<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: What's the most convenient way to send confidential information securely?</title>
	<link>http://ask.metafilter.com/224508/Whats-the-most-convenient-way-to-send-confidential-information-securely/</link>
	<description>Comments on Ask MetaFilter post What's the most convenient way to send confidential information securely?</description>
	<pubDate>Fri, 14 Sep 2012 12:00:03 -0800</pubDate>
	<lastBuildDate>Fri, 14 Sep 2012 12:05:03 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Question: What&apos;s the most convenient way to send confidential information securely?</title>
		<link>http://ask.metafilter.com/224508/Whats-the-most-convenient-way-to-send-confidential-information-securely</link>	
		<description>How can I electronically send confidential/private information to other people as conveniently but securely as possible? &lt;br /&gt;&lt;br /&gt; How can I securely send sensitive information like a credit card number, tax documents, medical records, software code, etc. to other people as simply and conveniently (for both parties) as possible?&lt;br&gt;
&lt;br&gt;
Dropbox?&lt;br&gt;
&lt;br&gt;
Google Docs?&lt;br&gt;
&lt;br&gt;
Encyrpted ZIP file? (How can I get the password to them securely if I can&apos;t call, fax, or see them in person)?&lt;br&gt;
&lt;br&gt;
I&apos;ve tried PGP but it&apos;s complicated and burdensome.&lt;br&gt;
&lt;br&gt;
Thanks.</description>
		<guid isPermaLink="false">post:ask.metafilter.com,2012:site.224508</guid>
		<pubDate>Fri, 14 Sep 2012 12:00:03 -0800</pubDate>
		<dc:creator>Dansaman</dc:creator>
		
			<category>encryption</category>
		
			<category>security</category>
		
	</item>
	<item>
		<title>By: InsanePenguin</title>
		<link>http://ask.metafilter.com/224508/Whats-the-most-convenient-way-to-send-confidential-information-securely#3246998</link>	
		<description>&lt;a href=&quot;http://www.bgr.com/2012/08/01/dropbox-security-breach-stolen-passwords-internet/&quot;&gt;Not DropBox.&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
A quick Google search reveals &lt;a href=&quot;http://www.wuala.com/&quot;&gt;Wuala&lt;/a&gt;, a free (for 5GBs,) encrypting alternative to Dropbox.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2012:site.224508-3246998</guid>
		<pubDate>Fri, 14 Sep 2012 12:05:03 -0800</pubDate>
		<dc:creator>InsanePenguin</dc:creator>
	</item><item>
		<title>By: hattifattener</title>
		<link>http://ask.metafilter.com/224508/Whats-the-most-convenient-way-to-send-confidential-information-securely#3247005</link>	
		<description>How are you contacting these people in the first place? How do you know who they are? How is it that you could give them access to a shared folder somewhere but can&apos;t give them a password?</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2012:site.224508-3247005</guid>
		<pubDate>Fri, 14 Sep 2012 12:08:51 -0800</pubDate>
		<dc:creator>hattifattener</dc:creator>
	</item><item>
		<title>By: saeculorum</title>
		<link>http://ask.metafilter.com/224508/Whats-the-most-convenient-way-to-send-confidential-information-securely#3247009</link>	
		<description>Are you doing this in a professional role? If so, you should know that handling things like medical records and credit card details have very strict regulations (HIPPA for medical records, credit card companies have their own regulations) that are not easily handled by an amateur. In particular, the methods you&apos;ve mentioned would not suffice and could conceivably get you prosecuted.&lt;br&gt;
&lt;br&gt;
I&apos;d have to ask what it is you are trying to do here.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2012:site.224508-3247009</guid>
		<pubDate>Fri, 14 Sep 2012 12:11:09 -0800</pubDate>
		<dc:creator>saeculorum</dc:creator>
	</item><item>
		<title>By: Nonsteroidal Anti-Inflammatory Drug</title>
		<link>http://ask.metafilter.com/224508/Whats-the-most-convenient-way-to-send-confidential-information-securely#3247016</link>	
		<description>&lt;em&gt;I&apos;ve tried PGP but it&apos;s complicated and burdensome.&lt;/em&gt;&lt;br&gt;
&lt;br&gt;
Can you expound on that? PGP (or &lt;a href=&quot;http://en.wikipedia.org/wiki/GNU_Privacy_Guard&quot;&gt;GPG&lt;/a&gt;) is the way to go for an email based solution. &lt;a href=&quot;http://www.enigmail.net/home/index.php&quot;&gt;Engimail&lt;/a&gt; is a plug-in for the freely available &lt;a href=&quot;http://www.mozilla.org/en-US/thunderbird/&quot;&gt;Thunderbird email client&lt;/a&gt;.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2012:site.224508-3247016</guid>
		<pubDate>Fri, 14 Sep 2012 12:18:39 -0800</pubDate>
		<dc:creator>Nonsteroidal Anti-Inflammatory Drug</dc:creator>
	</item><item>
		<title>By: yoyo_nyc</title>
		<link>http://ask.metafilter.com/224508/Whats-the-most-convenient-way-to-send-confidential-information-securely#3247017</link>	
