is today a umber of "standards" out
there, and the most common one is RSA and S/MIME, but all of them involves third party
involved. One other problem, with these "standards" is that they can't talk with
each other.
The RSA-algorithm, which is the one most people talk about,
is most likely also the one who most likely can be read by others.
The one who gives out these public keys, public and private
key's, dose not give any specific guaranties that information are kept as a secret.
Moreover, the human nature has difficulty to keep secrecies, and as stated earlier,
information has a value. If anyone gain access to these public or private keys, then he or
she also would have access to all the information, used by such key.
Experiences show that it is more dangerous to think that
you have a safe system rather then to not have any security at all. Without security you
would handle information differently. All the systems involving a third party create a new level of potential risks and also involve new
levels of individuals.
Other security programs
There are also other security and encryption solutions available in the market. Some program may encrypt a
specific file, which you thereafter can attach to your e-mail, and by giving the key
/ password to the receiver he or she can
encrypt such attachment.
Some of these products you can find on these links:
http://download.cnet.com/downloads/0-10000.htm?tag=st.cn10105-ron.sb.1000
http://online.data-encryption.com/index.asp
http://www.pepsoft.com/
Summary by Lars O. Känngård
By having read this information you can easily
determine the level of security you need for yourself, your friends and your business
associates. If you like to protect your self you should go for a solution there you
don't involving any third party. This will give you the highest and best security.
One of the most and widest spread encryption function is with no
daubs PGP
but each version of PGP can have manipulated software parts, which could be a
direct threat or a potential back-door to access the information you exchange.
To select a solution like SafeIT or a
corporate or Governmental version of SafeIT, which McGordons jointly with ARDY
Electronics Ltd tailor-designs, you are getting a security system which handle
all the security by it self - THERE IS NO THIRD PARTY INVOLVED. You don't need
to rely on someone else, because, that where you always has the largest threats
- when you need to involve another individual, who, under press or threats, would
be willing to give out some information "security-keys" just to spar
his own or a family members life.
SafeIT is secure - you cant threat a software.
The
SafeIT solution is far the most advanced and the best security method you can find on the market.
It is very easy to install and also affordable and it works - try it for a
few days, free of charge. If you don't have any one to test it with, you can make
a secure connection to me by sending me an e-mail.
Download the free software from the website,
install it as a trail-version and then just send me your e-mail: lars@safeit-me.com
One important reflection to make related any other
solution, for the one who might have experience from software developments. If you have
proven software, working and serving its purpose you do not need to release new versions
of the same software.
This reflection and the fact, that SafeIT is build on many years
(20) experiences from constructing and building encrypting equipment for the
telex traffic, that was may early choice to go for a secure solution, which
where brought out by SafeIT.
Use this link, and buy your own SafeIT solution today. www.safeit.com
Hope you have enjoined this information and if you might
have any comments, feel free to send me this, by just click here.
Back to the
top |