FREE Business Solutions For Remote Working

 

In the last month we have seen an increase in demand from clients for hosted desktops. With much of the UK being battered with multiple storms leading to widespread flooding and the increasing threat of the coronavirus impacting our lives, an increasing number of businesses have been dusting off their business continuity plans, that’s if they have one at all. Businesses are realising that their plans are not robust enough and that they need to look at remote working as a real option to ensure their people can continue to work even if they can’t access their normal office location.

Whilst COVID-19 is still at a relatively early stage in the UK, we are seeing the impact that it is having in Europe, America and Asia and the next few weeks will be critical in its management to keep its spread low. It is estimated that 20% of the workforce could be off sick at the virus’ peak, as well as significant numbers of employees being in self-isolation, looking after children during potential school closures or caring for ill relatives. Businesses recognise that doing nothing is no longer an option to ensure that they can continue to operate, albeit with lower capacity.

To help our clients ensure survival of their businesses, here are just a few reasons why a remote desktop solution or a simple Globalnet Connect account could be the remote working solutions your business needs.

Keeping Employees Safe and Well – Employers are under a duty of care to ensure the health, safety and welfare of all its employees. Providing tools to help reduce travel, face-to-face meetings as well as the ability to work in a safe environment can help keep employees productive and safe.

Keeping your Business Running – If any or all of your employees need to self-isolate, provide childcare or are unable to travel they can continue to access their PC from home and continue working.

Limit Financial Impact By providing remote working solutions for your staff, you can minimise any financial impact on both your business and on your employees.

Ease of Access – With a remote desktop solution, employees can work from anywhere with an internet connection and from most devices. Over 95% of employees have access to superfast broadband from home, meaning that even if their desktop or laptop is at the office, they can access all of their applications from home. (Source: Ofcom, Connected Nations Report).

 

Globalnet Connect

*UPDATE* WAS £10pm, now FREE for the duration of the crisis!

Fast Set-up – This is a software based solution that allows your team to connect with their office PCs from their home PCs and can be installed relatively quickly, though the more users you have the longer it will take!

Best for Small Companies or a Fast Fix This is suitable for small businesses with fewer than 20 people or larger companies with only a few employees working from home and needing a an emergency solution.

FREE   Low Cost– With a relatively small set up fee and user licence, this is an affordable solution for small businesses or when only a few employees are away. Larger companies may find our remote hosted desktops more cost effective.

Remote Desktop Server

On-site Server – One solution is an on-site server, which can be remotely accessed by your staff working from home.

Best for Larger Companies – This is suitable for larger companies and is more robust than Globalnet Connect.

Permanent Solution Once installed, the server will function for several years and provides a permanent solution moving into the future.

Cloud Hosted Desktops

*UPDATE* First two months FREE!

Off-site – Hosted desktops together with cloud servers and storage move much of the management of desktop computers and servers into the cloud so that any disruption to business use of IT can be minimised if and when the need arises.

Ease of Access – With a hosted desktop, employees can work from anywhere with an internet connection and from most devices. Over 95% of employees have access to superfast broadband from home, meaning that even if their desktop or laptop is at the office, they can access all of their applications from home. (Source: Ofcom, Connected Nations Report).

Keeping Data Safe – Losing data can have a major impact on businesses, in fact some businesses never recover from a large loss of data. With a Globalnet hosted desktop solution we backup all your server data to an offsite location.

Lower Risk – Moving to a hosted desktop solution reduces the risk of an incident leading to a disaster for your customers. Fires, floods and power failures can mean that customer’s IT systems are completely unusable. With a hosted desktop solution from Globalnet you have peace of mind that you can be back up and running almost immediately should the worst happen.

