Click here to close now.

SYS-CON MEDIA Authors: Pat Romanski, William Schmarzo, Elizabeth White, Carmen Gonzalez, JP Morgenthal

Related Topics: Government Cloud

Government Cloud: Article

Email, Privacy, Strong Cryptography and the NSA Whistleblower

Encryption is a broad term. Not all email encryption and methods of use are the same, in terms of privacy

There has been quite a buzz around the power of the alleged NSA eavesdropping considering the insights that the NSA Whistleblower, Edward Snowden, presented to the American public.

The NSA Whistleblower exposed how our digital identities are being captured, stored, analyzed, and categorized, allegedly by NSA, as well as companies that publicly state that they store and analyze your data (Facebook, Linkedin, Google email, etc.). The power of the NSA system, according to Snowden, is that they aggregate your digital communications across telephone, internet, web, mobile app, and email data.

With regards to email, email encryption works, to keep your email message content private. As The Guardian reported on Monday, June 17, the NSA Whistleblower said:

"Encryption works. Properly implemented strong crypto systems are one of the few things that you can rely on."

But, encryption is a broad term. Not all email encryption and methods of use are the same, in terms of privacy. Not all are "strong crypto systems".

What type of "encryption" works, for whom, what, and when?

"Caesar Cipher" and "Pig Latin" are Forms of Encryption

Suppose Alice wants to send a secret message to her friend Bob but worries that her snoopy Big Brother may intercept it. Alice needs a way to scramble her message so that only Bob can read it. A simple way to do this would be for Alice to replace each letter in her message with the next highest letter; shifting it by one (think "Caesar Cipher" or "Pig Latin").

But, of course, that is too simple. If Big Brother intercepts the message he'll be able to easily decipher it by looking for hidden patterns in the letters it contains. All it will take to crack the code is a little mathematics and a little trial and error.

And, of course, if Big Brother uses a computer he'll be able to crack the code even faster. So just shifting the first letter to the end and adding "ay" as a suffix (turning "HELLO" into "ELLOHAY" for example) isn't a very strong cipher. What can Alice do?

Well, she can try to think up a more complicated mathematical formula to scramble the letters and numbers. And maybe she could use a computer herself to apply the formula. This will help, but the problem is still that if Big Brother hires clever mathematicians, or if he just has a big enough computer, he will be able to crack the code eventually. So it looks like it's going to be an arms race with Big Brother to see who can come up with the biggest computers and the most complicated formula. But because Big Brother is big, it is a race Alice and Bob are bound to lose.

What is Considered "Strong Crypto"?

Then, what did the NSA Whistleblower mean by "strong crypto systems" when he said, according to The Guardian, "Properly implemented strong crypto systems are one of the few things that you can rely on."

We have established that more complex patterns used to encrypt are harder to read by Big Brother but capable of being read if Big Brother has a powerful computer to figure out the pattern; yet easy for Bob to read with knowledge of the pattern (the decryption key). Most technicians understand that more complex algorithms are harder to "crack", or said another way, take more computing power to crack.

How does Computing Power Impact the Time to Crack the Encryption?

Let's consider the example of using computing power to try to guess a 10 digit seemingly random alpha numeric password, such as: tjo9i0982d using a "Brute Force" attack (i.e. trial and error). This would be similar to trying to find a pattern in a universe of combinations of 36 digits (26 possible letters and 10 possible numbers). According to Gibson Research Corporation, in this example, there are 3700 trillion combinations, and the time to guess and test the right combination using trial and error in an online environment is one thousand centuries (assuming one thousand guesses per second). However, in what Gibson Research calls a "Massive Cracking Array Scenario" with one hundred trillion guesses per second offline, this password can be guessed in just 38 seconds.

Computing power does matter. But, not many, if any (today), can implement a "Massive Cracking Array Scenario".

Is Today's Commercial Encryption Readable by the NSA with its Computing Power?

