Crypto mail storage available for all users

Created on 29. May 2015, 16:00 | Category: Info

Dear Posteo users,

Introduction of the new crypto mail storage is complete: all Posteo users can now encrypt the email data they have saved with us at the click of a button. We make this new encryption feature available to you at no extra charge.

You don’t require any special technical knowledge: the encryption is activated at the click of a button and occurs in the background without you needing to do anything. You can find the new encryption option in the settings of your account via “Encryption” > “Posteo crypto mail storage”. Step-by-step instructions are found in the Posteo help section. If you have additional questions, our support team is available to you at no extra charge. #more#

When you activate crypto mail storage, all email data saved with Posteo is encrypted at the click of a button – with the help of your password. The encryption encompasses the content and attachments of all emails saved with Posteo as well as their corresponding metadata (e.g. subject and header). As well as your existing email archive, all newly-arriving emails are also encrypted. The encrypted data within crypto mail storage are no longer readable by us. Posteo can not deactivate the encryption; only you can do this yourself. If you are interested, you can find out concretely how the data is encrypted and where the technical data for encryption is viewable on our encryption info page.

Password must be taken special care of

When you have activated crypto mail storage, you need to take special care with your password. The password is the key to your data. If crypto mail storage is activated and you forget your password, you will lose access to your encrypted email storage. The password reset function is no longer available to you, as your data is encrypted using your forgotten password. Posteo support can no longer reset your password or deactivate the encryption. Please therefore consider carefully whether you would like to use this password-based encryption function before activating it.

Can be combined with all other encryption options

Posteo crypto mail storage constitutes an additional layer of encryption in our security model, with which you can protect the data you have saved with us. It can be combined with all other Posteo encryption features, for example, inbound encryption, without issue. Please note that each layer of encryption fulfills different protective purposes: crypto mail storage protects your saved email data and their corresponding metadata. By combining it with end-to-end encryption, which protects your emails during the communication process (when sending and receiving emails via the internet), you can further increase the security level of your communication.

The most frequently asked questions on crypto mail storage

Following our first blog entry we received many questions from users. We would like to respond to the most frequent ones again here.

– You can continue to use your account in the webmail interface as usual, though the search function could take a little longer.
– You can continue to access emails via IMAP and POP3 as usual.
– You can continue to manage your emails in local email programs.
– You can continue to access your emails on a smartphone, tablet or other device.
– Posteo crypto mail storage encrypts all email data saved on our servers. If local, insecure copies of your email data are created by a program, we recommend securing all devices used for this or deactivating creation of local copies.
– Legal: we had the legal situation checked by our lawyers. In Germany, email providers can not be compelled to “break” encryption. We designed crypto mail storage such that technically, Posteo can not remove the encryption of all saved email data applied by the users.
– Because incoming emails are first encrypted when they reach our server, crypto mail storage does not protect against lawful interception (TKÜ) of an account.
– Our encryption plug-in underwent an external, multi-level security audit (by Cure53). For reasons of transparency, the code for the encryption is also openly viewable. This conforms to our open-source strategy and is an essential trust-building measure in the post-Snowden era.
– We recommend that you further secure your account with two-factor authentication, to additionally increase your level of security.

Best regards,

The Posteo team

Posteo users safe from Logjam attack

Created on 22. May 2015, 16:00 | Category: Blog

Dear Posteo users,

For the last couple of days a so-called Logjam security flaw has been reported in the media. This was discovered by US scientists and can provide attackers with access to individual encrypted connections, which, for example, are used for secure access to websites, email traffic and online banking.

We wish to inform that as a user accessing Posteo, you are not affected by Logjam: our team observes developments in cryptography and security very intently and we always employ the newest encryption technologies. This means that when you access Posteo via your browser or a local email program, you are not vulnerable to Logjam as we do not offer the target over which this attack occurs. #more#

In your communications with other email providers, please be aware that for the moment, not all of them have secured their systems against Logjam.

Meantime, independent server test websites have extended their tests to include Logjam. You can confirm that Posteo is not affected by Logjam on these independent sites: on the Qualys test site we still obtain the best mark of A+ for web access, for example. Any vulnerability leads to a lower score.

Independent of Posteo, your browsers as well as local programs could still be vulnerable when using other services. In the coming days, please pay special attention as to whether updates are offered for your browser (e.g. Firefox, Safari or Chrome) or programs. You should install these important updates in order to increase the security of your online activities in this regard. In terms of security when accessing Posteo, no updates are necessary on your part.

Best regards,

The Posteo team

New Posteo migration service

Created on 21. May 2015, 17:00 | Category: Info

Dear Posteo users and interested parties,

Migrating your previous email accounts to Posteo just got easier: as of today, the new Posteo migration service is available to you, with which you can bring your previous accounts (including their folder structures) across to your Posteo account.

Many of you desired an ability to transfer folder structures without needing any particular technical knowledge.

For security reasons, we did not want to employ or recommend any third parties to transfer your sensitive email data; we therefore developed our own solution for secure and convenient migration to Posteo. #more#

The new migration service can now be found in the settings of your Posteo account (via “My account”).

You can now completely copy up to three external email accounts across to Posteo.

You do not require any special technical knowledge: when you set up a new migration service in the settings of your Posteo account, it will display the folders in your previous account. Conveniently, you can then decide which folders you would like to copy to Posteo with a click of the mouse. Our migration service will then transfer all selected folders across to your Posteo account.

