Archive

Posts Tagged ‘Email Encryption’

Windows Mobile 6.5, Google Wave and Windows 7 - review of past and gaze to the future

October 29th, 2009

Some changes ahead

I’m wrapping up my work here in Gwebs company and within China. It has been pleasant to work here and with nice atmosphere. So many new things learned and gained the idea of business in China. But like said, time flies and now it’s time for me to head back to Finland, finish up my studies and head for the new challenges. Anyway before that, I still have some ideas and things to share with you.

I mentioned earlier in my posts that I will test Google Wave, when it will come available for everyone. Well, I have to pass this job to my colleagues, ’cause the Google Wave for regular users hasn’t been released yet. Only the test version for selected persons is available so far. (Here is the post about Google Wave.)

Then some other things which I also mentioned earlier, is that I’m willing to try out the Windows Mobile 6.5 with some email encryption application and see how well it will work with our MailCloak encryption software. Well, guess what ? Windows Mobile 6.5 hasn’t been released yet for HTC Touch Diamond 2, so I have to wait until end of this or next month. So far, the estimated release date is “during October/November 2009″, so still some time to go. Maybe I’ll try it out back in Finland and then just send the results to my colleagues, ’cause I think that this topic is very interesting for mobile users like me. These mobile issues are getting more and more important, because the smart phone markets are increasing rapidly.  (Here is the post about email encryption mobile usage.)

What else ?
I guess, quite many people found out that Windows 7 is finally released and available for consumers. So we took a sneak peek for that to check how different it really is, and how are the security issues handled there. For me it has always been as a thought in my head that Microsoft Windows and security doesn’t really belong in to the same sentence, at least not in a positive way. But we will see, I’m open-minded with this one, so much good I have heard about Windows 7 during the beta-testing.

[Slashdot] [Digg] [Reddit] [del.icio.us] [Facebook] [Technorati] [Google] [StumbleUpon]

Gwebs, email, encryption, google, new, software , , , , , , , ,

Email Encryption for Mobile Users with GnuPG and PGP

September 9th, 2009

When I started my work at Gwebs, this was one of my first questions. I mean, so far that our own products don’t support mobiles, smartphones, pdas, etc.  Anyhow, our product co-operates nicely with all software that use GnuPG (GPG), it’s tested with quite wide scale of applications.

I wanted to know how I can access my encrypted messages whenever and wherever. I just got so dependent on mobile usage of email from my previous job at one telecommunications company, sometimes you just have to be there 24/7 available, for your colleagues all around the world, your customers and clients. This is it what’s going on right now within IT-industry. Although, no-one is paying me 24/7 salary, but it just integrated for me as a habit. And now, sometimes I found myself at the bus stop reading my email, thanks for the reasonable price of data transfer.

I made some research about this topic and found out that encryption with GPG in smartphones is not so common than I thought. Although, nowadays, when smartphones are having Windows Mobile, Linux, Android, Apple, Symbian and maybe some other operating systems too. It seems to be easier to find a solution for encryption from PGP (Pretty Good Privacy).

I found out that Symbian used to have one component, made by Nokia, but no-one really knows is it still usable or not. About Apple and Android I really cannot say so clearly, ’cause both systems are pretty unfamiliar to me. So far Apple seems to have quite much research and development around iPhone, so I’m pretty sure that there are some encryption software as well.

Windows Mobile then, there seems to be a huge gap between versions (5.0/6.0/6.1/6.5) while searching supported applications, anyhow there are some software for encryption available. I haven’t tested these yet by myself, but will do later. At first I’d like to have the official update for WM 6.5.

Well, Linux is another chapter of it’s own. There are so many free, open-source encryption software available that it will be more difficult to find the one which suits the best for your needs, than just find one.

The other solution for encryption in mobile devices is PGP (Pretty Good Privacy), it’s not open-source and normally these applications are not free. But this also makes the difference to availability. There are so many PGP applications available for all these operating systems that I mentioned earlier. And of course, while the software is not freeware, you can expect some support for troubleshooting and equivalent for your money.

Anyway, I think that this is one of the main things nowadays while talking about email security and privacy. Because so big share of today’s business emails are sent by mobile devices, it’s really needed to have some software to obtain privacy within this communication way too. And for covering usability issues, it’s nice to have a software which co-operates with the same encryption method as while using a PC.

