We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Emailing sensitive documents: Is it worth sending encrypted?

Options
2»

Comments

  • colin79666
    colin79666 Posts: 1,356 Forumite
    Part of the Furniture 1,000 Posts
    edited 2 April 2014 at 6:10PM
    I work for a company that requests this kind of information. What we do is send the customer a link to a website where they can securely upload the documents and "email" it back to us. That way we provide the customer with a simple means of avoiding emailing copies of their documents in the clear.

    If we are exchanging a lot of email with a particular domain (e.g. customerdomain.co.uk) then we speak to their IT department and see if we can enforce TLS encryption. Failing that we can fall back to the method outlined above.

    Your mortgage broker should be doing the same, in this day and age they really ought not to be asking for customers to send documents in an insecure manor, even if the risk of interception is small.

    Zip password protection is next to useless if you use the standard method. Provided you use AES 256bit which both 7-Zip (free) and WinZip supports then this is as good as any other method. Just use a good password and communicate it by another channel (text message or phone call). If their system blocks Zip you can usually get around it by renaming the file to example.abc and getting them to change it back to example.zip once they have downloaded the attachment.
  • paddyrg
    paddyrg Posts: 13,543 Forumite
    But yes, OP, email by default is completely insecure and hops from server to server via a path you don't control or predict upfront, and can very easily be archived along the way.

    However you can mitigate somewhat if you are sending from (say) gmail to gmail as the gmail web client is all https, their internal network is not public facing, and if the other person uses the gmail web client then only three world's biggest ad broker and security agencies will be reading your mail.
  • mattb5906
    mattb5906 Posts: 6 Forumite
    Thanks all for your input. Good information.
    In the end I sent the documents in bulk as encrypted PDFs. I've been told that if the broker has to send information on, it is sent via a secured web service controled by the 3rd party (e.g. the bank) or sent by snail mail.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 350.8K Banking & Borrowing
  • 253.1K Reduce Debt & Boost Income
  • 453.5K Spending & Discounts
  • 243.8K Work, Benefits & Business
  • 598.7K Mortgages, Homes & Bills
  • 176.8K Life & Family
  • 257.1K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.