Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 23, 2013, 04:44:26 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
663809
Posts
70589
Topics
145226
Members
Latest Member:
oldwiseowls
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Archived Boards
Discontinued Products
Comodo Secure Email - CSE
Help - CSE
FAQ - CSE
How does CSE EXACTLY work ?
« previous
next »
Pages:
[
1
]
2
Author
Topic: How does CSE EXACTLY work ? (Read 23743 times)
clig
Newbie
Offline
Posts: 6
How does CSE EXACTLY work ?
«
on:
November 15, 2008, 09:38:43 AM »
Hi !
I never used CSE yet, however it looks interesting. It is also free, which makes it a good deal. (And of course in the long run, in case I will open an office, I might stick to your product using a non-free version...)
However:
I would like to know the exact mechanism how CSE works regarding the exchange and creation of the certificates / keys especially. E.g. I write an email, what exactly happenes from the sending to the receiving of it ?
(In more detail than on your webpage here
http://www.secure-email.comodo.com/overview.html
)
Where can I get this info ?
Thank you,
P.S.: How does it exactly work, that someone unauthorised intercepting or receiving an email cannot read it or its attchments ?
«
Last Edit: November 15, 2008, 09:44:14 AM by clig
»
Logged
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12914
Re: How does CSE EXACTLY work ?
«
Reply #1 on:
November 15, 2008, 10:06:06 AM »
If you are sending to someone who has a digital certificate: then the message is encrypted and digitally signed (noone can read it but the recipient and noone can modify it as recipient will know its modified)
If you are sending it to someone who hasn't got a digital certificate: it has two modes.. just sends it digitall signed, which means people can still intercept and read it, but they can't modify the message. (eg: digitally signed)..or
in the 2nd mode where u can ask it to be encrypted: It uses our patent pending solution where we create a certificate for the recipient and the email is encrypted and digitally signed for the recipient (noone can read it but the recipient and noone can modify it as recipient will know its modified).
hope this simple explanation clarifies it for you.
thanks
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
clig
Newbie
Offline
Posts: 6
Re: How does CSE EXACTLY work ?
«
Reply #2 on:
November 16, 2008, 03:15:54 PM »
Thank you for your response Melih:
However, we would be thankful for some precisement:
Therefore the specific hypothetical scenario:
User A has a mail address UserA[at]yahoo.com
And
User B, mail address UserB[at]yahoo.com
Lets assume User A wants to write a securely encrypted and digitally signed email to user B:
User A therefore has got a free digital certificate (private person) from COMODO, using CSE.
User A writes the E-Mail, adds userB as the recipient. Mail is encrypted and digitally signed by CSE using User B's public key for encrypting the message to User B and then sent using Thunderbird.
Scenario All OK:
User B receives the encrypted and digitally signed message from user A (in Mozilla Thunderbird).
How does User B's CSE know the “decryption” code for the message ?
Where is the decryption code stored ?
And how does User B's CSE know that the message originates really from User A and not from somebody else ?( Especially if User B receives a digitally signed and encrypted message from User A for the first time)
And the final general question:
What encryption method is used ?
Sorry for the amount of questions, but we want to understand exactly what we might be using in future...
Thank you !
«
Last Edit: November 16, 2008, 03:41:56 PM by clig
»
Logged
Shane
Administrator
Comodo's Hero
Offline
Posts: 248
Re: How does CSE EXACTLY work ?
«
Reply #3 on:
November 18, 2008, 11:01:11 AM »
Identities are assured by the user of de facto industry standard PKI, with digital certificate and a trusted 3rd party (Comodo). For more info on PKI, please see here for more details:
http://en.wikipedia.org/wiki/Public_key_infrastructure
E-mails are sent using S/MIME, please see here for more details:
http://en.wikipedia.org/wiki/Smime
Encryption is carried out using ‘public key encryption’ aka asymmetric encryption. For more information, please see here:
http://en.wikipedia.org/wiki/Public-key_cryptography
As Melih said there are a few scenarios.
1) If A already has B’s digital certificate.
2) When A doesn’t have B’s digital certificate.
- 1) If A already has B’s digital certificate.
In this case CSE simply uses S/MIME encryption and PKI above.
- 1) If A already has B’s digital certificate.
If A doesn’t already have B’s certificate, CSE has a few options for B to read this mail, all determined by A using our patent pending single user certificate system and our server. A sends the e-mail using this system, setting which options from the list below B can use to read it.
i) B must install CSE to read the mail. This is our recommend method and is fully secure.
ii) B can forward the mail to our web reader, and read the mail by supplying a password which A agreed with B in advance, e.g. by telephone or letter. Not as secure as i)
iii) B can forward the mail to our web reader but does not need to supply a password. Not as secure as ii)
As I said, A the sender decides which of the options are avaible to B. Hope this answers your questions.
Regards,
Shane.
Logged
Please read the Forum Policy below before posting:
http://forums.comodo.com/new_member_information/forum_policy-t1516.0.html
clig
Newbie
Offline
Posts: 6
Re: How does CSE EXACTLY work ?
«
Reply #4 on:
November 19, 2008, 09:49:04 AM »
Excellent, thank you !
Now I will study what you gave me ...
Logged
J2897
Comodo's Hero
Offline
Posts: 333
Limted User Account Enforcer
Re: How does CSE EXACTLY work ?
«
Reply #5 on:
June 16, 2009, 06:41:02 PM »
I was going to try CSE a while ago (Months). But what put me off is, I think Comodo would be able to Decrypt my Emails.
As far as I'm aware, it would be almost the same as Two People (A & B) sending Secure Gmail's to each other; accessing their Web Mail Page using https. (Staff at Google would be able to Decrypt my Emails.)
I think this could be the Second main reason why a lot of people simply don't bother Encrypting. If a Company can easily Decrypt your Email, whether it is Comodo, Google, or your ISP who can Decrypt them, then why bother?
Is it possible to Encrypt Emails without a Digital Certificate from a Certificate Authority?
(This would take the power away from Comodo, Google, or the ISP, and give it completely to the User.)
If this is feasible, would this be possible in CSE?
I don't know much about Certificates, but how about CSE being able to generate randomized Self Signed Certificates so that the Emails can never be Decrypted by ANYONE but the User?
(And the recipient of course.)
If you find it difficult to understand this Post, its because I'm talking about a Subject I am not familiar with.
Thanks.
«
Last Edit: June 16, 2009, 07:03:34 PM by J2045
»
Logged
Welcome '
Home
'.
Favourite Security Software.
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12914
Re: How does CSE EXACTLY work ?
«
Reply #6 on:
June 16, 2009, 07:47:32 PM »
Quote from: J2045 on June 16, 2009, 06:41:02 PM
I was going to try CSE a while ago (Months). But what put me off is, I think Comodo would be able to Decrypt my Emails.
As far as I'm aware, it would be almost the same as Two People (A & B) sending Secure Gmail's to each other; accessing their Web Mail Page using https. (Staff at Google would be able to Decrypt my Emails.)
I think this could be the Second main reason why a lot of people simply don't bother Encrypting. If a Company can easily Decrypt your Email, whether it is Comodo, Google, or your ISP who can Decrypt them, then why bother?
Is it possible to Encrypt Emails without a Digital Certificate from a Certificate Authority?
(This would take the power away from Comodo, Google, or the ISP, and give it completely to the User.)
If this is feasible, would this be possible in CSE?
I don't know much about Certificates, but how about CSE being able to generate randomized Self Signed Certificates so that the Emails can never be Decrypted by ANYONE but the User?
(And the recipient of course.)
If you find it difficult to understand this Post, its because I'm talking about a Subject I am not familiar with.
Thanks.
Comodo does not read, cannot read your emails when you are using digital certificates. You own the your private key in your PC, Comodo has no access to it.