SPECIAL OFFER

Free Service for 2 months (if you signed up today, we wouldn’t invoice you for the service until June)

Free Set Up

Prioritised Set Up (to get you up and running ASAP)

Free Data Migration

Includes:

  • Windows 8/10 Style Desktop
  • 5GB Personal Storage
  • 10GB Network Storage (per user)
  • Data Backed Up Across Multiple Sites
  • Webroot
  • 24/7 UK Based Support
  • Application Server (min. 3 users)

 

We understand how worrying the recent events are for our customers and we have products that suit any business, whatever size and whatever industry, so that if disaster strikes we’ll be here to get you up and running. Our team of experienced engineers is dedicated to ensuring that our service is reliable, monitored and above all secure.

Call us on 0203 005 9650 today for find out more about remote access, whatever size your business!

Windows 10: Fuelling PC Sales Recovery?

Reports by IDC and Gartner that shows PC sales registering their first quarterly rise in six years have led to some speculation that Windows 10 may be fuelling a Business PC sales recovery.

Over 62 Million Q2 Shipments

According to Q2 figures compared to 2017, market analyst firms IDC and Gartner have both noted 62 million+ PC shipments.

Gartner’s figure of 62.1 million PC shipments represents a 1.4 % rise on last year, while IDC’s figure of 62.3 million PCs shipped represents a 2.7% rise on last year.

Either way, it looks like a small recovery in one segment of a market that many believed had been sent into decline by mobile device use.

Businesses Buying Windows 10 PCs

Most analysts agree that although the consumer side of the PC market has been negatively affected by people turning to their smartphones for even more daily tasks, this latest rise in PC sales is being fuelled by businesses.

Tech and business commentators appear to agree that the rise in PC sales is mainly due to businesses accepting that they need to make the switch to Windows 10, and buying the next office PC with Windows 10 already on it.

Big Brands Increase PC Sales

Not surprisingly, the manufacturers that are selling the most units are the big names i.e. Lenovo and HP, both with around 22% of the market, followed by Dell, Apple, then Acer in fifth place.

Supply Chain Problems Solved

Market analysts also believe that the solving of some of the supply chain problems that held back PC sales this time last year is contributing to the recent rise in sales.

What Does This Mean For Your Business?

While individuals in businesses have their own smartphones, and while some smartphones may be used for business and personal use e.g. in SME’s, many UK businesses still have PCs / desktops in the office that are used purely for business. Since support has stopped for many older versions of Windows, many people have experience of using Windows10, and Microsoft is essentially forcing PC users down the Windows 10 and SaaS route, it is not surprising that many businesses have simply ordered fully equipped Windows 10 PCs as part of the office upgrade.

Although these sales figures do show a small recovery of sorts, the prevailing direction of travel for computing tasks for the future is still in the mobile direction.

Globalnet works with businesses throughout London, Essex, Kent and Herts to ensure their data and networks are secure from all threats. Call us on 0203 005 9650 today to find out how we can provide the right protection for you.

Globalnet aims to be an integral part of your success, providing the best business advice, superior IT support and technology to help you reach your goals. 

Google Chrome New ‘Site Isolation’ Security Feature Activated

The new ‘Site Isolation’ security feature for the Google Chrome browser has been switched on, and could protect users from log-in credentials theft.

Decade-Long History

The newly switched-on feature actually has a decade-long history in the making. It has been reported that Google invested those engineer-years, mostly in the last 6 years, and a lot of money in producing a DiD (defence-in-depth) feature, and what is a now essential defence against a prolific class of attack.

What Does the Google Chrome Site Isolation Do?

It has recently been discovered that all modern chips / processors have security vulnerabilities in them that can contribute to the success of ‘data leakage’ attacks. These vulnerabilities, dubbed Spectre and Meltdown (Meltdown only on Intel chips), can be used by hackers to steal passwords or other confidential data from computers and mobile devices through popular web browsers like Chrome, Internet Explorer, Firefox, and Safari for Macs or iOS.

