4 ms·
Fax machine -> fax machine : secure And fax machines are easy to use. Securing document exchange by email is a PITA for 99.9% users. Explain to your mother ho
by grumpy-cowboy 8y ago
Fax machine -> fax machine : secure
And fax machines are easy to use.
Securing document exchange by email is a PITA for 99.9% users. Explain to your mother how to use PGP/GPG to encrypt the email she have to send to financial institutions, government, ... And imagine the government employee receiving the encrypted email. He will probably just delete it. :)
- jak92 8y agoWell, completely unencrypted, but depends on what you consider the threat to be.
- pintxo 8y agoI feel with you. I was shocked to learn that fax is still the default for Doctor 2 Doctor communication here in Germany. Turns out the reason is rather simple: the law explicitly requires phone lines to be confidential in terms of eavesdropping. (You need a warrant, else it‘s illegal). While all other means of transport are not covered by this. So everyone who wants to legally cover his ass, would rather use the legally privileged, but technically wide open phone line over technically sound solutions missing such a legal framework.
- gruez 8y ago>Turns out the reason is rather simple: the law explicitly requires phone lines to be confidential in terms of eavesdropping. (You need a warrant, else it‘s illegal). While all other means of transport are not covered by this. What about VOIP? Cell phones? WIFI calling?
- yebyen 8y agoWhat about them? (Can you send a fax over those media, and are they protected similarly?) Or are you asking a different question? If it's not on a phone line, then it's not afforded those legal protections. None of those communication media you just mentioned are using a phone line as a transport mechanism. (They're also not similar to fax from a UX standpoint.)
- gruez 8y ago>Or are you asking a different question? I was asking whether those protections applied to only landlines, or all telephone conversations (eg. cellphones). >If it's not on a phone line, then it's not afforded those legal protections. This sounds problematic considering that for PSTN, "phone lines" only cover the last few miles of transport[1]. Does that mean you can't tap outside someone's house (where it's a phone line), but you could tap outside the CO, where it's fiber or even public internet? [1] https://en.wikipedia.org/wiki/Public_switched_telephone_network https://en.wikipedia.org/wiki/Public_switched_telephone_netw...
- yebyen 8y agoI think that was exactly the story behind Room 641a, wasn't it? (And it was illegal, although now, in the USA, I don't think it would be anymore.) Largely depends on what TLA you are, and whether or which secret court you derive your authority from / are required to report to for renewal of your secret warrant. Of course the GP was about doctors in Germany, and this 641a business was about an NSA facility operated on an AT&T switching office in San Francisco, USA (so this does not also preclude that.) I think based on what I know about Germany and privacy laws, the court would use a favorable liberal interpretation of "phone line" to mean, say, any connection that begins and ends with a phone line, and terminates with a dial-tone. I don't know much about German courts though, so take that only for what it's worth.
- JohnFen 8y ago> the law explicitly requires phone lines to be confidential in terms of eavesdropping However, POTS these days commonly uses VoIP as an intermediary. I don't know if the law covers the same phone call during its passage through a VoIP segment.
- pintxo 8y agoAs I understand the law here in Germany, it's technology independent. So VoIP falls under the same rules, as long as you sell/market phone and fax services. How this relates to something like Skype I have no idea.
- darkpuma 8y agoSo it turns out the US Postal Service is very easy to trick. You merely fill out a simple form with no real verification and get them to forward somebody else's mail to your address, which enables all manner of profitable fraud. HOWEVER doing that is a hardcore crime. You can be sent to federal prison for years for doing that. So the USPS is not secure in any sort of mathematical sense, but in practice most people trust it most of the time, because security isn't just about technical implementation details like encryption. Similarly wiretapping telephone lines may be straight forward, but you'd have to be exceptionally daring or stupid to actually do it.
- dragonwriter 8y ago> HOWEVER doing that is a hardcore crime. You can be sent to federal prison for years for doing that. So the USPS is not secure in any sort of mathematical sense, but in practice most people trust it most of the time, because security isn't just about technical implementation details like encryption. But if your data is such that it would be a “hardcore crime” to seek access to it fraudulently, or the main reason people would do so is to commit a “hardcore crime”, using an information channel that is only considered secure because of the social safeguard that breaching it's trivial protection is itself a “hardcore crime” is probably foolhardy, since engaging in such a crime is cost already accepted by the attackers you are concerned about.
- darkpuma 8y agoThat's true. However most of what people would prefer be confidential isn't data that would be sufficiently profitable to make risking federal prison rational. e.g. medical records. I don't want my medical records made public, but nobody is going to make themselves rich by violating my privacy. So, for example, doctors using faxes makes a lot of sense. Maybe not for doctors with high profile celebrity or politician clients who value their privacy, but for the most part.
- dragonwriter 8y ago> However most of what people would prefer be confidential isn't data that would be sufficiently profitable to make risking federal prison rational. (1) Don't assume you know all potential criminals’ utility functions (especially, don't assume all of their utility is financial), and, more important (2) Don't presume crime is usually rational, in the first place.
- gruez 8y ago>Fax machine -> fax machine : secure Great in theory, until you realize that most people don't have fax machines, so they use some online fax service that's probably less secure than sending email.
- deleted 8y ago[deleted]
- dragonwriter 8y ago> Fax machine -> fax machine : secure Fax-to-fax is completely vulnerable to all kinds of attacks (even before considering situations where what seems to be fax-to-fax involves one end or the other actually being a gateway to some insecure system that pretends to be a fax machine), because: (1) phone number hijacking is a thing, (2) phone lines can be eavesdropped on, (3) fax lacks authentication between endpoints, (4) fax lacks encryption. OTOH, in HIPAA environments it's often preferred because fax is not considered “electronic media”, so it is not covered by either the transaction standards or security standards that apply to transactions conducted via electronic media.
- ipython 8y agoNot necessarily - if your all-in-one printer/fax/scanner combo machine is also connected to both the POTS and your internal network (as most probably are), it can be used as an attack vector: https://blog.checkpoint.com/2018/08/12/faxploit-hp-printer-fax-exploit/ https://blog.checkpoint.com/2018/08/12/faxploit-hp-printer-f...
- JohnFen 8y ago> Fax machine -> fax machine : secure Not even close. I can think of a lot of advantages to using old-school faxes, but security is not one of them. In fact, the complete lack of security is a big disadvantage to using old-school faxes.