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
J2897
Comodo's Hero
Offline
Posts: 333
Limted User Account Enforcer
Re: How does CSE EXACTLY work ?
«
Reply #7 on:
June 17, 2009, 05:06:45 AM »
Thanks Melih!
Quote from: Melih on June 16, 2009, 07:47:32 PM
Comodo does not read, cannot read your emails when you are using digital certificates.
I didn't think that Comodo read the Emails (same for Google). I did think Comodo 'could' read the Emails (same for Google) if they wanted to though, because:
Quote from: Comodo_Shane on November 18, 2008, 11:01:11 AM
- 1) If A doesn't already have B’s digital certificate.
iii) B can forward the mail to our web reader but does not need to supply a password.
My feeling is that, in all of the scenarios, Comodo 'could' Decrypt the Email if they had access to it (even if it was Password Protected).
Analogy:
If a Lock Smith produces a Key (Private Key), they 'could' keep a Copy of that Key.
If the User creates their own Key instead (out of Random Numbers), surely that would be much more Secure?
Again, I am talking about a Subject I am not familiar with (Digital Certificates). I just wanted to put my point across, because there could be many in the same state of thought.
Thanks.
Logged
Welcome '
Home
'.
Favourite Security Software.
Endymion
Comodo's Hero
Offline
Posts: 1362
Reality is subordinate to perception.
Re: How does CSE EXACTLY work ?
«
Reply #8 on:
June 17, 2009, 06:31:12 AM »
Quote from: J2045 on June 17, 2009, 05:06:45 AM
If the User creates their own Key instead (out of Random Numbers), surely that would be much more Secure?
I'm not an expert either but AFAIK using CSE users
already
create their keys
locally
.
IIRC is it not as simple as using any number as only
prime numbers
could be used to generate a primary key.
«
Last Edit: June 17, 2009, 06:33:44 AM by Endymion
»
Logged
I have learnt silence from the talkative, toleration from the intolerant, and kindness from the unkind; yet strange, I am ungrateful to these teachers.
Kahlil Gibran (1883 - 1931)
J2897
Comodo's Hero
Offline
Posts: 333
Limted User Account Enforcer
Re: How does CSE EXACTLY work ?
«
Reply #9 on:
June 17, 2009, 07:37:01 AM »
I think what I am really trying to say, after reading '
this
', is that I would like to Generate my own Public & Private Key's, but without sending my Public Key to a CA (Certificate Authority).
I don't think anyone would be able to Decrypt my Emails (apart from the recipient) that way.
«
Last Edit: June 17, 2009, 07:38:41 AM by J2045
»
Logged
Welcome '
Home
'.
Favourite Security Software.
Endymion
Comodo's Hero
Offline
Posts: 1362
Reality is subordinate to perception.
Re: How does CSE EXACTLY work ?
«
Reply #10 on:
June 17, 2009, 08:01:28 AM »
Quote from: J2045 on June 17, 2009, 07:37:01 AM
I think what I am really trying to say, after reading '
this
', is that I would like to Generate my own Public & Private Key's, but without sending my Public Key to a CA (Certificate Authority).
I don't think anyone would be able to Decrypt my Emails (apart from the recipient) that way.
As already posted if
both users got CSE
even
decryption will be carried locally
.
Anyhow I got the impression that what you actually trying to say is that CSE is insecure through analogies and feelings...
Besides:
Quote from: Melih on June 16, 2009, 07:47:32 PM
Comodo does not read, cannot read your emails when you are using digital certificates. You own the your private key in your PC, Comodo has no access to it.
Melih
«
Last Edit: June 17, 2009, 11:04:27 AM by Endymion
»
Logged
I have learnt silence from the talkative, toleration from the intolerant, and kindness from the unkind; yet strange, I am ungrateful to these teachers.
Kahlil Gibran (1883 - 1931)
xiuhcoatl
Unaffiliated Forum Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 911
Re: How does CSE EXACTLY work ?