With Site Isolation enabled, each renderer process contains documents from a maximum of one site which means that all navigations to cross-site documents cause a switch in processes, and all cross-site iframes are put into a different process than their parent frame. This ‘isolation’ of the processes provides effective detection against data leakage attacks like Spectre, which means that the vast majority of Chrome users are now theoretically safer from this one kind of attack. It has also been reported that work is underway to protect against attacks from compromised renderers.

It Does Sap Some Memory

One of the trade-offs that Google has had to make to in order to make this feature effective is greater resource consumption. With Site Isolation on, there is a 10-13% total memory overhead in real workloads due to the larger number of processes. Google is reported to be working on trying to reduce the memory burden.

Even 10-13% is good compared to the 20% memory overhead that was being used when Chrome 63 debuted with Site Isolation.

Not Android Yet – But Soon

Site Isolation is scheduled to be included in Chrome 68 for Android but reports indicate that Google is still working on resource consumption issues before that can be rolled out.

SSL Security Added

Google Chrome has also added security warnings for sites that do not have SSL Certificates, which switch websites from HHTP to HTTPS protocol. The warning alerts users to the fact that any information they enter into the set, such as usernames, passwords or email addresses may not be secure. Furthermore Google is gradually moving to penalise sites in its search engine without HTTPS with lower page rankings.

What Does This Mean For Your Business?

The switching on of this feature is, of course, good news for businesses, as it is an additional, free way to strengthen cyber resilience against a popular kind of attack that could have serious consequences. This is of particular importance when businesses are trying to do everything possible to achieve and maintain compliance with GDPR.

Up until now, all businesses have heard is that all modern processors have security flaws in them, and that software patching is the only real answer. Back in May, another 8 flaws, in addition to Spectre and Meltdown, were discovered in processors, dubbed Spectre Next Generation (Spectre NB). At least the switching-on of this Chrome feature is one tangible step in the journey to patch these vulnerabilities before cyber-criminals manage to exploit them all. Hopefully, more, similar features will be introduced across other browsers in the near future.

Globalnet works with businesses throughout London, Essex, Kent and Herts to ensure their data and networks are secure from all threats. Call us on 0203 005 9650 today to find out how we can provide the right protection for you.

Globalnet aims to be an integral part of your success, providing the best business advice, superior IT support and technology to help you reach your goals. 

Tech Tip – Arrange Multiple File Explorer Windows Easily

If you have multiple File Explorer windows on your screen, the clutter and confusion can get in the way of the task at hand. Here’s the fast and easy way to re-arrange them:

– Right-click the taskbar
– Choose Show windows stacked or Show windows side by side
– That’s it!

Globalnet is a managed servicer provider for a wide range of businesses throughout London, Essex, Kent and Herts. Call us today to find out how we can improve your IT infrastructure and increase productivity.

Globalnet aims to be an integral part of your success, providing the best business advice, superior IT support and technology to help you reach your goals. 

Tech Tip – Open Files With The Right App

Sometimes in Windows, when you double click on a file to open it, e.g. a file that’s been sent to you, the wrong app can open. Here’s how to make sure you select the right app for your file:

– Right-click your file.
– Choose Open with, then Choose another app.
– Make sure the ‘Always use this app’ box is checked before you pick.
– Scroll down to ‘More apps’ if you can’t see the right one at the top of the list.

Globalnet is a managed servicer provider for a wide range of businesses throughout London, Essex, Kent and Herts. Call us on 0203 005 9650 today to find out how we can improve your IT infrastructure and increase productivity.

New ‘No Cheat’ Locked Mode For Classroom on Chromebooks

The Google Forms Quiz in its free, browser-based educational software Classroom now features a locked mode on Chromebooks which prevents students from cheating during quizzes.

What Is Classroom?

Google Classroom is a free web service (app) for schools, non-profits or indeed anyone with a personal Google Account, that aims to simplify creating, distributing and grading assignments in a paperless way. It is reported to be used by over 30 million students globally.