This is a question that clearly some people know the answer to. I do not. Most commercial encryption uses algorithms that the NSA has "approved" for "civilian, unclassified, non-national security systems". These algorithms are what encrypt your email or financial transactions when using email encryption or secure HTTP web based connections with commercially available systems. Some of these NSA approved (unclassified) algorithms include DES, Triple DES, AES, DSA and SHA.

Note: it is not only use of encryption that is important, but as Snowden added, "properly implemented strong crypto systems". Those who encrypt email should be sure to use "properly implemented strong crypto systems".

So, let's explore this notion of "properly implemented strong crypto systems".

Security by Obscurity

Bringing this back to Bob and Alice, or you and me, would our use of commercial (NSA approved for unclassified use) encryption be strong enough for our general commercial purposes? I suppose you could consider it so, as long as those who you think may be trying to read your information do not have the computing power, financial resources, and incentive to try to crack the method of encryption you use in your correspondence. To get a sense of the scale in terms of NSA computing power, NPR reported that the NSA is putting the finishing touches on its biggest data farm yet, a $1.2 billion complex in Utah with 1.5 million square feet of top secret space including high-performance NSA computers alone filling up 100,000 square feet.

So, unless (or until, since the NSA Whistleblower says your messages are saved just in case they later need to be read) you elevate yourself the importance of your electronic correspondence to the level that makes your information interesting to the people with this power, your commercially encrypted email should remain private enough...

But if private enough is not good enough, if you are encrypting FOR personal privacy, you should use "properly implemented strong crypto systems" that also consider endpoint security.

As The Guardian reported, the NSA Whistleblower added, "Encryption works... Unfortunately, endpoint security is so terrifically weak that NSA can frequently find ways around it." What does Snowden mean by this? A properly implemented strong crypto system should take into account the endpoints, as well as the transmission.

Google Has an Easier Way to Read Your Email

Take Google as an example with your laptop as the endpoint. Google allegedly provides information to NSA and other government organizations upon request, and also perhaps others, depending on how you interpret what they disclose on their website privacy policies. (A quick glance at Google's privacy policies are revealing.) Google discloses: "Local storage: We may collect and store information (including personal information) locally on your device using mechanisms such as browser web storage (including HTML 5) and application data caches" and further "may combine personal information from one service with information, including personal information, from other Google services." With all of the hype about NSA computing power, we believe endpoint security should be of greater concern - Google is telling you (in our opinion based on our interpretation of their privacy policy disclosure) that they record, analyze, cross reference your personal information, not only what you type into a Google application, but potentially all application data that is stored on your device (the endpoint) that they can access using their techniques.

So, for example, if you take great care to type your email in a Gmail compose page, encrypt the transmission, and then send, you are forgetting that Google may be recording, storing, analyzing, and cross referencing the content of the message you type before you encrypt it (as well as perhaps other personal information on your computer or mobile device).

So, for those encrypting for privacy, endpoint security should be evaluated. Note, you can somewhat control your endpoint security by choices you make, but what about the encrypted email recipient's endpoint security?

What to Do to Keep Your Email Private

So, where does this leave us in the new light of the NSA Whistleblower (and Google privacy disclosures)?

The endpoint security is the most likely source of data exposure; meaning, it may be far less computer intensive to access the metadata stored on your computer hard drive every time you type, or access the messages stored in your mailbox on your desktop, mobile device, email server, or internet mail service provider host before encryption when composing, or after decryption, after reading.

If you use commercial encryption for email, you should consider strong crypto systems that take into account providing endpoint security, in particular at the recipient's end, which is out of your control.

There are generally three types of systems to commercially encrypt email today.

1. Public Key Exchange - Secure but Complex for Many. Exchanging public encryption keys among your contacts (PKI Digital Certificates) and using Microsoft Outlook on your desktop computer is a "strong crypto system", but has proven to be too cumbersome for most to purchase and install these certificates, manage the expiration, ensure your recipients have a copy of your public key and you theirs, and all are using a compatible email program such as Microsoft Outlook desktop software.

