Your Emails Are Not Secure! (And What You Can Do About It)

  Рет қаралды 5,034

Pro Tech Show

Pro Tech Show

Күн бұрын

Пікірлер: 27
@ProTechShow
@ProTechShow 4 жыл бұрын
Another way to secure your emails is to make sure they can't be spoofed: kzbin.info/www/bejne/iKWno4Kpndl5n6s
@andrew.schaeffer4032
@andrew.schaeffer4032 2 жыл бұрын
love the video - explaining concepts in plain english. I've read Google's instructions on setting up MTA-STS and wish you had written them XD
@ProTechShow
@ProTechShow 2 жыл бұрын
Haha! Cheers 🙂
@kumarnair143
@kumarnair143 Жыл бұрын
Good One.. very easy to Understand. Thank you :)
@ProTechShow
@ProTechShow Жыл бұрын
Thanks
@rajashahbaz3441
@rajashahbaz3441 3 жыл бұрын
Thank you for sharing this knowledge. Please make a video on E2E encryption.
@ProTechShow
@ProTechShow 3 жыл бұрын
I'll add it to the ideas list, thanks!
@talasilajayanth
@talasilajayanth 4 жыл бұрын
Love watching all your videos
@ProTechShow
@ProTechShow 4 жыл бұрын
Thanks 🙂
@blastedoak42
@blastedoak42 2 жыл бұрын
Really interesting. Thanks.
@ProTechShow
@ProTechShow 2 жыл бұрын
You're welcome 🙂
@arbilus5296
@arbilus5296 2 жыл бұрын
Hello, do we need to use Mta Sts if we configure connectors to use the "RequireTLS" option, please ? (I'm speaking about Exchange Server)
@ProTechShow
@ProTechShow 2 жыл бұрын
You don't have to use MTA-STS, but it is another security improvement you can add to your list.
@arbilus5296
@arbilus5296 2 жыл бұрын
@Pro Trch Show thanks for the answer. Then I don't understand what's the difference between activating the "RequireTls" option and using MTA STS. If RequireTLS ensure the use of TLS and not StartTLS then there is no issue with possible MITM attacks which could remove the 250 STARTTLS and then MTA STS is useless, no ?
@ProTechShow
@ProTechShow 2 жыл бұрын
@@arbilus5296 enforcing TLS on your receive connector won't prevent MitM because the sender only becomes aware of your enforcement once they've connected to your server. If someone positions themselves in the middle they can offer plaintext to the sender and that's all they will see. Your RequireTLS setting only forces the attacker to connect securely to you if they want to pass the message on. If you had MTA-STS set up then the sender could see your policy to require authenticated TLS before they attempted a connection and would refuse to use the MitM service that didn't match your MTA-STS policy.
@mohadesefakharnezhad6228
@mohadesefakharnezhad6228 2 жыл бұрын
Be aware of the risks and choose trusted communication and data apps. I communicate in the Utopia ecosystem (uMail) and I am not afraid that my personal data will get to third parties.
@shaikimran3196
@shaikimran3196 4 жыл бұрын
What's a certificate? I heard about it with website, servers, apps or programs etc I am aware that you made video about ssl cert but what is a certificate basically. Is it a file or some sort of verification. How many kinds of them are there (including certs used for apps and so onn)
@ProTechShow
@ProTechShow 4 жыл бұрын
It's a topic by itself to cover encryption and digital signatures, but... Usually, they're stored as files or a registry value - but data either way. They can be used for many purposes, but generally speaking they provide proof of identity, proof data hasn't been changed, and a key that can be used to send encrypted data to the owner of the certificate. For a website you'd use it to prove the identity of the website and to encrypt your connection to it. With software you'd use it to prove the author of the software and that it hasn't been tampered with. With email you'd use it to encrypt an email and/or prove the identify of the sender.
@shaikimran3196
@shaikimran3196 4 жыл бұрын
@@ProTechShow thank you❤️
@harrytrueman4216
@harrytrueman4216 4 жыл бұрын
Is email decreasing with the rise of teams and slack and do they use end to end encryption. What's your thoughts tech companies forcing parler out? A case for on prem?
@ProTechShow
@ProTechShow 4 жыл бұрын