Used in an actual educational setting, it enables teachers to create classes (set up a class online), distribute assignments, communicate, and stay organised, all in one place. Teachers can invite students and co-teachers, and in the class stream, they can then share information, assignments, announcements, and questions. They can also see who has or hasn’t completed the work, and give direct, real-time feedback and grades.

Classroom works with Google Docs, Calendar, Gmail, Drive, and Forms.

What About Chromebooks?

In the context of this story, Chromebooks are laptops that are sold with the sole purpose of being used in the classroom. They run Google’s Chrome OS and are designed to be used while connected to the Internet, with most applications and documents stored in the cloud. Chromebook are available from a range of PC manufacturers.

Cheating?

The problem that many teachers have reported experiencing is that in order to answer questions during Classroom quizzes and tests, some students are tempted to use the Internet connection on Chromebooks to look up the answers (also known as cheating).

Cheat-Proof Feature: Locked Mode

The newly added locked mode feature in the Google Forms Quiz prohibits students from surfing the web or opening apps until the answers are submitted. This is the first feature added to the app that’s exclusive to managed Chromebooks, and as such, it has meant that specialised controls have been added to what was basically a standardised system.

Other Features

Other features that have also been added include the ability to organise by topic or unit in the Classwork page, whereas everything was previously just categorised by date. Also, a new People page lets teachers add and remove fellow teachers, students and guardians. The Stream and system settings pages have also received some small improvements.

What Does This Mean For Your Business?

For educators and trainers who use Chromebooks and Classroom, the locked mode gives them greater control, and allows them to get a more accurate view of the level of knowledge of their students. More accurate measurements can help with the better planning and application of teaching resources, and can highlight areas that need improvement.

For Google, with such a popular system that has made inroads into the teaching / training market, it makes sense to keep their customers loyal and happy by introducing value adding improvements that solve long-running problems.

CALL US ON 0203 005 9650 FOR SUPERIOR IT SUPPORT

Globalnet aims to be an integral part of your success, providing the best business advice, superior IT support and technology to help you reach your goals. 

Bank Uses AI To Screen Job Applicants

A Singapore bank is reported to be using an AI-based system to make savings in the process of recruitment by automating the pre-screening of job applicants.

‘JIM’

The new AI screening platform, Jobs Intelligence Maestro (JIM) has been part of a pilot scheme that has been running at the DBS bank in Singapore since April.

JIM has been developed by Singapore start-up Impress.AI and DBS’ Talent Acquisition team, and has been used to support staff in the sometimes lengthy process of reviewing CVs, collecting responses to pre-screening questions, and conducting psychometric tests.

Savings

The main reason for the development of JIM is to save man-hours, to lighten the workload of the bank’s recruiters, and to enable the recruitment process to fit in more easily with the schedules of candidates who may be busy in normal office hours.

Wealth-Management Planning Roles

The AI system is intended to be used for screening candidates for wealth management planning roles in the bank in its main markets of Hong Kong, China, Taiwan, Indonesia and India. This will enable the bank to meet its target of target 40% growth in staff advising its high net worth customers.

High-Volume Roles

JIM will also be used in other ‘high-volume’ roles within the bank, such as the bank’s management associate and graduate associate programmes, where more than 7,000 candidates can apply for 20 just roles.

What Does This Mean For Your Business?

Up until now, banks have made the news for using AI bots to make savings in the customer service side of the business. Once again, but in a different role, AI is being deployed to essentially make savings in man-hours, and to enable the 24-hour provision of a service.

JIM the AI program is being used in a supporting, time-saving, pre-screening role, and it is in these types of roles that AI is making in-roads into the world of business, and providing cost savings for those companies / organisations that can afford to and need to deploy them to add real value areas of their business e.g. for high-volume, intelligent processing work.

Automation using AI-based systems is likely to be an increasing trend, and back in 2017 the EU even voted to give a Bill of Rights to ‘robots’ that will give them “electronic personhood” status in the eyes of the Law in anticipation of a new kind of industrial robot revolution.