		<description>Well GPG. If this is to &quot;complicated and burdensome&quot; a small, encrypted&lt;a href=&quot;http://www.google.de/url?sa=t&amp;rct=j&amp;q=truecryt&amp;source=web&amp;cd=1&amp;cad=rja&amp;ved=0CCkQFjAA&amp;url=http%3A%2F%2Fwww.truecrypt.org%2F&amp;ei=FYNTUKasKIXK0AGh9oCACQ&amp;usg=AFQjCNH8UXHuTTPFsxxhk9LfQtfx7CG5Pg&quot;&gt; truecrypt&lt;/a&gt; container may work. &lt;br&gt;
&lt;br&gt;
I would not give anything on an encrypted ZIP file.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2012:site.224508-3247017</guid>
		<pubDate>Fri, 14 Sep 2012 12:19:26 -0800</pubDate>
		<dc:creator>yoyo_nyc</dc:creator>
	</item><item>
		<title>By: hattifattener</title>
		<link>http://ask.metafilter.com/224508/Whats-the-most-convenient-way-to-send-confidential-information-securely#3247023</link>	
		<description>(yeah, ZIP&apos;s builtin encryption is bad. If the trouble with PGP/GPG is the public-key setup and trust management stuff, then you could just use its symmetric-encryption mode, which does simple passphrase-based encryption like ZIP&apos;s but with a non-broken algorithm.)</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2012:site.224508-3247023</guid>
		<pubDate>Fri, 14 Sep 2012 12:22:40 -0800</pubDate>
		<dc:creator>hattifattener</dc:creator>
	</item><item>
		<title>By: strangely stunted trees</title>
		<link>http://ask.metafilter.com/224508/Whats-the-most-convenient-way-to-send-confidential-information-securely#3247029</link>	
		<description>If you&apos;re seriously thinking about transmitting medical records and credit card numbers via DropBox or encrypted zip file, you need immediate help from a compliance consultant - you are risking substantial fines, losing the ability to process credit card payments, and possibly even criminal liability if you continue down the road you&apos;re on.&lt;br&gt;
&lt;br&gt;
This is not a problem that is amenable to a roll-your-own solution with advice from some internet strangers - the regulations around protecting these types of data are complicated and the penalties for non-compliance are severe.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2012:site.224508-3247029</guid>
		<pubDate>Fri, 14 Sep 2012 12:32:02 -0800</pubDate>
		<dc:creator>strangely stunted trees</dc:creator>
	</item><item>
		<title>By: Dansaman</title>
		<link>http://ask.metafilter.com/224508/Whats-the-most-convenient-way-to-send-confidential-information-securely#3247032</link>	
		<description>Both for personal and business things, such as sending tax documents to an accountant, medical records to a family member or doctor, software code or API keys to a developer, etc. Nothing that directly falls under regulations such as HIPPA as far as my own use of the information.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2012:site.224508-3247032</guid>
		<pubDate>Fri, 14 Sep 2012 12:34:47 -0800</pubDate>
		<dc:creator>Dansaman</dc:creator>
	</item><item>
		<title>By: Dansaman</title>
		<link>http://ask.metafilter.com/224508/Whats-the-most-convenient-way-to-send-confidential-information-securely#3247037</link>	
		<description>Again let me emphasize that I&apos;m not talking about situations that are subject to regulatory compliance. And I&apos;d also like to mention for those who don&apos;t know that it&apos;s very common for customers of businesses to (insecurely) email credit card numbers to those businesses (not because the businesses requested they do it that way but because people generally are not aware of the security risks or think those risks don&apos;t justify the extra effort involved in transmitting via a more secure method). It&apos;s also very common for software developers and their clients to exchange sensitive information such as code and API keys insecurely.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2012:site.224508-3247037</guid>
		<pubDate>Fri, 14 Sep 2012 12:38:30 -0800</pubDate>
		<dc:creator>Dansaman</dc:creator>
	</item><item>
		<title>By: supercres</title>
		<link>http://ask.metafilter.com/224508/Whats-the-most-convenient-way-to-send-confidential-information-securely#3247048</link>	
		<description>PGP/GPG is really the way to go. If you&apos;re on a Mac, &lt;a href=&quot;https://www.gpgtools.org&quot;&gt;GPGTools&lt;/a&gt; has select-and-encrypt tools for any text anywhere in the system.  You just need to exchange public keys with anyone you need to send information to. As long as you trust that the public keys are coming from who you think they&apos;re coming from, there are no holes in your setup, like sending or faxing passwords.  You use someone&apos;s public key to encrypt a message for them, and they use their private key to decrypt it.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2012:site.224508-3247048</guid>
		<pubDate>Fri, 14 Sep 2012 12:46:38 -0800</pubDate>
		<dc:creator>supercres</dc:creator>
	</item><item>
		<title>By: RonButNotStupid</title>
		<link>http://ask.metafilter.com/224508/Whats-the-most-convenient-way-to-send-confidential-information-securely#3247085</link>	
		<description>Nthing PGP/GPG. &lt;br&gt;
