Sunday, April 17, 2011

Tutorial 4: How to Create Secure Emails

For my final tutorial of ISM3004 I will discuss how to secure vital information that you send through emails. First thing you need to know is what are the most popular Email Clients that allow you to secure your emails. The most popular email clients are Thunderbird, Endora 5.1, Outlook, and Outlook Express.(http://webnet77.com/secure-email.html)  For the purpose of this discussion will use Mozilla Thunderbird. There are several ways to secure an email like popping which allows  "the user name and password are sent in the clear over the internet." (http://webnet77.com/secure-email.html) The way we are going to secure our email is by getting a certificate from Comodo. Here are the steps in how to secure your email:


  



  • Next type in the required information into the text fields. 
  • Next Submit the information and look in your Thunderbird inbox for a message from Comodo.   
  • You will click on the link which will allow you to download the certificate (make sure it opens with Mozilla Firefox)
  • Once the certificate is downloaded you must import it into Thunderbird by going to the tools menu on the Firefox window that opened from clicking the link, click "options", than click "advanced" icon,  click "view certificates".

  • Click your certificate than click "backup"
  • Save to a location you can find easily and return to Thunderbird.(may be required to create a user name and password)
  • Once in Thunderbird, Click the tools menu and select "Account Settings"
  • Click "View Certificates",  and while in the certificate manager select import and locate the file containing the certificate you downloaded.
  • After selecting to import this certificate it may ask you for the user name and password you created for the certificate.
  • Now return to the "Account Settings" Menu and choose the "Security" Tab. There should be a sections titled "Digital Signing". Click the "Select" button in that section and choose the newly imported certificate in the drop down menu and click "OK"


 Now you have successfully installed a certificate into Thunderbird which allows you to sign your messages, by choosing the security drop down menu while composing a message and choosing "digitally sign."  This is the first level of security you can give your emails.The next step in security is to encrypt the email. To send an encrypted email to somebody they must first send you an email containing their public key which allows you to encrypt an email that only they can read. Once this has been done you just compose a message and in the security tab choose "encrypt this message."
 
References:
  • http://www.comodo.com/
  • http://webnet77.com/secure-email.html
  • http://kb.mozillazine.org/Installing_an_SMIME_certificate

Sunday, April 10, 2011

Secure Email Project

For this project we were required to use Thunderbird to send a secure email and an encrypted email. The following are the screen shots of my professors return email for both the secure and encrypted email.









I found an article about how the Boston Medical Center chose Voltage Security to increase their level of security for emails. Here is a link to the article. To summarize, the article explains how the busy hospital staff would need a secure email system so that no sensitive information could leave and violate any government mandates. Also it would need to be simple and not add any unnecessary steps to the hectic days of the staff. Brad Blake, the director of  the IT department,  chose Voltage Security SecureMail  because it was customizable, little training needed, no support desk, and was simple enough for all the staff. The program scans outgoing messages for keywords like MRN(medical record number) or SSN(social security number) and if any keywords are found it encrypts the message automatically. Another reason Blake chose this program was that he could make emails received and sent on the hospital's Blackberry to make them just as secure as if they were connected to a hospital computer. After the program was rolled out, Blake saw very few problems and most people barely noticed the change which made the change a great success.