I’ll let you know later about my testing, WM 6.5 + PGP or GPG encryption software + MailCloak in PC. Having my own key in every single device (work, laptop and smartphone). And then testing it out, how it works and how easy it is really to use. But that’s going to happen after the Windows Mobile 6.5 release, which suppose to be soon.

[Slashdot] [Digg] [Reddit] [del.icio.us] [Facebook] [Technorati] [Google] [StumbleUpon]

Gwebs, PGP, Security, email, encryption , , , , , , , , , , , , ,

Comparison about Postcard and E-mail and also Registered letter and Encrypted E-mail, e.g. with MailCloak

August 28th, 2009

Security issues have been at the news recently and all the time more and more things are coming up. So many people are interested about their own security, when spending time with online societies and communicating with others, but just so few people are really using any software which is offering better security. The most of these people are just waiting the easiest one to use and cheapest one to buy, the whole field of Internet security seems to be offering too many options and choices. “Do I really need this? Which one is best for me? It’s too difficult to use, isn’t it ?” These questions are common among people, who have interest but don’t know where to start.

It seems to be that the most of the people have a belief that “e-mail is pretty secured service”, and “anyway no-one is interested about my e-mails”, but in fact there are so many people who have interest for normal users’ accounts, and information. And e-mail itself, is not secured at all. Even if the user’s own computer is having anti-virus software and firewall doesn’t guarantee that outgoing or incoming messages are secured. The following table (Table 1.) shows a little comparison between postcard, e-mail, registered letter and encrypted e-mail. This kind of comparison is quite common while talking about security issues among delivering messages from person to another. In my humble opinion I think this comparison is pretty close to truth, and gives you the idea, how messages are really going “out-there”.

\

The following picture (Pic.1.) shows how message can change on the way and how come neither sender or receiver cannot be sure that if the message has been tampered or not, if any kind of encryption is not used. This case represents also the postcard. Posting a letter or encrypted e-mail, then the possibility that message changes on the way is decreasing significantly, it’s represented in a picture (Pic.2.).

Pic 1. Postcard / E-mail without encryption

Pic 2. Letter / E-mail with encryption

The animations above are representing the situations of sending a message via postcard and letter / or e-mail with and without encryption. In both cases sender and receiver are not aware which kind of picture the other one is seeing. They can just believe that “This is the picture the receiver will see. / This is the picture the sender wanted me to see.” So it is very difficult to prove afterwards that was the message changing on the way or not. Well, common sense says: “How about I give him/her a call and ask about this?” But are people really willing to do it after every single message? I am not. Then the whole idea about sending an email is basically useless, if it’s not sure whether the message is going through without changing on the way.

Whenever people are sending their personal information, job applications, contracts, what ever that contains any piece of personal information, like name, social security number, address, phone number, etc. Why not using encryption ? Well, at least I’m not willing to put those pieces of information to the postcard, are You ?

There was earlier a bit similar post in our blog: “The Difference Between A Stolen Mailbox and a Steel Envelope: An interview with gWebs CTO Anderson Jin.” Please check it through also!

[Slashdot] [Digg] [Reddit] [del.icio.us] [Facebook] [Technorati] [Google] [StumbleUpon]

MailCloak, Security, email, email encryption, encryption, personal , , , , , , , ,

MailCloak Pro in Public Beta!

April 17th, 2009

MailCloak Pro is now in Public Beta!

MailCloak for Pro is a combination of all of Global Web Security Systems’ breakthrough encryption programs, and a little more. Download MailCloak Pro here!

MailCloak Pro = MailCloak for Firefox + MailCloak for Mail Clients + MailCloak for Internet Explorer (only available in MailCloak Pro)!

MailCloak was designed from the ground up to be the first encryption program for browser-based email, and POP3/SMTP email. MailCloak Pro supports ALL mail clients, while making GnuPG public-key encryption so simple anyone can use it! And everyone using it is the goal, That’s why MailCloak works with today’s most popular webmail systems as well.

Now you and your contacts can easily exchange encrypted email, and it doesnt matter what they use - Gmail on Firefox? Hotmail in Internet Explorer? YourCustomDomain.Com with Outlook (custom domains are only supported in Outlook and our upcoming SMB version)? They’re all supported! And MailCloak works with cross platform systems too -  that’s because we use the Gnu Privacy Guard MailCloak compatible with tons of other GPG programs on any platform you can think of. Mac, Linux, even legacy DOS users can exchange email with MailCloak users.

