<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Calazan.com &#187; encryption</title>
	<atom:link href="http://www.calazan.com/tag/encryption/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.calazan.com</link>
	<description>Share the Knowledge</description>
	<lastBuildDate>Sun, 05 Sep 2010 00:59:26 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Opportunistic TLS</title>
		<link>http://www.calazan.com/opportunistic-tls/</link>
		<comments>http://www.calazan.com/opportunistic-tls/#comments</comments>
		<pubDate>Sat, 21 Mar 2009 19:42:15 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SysAdmin]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[Exchange 2007]]></category>

		<guid isPermaLink="false">http://www.calazan.com/?p=412</guid>
		<description><![CDATA[We had to upgrade our mail gateway/anti-spam software on Sunday because one of our vendors requires us to use encryption when exchanging emails with them.  The easiest solution is to use opportunistic TLS, where the server will always try to connect to the other server using the TLS protocol.  If the other server supports TLS, [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.calazan.com/wp-content/uploads/2009/03/secure_email.jpg"><img class="alignleft size-medium wp-image-422" title="secure_email" src="http://www.calazan.com/wp-content/uploads/2009/03/secure_email.jpg" alt="" width="136" height="140" /></a>We had to upgrade our mail gateway/anti-spam software on Sunday because one of our vendors requires us to use encryption when exchanging emails with them.  The easiest solution is to use opportunistic TLS, where the server will always try to connect to the other server using the TLS protocol.  If the other server supports TLS, then traffic is encrypted.  If not, then the email is sent using just regular SMTP without encryption.</p>
<p>This is actually the first time I&#8217;ve even heard of opportunistic TLS, I&#8217;m used to seeing S/MIME and PGP when reading about email encryption.  What I like about this is encryption/decryption is done on the server side so the users don&#8217;t have to do anything different when sending emails and we don&#8217;t have to issue a certificate to each user and manage the keys.</p>
<p>If you&#8217;re using Exchange Server 2007, opportunistic TLS is already enabled by default.  You can check this by entering <em>Get-SendConnector &#8220;Send Connector Name&#8221; | Format-List</em> in the Exchange Management Shell.  Look for the <strong>IgnoreStartTLS</strong> parameter, if it&#8217;s set to <strong>false</strong> then opportunistic TLS is enabled.</p>
<p>To check whether a server supports TLS, telnet to the server on port 25 and check if the server supports the <strong>STARTTLS</strong> command, for example:</p>
<p><em>telnet mail.global.frontbridge.com 25</em></p>
<div id="attachment_419" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.calazan.com/wp-content/uploads/2009/03/smtp_tls.png"><img class="size-medium wp-image-419" title="smtp_tls" src="http://www.calazan.com/wp-content/uploads/2009/03/smtp_tls-300x150.png" alt="" width="300" height="150" /></a><p class="wp-caption-text">This server supports TLS</p></div>
<p>Here&#8217;s an example of the header of an email that was delivered with TLS enabled (I modified the IP addresses and names for privacy reasons):</p>
<p><em>Received: from mailgateway01 (1.2.3.4) by mailserver01.domain.com (1.2.3.5)<br />
with <strong>Microsoft SMTP Server (TLS)</strong> id 8.1.263.0; Mon, 16 Mar 2009 18:05:18<br />
-0400<br />
Received: from mail.global.frontbridge.com ([65.55.88.22]) by mail.somedomain.com<br />
([1.2.3.4]) with ESMTP (TREND IMSS SMTP Service 7.0; <strong>TLS:<br />
TLSv1/SSLv3,128bits,AES128-SHA</strong>) id 06456c96000057da for &lt;jdoe@microsoft.com&gt;;<br />
Mon, 16 Mar 2009 18:05:16 -0500</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.calazan.com/opportunistic-tls/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>UK Government Laptop Sold on eBay, Including a Confidential Disc</title>
		<link>http://www.calazan.com/uk-government-laptop-sold-on-ebay-including-a-confidential-disc/</link>
		<comments>http://www.calazan.com/uk-government-laptop-sold-on-ebay-including-a-confidential-disc/#comments</comments>
		<pubDate>Fri, 29 Feb 2008 01:52:09 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[encryption]]></category>