You can decide yourself whether you would like to permanently delete the emails from your previous provider. The Posteo migration service is free of charge – and you retain control over your data:
At no point are your emails transferred via a third party.
The selected folders are collected from your previous provider by Posteo and transferred directly to your Posteo account over an encrypted connection.
We have designed the Posteo migration service in line with our policy of maximum data economy: we do not, for example, save information such as which email address the data is copied to your Posteo account from.

Best regards,

The Posteo team

New: Posteo introduces crypto mail storage

Created on 09. April 2015, 16:15 | Category: Info

New: Posteo introduces crypto mail storage

Dear Posteo users,

We have news:
Today we have introduced a new encryption option for you: Posteo crypto mail storage. The new function was already made available to users this morning. In the coming weeks, we will progressively make crypto mail storage available for all accounts. With crypto mail storage you have the ability to personally encrypt all email data you have saved with Posteo at the click of a button. The encryption is comprehensive. It encompasses the content and attachments of all emails saved at Posteo as well as their corresponding metadata (for example, the subject and email header). As well as your existing email storage, all newly-arriving emails will be encrypted.

We are making this new encryption feature available to you at no additional charge. It is important to us that all Posteo users obtain maximum security. You don’t need any special technical knowledge, either: the encryption is activated at the click of a button. It occurs in the background without you needing to do anything. #more#

The data within the crypto mail storage is no longer readable by us. We can not deactivate the encryption; only you can do this yourself. You can see whether this new encryption option is already available for your account via “Encryption” > “Posteo crypto mail storage”. If it is not yet available, we ask for your patience. Crypto mail storage will be made available to all users in the coming weeks.

Encryption at the click of a button – with the help of your password:

As soon as you have activated crypto mail storage in the settings of your account, Posteo creates a personalised key pair for you. Using this, we encrypt all the email data (content, attachments and metadata). This occurs with the part of your key that is responsible for “encrypting”. Each email is encrypted individually. The key that can make an email “readable” again is stored in the Posteo database, protected by your password. Thus, only you can access your encrypted email storage. Nothing changes in the workflow in your account: if you click on an email when crypto mail storage is activated, it is made readable for you in the background – and only for the moment of access. You manage your emails just as simply and conveniently as before.

Password must be taken special care of
When you have activated crypto mail storage, you need to take special care with your password. The password is the key to your data. If crypto mail storage is activated and you forget your password, you will lose access to your encrypted email storage. The password reset function is no longer available to you, as your data is encrypted using your forgotten password. Posteo support can no longer reset your password or deactivate the encryption.

Crypto mail storage is a plug-in we developed for the open-source email server Dovecot. Asymmetrical encryption occurs with the help of RSA; symmetrical encryption and authentication happens with AES and HMAC. Hashing occurs with bcrypt.

Further information can be found on our encryption info page.

Comprehensive tests and external security audit
Your personal email data is a sensitive commodity and worthy of protection. For this reason, extensive preparation work has been done prior to making crypto mail storage available. We not only comprehensively tested our encryption plug-in internally: the feature was also submitted to an external, multi-level security audit (by Cure53).

Transparent code and legal check
In addition, we had the legal situation clarified in advance. The result was that in Germany, email providers can not be compelled to “break” encryption.

We have implemented the crypto mail storage such that from a technical standpoint, the encryption initiated by Posteo users can not be removed by Posteo. In addition, the code for the encryption is openly viewable for reasons of transparency. This conforms to our open-source strategy and is an essential trust-building measure in the post-Snowden era.

Can be combined with all other encryption options
Posteo crypto mail storage can be combined with all other Posteo encryption features without issue. Thus, you can encrypt all your calendar and address book data at the click of a button. Posteo inbound encryption, which encrypts all newly-arriving emails with OpenPGP or S/MIME, can also be combined with crypto mail storage without issue.

If you already use inbound encryption, we recommend also activating crypto mail storage, as crypto mail storage encrypts not only newly-arriving emails but also all emails in all folders of the account as well as their corresponding metadata.

If you already use end-to-end encryption, you will also profit from crypto mail storage. The end-to-end process such as OpenPGP will generally only encrypt the content of individual emails, and not your saved emails or the emails’ metadata. Our password-based crypto mail storage constitutes comprehensive encryption, which distinctly increases the security level at Posteo. For maximum security, we recommend securing access to your crypto mail storage with Posteo two-factor authentication. Then, at login, not only your regular password will be required, but also a current one-time password. Such is the overall security level further increased. If you create local, insecure copies of your email data, we recommend securing all devices used for this.

We have made numerous pages with information and help instructions on Posteo crypto mail storage and our other encryption options available on our website.

Best regards,

The Posteo team

Posteo webmail: New "Gentle Grey" theme available

Created on 07. April 2015, 14:30 | Category: Info

En_1


Dear Posteo users,

As of today, a new “Gentle Grey” theme for our webmail interface is available. This is a reduced-colour version of our new standard design for those who prefer a more discreet colour scheme.

You can now activate the “Gentle Grey” theme in your account settings via “Settings” → “Preferences” → “User Interface”. To use the theme, simply select “Gentle Grey” and confirm by clicking “Save”.

We will soon be making additional versions of the webmail interface available to choose from.

Best regards,

The Posteo team