2. Secure Store and Forward - "Man in the Middle" Problems. Systems that store your message content in the middle, and send a link to the recipients to download the content, are often used, but are not considered "strong crypto systems", as your most sensitive information is now stored on a third party server with unknown data security and message purge practices (which may differ from their stated policies). Further, there is no protection from unknown recipient endpoint security or lack thereof. Note, systems that wrap your email in an encrypted HTML file and send, often purport themselves to be "direct delivery" but leave out the important point that the process of decrypting, is often sending the data back to the server in the middle, and that server storing the decrypted message and displaying it in a web browser (with the same Man in the Middle storage purge concerns). Further, there is no protection from unknown recipient endpoint security or lack thereof. This is better than simple Secure Store and Forward but still has Man in the Middle issues, and for these reasons, these are also not considered "strong crypto systems".

3. True Direct Delivery - Best Method. Systems that wrap the message in an encrypted PDF file are "strong crypto systems" as (a) the message content is not stored in the middle, (b) content is truly delivered to the recipients' desktops encrypted, AND (c) the content remains encrypted at the recipient endpoint to prevent potential disclosure regardless of the recipient endpoint security. Systems that make this method easy to use and implement for both sender and recipient become the true best method "strong crypto systems" for email encryption (for both compliance and personal privacy).

More Stories By Zafar Khan

Zafar Khan is the chief executive officer of RPost (www.rpost.com). RPost, winner of the World Mail Award for best in security, provides what is described here as True Direct Delivery strong crypto systems that are simple to use and install with no storage by RPost. Both government and commercial organizations have relied on RPost email encryption all over the world, as part of its RMail® service offering (video and free trial click here). RPost has been offering secure electronic messaging services for more than 10 years.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