Google Accused of Being Unethical Over Cryptocurrency Ad Ban

Some industry commentators have suggested that Google’s motives for introducing a blanket ban on cryptocurrency ads may not be all they seem, and could make the company appear unethical.

What Ban?

Back in March, Google followed Facebook’s lead (from January) and imposed a blanket ban on all cryptocurrency adverts on its platforms. The ban, which starts from this month, was announced following reports of scammers using adverts on popular platforms to fraudulently take money from people who believed they could cash in on the massive rise in the value of cryptocurrencies such as Bitcoin.

A popular con has been to use scam ad campaigns to sell units of a cryptocurrency ahead of its launch – known as initial coin offerings (ICO). Research has found that 80 per cent of ICOs have been fraudulent.

Also, the cryptocurrency value bubble led to the rise of ‘crypto-jacking’, where devices are taken over by people trying to mine crypto-currencies e.g. using Android phone-wrecking Trojan malware ‘Loapi’.

Why Unethical?

Online tech commentators have been quick to point out that even though Google has said that it made the move to ban cryptocurrency ads to confront criminality, protect web users, and to regulate what their users are reading, Google is also believed to have an interest in cryptocurrencies itself.

For example, back in May, Google is reported to have approached the founder of the world’s second most popular cryptocurrency, Ethereum, to explore possible market opportunities for the two companies. In fact, some commentators believe that Google may be acting unethically by banning cryptocurrency adverts because it is planning to launch its own cryptocurrency and, therefore, wants to give its own product the best chance in the marketplace.

This idea has been strengthened by the fact that Google continues to show adverts with links to gambling websites and other services which some would describe as unethical. It has been suggested that Google appears willing to ban cryptocurrency adverts, but still allows job postings, and adverts for anti-virus software or charities, all of which can also be known entry points for scammers.

Blockchain Ambitions

Google is also thought to have ambitions to make use of blockchain, which is among other things, the underlying technology behind the bitcoin currency. It is interesting that this interest follows Facebook, which is reported to be setting up a blockchain group that will report directly to the company’s CTO, Mike Schroepfer.

Circumvented

Putting a blanket ban on cryptocurrency adverts does not appear to have been an entirely successful strategy for others i.e. Facebook. For example, some advertisers have been able to circumvent Facebook’s cryptocurrency ad ban by abbreviating words like cryptocurrency to c-currency, and by simply switching the letter ‘o’ in the word bitcoin to a zero.

What Does This Mean For Your Business?

Google is a powerful private company, and with other big players in the market, it is looking to make the most of market opportunities e.g. Facebook, and it is only natural that Google is likely to also want to explore the potential of those opportunities, even if it has made an ethical stand in public about cryptocurrency adverts.

This story does illustrate, however, that ethics play an important part in business, and can play an important role in supporting the value of a brand, particularly in a digital world where inconsistencies can be spotted and widely reported immediately.
When you think about it, Google has a trusted brand and is well placed in the market to perhaps get involved in, or even produce its own cryptocurrency, particularly where there are profits to be made and when cryptocurrencies appear to have an important future beyond the initial bubble of bitcoin-mania. The important thing for Google is that it, along with Facebook, was seen to be doing the right thing when cryptocurrency scam adverts began making the news, and there is still no real, firm proof that Google will commit itself to its own cryptocurrency yet.

It is also not surprising that companies such as Google and Facebook would want to explore the huge potential opportunities that blockchain offers. It is worth remembering that blockchain has shown itself to have many great uses beyond just cryptocurrecies e.g. enabling students to share their qualifications with employers, recording the temperature of sensitive medicines being transported from manufacturer to hospital in hot climates, as a ledger to record data about wine certification, as a ledger for ownership and storage history, as a system for tracking consignments that addresses visibility and efficiency, and for sharing information between energy suppliers to speed the supplier switching process. Dubai has also invested in using blockchain to put all its documents on blockchain’s shared open database system by 2020 in order to help to cut through Middle Eastern bureaucracy, speed up civic transactions and processes, and bring a positive transformation to the whole region.

