4 ms·
I use GPGTools when sending sensitive client information, to avoid situations like this. GS has zero excuses, they could very easily code a Microsoft Outlook v
by SatoshiPacioli 12y ago
I use GPGTools when sending sensitive client information, to avoid situations like this.
GS has zero excuses, they could very easily code a Microsoft Outlook version of it that is seamlessly integrated. Instead they fail at proper risk management and rely on government intervention, sound familiar?
- SatoshiPacioli 12y agoLink for those interested: https://gpgtools.org/ https://gpgtools.org/
- deleted 12y ago[deleted]
- smackfu 12y agoDo you also use encryption when sending information internally to a colleague? That's the situation here: it was an internal email accidentally sent to GMail instead of Goldman Sachs. I bet a lot of firms fail in this case.
- eru 12y agoInternal email should be easier to encrypt, if anything. Because the company can control both end-points, so can make the encryption automatic.
- viraptor 12y agoNot sure why this was downvoted. If you're in an outlook/exchange integrated environment, you only have to click "encrypt/sign this". It's almost transparent to the user and in addition it would raise an error for the original sender. (saying the key for user blah@gmail.com cannot be found)
- yebyen 12y agoAnd how would it help to automatically encrypt internal e-mails when an e-mail accidentally gets an external delivery address because someone fat-fingers?
- deleted 12y ago[deleted]
- SatoshiPacioli 12y agoDo you understand how PGP encryption functions?
- yebyen 12y agoYes, I understand (on a superficial "don't actually use it on a day-to-day basis, but have encrypted e-mails before" level) I am imagining this program that looks through your To: field for recipients in your address book that have shared their public key with you. If it finds any, those people get a copy sent to them which is encrypted and only they can read... Now what happens if you accidentally try to send mail to someone not in your address book? I guess hopefully you get a big popup that says "Warning: mail will not be encrypted!" Maybe not? I've used the command-line tools to encrypt files and send encrypted attachments. It's nothing like "automatic" and it's certainly not an envelope for the whole message.
- andreasvc 12y agoYou can set up the encryption so that it requires a verified public key. If you mistype an address, you won't have their public key, and can't encrypt the message to them.
- fpgeek 12y agoSome firms have email triggers that tell you when you're sending something outside the firm to minimize those accidents (and to make the employee carelessness associated with any remaining accidents clearer).
- brisance 12y agoOS X Mail does this for quite some time.
- Marazan 12y agoI would be extremely surprised if GS didn't have a system like other investment banks that popped up an ugly and obvious "you are sending an external e-mail. Are you sure?" dialog when sending to non-internal e-mail addresses.
- eru 12y agoAnd I guess, people are trained by now to automatically click away those dialogs. A 30 second (or so) undo window would be better.
- twistedpair 12y agoI've worked for two of GS's competitors. Any email with confidential information (internal or external) has to be encrypted and signed. Standard operating procedure. I assume it is at GS too and this fella, like most folks on the investment side, just didn't give a hoot about the SOP.