Godai Group reports on huge sensitive information leakages due to incorrect addressing of ordinary e-mails.
“The intercepted correspondence included employee usernames and passwords, sensitive security information about the configuration of corporate network architecture that would be useful to hackers, affidavits and other documents related to litigation in which the companies were embroiled, and trade secrets, such as contracts for business transactions.”
The Wired.com has interview the two researchers who set up doppelganger domains to mimic legitimate domains belonging to Fortune 500 companies say they managed to vacuum up 20 gigabytes of misaddressed e-mail over six months. Kim and colleague Garrett Gee, who released a paper this week (.pdf) discussing their research, found that 30 percent, or 151, of Fortune 500 companies were potentially vulnerable to having e-mail intercepted by such schemes, including top companies in consumer products, technology, banking, internet communication, media, aerospace, defense, and computer security.
http://www.wired.com/images_blogs/threatlevel/2011/09/Doppelganger.Domains.pdf
The problem of incorrect addressing of e-mails, causing information leakages may be both domain centric and unsystematic.
The doppelganger method visualizes the top of the iceberg, as a domain centric and more efficient arrangement of getting others information than previously is documented. But this arrangement signals also that the unsystematic problem of incorrectly sent e-mails to any recipient may be even larger than previously acknowledged. The reason is that ordinary e-mail applications neither help users to understand risks nor addressing e-mail recipients correctly. This is especially due to the use of cached e-mail addresses combined with the use of acronyms in e-mail addresses that ordinary e-mail systems natively supports.
Protectoria offers user-friendly and powerful features to prevent sensitive information in e-mails from leaking into wrong hands.
Protectoria user’s has support from both the Extended Addressing Dialogue and the Policy filter which detects and helps from sending sensitive information to incorrect recipients. Furthermore, any recipient has to be addressed by the combination of the e-mail address and mobile phone number, before a Protectoria protected message actually can be sent.