		<guid isPermaLink="false">http://www.calazan.com/uk-government-laptop-sold-on-ebay-including-a-confidential-disc/</guid>
		<description><![CDATA[More of these news about confidential data getting lost&#8230;
A local PC repair firm found the disc under the the laptop&#8217;s keyboard when the laptop was put in for repair.   The disc had the words &#8220;Home Office&#8221; and &#8220;Confidential&#8221; written on it.
The good news is, at least this time both the laptop and the disc have [...]]]></description>
			<content:encoded><![CDATA[<p>More of these news about confidential data getting lost&#8230;</p>
<p>A local PC repair firm found the disc under the the laptop&#8217;s keyboard when the laptop was put in for repair.   The disc had the words &#8220;Home Office&#8221; and &#8220;Confidential&#8221; written on it.</p>
<p>The good news is, at least this time both the laptop and the disc have been encrypted.</p>
<p>Read the full article <a href="http://www.networkworld.com/news/2008/022808-uk-govt-laptop-with-confidential.html" title="U.K. gov't laptop with confidential disc sold on eBay" target="_blank">here</a>.</p>
<p><strong>Related Posts:</strong></p>
<p><a href="http://www.calazan.com/backup-tape-lost-650000-customers-affected/">Backup Tape Lost &#8211; 650,000 Customers Affected</a></p>
<p><a href="http://www.calazan.com/laptop-with-data-on-600000-people-stolen/">Laptop with Data on  600,000 People Stolen</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.calazan.com/uk-government-laptop-sold-on-ebay-including-a-confidential-disc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TrueCrypt Disk Encryption Software</title>
		<link>http://www.calazan.com/truecrypt-disk-encryption-software/</link>
		<comments>http://www.calazan.com/truecrypt-disk-encryption-software/#comments</comments>
		<pubDate>Fri, 04 Jan 2008 11:00:55 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[aes]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[open source software]]></category>

		<guid isPermaLink="false">http://www.calazan.com/2008/01/04/truecrypt-disk-encryption-software/</guid>
		<description><![CDATA[I&#8217;m sure you&#8217;ve heard or read many stories before about laptops getting stolen containing thousands/hundreds of thousands of records on patients/customers/etc.  Those records usually include very sensitive information such as a person&#8217;s Social Security Number.  And a lot of times the data on those stolen laptops were not encrypted!!! Now those people are [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: left;"><a title="TrueCrypt Main" href="http://www.calazan.com/wp-content/uploads/2008/01/truecrypt_main.png"><img class="alignleft" src="http://www.calazan.com/wp-content/uploads/2008/01/truecrypt_main.thumbnail.png" alt="TrueCrypt Main" width="128" height="108" align="left" /></a>I&#8217;m sure you&#8217;ve heard or read many stories before about laptops getting stolen containing thousands/hundreds of thousands of records on patients/customers/etc.  Those records usually include very sensitive information such as a person&#8217;s Social Security Number.  And a lot of times the data on those stolen laptops were not encrypted!!! Now those people are at high risk of identity theft.  This wouldn&#8217;t have been such a big deal if they took an extra step of saving the data in an encrypted volume using a strong encryption algorithm.  This is very easy and simple to do, too, and there are many encryption software out there.</p>
<p style="text-align: left;">The one I would recommend is this free open-source disk encryption software called <a title="TrueCrypt" href="http://www.truecrypt.org" target="_blank">TrueCrypt</a>.  I&#8217;ve been using this software for about a year and a half now and never had a problem with it.  It&#8217;s very easy and simple to use and supports different encryption algorithms, including AES-256 (Advanced Encryption Standard, 256-bit key)  which is the encryption standard adopted by the U.S. government.</p>
<p style="text-align: left;">My new laptop actually came with its own encryption software but I still prefer TrueCrypt better because of its simplicity.  What you basically do is you create a volume using the software by specifying how much disk space you want to allocate for it, the type of encryption to use, and the volume password (make sure you choose a strong password!!!).  Then this encrypted volume would look just like a regular file on your hard drive.  You then use TrueCrypt to mount that volume to your OS (it will prompt you for the volume password that you created earlier).  The mounted volume would look just like a regular hard disk drive and you use it just like a regular hard disk drive as well.  The encryption is done on-the-fly.  You can also set TrueCrypt to automatically mount the volumes on startup.  TrueCrypt is available for Windows Vista (32-bit and 64-bit)/XP/20003/2000 and Linux.</p>
<p style="text-align: left;">You can <a title="Download TrueCrypt" href="http://www.truecrypt.org/downloads.php" target="_blank">download TrueCrypt from here for free</a>.</p>
<p style="text-align: left;">Cost of TrueCrypt? $0.  Cost of your stolen data falling into the wrong hands?  Well, that depends, but it could be HUGE!!!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.calazan.com/truecrypt-disk-encryption-software/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