Both cryptocurrencies and blockchain have a long way to run yet, and Google and Facebook will certainly not be the only web giants exploring their potential.

CALL US ON 0203 005 9650 FOR SUPERIOR IT SUPPORT

Globalnet aims to be an integral part of your success, providing the best business advice, superior IT support and technology to help you reach your goals. 

Police Facial Recognition Software Flawed

Following an investigation by campaign group Big Brother Watch, the UK’s Information Commissioner, Elizabeth Denham, has said that the Police could face legal action if concerns over accuracy and privacy with facial recognition systems are not addressed.

Which Facial Recognition Systems?

A freedom of information request sent to every police force in the UK by Big Brother Watch shows that The Metropolitan Police used facial recognition at the Notting Hill carnival in 2016 and 2017, and at a Remembrance Sunday event, and South Wales Police used facial recognition technology between May 2017 and March 2018. Leicestershire Police also tested facial recognition in 2015.

What’s The Problem?

The two main concerns with the system (as identified by Big Brother Watch and the ICO) are that the facial recognition systems are not accurate in identifying the real criminals or suspects, and that the images of innocent people are being stored on ‘watch’ lists for up to a month, and this could potentially lead to false accusations or arrests.

How Do Facial Recognition Systems Work?

Facial recognition software typically works by using a scanned image of a person’s face (from the existing stock of police photos of mug shots from previous arrests), and then uses algorithms to measure ‘landmarks’ on the face e.g. the position of features and the shape of the eyes, nose and cheekbones. This data is used to make a digital template of a person’s face, which is then converted into a unique code.

High-powered cameras are then used to scan crowds. The cameras link to specialist software that can compare the camera image data to data stored in the police database (the digital template) to find a potential ‘match’. Possible matches are then flagged to officers, and these lists of possible matches are stored in the system for up to 30 days.

A real-time automated facial recognition (AFR) system, like the one the police use at events, incorporates facial recognition and ‘slow time’ static face search.

cctv, facial recognition
Big Brother may be watching, but the facial recognition doesn’t work
Inaccuracies

The systems used by the police so far have been criticised for simply not being accurate. For example, of the 2,685 “matches” made by the system used by South Wales Police between May 2017 and March 2018, 2,451 were false alarms.

Keeping Photos of Innocent People On Watch Lists

Big Brother Watch has been critical of the police keeping photos of innocent people that have ended up on lists of (false) possible matches, as selected by the software. Big Brother Watch has expressed concern that this could affect an individual’s right to a private life and freedom of expression, and could result in damaging false accusations and / or arrests.
The police have said that they don’t consider the ‘possible’ face selections as false positive matches because additional checks and balances are applied to them to confirm identification following system alerts.

The police have also stated that all alerts against watch lists are deleted after 30 days, and faces in the video stream that do not generate an alert are deleted immediately.

Criticisms

As well as accusations of inaccuracy and possibly infringing the rights of innocent people, the use of facial recognition systems by the police has also attracted criticism for not appearing to have a clear legal basis, oversight or governmental strategy, and for not delivering value for money in terms of the number of arrests made vs the cost of the systems.

What Does This Mean For Your Business?

It is worrying that there are clearly substantial inaccuracies in facial recognition systems, and that the images of innocent people could be sitting on police watch lists for some time, and could potentially result in wrongful arrests. The argument that ‘if you’ve done nothing wrong, you have nothing to fear’ simply doesn’t stand up if police are being given cold, hard computer information to say that a person is a suspect and should be questioned / arrested, no matter what the circumstances. That argument is also an abdication from a shared responsibility, which could lead to the green light being given to the erosion of rights without questions being asked. As people in many other countries would testify, rights relating to freedom and privacy should be valued, and when these rights are gone, it’s very difficult to get them back again.