Many a person has declared email dead over the years, but so far its use grows year-on-year. I'll believe it when I see it! Instant messaging serves a different use case, so I think we'll see both continue. The other big difference is that email is completely interoperable and has no vendor lock-in. I can move my mailbox from Microsoft to Google and it'll keep working and keep communicating with anyone on any platform. If you try to do the same Teams to Slack then keeping your data intact will be a nightmare and you can't talk to anyone on a different service (with some exceptions).
@ProTechShow
@ProTechShow 4 жыл бұрын
TBH I haven't been following the Parler stuff very closely. My biggest surprise is that people are surprised. If you use someone else's platform you play by their rules. There are plenty of other places to go... whether on-prem or cloud. I don't think it'll bother most companies as they're not likely to cause AWS a PR headache. If going full cloud it's not a bad idea to have a backout plan just in case, though. This scenario might not be likely to affect the average person, but what if AWS cranked the price up significantly? It's always useful to have a plan B so no one vendor can bend you over a barrel.
@stacyhackney6100
@stacyhackney6100 3 жыл бұрын
Thank you
@ProTechShow
@ProTechShow 3 жыл бұрын
You're welcome
@salvatore_gareggio
@salvatore_gareggio 4 жыл бұрын
Ciao ti scrivo dall'Italia. Ho guardato il video ed è molto interessante. Purtroppo il problema della crittografia della posta elettronica è annoso. In Italia esiste però un' alternativa, si chiama PEC ovvero posta elettronica certificata ed è soggetta a rigorosi controlli ed ha garanzia legale. Però entrambe le caselle devono essere 'certificate' . Conosci questo tipo di posta elettronica? 🙂
@ProTechShow
@ProTechShow 4 жыл бұрын
Hello. Interesting. I haven't come across that over here yet. I suspect interoperability would be a barrier to adoption. Technologies like MTA-STS and TLS are backwards compatible with traditional email, whereas it sounds like PEC only talks to PEC and there are a limited number of approved providers to choose from. Is it being promoted by the Italian government? It feels like something that would need to achieve a certain critical mass before people would be likely to use it over here.
@salvatore_gareggio
@salvatore_gareggio 4 жыл бұрын
@@ProTechShow Si è giusto. Per poter funzionare entrambe le caselle devono essere 'PEC". Tuttavia tieni presente che gli standard di sicurezza sono elevati di conseguenza garantiscono che il messaggio sia inalterabile, protetto ed arrivi con certezza nella casella di destinazione perché i provider invia due ricevute di accettazione ed avvenuta consegna. Lo so che fuori dall'Italia non esiste questa cosa ma se tutti la adottassero saremmo più sicuri da occhi indiscreti.
Is Proton Mail Really Private, Secure, and Anonymous?
15:05
Mental Outlaw
Рет қаралды 281 М.
How to Prevent Email Spoofing with DKIM, DMARC & SPF
11:41
Pro Tech Show
Рет қаралды 25 М.
Support each other🤝
00:31
ISSEI / いっせい
Рет қаралды 81 МЛН
Гениальное изобретение из обычного стаканчика!
00:31
Лютая физика | Олимпиадная физика
Рет қаралды 4,8 МЛН
More Useful Tools for IT Pros
16:17
Pro Tech Show
Рет қаралды 7 М.
How to Protect Your Devices from Hackers
13:36
Pro Tech Show
Рет қаралды 21 М.
Why VPNs are a WASTE of Your Money (usually…)
14:40
Cyberspatial
Рет қаралды 1,5 МЛН
5 Dangerous Things to Avoid Saying In a Job Interview
12:57
Don Georgevich
Рет қаралды 7 МЛН
You Should Learn PowerShell
13:18
Pro Tech Show
Рет қаралды 28 М.
Cybersecurity Architecture: Five Principles to Follow (and One to Avoid)
17:34
Kevin Mitnick Email Interception Demonstration
6:40
Zix
Рет қаралды 74 М.
Do This Before Selling Your Computer
13:14
Pro Tech Show
Рет қаралды 46 М.
QUITTING GMAIL -  alternatives for email, calendar, contacts
7:49
The Linux Experiment
Рет қаралды 517 М.
Support each other🤝
00:31
ISSEI / いっせい
Рет қаралды 81 МЛН