Ask HN: How can I send a secure email?
What's the best way to do this?
What's the best way to do this?
It's really not clear what you're asking ...
Do you want to defend against:
* ... someone in their office reading the email if your accountant's computer is left unattended?
* ... your ISP storing the email and reading it?
* ... their ISP storing the email and reading it?
* ... someone sniffing the packets through a router?
* ... the NSA reading the emails?
If you want your accountant not to have to do anything, then you need something like storing the emails and/or documents on an "https" only server, and then sending them a link. Given your comment about not wanting them to have to do anything, this will be one way only, and they won't be able to reply securely.
Sending them an encrypted email and asking them to read it will, I believe, require them to set something up, and you seem to have ruled that out.
You could use something like a password in a standard document format, and then phone and tell them the password separately. I think you can password lock Microsoft Word files, for example. Not very secure, but secure enough against idle sniffing. Probably not secure against a full on attack by someone seriously capable.
So, again, against what, exactly, are you defending?
Using a password-protected Microsoft Word file is an option, but it's a little cumbersome because (a) I would also have to password-protect the other attachment files separately; and (b) he would have to reply with a password-protected Microsoft word file and individually password-protect any files he wants to send me.
I like the idea of an https server, but why won't my accountant be able to reply? That is, accountant clicks a link to the https site, puts in password, sees message, clicks the 'reply' button on the webpage, then I get an email saying 'click here to see your accountants reply'.
With regards the password protected Word files, yes, you would have to protected every attachment, and your accountant would have to password protect every document in the reply. But what else would you expect?
With the https server, will you implement the mail package? In other words, what "Reply" button? Even then, the document will be stored in clear on the server, so whoever owns it will be able to read them. So that had better be you.
Encrypt all outgoing messages Choosing to encrypt all outgoing messages means, in effect, your e-mail is encrypted by default. You can write and send messages the same as with any other e-mail messages, but all potential recipients must have your digital ID to decode your messages. 1. On the Tools menu, click Trust Center, and then click E-mail Security. 2. Under Encrypted e-mail, select the Encrypt contents and attachments for outgoing messages check box. 3. To change additional settings, such as choosing a specific certificate to use, click Settings. 4. Click OK twice. Note3DES is the default encryption algorithm used in Outlook 2007. For more information, see the Overview of certificates and cryptographic e-mail messaging in Outlook.
It should be obvious that this isn't secure if your local government decides to come after you, and will likely fail if someone specifically comes after you(r accountant), but it does keep mail from travelling over unprotected lines and stored on a pretty well-protected system. Crucially, although it's slightly less secure than a perfect implementation of some of the other suggestions on this page, it's much easier.
[GMail is good, but not magical; if your accountant already has an account at, say, Hotmail, consider setting up a Hotmail account instead, even if you do lose two-factor authentication in the process.]
You and your accountant just need a shared password. For the other attachments, a protected zip/rar file should be sufficient.