Security Basics mailing list archives

Re: Email Encryption


From: m0untainrebel <m0untainrebel () riseup net>
Date: Wed, 14 May 2008 15:02:54 -0400

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

If it works well with your current email setup, I would suggest
installing gnupg for encryption on all computers, setting everyone up
with thunderbird, and using the enigmail plugin. It's all free software
(as in speech and beer) and uses as strong encryption as an proprietary
alternative.

Preston Kutzner wrote:
| On 14 May 2008 08:08:07 -0000
| pete.hill () sit-up tv wrote:
|
|> Hi there,
|>
|> I am currently running through a PCI program at my company and am
looking for recommendations on an email encryption tool.
|>
|> We currently use a licensed version of Winzip, but I have heard that
this may not be up to job as far as passing a PCI DSS audit is concerned.
|>
|> Is Winzip good enough?  and if not, what should we be using to get a
pass on this?
|>
|> Many thanks
|> Pete
|>
| More information would be handy to help give a reasonable answer.  What
| OS are you using?  What MUA are you using?  What are you trying to
| encrypt in your email?  If you're using WinZip currently, I would
| assume you're just looking to encrypt the attachment.  Are you also
| looking to be able to encrypt (and sign) the entire email message?  Is
| compression necessary for your application?
|
| As far as email encryption is concerned, typical methods for this
| application usually consist of either SSL certificates or PGP/GPG
| encryption.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFIKzddRG/CQ+6vf9ARAtmUAJ0Yd/InmRuQn6Ib5moQI6VQd+TPcQCfTqD+
GFpGHK3ALSEzS6yKg96vhi4=
=5MHo
-----END PGP SIGNATURE-----


Current thread: