Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - DNC Email, Email Encryption Comments/Background
News & Analysis

DNC Email, Email Encryption Comments/Background

ISBuzz TeamBy ISBuzz TeamJuly 27, 2016Updated:December 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Security experts from VASCO Data Security, STEALTHbits Technologies, Lastline and InfoArmor provide their insight on DNC email and email Encryption below.

John Gunn, VP of Communications at VASCO Data Security:

“Encryption iJohn-Gunns simple to use, inexpensive, and highly effective. It doesn’t guarantee the hackers could not have obtained the information, but it certainly would have made their job a lot more difficult. This issue again underscores that there is a significant shortage of qualified IT security professionals – this

event is just more evidence of the problem. Political campaigns are not known for paying well or for providing long-term employment. They should have hired outside consultants, but buying was airtime likely the priority. (Re emails sent to known associates) The old “if someone is respected they can’t be hacked and have no personal motives” strategy: obviously, it is utter nonsense.

“With Public Key Encryption (PKI), the email message is encrypted with the sender’s key, so it is actually integrated into the data that is sent along with the contents of the email.  There are multiple ways to obtain information in emails. The primary methods are: intercepting the email in transit, accessing the data files on an email server, and simply logging in as the sender or the recipient. The highest level of security uses public-key infrastructure (PKI) encryption, but this involves exchanging keys and is not easy for most individuals. This process is automated by use of gateway appliances in government and private enterprises where security is important. There are many commercial solutions that do exactly what was needed to protect these leaked emails – it just takes a pro and some dough.”

Brad Bussie, Director of Product Management at STEALTHbits Technologies:

Brad-Bussie

“The technology to encrypt emails is well known, but not commonly implemented. The main reason for this is complexity and infrastructure cost. Most weight the value of the information that is transmitted against what it would cost to protect it. If the protection cost outweighs the value of the information then most do nothing and let operations continue as normal.”

(Re Sec. Clinton comment that messages were sent to a relatively few, highly respected and trusted professionals who would not have shared such information)

“The reason that this is not a secure approach is that Sec. Clinton was not using a messaging service that would have guaranteed the recipient of her email was indeed the intended party. A person being “highly respected and trusted” does not immediately grant them cyber security skills. It is unknown if any of the recipients systems may be compromised or if others outside of the user have access to the system or account used to access the information. Closed and secured networks are created for a reason and the open nature of the internet has made sensitive and privileged information unfit for general devices.

“There are services that represent a true encrypted approach by offering end to end encryption. The method involves the sender logging into an encrypted service, created the message and then sending it. The recipient then visits the same service, logs in, and then is able to obtain the message. Not even the provider of the service has the private key to unencrypt data, making the sender and receiver the only two that can get the information. Keep in mind, once messages have been opened, the basic threats users expose themselves to are still in play (leaving a device unattended, copying or printing the email, or an attacker socially engineering personal information from the user).”

Giovanni Vigna, Ph.D, Co-founder and CTO at Lastline:

giovanni-vigna“Using encrypted email would have helped. Encryption adds another layer of protection, which requires an attacker to obtain the encryption keys of a user in order to decrypt the messages. However, if a nation-state is involved, it is not unthinkable that a compromise might include access to the secret key of the email recipient(s).

“People do not use encryption because it requires additional tools and procedures. For example, the handling of keys is often too complex a task for many non-tech-savvy users.

(Re Sec. Clinton comment that messages were sent to a relatively few, highly respected and trusted professionals who would not have shared such information)  “Information flow control in such a large group is a daunting task, and probably not feasible. Security is as strong as the weakest link. If a message is sent to 300 people, the security around the handling of that message is determined by the person with the worst security setup.”

John Marshall, Sales Engineering Director at Lastline:

“The DNC incident highlights a couple of realities of e-mail that organizations need to reflect in how they think about security:

  1.       You cannot pre-emptively stop anyone sending you an e-mail. That is why email-based phishing attacks remains a significant exposure
  1.       E-Mail encryption is very limited in terms of being able to work across organizations or different mail systems
  1.       Ongoing use of personal archives means that e-mail content is exposed to an infiltrator without them needing to gain access to the email system

The use of web-based email that requires two-factor authentication does help in terms of encrypting access but the usability and functional differences these have to corporate mail systems will lead users to prefer to use those, which typically rules encryption out.”

Byron Rashed, Senior Director of Marketing at InfoArmor:

Byron Rashed

“When dealing with sensitive information through email, it should always be encrypted. It is imperative that organizations – especially any political or government agency – encrypt emails due to the high level of cyber espionage, hacktivism and state sponsored infiltration. As we know, security is an inconvenience and there is a surprisingly number of organizations that are lacking data and network security. Still today, many think that a “firewall” is sufficient, and of course it’s not.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}