&lt;br&gt;
I think your only other option (for email anyway) is &lt;a href=&quot;https://en.wikipedia.org/wiki/S/MIME&quot;&gt;S/MIME&lt;/a&gt;, but with that you either need to &lt;a href=&quot;http://kb.mozillazine.org/Getting_an_SMIME_certificate&quot;&gt;obtain certificates&lt;/a&gt; from a recognized certificate authority ($$$), or&lt;a href=&quot;http://www.howtoforge.com/how-to-encrypt-mails-with-ssl-certificates-s-mime&quot;&gt; build your own certificate authority&lt;/a&gt; (with blackjack....and hookers....and lots of convincing clients that they should ignore error messages about your certificates being untrustworthy).</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2012:site.224508-3247085</guid>
		<pubDate>Fri, 14 Sep 2012 13:16:59 -0800</pubDate>
		<dc:creator>RonButNotStupid</dc:creator>
	</item><item>
		<title>By: odinsdream</title>
		<link>http://ask.metafilter.com/224508/Whats-the-most-convenient-way-to-send-confidential-information-securely#3247146</link>	
		<description>It sounds like you&apos;re on the consumer side of these relationships. As such, it&apos;s not really going to be possible for you to dictate the means of transmission. Asking your accountant to install whatever encryption software you use, or download via a certain website, just isn&apos;t typically going to work. I&apos;ve tried, believe me.&lt;br&gt;
&lt;br&gt;
It&apos;s a shame that the state of secure electronic communication, for instance via public-key encrypted e-mail, isn&apos;t better, but it just isn&apos;t. There&apos;s nothing you can do about that.&lt;br&gt;
&lt;br&gt;
As such, your safest best is to physically send stuff via certified mail, keep good backups, and remain nimble so that you can discard data you know got lost (i.e., package not delivered, API keys get revoked).</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2012:site.224508-3247146</guid>
		<pubDate>Fri, 14 Sep 2012 14:01:40 -0800</pubDate>
		<dc:creator>odinsdream</dc:creator>
	</item><item>
		<title>By: yoHighness</title>
		<link>http://ask.metafilter.com/224508/Whats-the-most-convenient-way-to-send-confidential-information-securely#3247304</link>	
		<description>Seconding TrueCrypt or EncFS on a dropbox or similar (&lt;a href=&quot;http://dailymoe.blogspot.co.uk/2009/01/dropbox-with-personal-encryption.html&quot;&gt;article&lt;/a&gt; from google). Though one of the engineers at work thought this insecure for some reason and google skills fail me, anybody hear of a similar thing?&lt;br&gt;
&lt;br&gt;
Vis a vis the (hard to imagine) situation where you can&apos;t call them, mail the password with signed for snail mail.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2012:site.224508-3247304</guid>
		<pubDate>Fri, 14 Sep 2012 15:47:04 -0800</pubDate>
		<dc:creator>yoHighness</dc:creator>
	</item><item>
		<title>By: vasi</title>
		<link>http://ask.metafilter.com/224508/Whats-the-most-convenient-way-to-send-confidential-information-securely#3247698</link>	
		<description>It&apos;s impossible to give a good answer without knowing what you&apos;re defending against.&lt;br&gt;
&lt;br&gt;
Are you worried about random people sniffing your network traffic? That your email provider will go rogue? GPG will be fine. Are you worried about spyware? Your laptop getting stolen? GPG won&apos;t help much at all.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2012:site.224508-3247698</guid>
		<pubDate>Sat, 15 Sep 2012 00:14:26 -0800</pubDate>
		<dc:creator>vasi</dc:creator>
	</item><item>
		<title>By: Dansaman</title>
		<link>http://ask.metafilter.com/224508/Whats-the-most-convenient-way-to-send-confidential-information-securely#3248334</link>	
		<description>Just addressing the issue of whom might be able to see information once it&apos;s been emailed. So it&apos;s not about spyware or a stolen computer, rather about what happens after clicking &quot;Send&quot; (on the way to the recipient and when received by the recipient).</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2012:site.224508-3248334</guid>
		<pubDate>Sat, 15 Sep 2012 16:50:31 -0800</pubDate>
		<dc:creator>Dansaman</dc:creator>
	</item><item>
		<title>By: odinsdream</title>
		<link>http://ask.metafilter.com/224508/Whats-the-most-convenient-way-to-send-confidential-information-securely#3248381</link>	
		<description>In that case, use 7-Zip to make an AES encrypted ZIP archive, e-mail that, and call the recipient with the password. This requires the recipient to be able to install software and follow minimal instructions.&lt;br&gt;
&lt;br&gt;
If that&apos;s still too hard, get your own web server and set up an HTTPS folder with Basic authentication. E-mail a link to the files then call the recipient with the username and password.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2012:site.224508-3248381</guid>
		<pubDate>Sat, 15 Sep 2012 18:02:15 -0800</pubDate>
		<dc:creator>odinsdream</dc:creator>
	</item>
	</channel>
</rss>
