5 ms·
Perfect timing. Just used this to send personal information across email. I still included the password in the email, but the expiry date means my personal data
by throw14082020 6y ago
Perfect timing. Just used this to send personal information across email. I still included the password in the email, but the expiry date means my personal data won't be collected through passive email logging. Also added max 2 read attempts: one for me test it, and another for the accountant.
And of course, the accountant at my company still insists on passing personal information through email. Another example, Monese bank asking me to submit all sorts of pdf scans of personal documents to close an account with them.
- alias_neo 6y agoIt's such a battle. When my wife and I were buying our home, we needed to send our entire lives in paperwork form to the solicitors. I asked if they have a secure mechanism for file uploads and they responded "email is fine". No, email is not fine. They _really_ struggled to understand why I wouldn't just email them every document they asked for (from birth certificates, marriage certificates, 6 months of financial data, 12 months of pay slips, and a host of other things). In the end I hosted them myself and phoned them with a password, then deleted them once I'd seen they'd been accessed. Unfortunately, I have no confidence that they have, did nor will handle all of that information appropriately once they receive it. How is it not complete insanity to require _that much_ information on someone and _not_ have strict training and liability for managing it? Between then and now, Firefox Send has come and gone, but fortunately it's open source, so I'll host that if I find myself in a similar situation in the future.
- monkeydust 6y agoYou have to assume anything you send can become compromised and then game out what would be the ramifications of that. Its good you de-risked this somewhat by avoiding email thought, that's a good first step and I wish there was a standard for this.
- blub 6y agoAnd after they downloaded your secured file, they probably sent them between themselves over e-mail. This is why laws like the GDPR are needed.
- VMG 6y agoThe GDPR does not fix this at all.
- coddle-hark 6y agoYes it does. For instance, most places don’t send payslips over email for GDPR compliance reasons.
- rlpb 6y agoIt does. See for example the Ticketmaster case. They were fined £1.25 million under the GDPR: https://ico.org.uk/action-weve-taken/enforcement/ticketmaster-uk-limited/ https://ico.org.uk/action-weve-taken/enforcement/ticketmaste... A key justification for the fine (see the report eg. sections 6.3 through 6.7) is that "there were multiple failures by Ticketmaster to put in place appropriate technical or organisational measures to protect the personal data being processed on Ticketmaster's systems, as required by the GDPR." Process data without taking appropriate steps to protect that data and you face being fined under the GDPR.
- HenryBemis 6y agoIf the solicitors were acting on behalf of the bank, then they are bound by the contract with the bank. If the bank is a half-decent bank, they have a third-party security risk assessment & risk management team, that audits them regularly. You are thus covered/protected, because if they (solicitors get hack, leak data, etc) the bank will (most likely) spot this, and move to protect you.
- jtbayly 6y agoThis sounds like wishful thinking at every step.
- HenryBemis 6y agoWhoah plenty downvoting.. I assume that everyone is fully aware of Banks' Third-Party Security protocols/procedures and have good/working knowledge that they don't operate? Anyway, not wishful thinking. Actual/reality. Feel free to ask your banks about their TPSM. Good opportunity to see some info: I use BrightTalk (not affiliated) to collect CPEs for my certifications. They have plenty of webinars on Third Party Security: https://www.brighttalk.com/search/?q=%2Bthird+%2Bparty+%2Bsecurity&start=0&size=25&type=webcast&duration=0..&rank=-entrytime https://www.brighttalk.com/search/?q=%2Bthird+%2Bparty+%2Bse...
- A4ET8a8uTh0 6y agoEh, I am in both camps at the same time. I know what you are saying is true in theory, but in practice ability to make money efficiently trumps everything else. Even at bank bank you see people cutting corners for variety of reasons ( and when you see it you have to react ). I can't even imagine how bad it is in unregulated/less regulated industry.
- jtbayly 6y agoSetting aside everything else, on what basis would they moved to protect you as opposed to protecting themselves? And even even if they are forced to by bad publicity or something, what can they possibly do for you anyway if there’s a leak, other than offer you a useless year of identity theft “protection”? In other words, I still maintain this is wishful thinking.
- cube00 6y agoThe real estate agent we had replied with "but I don't understand why you won't email your documents, we've never had a problem using email to send sensitive documents before and we've done it hundreds of times" We hear about leaks of user databases all the time now so I'm surprised we don't hear more about mail boxes leaking out. All these small business mail boxes must be an identity thief's dream.
- girvo 6y agoAccess to small business mailboxes is used for a “neat” form of fraud; they intercept invoices and change the account details to theirs. It’s a bit of a long-ish targeted attack, but it makes the news now and then.
- apecat 6y agoAnd the best thing is that with Office 365, you have to pay for obscenely priced license tiers to get access to logs of mailbox activity. Wanna know if that attacker downloaded all of an inbox? You should've thought of that and paid $35.00 user/month (and that's the lower yearly commitment price) https://www.microsoft.com/en-us/microsoft-365/enterprise/office-365-e5?activetab=pivot:overviewtab https://www.microsoft.com/en-us/microsoft-365/enterprise/off...
