LuxSciLuxSci
be Smart.
be Secure.
Phone: 800-441-6612
sales@luxsci.com
support@luxsci.com

Automating the Sending of Secure Messages

Published: February 1st, 2016

Do you have an application or system that needs to send secure messages on demand?  Do you need the flexibility to encrypt messages in different ways, to include files, HTML, and read receipts, or to have the messages be fully HIPAA compliant?

LuxSci has added secure messaging functionality to its Application Programming Interface (API).

Customers with SecureLine, LuxSci’s message encryption service, can now send secure messages though LuxSci’s REST API.  Features of this service include:

  1. Up to 100 recipients/message  (total daily and monthly recipient limits also exist and can be negotiated).
  2. Up to 70MB of content (body and attachments) per message.
  3. Email encryption via SMTP TLS, Escrow, PGP, and/or SMIME.
  4. The ability to toggle between use of TLS and Escrow on a per-message basis, depending on the level of security needed.  See: next generation opt-in email encryption.
  5. Message delivery tracking
  6. Read receipts — invisible to the recipient and reliable (with SecureLine Escrow).

If you would like to give LuxSci’s SecureLine messaging API a try, please contact LuxSci support and we can enable API access for your real or free trial account.

See also our General API Usage guide, and our API User Functions guide.

Introducing Proofpoint and Sonian to Replace McAfee for Premium Filtering and Archival

Published: December 22nd, 2015

McAfee announced several months ago that it is “end-of-lifeing” its Email Filtering and Email Archival services.  These are the services that LuxSci has been reselling for more than 10 years (as one of McAfee’s first resellers in this area) as its Premium Email Filtering and Archival solutions.

After a lot of internal review, LuxSci has chosen to replace McAfee’s services with Email Filtering from Proofpoint and Archival from Sonian.  While McAfee (formerly MXLogic) had its time as the premier service for Filtering and Archival, they have declined over time compared to alternatives.  Both Proofpoint and Sonian are leaders in their respective areas and provide a level of service significantly superior to the disappearing McAfee services.

Beginning in early January of 2016, LuxSci will switch to selling Proofpoint and Sonian as its solutions for Premium Filtering and Archival for all new accounts and for all accounts that do not yet have these services and wish to upgrade.  Starting in January, LuxSci will also begin migrating existing Premium Email Filtering customers who do not also have Archival over to the new Proofpoint solution.  Later, starting March or April, we will begin migrating customers who have Archival as well.

How does Proofpoint differ from McAfee for Premium Filtering?

Analysis has show that Proofpoint is much more accurate than McAfee filtering — stopping more spam with fewer false positives and stopping more phishing-related traffic automatically.  This is in part due to the much larger size of Proofpoint’s client base and their ability to leverage dynamic analysis of all of the data flowing through their systems.

Read the rest of this post »

Train your Filters with Bayesian Email Filtering

Published: November 17th, 2015

LuxSci’s Basic Spam Filtering service has just been augmented to include Bayesian analysis.  with Bayesian analysis, each user can train his/her own Spam filters with examples of what that user considers “Spam” and “not Spam”.  With enough examples, Bayesian analysis allows for the classification of new messages by their likelihood to be Spam or not and this drastically  increases the accuracy of your Spam filtering.

All users of LuxSci’s Basic Spam Filtering system get Bayesian analysis at no additional charge — all you have to do is (1) enabled it and then (2) train it.

Read the rest of this post »

Does TLS Corruption Spell the end of SMTP TLS?

Published: November 3rd, 2015

We have seen discussions recently about how attackers can interfere with SMTP TLS, influencing connections, and causing them to be downgraded to insecure — SMTP without TLS.  E.g. Ars Technica’s – “Don’t Count on STARTTLS to Automatically Encrypt your Sensitive Emails“.

What is being discussed here is a very real attack on Opportunistic TLS. I.e. the kind of automated establishment of encryption that can happen when two email servers being their dialog and discover that “hey, great, we both support TLS so lets use it!”  In such cases, servers take the “opportunity” to use TLS to encrypt the delivery of an email message from one server to another.  Opportunistic TLS is great as it is enabling automatic encryption of more and more email over time (see: Who supports TLS?).

The problem is that the initial negotiation of the SMTP email connection, before TLS is established, occurs over an insecure channel.  A man-in-the-middle attacker can interfere with this connection so that it appears that TLS (i.e. the STARTTLS command) is not supported by the server (when it really is).  As a result, the sending server will never try to use TLS and the connection will remain insecure — transmitting the email message “in the clear” and ripe for eavesdropping.

