Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,173,107 members, 7,887,228 topics. Date: Friday, 12 July 2024 at 02:33 AM

Gtbank Is Not Encrypting Emails Containing Sensitive Information - Webmasters - Nairaland

Nairaland Forum / Science/Technology / Webmasters / Gtbank Is Not Encrypting Emails Containing Sensitive Information (1029 Views)

HELP! Can I Receive My Adsense Payment To Gtbank Savings Account / Notorious Fraudster Adeniyi Bayo Gtbank 0168097918 Account Blocked By Gtbank / Major Cloudflare Bug Leaked Sensitive Data From Customers’ Websites (2) (3) (4)

(1) (Reply) (Go Down)

Gtbank Is Not Encrypting Emails Containing Sensitive Information by ib22003(m): 2:49pm On Jul 31, 2017
Before I get into the issue, I will like to start by saying that signing and encrypting emails are necessary to protect communication and data integrity between all parties. signing is necessary because it tells the receiver that the email is actually from you and was not forged while TLS (standard encryption) helps provide privacy between communicating applications and their users during email delivery. When a server and client communicate, TLS ensures that no third party can overhear or tamper with any messages.

I was in the office yesterday working on an email server using an Ec2 instance in Aws, I had just finished adding a certificate, SPF, and Dkim and I sent an email to my Gmail account to verify if the emails are signed and encrypted.

After checking other emails to see if they are also signed and encrypted. I checked through a few and found that GTbank has not encrypted any of the emails sent to me as far back as I could check The emails are signed but there is no type of encryption at all. Even gmails says "gtbank.com did not encrypt this message"

https://ibidapoibrahim.com/gtbank-is-not-encrypting-emails/

Re: Gtbank Is Not Encrypting Emails Containing Sensitive Information by ib22003(m): 2:51pm On Jul 31, 2017
This is what it should look like

Re: Gtbank Is Not Encrypting Emails Containing Sensitive Information by dogstyle007(m): 6:28pm On Jul 31, 2017
Hmm
Re: Gtbank Is Not Encrypting Emails Containing Sensitive Information by yomalex(m): 11:04pm On Jul 31, 2017
interesting
Re: Gtbank Is Not Encrypting Emails Containing Sensitive Information by bennymark(m): 12:03am On Aug 01, 2017
ib22003:
Before I get into the issue, I will like to start by saying that signing and encrypting emails are necessary to protect communication and data integrity between all parties. signing is necessary because it tells the receiver that the email is actually from you and was not forged while TLS (standard encryption) helps provide privacy between communicating applications and their users during email delivery. When a server and client communicate, TLS ensures that no third party can overhear or tamper with any messages.

I was in the office yesterday working on an email server using an Ec2 instance in Aws, I had just finished adding a certificate, SPF, and Dkim and I sent an email to my Gmail account to verify if the emails are signed and encrypted.

After checking other emails to see if they are also signed and encrypted. I checked through a few and found that GTbank has not encrypted any of the emails sent to me as far back as I could check The emails are signed but there is no type of encryption at all. Even gmails says "gtbank.com did not encrypt this message"

https://ibidapoibrahim.com/gtbank-is-not-encrypting-emails/



forgive my ignorance, what information can you intercept from those communications?
aren't those just mail server encryptions (smtp)?


asides your account balance after a transaction, GTB never sends any confidential info via email


question: do you consider a website with secured socket layer (https) as 'secured'?
Re: Gtbank Is Not Encrypting Emails Containing Sensitive Information by bennymark(m): 12:03am On Aug 01, 2017
.
Re: Gtbank Is Not Encrypting Emails Containing Sensitive Information by ib22003(m): 6:30am On Aug 01, 2017
Yes you are right this is just an encryption between the mail relays, TLS ensures that no third party can overhear or tamper with any messages. You can't really say aside from account transactions because account transactions are also confidential information. yes, I also regard any website with https as basic security, because at least they have prevented their user's credentials from being stolen in transit.
bennymark:




forgive my ignorance, what information can you intercept from those communications?
aren't those just mail server encryptions (smtp)?


asides your account balance after a transaction, GTB never sends any confidential info via email


question: do you consider a website with secured socket layer (https) as 'secured'?

(1) (Reply)

Need Instagram And Twitter Accounts With 2k+ Followers / Need To Make An On-line Registration Form For A Program / Article Writer Needed For A Long Term Project

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 21
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.