- icecap12 6y agoAgreed - there are entire industries that simply have not caught up with secure management of paperwork, PII and financial information. To be frank, I'm not sure how that's possible with all the regulation. The mortgage industry is shockingly one of these. I just refinanced again after doing it 5 years ago. I was really curious to see if anything had changed in the 5 years. Any advances in basic tech? Was my experience going to be more secure? Answer: Nope. Still the same old stuff, hard copies of everything, people asking me for stuff via email. Blatant disregard for privacy. Just absolutely terrible. Multiple times the guy at the bank asked for my banking statements (which include full account number, balances, PII, etc.) and EVERY TIME I had to ask him to resend the link to their secure email portal. Worse - they never even offered secure transmission as an option...I had to ask about that option. It's clearly not the default behavior. Interestingly, the closing company was lightyears ahead of the bank. They had contracted a SaaS vendor that provided a secure digital document management product focused on mortgage closing, and I was able to e-sign everything (even able to scan in my signature and apply to documents). I mean, this isn't earth-shattering tech, but it sure was one hell of an upgrade compared to the bank. That's what all banks should be providing today; overall it was a far better experience than the bank.
- bitexploder 6y agoI work in infosec consulting and reversing for 15 years. My identity has been compromised numerous times via OPM, Equifax, and Home Depot, just to name a few. I just don’t care about emailing sensitive docs anymore. I find an alternative if possible, which usually it works. I put in some effort. But realize emailed financial docs aren’t likely how you get owned. It doesn’t feel great, but it is what it is. E: also, almost everyone I’ve asked will delete the documents after you try and fail to set up an expedient file share. Also, password protected zip files in Dropbox are usually good enough for most everyone and are a very simple system. Just make sure you use modern zip protection and not old crappy Zip crypto :)
- waheoo 6y agoCompromised or stolen? Identity theft can fuck you indefinitely.
- bitexploder 6y agoIdentity theft happened to me once from another person with my same name using my identity to run up credit. It's not that hard to fix, it just takes fighting bureaucracy. They got my info from some lender somehow getting my data and giving it to them. Someone's email spool getting compromised and that leading to identity theft is such a smaller concern compared to all these data warehouses just leaking your data.
- weird-eye-issue 6y agoMaybe if it goes unnoticed for several years... But even then indefinitely sounds like a stretch. I've personally had my identity stolen last year and they got a car loan, insurance, and bought a couple iPhones and lines with two different providers. It happened in the month I was closing on my house and getting a mortgage. Yeah it was a bit of a pain but some phone calls, a police report, notarization, and snail mail later and it is off my record and my credit score went right back over 800. Also I was still able to get the mortgage even with it going on.
- croutonwagon 6y ago
- Legogris 6y agoDouble-comment but check out https://github.com/algolia/sup3rS3cretMes5age https://github.com/algolia/sup3rS3cretMes5age I live in a country where sharing my entire life in paperwork is sadly normalized. Having a self-hosted one-time-secret service for file uploads is so nice.
- pentae 6y agoThis is the only thing I still use Dropbox for after moving my files away a long time ago. Set up a password protected folder, send the link over email and SMS them the password or tell them over the phone. Easy peasy.
- kevincox 6y agoAssuming that you have your email configured to require TLS on the receiver than I don't see what is wrong with email. Even if they downloaded the files from your server they probably just stuck them on some file share which at best is just as secure as their email inbox was. Many organizations have policies for email retention and similar that is less likely to be enabled for file storage. I would love to see more places just use email. Instead I get these messages with links to proprietary services to get the file. Now I need to download and store it out-of-line with my conversation. I think the major issue with email is that encryption is optional with transparent downgrading. You can imagine that if it supported something like mailtos:me@example then it could be used as a secure medium, much like https can be trusted today.
- adolfojp 6y agoI know of a reasonably large travel agency that asks their customers to send a photo of their passport, driver's license, and credit card to a random employee's personal email account. I warned my brother against sending them his information and he saw me as the problem. I have a client that stores similar information in an external HDD in a shared office that a lot of people have access to. I convinced him to let me install BitLocker at a minimum and to allow me to have his computer lock automatically. He had another guy remove full disk encryption because it was a hassle when he moved the HDD around and remove the auto lock because he wanted his secretary to access the computer when he was away from keyboard. I know an accountant who calls me paranoid when I talk to him about securing the devices that he uses to store tax information about all his clients. We need regulations and fines because the only way in which people are going to listen about security is if it hurts their pockets.
- solarkraft 6y agoLuckily there is such regulation in the EU (but it could arguably be better enforced). Are there no such things in the US?
- adolfojp 6y agoSort of but not quite. Sending CC info through email violates the PCI DSS. The PCI is a private organization so noncompliance is not a violation of the law. There is no unified law across the US that deals with data privacy. Several states are starting to address this problem but there's nothing like what the EU offers.
- JshWright 6y agoYeah, they definitely just attached them to an email they sent to whoever they would have forwarded your email to if you had sent it that way.
- orev 6y agoIn the past the risk with email was mostly network sniffing during the transfer, which is somewhat low risk given who has access to backbone networks, and many systems have opportunistic TLS enabled, which is at least better than nothing. However, after the Exchange hack, now we suddenly have to worry about all the stuff that’s stored in people’s mailboxes after delivery, which is likely a huge amount of data. I expect we’re going to see a huge wave of identity theft stemming from this.