Read the rest of this post »

WebAide and WebMail Features for More and Larger Files

Published: October 9th, 2015

LuxSci has introduced a series of new features and improvements over the past few months to enable better security, larger files, and more ease of use.  Here is a brief rundown of these:

No More JAVA Applets!

LuxSci previously provided JAVA Applets to enable the optional bulk uploading and downloading of files.  However, these days, one can bulk upload files using “drag and drop” and web browsers are moving away from support of JAVA applets for security reasons.  To simplify our interface and remove any need for JAVA, we have removed these applets altogether.

  • To upload files in bulk, simply use “drag and drop”
  • Downloading files in bulk is now done by providing you with a ZIP Archive of the selected files

This change impacts email message composition, downloading attachments from email messages, and uploading and downloading files from WebAides and the File Manager.

Read the rest of this post »

Infographic – SSL vs TLS: What is the Difference?

Published: October 9th, 2015

SSL (Secure Sockets Layer) and TLS (Transport Layer Security) are foundations of security on the Internet.  However, between colloquial usage and the relationship between these security protocols, there is a lot of confusion regarding how they are related, how they are different, and what to use in what situation.

For a detailed analysis of these differences and similarities, see: TLS versus SSL: What is the Difference?

The following infographic simplifies and summarizes the comparison.

Read the rest of this post »

Next Generation Data Loss Prevention (DLP) with LuxSci Secure Email

Published: September 29th, 2015

Data Loss Prevention (DLP) describes a plan for companies to control the sending of sensitive data.  E.g. this can include controls to stop the flow of sensitive data or to ensure that sensitive data is always well-encrypted (for compliance) when sent.

In the context of email, DLP is usually achieved through the following formula:

  1. Construct a list of words, phrases, or patterns that, if they are present in an email, signify an email message that may contain sensitive information.
  2. Have all outbound email scanned for these words, phrases, or patterns
  3. For messages that match, take action:
    1. Block: Refuse to send the message, or
    2. Encrypt: Ensure that the message is encrypted
    3. Audit: (and maybe send a copy of the message to an “auditor”)

This classic DLP system is available through many email providers and has been available at LuxSci for many years as well. However, it does have a glaring limitation — no matter how complete and complex your DLP pattern list is, it is almost certain that some messages containing sensitive information will not quite match (or the information will be embedded in attachments that can’t be searched properly).  If they do not match, then they will escape in a way that may be considered a breach.

Read the rest of this post »

Get facebook Email Notifications Securely with LuxSci Email

Published: September 23rd, 2015

facebook has a great feature where you can have all facebook notifications sent to you using PGP-encrypted email.  This is great if you want to be sure that noone except for you can read these messages.

LuxSci has supported sending and receiving PGP-encrypted email for the last 10 years, since the introduction of SecureLine email encryption services (10 years old this month).

In this article, we show you how users of LuxSci WebMail with SecureLine can setup facebook so that all facebook notices will be encrypted and delivered securely to their email Inboxes.

If you don’t have LuxSci email hosting yet, you can try it free.

If you are a LuxSci customer but don’t have SecureLine yet, you can upgrade.

Read the rest of this post »

Are you Minimizing your Risk by using the Next Generation of Opt In Email Encryption?

Published: September 11th, 2015

We have long held that leaving it to each sender/employee to properly enable encryption for each sensitive message (a.k.a “Opt In Encryption”) is too risky.  Why? Any mistake or oversight immediately equals a breach and liability.

Instead, LuxSci has always promoted use of “Opt Out Encryption,” in which the account default is to encrypt everything unless the sender specifically indicates that the message is not sensitive.  The risk with Opt Out Encryption is very much smaller than with Opt In.  (See Opt-In Email Encryption is too Risky for HIPAA Compliance).

The problem is: many companies use Opt In Encryption because it is convenient when sending messages without sensitive information — you just send these messages “as usual,”  without forethought.  These companies are trading large risks in return for conveniences.

LuxSci has solved the “Opt In vs. Opt Out” conundrum with its SecureLine Email Encryption Service.  You could say that SecureLine enables the “Next Generation” of Opt In Email Encryption — combining both usability and security.

