Link to home
Start Free TrialLog in
Avatar of computerlarry
computerlarryFlag for United States of America

asked on

Good ways to send confidential documents via email?

The user want to securely send documents via email.
I am experienced with Symantec Encryption Desktop and using PGP with Outlook.

They want to send confidential documents from time to time to several different recipients.  What other methods are acceptable?

They heard about Sharefile.com, but I'm not familiar with its operation.


Thanks.
Avatar of Dr. Klahn
Dr. Klahn

If they are bound and determined that they must move confidential documents by email -- not a real good idea, i/m/o -- then the only way I know of that is secure is, as you have mentioned, pre-encryption which processes the content before the email is sent.

I like GPG/PGP because only the receiver has the key to decrypt.  If the email leaks, you have a solid backstop:  "Only you hold the private key to decrypt that message, so don't point that finger at us."
Your user and the recipient should share a long/complex password.
Encrypt the attachments and email them.

ZIP is the most common encryption format used for this type of encryption.
7Zip is a popular free program.

However, I recommend that you use the RAR format to encrypt attachments.
It is much more secure than using zips and has more options.
https://www.rarlab.com  (Shareware €30)

WinRAR offers you the benefit of industry strength archive encryption using
AES (Advanced Encryption Standard) with a key of 128 bits.
An important element of the security is in the Key formed.
WinRAR uses 262144 rounds of SHA-1 with a 64-bit salt.
Encryption is really the only option that makes sense. Dr. Klahn's suggestion is the most ideal because it binds each person. Depending on your mail system, it may have built in capabilities  (i.e. 365), but even that only encrypts at a certain point along the path.
Look at Mimecast Secure Messaging. We use this for several clients and all are happy.
S/mime encryption..
Pgp, gpg, s/mime requires a prior exchange of public keys.

Using a compressing winzip, 7zip, winrar, etc is a more easily accessible tool to compress and password protect.
Difficulty with password protected archives often are blocked by reciepient system because the password prevents the anti-virus scan of contents and often is being blocked...

Depending on industry as was suggested there are email hosting sites/providers that provide such a transfer.
As Eirman wrote :

Your user and the recipient should share a long/complex password.
Encrypt the attachments and email them.

ZIP is the most common encryption format used for this type of encryption.
7Zip is a popular free program.

However, I recommend that you use the RAR format to encrypt attachments.
It is much more secure than using zips and has more options.
https://www.rarlab.com  (Shareware €30)

WinRAR offers you the benefit of industry strength archive encryption using
AES (Advanced Encryption Standard) with a key of 128 bits.
An important element of the security is in the Key formed.
WinRAR uses 262144 rounds of SHA-1 with a 64-bit salt.

On this I'll add the following :

Choose a different way to send the password :

Don't send the file and the password in the same e-mail. And if possible, avoid to send PASSWORD via E-mail, SMS should be the best.
by order of preference : 7zip the file, setup pgp, ... that is more than enough
ASKER CERTIFIED SOLUTION
Avatar of computerlarry
computerlarry
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial