Go Back   PCMech Forums > Help & Discussion > Internet, Web Applications, & The Cloud

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 03-03-2004, 09:08 PM   #1
Audio/Video Expert
 
SonicVanguard's Avatar
 
Join Date: Jul 2003
Location: West Michigan
Posts: 1,625
Encrypted/Digitally Signed E-Mail

Our studio is starting to do more and more work with larger studios - for example, we just inked a deal with New Line. We are working in a team environment - meaning projects will be divided between 3 or 4 studios like ours to facilitate post production.

One concern we have is our e-mail contact. Much of what we are working on is copyrighted material and some of it is somewhat secrative (plot lines, movie endings and the like). We would like to start encrypting or digitally signing our e-mails - how hard or simple is this to do?

I found one certificate provider: http://www.cacert.org/ and a few of us have signed up for their certificates. The problem with this particular certificate is that it is not common so when I e-mail my contact at New Line, the certificate appears in-valid on his end. And to have all of New Line sign up at CAcert is pointless - the powers that be won't allow that to happen.

So...is there any way to get a certificate that is commonly known by most browsers without spending a fortune to do it?

Dave.
__________________
Dave.

Go where there is no path and leave a trail.
SonicVanguard is offline   Reply With Quote
Old 03-06-2004, 04:33 PM   #2
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 37,771
Why don't you just use something like PGP ($50), or Winzip 9.0 (shareware) which can 256-bit encrypt zip files?
glc is offline   Reply With Quote
Old 03-08-2004, 04:01 AM   #3
Member (13 bit)
 
Xayd's Avatar
 
Join Date: Jun 2000
Location: nowhere.com
Posts: 4,819
Send a message via AIM to Xayd
PGP is a pain in the ass, and only as secure as the machine that the message came from for email messages. For instance some versions of Outlook save unencrypted versions of messages on the local hard drive for any virus or trojan to just pick up and forward how they see fit, even if the message was originally encrypted.

The problem as you're finding with SSL certs and such is that not all certificate authorities are recognized as highly as others, the only sure bets are probably Verisign and Thawte, both of which are pretty expensive (500 to 1000 dollars).

If you want absolutely secure communication? I dunno. You could set up a forum such as this with SSL + passworded forums + a firewall that only allowed access from certain IPs, that only responded to an IP address and didn't have a registered domain. This is all relatively simple to do with a Unix/Linux machine, and would give you in-transit encryption as well as multiple password checks and a check on the host IP address, but again it's only as secure as the machines that are allowed to view it. Once their web browsers view and cache a page you're back to square one .
Xayd is offline   Reply With Quote
Old 03-08-2004, 09:34 AM   #4
Professional gadfly
 
doctorgonzo's Avatar
 
Join Date: Jan 2002
Location: Minneapolis, MN
Posts: 6,364
Send a message via MSN to doctorgonzo
I don't think that PGP is a pain in the ass. And any form of encryption is only as secure as the computers used at both ends of the process.

Outlook may have holes when using the PGP e-mail plugin (wouldn't suprise me at all), but there are other ways to sign and encrypt messages. You can write the e-mail message in Notepad and encrypt and sign the file itself. You can also encrypt and sign any other files you want to e-mail. Attach those encrypted files to an e-mail, and even if Outlook saves a message, it won't be saving the cleartext (since it never had access to it).

The question you need to ask yourself is how much it would cost for your information to leak out, and how likely that is. If the impact would be hundreds of thousands of dollars, and people are actively trying to get this information from you, then it makes sense to spend thousands on reliable SSL certs. If the threat is less, then I think you can make do with PGP and some good, enforced rules for e-mailing this information around.
doctorgonzo is offline   Reply With Quote
Old 03-08-2004, 03:22 PM   #5
Member (13 bit)
 
Xayd's Avatar
 
Join Date: Jun 2000
Location: nowhere.com
Posts: 4,819
Send a message via AIM to Xayd
All of that comes at the expense of ease of use, though. Will users cease typing emails and only type attachments to emails?

No, of course they won't. They haven't been doing anything that way for all these years why would they change now.

Finding a solution to a problem is one thing, getting users to use it is another thing entirely.
Xayd is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 06:38 AM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 PL2