Latest Stories
The widespread success of cloud computing is driving the DevOps revolution in enterprise IT. Now as never before, development teams must communicate and collaborate in a dynamic, 24/7/365 environment. There is no time to wait for long development cycles that produce software that is obsolete at launch. DevOps may be disruptive, but it is essential. The DevOps Summit at Cloud Expo – to be held June 3-5, 2015, at the Javits Center in New York City – will expand the DevOps community, enable a wide...
P2P RTC will impact the landscape of communications, shifting from traditional telephony style communications models to OTT (Over-The-Top) cloud assisted & PaaS (Platform as a Service) communication services. The P2P shift will impact many areas of our lives, from mobile communication, human interactive web services, RTC and telephony infrastructure, user federation, security and privacy implications, business costs, and scalability. In his session at @ThingsExpo, Robin Raymond, Chief Architect...
Explosive growth in connected devices. Enormous amounts of data for collection and analysis. Critical use of data for split-second decision making and actionable information. All three are factors in making the Internet of Things a reality. Yet, any one factor would have an IT organization pondering its infrastructure strategy. How should your organization enhance its IT framework to enable an Internet of Things implementation? In his session at Internet of @ThingsExpo, James Kirkland, Chief Ar...
The world is at a tipping point where the technology, the device and global adoption are converging to such a point that we will see an explosion of a world where smartphone devices not only allow us to talk to each other, but allow for communication between everything – serving as a central hub from which we control our world – MediaTek is at the heart of both driving this and allowing the markets to drive this reality forward themselves. The next wave of consumer gadgets is here – smart, con...
Cloud Expo, Inc. has announced today that Andi Mann returns to DevOps Summit 2015 as Conference Chair. The 4th International DevOps Summit will take place on June 9-11, 2015, at the Javits Center in New York City. "DevOps is set to be one of the most profound disruptions to hit IT in decades," said Andi Mann. "It is a natural extension of cloud computing, and I have seen both firsthand and in independent research the fantastic results DevOps delivers. So I am excited to help the great team at ...
Container technology is sending shock waves through the world of cloud computing. Heralded as the 'next big thing,' containers provide software owners a consistent way to package their software and dependencies while infrastructure operators benefit from a standard way to deploy and run them. Containers present new challenges for tracking usage due to their dynamic nature. They can also be deployed to bare metal, virtual machines and various cloud platforms. How do software owners track the usag...
CA Technologies has announced it has signed a definitive agreement to acquire Rally Software Development Corp. for $19.50 per share, which equates to approximately $480 million, net of cash acquired. The transaction has been unanimously approved by both Boards of Directors, and is expected to close in the second quarter of CA’s fiscal 2016. Based in Boulder, CO, Rally has approximately 500 employees across four continents and FY 2015 sales of $88 million. “Software applications are changing the...
The security devil is always in the details of the attack: the ones you've endured, the ones you prepare yourself to fend off, and the ones that, you fear, will catch you completely unaware and defenseless. The Internet of Things (IoT) is nothing if not an endless proliferation of details. It's the vision of a world in which continuous Internet connectivity and addressability is embedded into a growing range of human artifacts, into the natural world, and even into our smartphones, appliances, a...
Enterprises are fast realizing the importance of integrating SaaS/Cloud applications, API and on-premises data and processes, to unleash hidden value. This webinar explores how managers can use a Microservice-centric approach to aggressively tackle the unexpected new integration challenges posed by proliferation of cloud, mobile, social and big data projects. Industry analyst and SOA expert Jason Bloomberg will strip away the hype from microservices, and clearly identify their advantages and d...
The OpenStack cloud operating system includes Trove, a database abstraction layer. Rather than applications connecting directly to a specific type of database, they connect to Trove, which in turn connects to one or more specific databases. One target database is Postgres Plus Cloud Database, which includes its own RESTful API. Trove was originally developed around MySQL, whose interfaces are significantly less complicated than those of the Postgres cloud database. In his session at 16th Cloud...
All major researchers estimate there will be tens of billions devices - computers, smartphones, tablets, and sensors - connected to the Internet by 2020. This number will continue to grow at a rapid pace for the next several decades. With major technology companies and startups seriously embracing IoT strategies, now is the perfect time to attend @ThingsExpo, June 9-11, 2015, at the Javits Center in New York City. Learn what is going on, contribute to the discussions, and ensure that your enter...
SYS-CON Events announced today that MetraTech, now part of Ericsson, has been named “Silver Sponsor” of SYS-CON's 16th International Cloud Expo®, which will take place on June 9–11, 2015, at the Javits Center in New York, NY. Ericsson is the driving force behind the Networked Society- a world leader in communications infrastructure, software and services. Some 40% of the world’s mobile traffic runs through networks Ericsson has supplied, serving more than 2.5 billion subscribers.
Software Development Solution category in The 2015 American Business Awards, and will ultimately be a Gold, Silver, or Bronze Stevie® Award winner in the program. More than 3,300 nominations from organizations of all sizes and in virtually every industry were submitted this year for consideration. "We are honored to be recognized as a leader in the software development industry by the Stevie Awards judges," said Steve Brodie, CEO of Electric Cloud. "We introduced ElectricFlow and our Deploy app...
What do a firewall and a fortress have in common? They are no longer strong enough to protect the valuables housed inside. Like the walls of an old fortress, the cracks in the firewall are allowing the bad guys to slip in - unannounced and unnoticed. By the time these thieves get in, the damage is already done and the network is already compromised. Intellectual property is easily slipped out the back door leaving no trace of forced entry. If we want to reign in on these cybercriminals, it's hig...
The 4th International Internet of @ThingsExpo, co-located with the 17th International Cloud Expo - to be held November 3-5, 2015, at the Santa Clara Convention Center in Santa Clara, CA - announces that its Call for Papers is open. The Internet of Things (IoT) is the biggest idea since the creation of the Worldwide Web more than 20 years ago.