Key features include:

Automatic Key Exchange: MailCloak’s automatic key exchange feature automatically attached your public keys to outgoing emails, and automatically imports your contact’s public keys from incoming emails.

Automatic Encryption: Just turn MailCloak on and send email as usual - if you have already done a key exchange, your email will be encrypted.

Respect for Privacy: MailCloak stores your keys on your computer, not ours. So you can be confident that only you and your recipients can read MailCloak encrypted emails

End-to-End Encryption: MailCloak encrypts your email on your computer, and decrypts it on the recipient’s computer. Absolutely no one else will ever be able to read your email. See my previous post to understand the difference between HTTP/S encryption and End-to-End encryption.

Here’s an animation of MailCloak working in Mozilla Thunderbird:
Encrypt and Digital Signatures in MailCloak For MailClients

MailCloak Pro is tested and works with the following email clients:

  • Outlook 2002
  • Outlook 2003
  • Outlook2007
  • Foxmail 5
  • Foxmail 6
  • Outlook Express 6
  • Koomail 5.32
  • Thunderbird 2.0.0.21
  • DreamMail 4.4

If you don’t see your email client on the list, don’t fret, MailCloak for Mail Clients  works with most (all that we’ve tested) Windows XP POP3/SMTP Mail clients- so go ahead, download MailCloak and give it a spin.

MailCloak has also been tested on following web browsers:

Mozilla Firefox 3.0 - 3.1b (not included in our current beta, but can be added seperately with a free download and will be included in future releases.)

Microsoft Internet Explorer 6, 7

And all Trident based browsers, including (but not limited to):

  • Avant Browser  11.0
  • gisoon 1.0
  • GreenBrowser 5.0
  • maxthon 2.0
  • MyIE 3
  • Tencent Treveler 4
  • The World Browser 2

Download MailCloak Pro here!

If you would like to report that MailCloak works with your email client or browser, or if you experience any problems installing or using MailCloak, please let us know!

[Slashdot] [Digg] [Reddit] [del.icio.us] [Facebook] [Technorati] [Google] [StumbleUpon]

Gwebs, MailCloak, Release, Security, email, encryption, new, software , ,

MailCloak for Mail Clients now in public beta!

April 9th, 2009

MailCloak for Mail Clients now in public beta!

MailCloak for Mail Clients, a cross-compatible cousin of MailCloak for Firefox, is the first GnuPG encryption plug-in which works in any email program, and it’s super easy to use too! You just install it on your Windows XP or Vista computer and then continue sending email with your current email client.

MailCloak supports: Outlook, Outlook Express, Thunderbird, Foxmail, Eudora, Pegasus Mail, Lotus Notes, and more (we haven’t tested all email clients, but it works with everything we’ve tested).

To start using MailCloak for Mail Clients, you don’t have change a thing, just download, install, do a key exchange, and start sending strong GnuPG encrypted emails! MailCloak even works with your existing PGP keys.

Click here to go to the MailCloak for MailClients download page.

Using MailCloak in Thunderbird

MailCloak for Mail Clients allows users of any POP3 or SMTP email service to use MailCloak’s GnuPG email encryption. GnuPG is strong PGP encryption with up to 4096 bit public keys, and MailCloak is compatible with all other GnuPG encryption programs, so with MailCloak you can send secure email to anyone on just about any platform.

MailCloak supports Outlook, Thunderbird, Eudora, and more (we think it supports all POP3/SMTP mail clients, but we can’t test them all).  If you use webmail, like Yahoo! mail or Gmail, try MailCloak for Firefox!

MailCloak GPG Encryption in Windows

We worked really hard to ensure using MailCloak for Mail Clients is easy as pie.

To use MailCloak for Mail Clients install it and fire up your mail client – which ever it may be.

At this point you should notice the MailCloak floating menu. Right click it to turn it on, and send an email. MailCloak will automatically attach your public key to this message if you don’t have the recipients public key, or encrypt the message if you do. When you are done sending encrypted messages, simply turn MailCloak off and write emails as usual.

To make MailCloak even easier, we’ve created an automated testing program called Cryptobot. Turn MailCloak on to attach your public key to all outgoing email, send Cryptobot an email, and wait for a reply to see what happens!