«
Reply #11 on:
June 17, 2009, 10:10:08 AM »
Quote from: J2045 on June 17, 2009, 07:37:01 AM
I think what I am really trying to say, after reading '
this
', is that I would like to Generate my own Public & Private Key's, but without sending my Public Key to a CA (Certificate Authority).
I don't think anyone would be able to Decrypt my Emails (apart from the recipient) that way.
Some of the very early versions of PGP operated that way. I do not know if you can find software that works in that way now. Possibly OPGP or GnuPG but then you must get you Key signed by other users of the same in order to verify the identity of your key and your key still ends up public.
read this
http://en.wikipedia.org/wiki/Public-key_cryptography
but as has been said with current public key encryption no one can decrypt your message except the recipient with out significant computing power and a lot of time.
I prefer CSE
«
Last Edit: June 19, 2009, 09:54:49 AM by xiuhcoatl
»
Logged
When things go wrong, and they usually will,and your daily road, seems all uphill, when machines are down,and tempers high, when you try to smile, but can only cry,and you really feel you'd like to quit, don't run to me I don't give a sh*t.
(A semi retired systems analyst's credo)
J2897
Comodo's Hero
Offline
Posts: 333
Limted User Account Enforcer
Re: How does CSE EXACTLY work ?
«
Reply #12 on:
June 17, 2009, 10:53:38 AM »
Quote from: xiuhcoatl on June 17, 2009, 10:10:08 AM
... no one can decrypt your message except the recipient...
Comodo can.
There must be a better way possible IMHO. In a Two Way conversation, there should only be Two People with access to the Public Key (A & B). Not Three (A, B & C).
Thanks for your help though.
Logged
Welcome '
Home
'.
Favourite Security Software.
xiuhcoatl
Unaffiliated Forum Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 911
Re: How does CSE EXACTLY work ?
«
Reply #13 on:
June 17, 2009, 11:03:11 AM »
the public key does not permit decryption
it is used to encrypt the message. there are no back doors installed in CSE. If you do not want to believe what you are being told so be it.
sorry, we could not help you
X
Logged
When things go wrong, and they usually will,and your daily road, seems all uphill, when machines are down,and tempers high, when you try to smile, but can only cry,and you really feel you'd like to quit, don't run to me I don't give a sh*t.
(A semi retired systems analyst's credo)
J2897
Comodo's Hero
Offline
Posts: 333
Limted User Account Enforcer
Re: How does CSE EXACTLY work ?
«
Reply #14 on:
June 17, 2009, 02:32:57 PM »
Ah' NOW I GOT YOU!
The
PRIVATE KEY
is Generated on the
USERS PC
.
(The User is me; the person installing CSE.)
The
PUBLIC KEY
can ONLY be used to
ENCRYPT THE MESSGE
.
The
PRIVATE KEY
can ONLY be used to
DECRYPT THE MESSAGE
.
If only everyone else knew this...
Thank you!
I was under the impression that you could also do it the other way around; use the Private Key to Encrypt, and use the Public Key to Decrypt. This however is False!
Just one more question:
In these Two scenario's, was the Email simply signed with Comodo's own PUBLIC KEY?..
(And then Decrypted with Comodo's own PRIVATE KEY when 'B' goes to view it Online with Comodo's Web Reader?)
Quote from: Comodo_Shane on November 18, 2008, 11:01:11 AM
- 1) If A doesn't already have B’s digital certificate.
ii) B can forward the mail to our web reader, and read the mail by supplying a password which A agreed with B in advance, e.g. by telephone or letter. Not as secure as i)
iii) B can forward the mail to our web reader but does not need to supply a password. Not as secure as ii)
Note:
Where I say, "Comodo's own * KEY", I am NOT referring to the Key's in the Digital Certificate that the User gets Free with CSE!
I am referring to Comodo's OWN key!
Logged
Welcome '
Home
'.
Favourite Security Software.
Tags:
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.163 seconds with 22 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com