Outlook web based email security question

groze

Tester
Power User
VIP
Local time
2:08 AM
Messages
1,162
Outlook web based email security question.

I am sending an email to someone but I don't want third parties to look at it.

Which is the best method?
Uploaded to Outlook dot com, then send the email
Use Thunderbird IMAP and send email through outlook dot com servers

I know once mail is uploaded to Outlook dot com servers or outlook dot com it remains secure.

Does it remain secure after outlook dot com sends the email or is it wide open? I hope you can understanding what I am asking.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell All in one Inspiron 2020
OS
W10 32 bit, XUbuntu 18.xx 64 bit
CPU
Intel(R) Celeron(R) CPU G1620T @ 2.40GHz, 2400 Mhz
Motherboard
Dell
Memory
4GB
Graphics Card(s)
Intel HD graphics
Sound Card
High Definition Audio Device
Monitor(s) Displays
20 inch Screen
Screen Resolution
W7=1280 x 720 & Linux Mint Xfce=1360 x 768
Hard Drives
500 GB hard drive
Keyboard
Usb
Mouse
Usb
Internet Speed
High-Speed
Antivirus
MSE
Browser
Main Browser Firefox
Other Info
I have done a clean install of Windows 7 using Dell re-installation disk (Dell sent me one). I also use Free Macrium reflect backup and restore.
Email is an incredibly insecure protocol. It provides NO authentication and NO validation, meaning that anyone can read and modify emails in transit, and spoof the sender/receiver too if someone really wants to. The immediate consequence is that it's impossible to use with confidential data.

The ideal solution is to not use email at all. Ideally, you would use an encrypted peer-to-peer connection, without any intervening thrd party. This of course is pretty difficult if you don't know how to host a server and secure it, but it's a good option otherwise.
A non-electronic method is even more secure too :p

But back on email, the only way to make it totally safe is to use an end-to-end encryption protocol. PGP is an option for such thing. It encrypts the content on the sender machine and only the final receiver can decrypt it (using a previously shared key), so the whole chain of servers involved in mail delivery only see the cipher text. On the bad side it requires both parties to actively use this technique to send/receive the email, a naive email program would not suffice. A Windows implementation could be Gpg4win. No idea how easy or difficult it's to use, though.

The most straighforward way could be to send a normal email with an encrypted attachment containing the private data. TrueCrypt would be the ideal program to create such file (sending the container as an attachment). 7zip and WinRar also similar functions though password protected archives, attaching the 7z/rar file. The problem this approach has is that you must share the key though some other, secure channel for the receiver to decrypt the data. Needless to say that the password must be strong enough to resist a guessing by a potential attacker.


I know once mail is uploaded to Outlook dot com servers or outlook dot com it remains secure

That's not correct. With email, the only thing you can warrant is that the message is encrypted between the sender and the sender's server, while it's in transit, if it uses SSL. But from server to server, and to server to receiver, that's optional, and depends on each server configuration. Moreover, when the email is stored in each intermediate system, it stays there in plain text. That's the main reason why email is so weak, the protocol has not been updated in decades to introduce any kind of security. SSL is only an optional component, and only can be ensured in the initial connection, not in subsequent retransmitions.
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Toshiba Sattelite A665-S6092
OS
Windows 7 Ultimate x64
CPU
Intel Core i7-740QM
Memory
8 GB DDR3
Graphics Card(s)
NVIDIA GeForce 330GT
Screen Resolution
1366x768
Hard Drives
Samsung 840 SSD 500GB
1TB USB3 external HD
Cooling
Coolermaster Notepal U3 notebook cooling pad
Internet Speed
3mbps ASDL
Antivirus
ClamWin 0.98.7
Browser
Opera 12.17 x86 (main), Firefox 38 (sec), IE11 (last resort)
Boy oh boy am I glad I don't have any email worth encrypting. Anybody reading my email would get bored and leave me alone.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Back
Top