BMW X3 Forum
BMW X3 Forum
Welcome to the ultimate G45 BMW X3 community.
BMW Garage BMW Meets Register Today's Posts
Post Reply
 
Thread Tools Search this Thread
      08-27-2024, 11:39 AM   #45
reallymarkedup
First Lieutenant
762
Rep
304
Posts

Drives: 2021 M2C
Join Date: Aug 2024
Location: CO

iTrader: (1)

Quote:
Originally Posted by zx10guy View Post
I was told to email those documents to them. I was stunned. I said to her that you know sending sensitive documents via email is a huge security risk. She said that's the only way they can receive documents. I asked if they have a fax number. No.
Email is incredibly secure, the primary security risk inherent to sending an email is sending something to the wrong address. The easiest way to mitigate that is to have the third party send you an email you can respond directly to.

If you want an extra layer of security save your documents as a PDF and secure that with a password. If you want even more, secure the PDF with a password and then upload it to a protected server with 2fa requirements so that the receiving party has to log in, download the document, and then still enter their password. But really all of that is theater at that point, you would have been fine just sending the email.

None of the security breaches that have occurred were because of someone hacking an SMTP server. They were all stupidity on the part of the organization we blindly trusted to protect that data.
Appreciate 1
vreihen1623394.50
      08-27-2024, 11:45 AM   #46
zx10guy
Brigadier General
5642
Rep
3,270
Posts

Drives: 2013 135i
Join Date: Feb 2014
Location: DC

iTrader: (0)

Quote:
Originally Posted by reallymarkedup View Post
Email is incredibly secure, the primary security risk inherent to sending an email is sending something to the wrong address. The easiest way to mitigate that is to have the third party send you an email you can respond directly to.

If you want an extra layer of security save your documents as a PDF and secure that with a password. If you want even more, secure the PDF with a password and then upload it to a protected server with 2fa requirements so that the receiving party has to log in, download the document, and then still enter their password. But really all of that is theater at that point, you would have been fine just sending the email.

None of the security breaches that have occurred were because of someone hacking an SMTP server. They were all stupidity on the part of the organization we blindly trusted to protect that data.
That's a big negative. Email flows through servers and can traverse different servers before arriving to its ultimate destination. Even financial institutions tell people to never send anything over email with sensitive personal information. For my day to day work we are not allowed to send email with sensitive information outside of the organization without first encrypting it with tools such as PGP.

What you don't understand with this state agency is there is no method of doing pseudo two factor authentication. It goes into one general email bin and gets processed from there. Me sending something password locked/encrypted and then following up with an email with the password does nothing in this case. At a minimum my state should have half a brain to set up a secure "drop box" for me to upload my documents which most financial agencies I've worked with now do.
__________________
Quote:
Originally Posted by Lups View Post
We might not be in an agreement on Trump, but I'll be the first penis chaser here to say I'll rather take it up in the ass than to argue with you on this.
Appreciate 4
JeffL01978.00
BMWGUYinCO4462.50
vreihen1623394.50
David701731.50
      08-27-2024, 12:04 PM   #47
reallymarkedup
First Lieutenant
762
Rep
304
Posts

Drives: 2021 M2C
Join Date: Aug 2024
Location: CO

iTrader: (1)

Okay. Well carry on then.
Appreciate 0
      08-27-2024, 12:35 PM   #48
JeffL0
Private
JeffL0's Avatar
United_States
1978
Rep
93
Posts

Drives: '25 X5 50e
Join Date: Apr 2024
Location: Music City

iTrader: (0)

Quote:
Originally Posted by zx10guy View Post
That's a big negative. Email flows through servers and can traverse different servers before arriving to its ultimate destination.
This. SMTP was never intended to be secure, the protocol was implemented before anyone knew how to spell security.

The above mention of encrypting files before sending is the bare minimum, the further suggesting of uploading to a secure sever rather than sending via email is another good measure. Where people often fail in this encryption attempt is they then send the password over the same insecure channel. Better to convey the password over a different/independent method, such as a voice call.
Appreciate 2
zx10guy5642.00
vreihen1623394.50
      08-27-2024, 09:37 PM   #49
M_Six
Free Thinker
M_Six's Avatar
United_States
20217
Rep
7,564
Posts

Drives: 2016 MB GLC300 4matic
Join Date: Jan 2009
Location: Foothills of Mt Level

iTrader: (0)

Quote:
Originally Posted by vreihen16 View Post
The latest breach was of a company that did background searches for employers, and somehow they had a private copy of every single SS# ever issued that was stolen.

The news is full of "how to know if your info was stolen" clickbait articles. Rather than read the article, assume that it has been stolen if any digit in your SS# is in the range of 0-9.....
Up until the Age of the Internet, Massachusetts used your SSN for your driver's license number. It was printed right there on your license. Imagine losing such a license today? Full name, DOB, SSN, address, all on one card.
__________________
Mark
markj.pics

"Life is uncertain, eat bacon now."
-UncleWede
Appreciate 1
vreihen1623394.50
      08-28-2024, 07:00 AM   #50
vreihen16
Recovering Perfectionist
vreihen16's Avatar
23395
Rep
1,043
Posts

Drives: BMW-less :(
Join Date: Jun 2019
Location: Orange County, NY

iTrader: (0)

Garage List
Quote:
Originally Posted by M_Six View Post
Up until the Age of the Internet, Massachusetts used your SSN for your driver's license number. It was printed right there on your license. Imagine losing such a license today? Full name, DOB, SSN, address, all on one card.
Funny thing is that NY State used a 17-character driver's license number until converting to a 9-digit number in the 1990's. I still remember mine, because I had to write all 17 characters on racing registration forms every weekend.....
__________________
Currently BMW-less.
Appreciate 2
cmyx6go17133.00
M_Six20216.50
Post Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



All times are GMT -5. The time now is 03:16 PM.




x3:
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, vBulletin Solutions Inc.
1Addicts.com, BIMMERPOST.com, E90Post.com, F30Post.com, M3Post.com, ZPost.com, 5Post.com, 6Post.com, 7Post.com, XBimmers.com logo and trademark are properties of BIMMERPOST