Follow Us

The problem with S/MIME email encryption

Searching emails becomes virtually impossible, once they are encrypted

A few times a year, I recognise the need for a product where none exists because I hear multiple customers asking for it. This is one of those times. The products that an increasing number of my clients is looking for are e-mail scanning and archiving systems that can handle S/MIME-encrypted messages.

In a normal year, I visit 20 to 40 clients, ranging from small companies to Fortune 10, where I get to see what products they are using and how well these products work in a real-world scenario. Increasingly popular these days is the use of S/MIME and other e-mail encryption methods (such as PGP, proprietary web mail portals, and so on) to protect email both within the enterprise and externally.

S/MIME isn't necessarily the best method to use, but it's a stable, open standard and probably the most common email encryption method I've seen in use.

Every S/MIME customer I have goes through a few phases. First, they need to understand how it works. How do you turn it on? Who gets what keys? How are the keys distributed? What training will end-users need? How to automate its use? It's no small undertaking.

Emailing in the dark

Often in the second phase, S/MIME ends up nearly crippling the company's normal email functionality. S/MIME involves encryption, and when you encrypt email, it is no longer searchable. At the very least, users can no longer retrieve past emails based upon message text keyword searches, although the email subject line and some other information, such as file attachment name, may remain visible.

This may sound merely bothersome at first, but it becomes mission critical when you need that one single email for proof in a disagreement. Some users respond by turning their email subject lines into more descriptive headings that can be more easily found using keyword searches, but at some point, the sender begins to reveal information that should probably be protected within the S/MIME body.

Worse for today's computer security departments is the fact that S/MIME ends up defanging their anti-virus scanners, DLP (data loss prevention) tools, and email archiving and retrieval systems. Outgoing S/MIME-encrypted email can be antivirus scanned before encrypting and sending, but it's more difficult to scan incoming S/MIME messages, where the scanning is done on a gateway or by an external service provider.

Most of the risk from email malware isn't from the stuff you send, anyway. It's from the stuff sent to you. If you use S/MIME and don't have client-side malware detection for email, you now have a problem.






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Desktop modernisation

On the one hand, there is the need to keep the existing desktop environment efficient, secure...

Download Whitepaper

Top 10 myths about virtualising business-critical applications

Even though virtualization has brought positive change to enterprise IT over the last decade,...

Download Whitepaper

Aligning CFO and CIO priorities

Forward-thinking organisations are viewing cloud computing as an investment in business...

Download Whitepaper

The new corporate network

Businesses can’t afford to have employee productivity suffer because they cannot use their...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Awards

Techworld Awards 2012
Coming Soon

Opening for submissions May 2012

 

Find out more

Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...
LogMeIn Rescue

Accelerate Your IT Efficiency

View the latest capacity management resources including whitepapers, videos and news.

Find out more...

Site Map

* *