The problem with S/MIME email encryption

Searching emails becomes virtually impossible, once they are encrypted

A few times a year, I recognise the need for a product where none exists because I hear multiple customers asking for it. This is one of those times. The products that an increasing number of my clients is looking for are e-mail scanning and archiving systems that can handle S/MIME-encrypted messages.

In a normal year, I visit 20 to 40 clients, ranging from small companies to Fortune 10, where I get to see what products they are using and how well these products work in a real-world scenario. Increasingly popular these days is the use of S/MIME and other e-mail encryption methods (such as PGP, proprietary web mail portals, and so on) to protect email both within the enterprise and externally.

S/MIME isn't necessarily the best method to use, but it's a stable, open standard and probably the most common email encryption method I've seen in use.

Every S/MIME customer I have goes through a few phases. First, they need to understand how it works. How do you turn it on? Who gets what keys? How are the keys distributed? What training will end-users need? How to automate its use? It's no small undertaking.

Emailing in the dark

Often in the second phase, S/MIME ends up nearly crippling the company's normal email functionality. S/MIME involves encryption, and when you encrypt email, it is no longer searchable. At the very least, users can no longer retrieve past emails based upon message text keyword searches, although the email subject line and some other information, such as file attachment name, may remain visible.

This may sound merely bothersome at first, but it becomes mission critical when you need that one single email for proof in a disagreement. Some users respond by turning their email subject lines into more descriptive headings that can be more easily found using keyword searches, but at some point, the sender begins to reveal information that should probably be protected within the S/MIME body.

Worse for today's computer security departments is the fact that S/MIME ends up defanging their anti-virus scanners, DLP (data loss prevention) tools, and email archiving and retrieval systems. Outgoing S/MIME-encrypted email can be antivirus scanned before encrypting and sending, but it's more difficult to scan incoming S/MIME messages, where the scanning is done on a gateway or by an external service provider.

Most of the risk from email malware isn't from the stuff you send, anyway. It's from the stuff sent to you. If you use S/MIME and don't have client-side malware detection for email, you now have a problem.


What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.


Characters remaining: 500

Add your commentComments

Angelo Comazzetto | Published: 14:59 GMT, 17 November 2009

Passing encrypted messages to the desktop can hinder the visibility of network tools and security functions. Astaro recognizes the benefits of moving encryption and decryption to the gateway; you take the load off of how to use an encryption system from the end-user while at the same time maintain control of messages. Since you aren’t dealing with encrypted contents directly on the desktop instead you can first decrypt the messages then archive, search, run DLP, and other functions.

Dr Chris Gaskett | Published: 19:57 GMT, 11 November 2009

CoolRock software's email archiving and discovery product "TEAL Secure+ Edition" fully supports S/MIME encrypted email. http://www.coolrocksoftware.com/

Related Security news

Russian software assisted Citibank hack

Black Energy for the black hat hackers

Microsoft recommendations help hackers says Trend Micro

Whitelisting puts users at risk claims security company

Twitter account hijack was not attack on servers

Company's own DNS records were altered - site not compromised say execs

File sharing networks top target for cyber criminals

Kaspersky warns of new danger areas for 2010



Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Unlocking the benefits of Google Apps

Download this whitepaper to learn more about how you can save time and money by migrating from Microsoft Exchange to Google Mail.

Download Whitepaper

Application Grid: The ideal platform for IT consolidation

Evaluating the opportunity for consolidation of middleware — Java application servers and related technologies.

Download Whitepaper

Enterprise mashup services

Mashups are part of the Web 2.0 evolution of IT that can empower a business to enhance productivity, innovate more readily and collaborate more effectively – both internally, and with suppliers, partners and customers

Download Whitepaper

Database security: Preventing enterprise data leaks at the source

IDC discusses the growing internal threats to business information, the impact of government regulations on the protection of data, and how enterprises must adopt database security best practices...

Download Whitepaper

Techworld UK - Technology - Business

COLT White Paper

Are all VoIP services the same?

Questions to ask your service provider to ensure you get the VoIP service you need
With careful choice of partner, your business can have all the advantages of VoIP access - reduced costs, flexibility and simplicity - without the drawbacks.
This white paper is your guide to ensure you get right the VoIP service and details the pitfalls which businesses would do well to avoid.

Download white paper

Enterprise communications and collaboration in a fast changing world

With capital expenditure budgets drastically reduced, the IT team is facing an unprecedented challenge: just how can it meet demands for more flexible working and improved productivity without embarking upon a sustained investment program.

Download white paper

Webcast: IT Financial Management: Cost Optimisation for Efficiency and Agility.
On Demand Webcast
Join this webcast to learn about the techniques and technologies that can help you prove the value of IT to the business by understanding the true cost of today's IT services and those that will be necessary to deliver future success.

Register Today

Site Map

IDG Network

* *