After you give MailCloak for Mail Clients a whirl, please tell us what you think on the MailCloak Encryption Forum. You can also use the forum to ask us your questions. We’ll do our best to answer your questions and help you through any problems you might have.

You also can find documentation on our email encryption wiki.

[Slashdot] [Digg] [Reddit] [del.icio.us] [Facebook] [Technorati] [Google] [StumbleUpon]

MailCloak, Release, Security, email, email encryption, encryption , , , ,

HTTP/S, Email Encryption and the Email Life Cycle

March 20th, 2009

Misguided Impressions.
A majority of the people I talk to mistakenly think that email is safe. The slightly more tech savvy among us – people who read about things like email security in Wired or Cnet or Lifehacker, believe, incorrectly, that HTTP/S encryption will protect their email from eavesdroppers. Yet only the true security aware understand that it takes “end-to-end” and “data-at-rest” encryption to truly protect an email message across its entire life cycle. These individuals also understand that whole accounts are practically impossible to protect – so they concentrate on protecting the important messages.

Traceroute to gmail

While it is true that “data-in-motion” encryption like SSL and HTTP/S will protect emails from internet-café wireless eavesdroppers; we should be cognizant of the fact that that’s about all they protect us from. As the notorious Sarah Palin incident so poignantly illustrates, it doesn’t matter how you connect to your webmail, using just data-in-motion encryption is not enough.

So let’s get things straight. HTTP/S, SSL and TSL protect your messages as they travel from you to your email service provider or vice versa – usually the first fraction of a second in an email’s online life. During the rest of the email life cycle, HTTP/S encrypted emails exist in plain text. Only true end-to-end encryption, encryption like MailCloak, FireGPG, Enigmail and PGP provide, can protect an important email for it’s entire life cycle.

The Email Life Cycle:
Below as an outlined the life cycle of a typical email. As you’ll see, an email passes through a lot of hands (routers) between sender and recipient – and there’s no way to tell how clean these hands are. We will use the example of you, a gmail user, sending email to your friend Alice, a Yahoo! Mail user, to make things more concrete.

1.    You write an email and click send.

2.    The email travels from your computer over your LAN to your router, it then “hops” to your ISP, and then over the Internet to Google’s nearest gmail data center. The connection between your computer and Gmail may be encrypted with HTTP/S. If so, your message will be protected across these hops (I usually count 12-15 hops on a traceroute to gmail). If you didn’t use HTTP/S, each of these routers could (and many of them do) copy and index your message – you have no way to know.

3.    The message arrives at Google, and is indexed and saved on redundantly backed up servers. You can now see your message in your “sent” mailbox.

4.    Google now sends your message across the Internet to Yahoo’s datacenter. You can’t do a traceroute from Google to Yahoo, but you can assume that the route takes at least a few hops. At this point your message is traveling in plain text, so each router between Google and Yahoo can copy and index your message. And of these routers may be located in a government surveillance center.

5.    Yahoo! receives and indexes your message, then transfers it to Alice’s inbox.

6.    Alice now connects to Yahoo! and downloads the message. Again, the message hops over a dozen or more routers or computers before reaching Alice.

7.    Alice reads the message.

8.    The message and attachment resides indefinitely on Google’s and Yahoo’s servers. Anyone who logs into either your or Alice’s account can search the account, and if they search the right keywords, they will find your message.

Protecting an Email Message Throughout its Life Cycle.
It turns out that with minimal changes to this life cycle and the user experience, a message can be permanently protected from any and all eavesdroppers. All one has to do is encrypt (cloak/scramble) the message between steps one and two (after clicking send, but before the message goes out over the network), and decrypt the message between steps six and seven (after downloading, but before reading) and the message will always be safe, because it will never be exposed to the internet in plain text. This is called end-to-end encryption because your message is only in plain text at the endpoints. It’s also called data-at-rest encryption, because the email is only stored as an encrypted message.

MailCloak and Standards-Based Encryption
MailCloak, along with a host of other OpenPGP based programs, will all help you to encrypt your messages with end-to-end encryption. When we wrote MailCloak, we chose to use GnuPG OpenPGP encryption because all OpenPGP programs can talk to each other – and there’s an OpenPGP program for just about every computing platform out there. If you have Windows XP and you use Gmail, Hotmail or Yahoo! Mail, or a standard POP3 Email Client, you can use MailCloak – MailCloak will be available for Vista and Windows 7 soon. If you have Mac or Linux we recommend FireGPG for Gmail on Firefox, Enigmail from your POP Mail.

