When is “Secure Email” only a Veneer of Security?
Wednesday, March 7th, 2012
I recently applied for a new insurance policy with fairly well known insurance agency (who shall remain nameless). When all the preliminaries were done, the representative emailed me copies of the new policies. They were “secure” emails. I was very impressed … they thought enough of my privacy and identity to ensure that sensitive documents would be sent securely. And, working in an email security company, I actually know and appreciate the ramifications of that perhaps more than most.
So, once I finally got around to accessing the message, I discovered that it was really not secure at all! Even though the subject said “secured”, the representative said it was secure, and the PDFs of the policy documents were not physically in the message, it was really completely insecure! My faith in the company is now somewhat tarnished (though they might not even know about the issue) … and I have serious doubts about whatever provider they are using to facilitate these “secure messages”.
How do I know it was insecure?
Read the rest of this post »