Read the rest of this post »

Toggling Between TLS-Only and More Secure Encryption Methods

Published: September 10th, 2015

There are many ways to send an email securely.  These range from the super-easy-to-use but less secure “TLS” method (see About SMTP TLS) to the universal “pick it up on a secure portal method” (that we call Escrow), to the very secure but harder to deal with PGP and S/MIME methods.

Many people like to use just TLS for email transmission security whenever possible, simply because it is so easy for everyone to use — you can encrypt everything, using TLS when possible and Escrow when TLS is not supported by your recipients.

However, if you have compliance needs or deal with sensitive information, there are many situations where you may like to “jack up” the level of encryption from just enforced TLS to TLS if possible plus one of the other methods … one that is more secure and which provides for encryption at rest.  (See: Is Email Encryption via Just TLS Good Enough for Compliance with Government Regulations?)

Disabling “Just TLS” on a per-message basis is quite easy with LuxSci.

Read the rest of this post »

• Access Anywhere
• Fast and Robust
• Super Secure
• Tons of Features
• Customizable
• Mobile Friendly

Send and receive email from your favorite programs, including:

 Microsoft Outlook
 Mozilla Thunderbird
 Apple Mail
 Windows Mail

... Virtually any program that supports POP, IMAP, or SMTP

Keep your email, contacts, and calendars in sync:

 Apple iPhone and iPad
 Android Devices
 BlackBerry
 Windows Phone

... Any device with Exchange ActiveSync (EAS) support

Relay your server's mail through LuxSci via smarthost:

• Resolve issues with ISP sending limits and restrictions
• Improve deliverability with better IP reputation and IP masking
• Take advantage of Email Archival and HIPAA Compliance
• Even setup smarthosting from Google Apps!

Free web site hosting with any email account:

• Start with up to 10 web sites and MySQL databases
• DNS services for one domain included
• Tons of features and fully HIPAA capable

LuxSci's focus on security and privacy:

• Read The Case for Email Security
• Read Mitigating Security & Privacy Threats
• Review our Privacy Policy

The most accurate, flexible, and trusted filters in the business:

• Premium protection with Intel Security Saas
• Realtime virus database guards against the latest threats
• Seven-day quarantine lets you put eyes on every filtered email
• Supplement with our Basic Spam Filter for even more features

End-to-end secure email encryption — to anyone, from anyone:

• No setup required — encryption is automatic and easy to use
• Secure outbound email with TLS, PGP, S/MIME, or Escrow
• Free inbound encryption via our SecureSend portal
• Independent of your recipient's level of email security
• Widely compatible and fully HIPAA Compliant

Add an extra layer of security with an SSL Certificate:

• Secure your web site
• Debrand LuxSci WebMail with your own secure domain
• Access secure email services via your own secure domain

Encrypt your service traffic via secure tunnel:

• Add another layer of security to your SSL connections
• WebMail, POP, IMAP, SMTP, web/database access
• SecureForm posts, SecureLine Escrow, SecureSend access
• Restrict your account to VPN access only

Secure long-term message archival:

• Immutable, tamperproof email retention with audit trails
• No system requirements — minimal setup, even less upkeep
• Realtime archival of all inbound and outbound messages
• Works anywhere — even with non-LuxSci email hosting

Free data backups included with all email hosting accounts:

• Automatic backups of all email, WebAides, web/database data
• Seven daily backups and up to four weekly backups
• Unlimited restores included at no additional cost
• Custom backup schedules for dedicated servers

Automate your email management:

• Save messages to specific folders or to LuxSci WebAides
• Advanced text scanning with regular expressions
• Tag messages, alter subject lines, or add custom headers
• Filter by message charset, type, TLS status, DKIM status
• Chain filters together for even more complex actions

• Bulk add and edit users, aliases and more
• Control sharing and access globally or on a granular level
• Delegate user roles through permissions
• Configure account-wide taglines, sending restrictions, and more
• Remotely administer account via SOAP API

Share, collaborate, organize, synchronize:

• Calendars, Contacts, Documents, Notes, Widgets, Workspaces
• Fine-grained access control and security
• Access anywhere via secure web portal or smartphone
• Save over solutions like Microsoft Exchange

Free folder sharing for all email hosting accounts:

• Share mail folders with other users in your account
• Subscribe to only the folders you want to see
• Set read-only or read-write access control
• View all personal and shared folders via unified web interface

Color code and label your email messages:

• Define and assign multiple IMAP keywords to each message
• Filter, search, and sort by tags
• Compatible and synchronizes with any IMAP email client
• Also usable with WebAide entries