[Slashdot] [Digg] [Reddit] [del.icio.us] [Facebook] [Technorati] [Google] [StumbleUpon]

Security, email, email encryption, encryption ,

The Difference Between A Stolen Mailbox and a Steel Envelope: An interview with gWebs CTO Anderson Jin.

December 2nd, 2008

Recently, all of the big email providers in the consumer arena, including Yahoo! Mail, Gmail, and MSN Live Mail have begun to offer “security solutions”.  Google Apps, Microsoft’s Live Admin Mail, Bluetie and Rackspace also offer business security solutions for both small and large enterprises.
But what are these solutions, and how does our new product, MailCloak, differ from them?  In this blog post Sarah Yu, Global Web Security Systems’ (gWebs) marketing executive, interviews gWebs CTO and lead programmer Jin Anderson to discuss what’s happening in the email security space and how MailCloak differs from the security solutions already offered by these providers. I have translated this post from the original Chinese.

“Let’s take the metaphor of snail-mail. The username and password authentication system is a lot like the key to a mailbox. If this key is copied or stolen, all the mail inside can be stolen and read. But MailCloak is like a steel envelope. It will protect the message even if an intruder guesses or steals your login credentials.”

Read more…

Security, email encryption, encryption, interview, software , ,

Do you know who is watching your email?

September 8th, 2008

Sometimes you send and receive important email.

Do you know who is watching?

Your email can be viewed by anyone with access to the systems it passes through.

Check out this new video, and then start protecting your email!

MailCloak is compatable with dozens of email services. To learn more, check out Global Web Security’s Offical Website!

[Slashdot] [Digg] [Reddit] [del.icio.us] [Facebook] [Technorati] [Google] [StumbleUpon]

PGP, Security, email, encryption, privacy , , , , , , , , , , , ,

Gwebs Website goes to 3.0, MailCloak in Beta!

April 21st, 2008

Here at Global Web Security we have been working round the clock to bring our users a new, brighter, better, more functional and more interesting website. Our homepage has undergone a complete rewrite and redesign.

Gwebs Homepage Banner

We’ve added a forum and tons of information about our MailCloak software (which provides strong encryption for webmail), as well as brief introductions for products that are in development: PassDancer our biometric authentication software, DriveCloak and DocCloak. In-depth documentation is coming soon!

MailCloak - Strong Encryption For Webmail

Also MailCloak is now “open” for beta testing. Sign up here!

Download MailCloak Encryption for Webmail

About MailCloak: MailCloak is Strong encryption software for Webmail. MailCloak utilizes GnuPG to encrypt email on Gmail, Yahoo! Mail, Hotmail and re em

[Slashdot] [Digg] [Reddit] [del.icio.us] [Facebook] [Technorati] [Google] [StumbleUpon]

Security, email, email encryption, encryption, software , , , , , , ,

MailCloak 3.0 Sneak Preview!

February 25th, 2008

Here at Gwebs, the makers of the world’s easiest encryption software, we’ve been hard at work on a new, completely re-written and altogether better version of WebmailSafety. So much about this product has changed that we’re even changing the name!

Gwebs WebmailSafety, which offers email encryption for Webmail and desktop clients, is now called MailCloak, and with version 3.0 on the way webmail users are in for some great surprises.

Like what?

The world’s easiest encryption software just got even easier!

Encrypting Gmail With MailCloak 3.0!

Here are the basic features:

  • Free!
  • Automatic protection for emails and attachments.
  • Supports Internet ExplorerFirefox and Outlook.
  • Supports Gmail, Hotmail, Live mail, AOL Mail, Yahoo mail, 126 mail, QQ mail and 163 mail.
  • Auto-update keeps you secure with the latest features and bug-fixes installed as soon as they are available.
  • Simplified backup.
  • Automatic Key Management.
  • No Adware, Spyware, or Malware.
  • Easy invitations.
  • Automatic draft encryption.
  • Enable/Disable with a single click.
  • Supports English, Simplified Chinese, Traditional Chinese and French.

Read more…

Security, email, email encryption, encryption, google, personal ,