Ask Slashdot: What Is the Best Email Encryption Gateway For a Small Business?
Attila Dimedici writes "I am in the process of implementing an Email Encryption Gateway for my company. I checked with my various contacts in the industry and came away with Voltage as the best solution. However, as I have been working with them to implement a solution, I have been sadly disappointed by their lack of professionalism. Every time I think I am one question away from being ready to pull the trigger, I discover something that my contact with them had not mentioned before that has to be ironed out by the various stakeholders on my end. So, my question for Slashdot readers is this: what is your experience with implementing an Email Encryption Gateway for your company and what solution would you recommend?"
I'd ask for a different account rep. I've used Voltage for about 10 employees to great results. I've never encountered this professionalism problem you report.
Be very, very careful what you put into that head, because you will never, ever get it out. -Thomas Cardinal Wolsey
I use and like Entrust Entelligence PKI solution. Signed and/or encrypted email, used by most US gov. agencies for easier interoperability.
BES offers a shitload of benefits if you want to use them. Blocking things like the camera or SMS, limiting WiFi connectivity, security configuration, password requirements, etc, on company owned and paid for phones is a requirement for many large enterprises. Additionally, ActiveSync isn't as feature complete with syncing in most cases (Android doesn't do tasks or notes for example), while BES provides complete bi-directional sync between BlackBerrys and Exchange. Remote software management, an always on administrator controlled VPN connection is another benefit.
We had issues with our Exchange server's gateway and it wasn't able to get to the internet, however the tunnel to our location that had BES was up and it had internet connectivity, so our BBs were receiving email communicating what was going on and who was doing what. Sure we could've done that with personal email or with BBM/GTalk, but this way we didn't need to.
BES is a pain in the ass when you don't need any of the above and all you're doing is syncing email, calendar and contacts. But those are all critical features in many places.
Keep on knockin'
https://robbiecrash.me
I disagree that Outlook.com is all that great. If you want your email to be truly secure, you need to encrypt it at the client and, in trying to set this up with one of my clients, I found that a) the documentation on this process using Outlook is very poor, b) one must pay to purchase a Digital Certificate for Outlook, and c) once my client did purchase a Digital Cert from one of the vendors listed on microsoft's website, windows and/or Outlook 2010 could not find this certificate or did not recognize it. A waste of time and money.
I found it much easier to configure Thunderbird with a self-signed certificate and OpenPGP. The email is encrypted on my computer and decrypted on the client's computer. However, it's probably not feasible to train a bunch of tech-challenged workers to do this themselves and would likely introduce too much of a training/support burden for any sizeable IT shop.
I realize that M$ may offer some handy tools for IT managers tasked with managing a large organization -- if you are willing to pay for it. I also find it extremely disappointing that client-based email encryption is not more widespread and easy to implement.
Rather than an encryption gateway, having your email client handle encryption avoids the problem of man-in-the-middle attacks between the gateway and the client.
I don't have much reason to encrypt, but Thunderbird has my certificate installed and does my digital signing. This is not unusual for a modern email client.
Bruce Perens.
I setup a ZixGateway appliance and it's worked quite well for encrypting mail. Users can enter a keyword in the subject line and it will encrypt the messages, or if it scans a message and finds something that's in one the lexicons it encrypts it. They were very professional during initial setup and every time I've had to contact support things have gone well with quick responses. Not sure how small of a company you're working for but we're under 100 people and this solution works well for us.
THIS. Once it gets off your LAN, there are SO many ways for you to get tapped into. Not counting the illegal ways, look at all the options the govt has and is well known to use, often ignoring or pencil-whipping judicial oversight. They can subpoena your ISP, whoever is doing your email encryption, whoever is providing them with their SSL keys, or their ISP.
If you are serious about protecting your privacy, make darn sure your data is secured before it leaves your property. At least then, if they want to snoop, you're a lot more likely to at least know it's happening. And that will keep out most of your threats, short of spear-phishing, stray bait flash drives left in your parking lot, and internal threats. (malicious employees)
In the short term, get everyone an email certificate, and USE them to sign and encrypt outgoing email. (any decent email client will support signing and encryption) That data could still be subpoenaed from the group you get them from though. You can roll your own if you want to also, but you won't be easily able to revoke if need be.
I work for the Department of Redundancy Department.
Cisco IronPort. We use it and rely on it heavily for secure emails regarding pii for our pension fund.
Then I can't (won't) read any email you send me.
To read Cisco IronPort mail you must install software from Cisco.
To install the software from Cisco you must sign an EULA - which makes a BIG POINT of being a binding contract.
The EULA has anti-reverse-engineering terms that, were I to sign them, would (IMHO) make me unemployable in the computer security field.
Therefore I will not install the software.
Therefore I cannot decrypt "secure" email you send me.
Therefore I will not do business with your company.
Do you REALLY want to FORCE your clients to CONTRACT WITH A THIRD PARTY and SIGN AWAY THEIR RIGHTS in order to exchange important email with you?
Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
I'm the CTO at Voltage, and I'm disappointed to hear that the original poster is having a poor experience with us. While I'm not going to claim the Voltage's gateway product is the ideal solution for every small business, we do feel like we do a great job helping businesses of many sizes that handle and exchange sensitive data comply with privacy requirements. There are a lot of security solutions that have been mentioned in this thread, ranging from GPG to SMTP over TLS. All of these solutions have value, depending on the problem that you are trying to solve. Our product focusses on encrypting email messages to end users without needing to enroll those users into a traditional certificate structure, and allowing those users to decrypt those messages with minimal difficulty. Regardless, I'd like to solve the original poster's problem. I'd ask that he contacts me at Voltage, and I'll handle any issue he's having at the moment.
The IT department provides all staff with a client that is already configured to send and receive PGP email...
The client is configured to automatically encrypt when sending mail to a recipient for which it has a public key, and displays a warning if it doesn't have a key available.
When it receives a public key via email it prompt the user to import it.
It's really not terribly difficult if done right, and users will soon be sending encrypted mail without even realising it.
http://spamdecoy.net - free throwaway anonymous email - avoid spam!
I know your comment is meant to be funny (and it is), but what I really don't get is why everyone is talking about Outlook (argh) and sharepoint (*shudder*), and not about Lotus Domino. I'm also a bit... confused about why Lotus Domino isn't the default choice for anyone even remotely thinking about secure mail.
Lotus had a place for storing certificates since they were invented. In fact, ALL authorization is done using keys. It's been designed to work with them from the ground up. If the admin manages to remove his ID from the database, he's just as thoroughly holed under the waterline as any user. Inside the company everything can remain encrypted and when going out you can use encryption for everyone you have the certificates for, or make it impossible to send unencrypted mail. Using Lotus there is absolutely no barrier to using encryption (only to using the damn client in the first place - the GUI has issues).
Ofcourse, one can also keep on bolting random software on top of other software, like that factory in Bangladesh: at some point, the foundation can't hold the weight anymore and you're done.
Therefore, by the (faulty) logic you're using, you're just a cow with a keyboard - osu-neko (2604)