The storing of facial images on computer systems is also a matter for security, particularly since they are regarded as ‘personal data’ under the new GDPR which comes into force this month.

There is, of course, an upside to the police being able to use these systems if it leads to the faster arrest of genuine criminals, and makes the country safer for all.

Despite the findings of a study from YouGov / GMX (August 2016) that showed that UK people still have a number of trust concerns about the use of biometrics for security, biometrics represents a good opportunity for businesses to stay one step ahead of cyber-criminals. Biometric authentication / verification systems are thought to be far more secure than password-based systems, which is the reason why banks and credit companies are now using them.

Facial recognition systems have value-adding, real-life business applications too. For example, last year, a ride-hailing service called Careem (similar to Uber but operating in more than fifty cities in the Middle East and North Africa) announced that it was adding facial recognition software to its driver app to help with customer safety.

 

Globalnet IT Innovations offer a range of managed IT services and on-demand IT services. Call us on 0203 005 9650 to speak to one of our IT consultants and discover how we can help you reach your business goals.

PGP Encryption Flaw Discovered in Email Security

A German newspaper has released details of a security vulnerability, discovered by researchers at Munster University of Applied Sciences, in PGP (Pretty Good Privacy) data encryption.

What Is PGP?

PGP (Pretty Good Privacy) is an encryption program that is used for signing, encrypting, and decrypting texts, e-mails, files, directories, and disk partitions, and to increase the security of e-mail communications. As well as being used to encrypt and decrypt email, PGP is also used to sign messages so that the receiver can verify both the identity of the sender and the integrity of the content. PGP works using a private key that is kept secret, and a public key that the sender and receiver share.

The technology is also known by the name of GPG (Gnu Privacy Guard or GnuPG), and is a compatible GPL-licensed alternative.

PGP, email encryption flaw
PGP encryption flaw found
What’s The Flaw?

The flaw, which was first thought by some security experts to affected the core protocol of PGP (which would make all uses of the encryption method, including file encryption, vulnerable), is now believed to be related to any email programs that don’t check for decryption errors properly before following links in emails that include HTML code i.e. email programs that have been designed without appropriate safeguards.

‘Efail’ Attacks

The flaw leaves this system of encryption open to what have been called ‘efail’ attacks. This involves attackers trying to gain access to encrypted emails (for example by eavesdropping on network traffic), and compromising email accounts, email servers, backup systems or client computers. The idea is to reveal the plaintext of encrypted emails (in the OpenPGP and S/MIME standards).

This type of attack can be carried out by direct exfiltration, where vulnerabilities in Apple Mail, iOS Mail and Mozilla Thunderbird can be abused to directly exfiltrate the plaintext of encrypted emails, or by a CBC/CFB gadget. This is where vulnerabilities in the specification of OpenPGP and S/MIME are abused to exfiltrate the plaintext.

What Could Happen?

The main fear appears to be that the vulnerabilities could be used to decrypt stored, encrypted emails that have been sent in the past (if an attacker can gain access). It is thought that the vulnerabilities could also create a channel for sneaking personal data or commercial data and business secrets off devices as well as for decrypting messages.

What Does This Mean For Your Business?

It is frustrating for businesses to learn that the email programs they may be using, and a method of encryption, supposed to make things more secure, could actually be providin a route for criminals to steal data and secrets.

The advice from those familiar with the details of the flaw is that users of PGP email can disable HTML in their mail programs, thereby keeping them safe from attacks based on this particular vulnerability. Also, users can choose to decrypt emails with PGP decryption tools that are separate from email programs.

More detailed information and advice concerning the flaw can be found here: https://efail.de/#i-have

Globalnet IT Innovations offer a range of managed IT services and on-demand IT services, including secure Outlook 365 email. Call us on 0203 005 9650 to speak to one of our IT consultants and discover how we can help you reach your business goals.