An international mining company was approached recently by an official from a South American country in which it has operations. “What have you done with your faxes?” the official demanded. “We can no longer read them.”
This unnerving conversation took place two months after the company had installed a company-wide encryption system for its facsimile and data transmissions.
Surprising? Not really. The only really surprising aspect for the mining company is that the snooper told the victim what was being done. Today, most fax, data or voice transmissions are as open to electronic snoopers as are cellular telephone calls or business meetings in a restaurant. With organizations competing on a global scale, information has become a premium commodity for those seeking competitive advantage. In the post-Cold War era, in which many members of the old intelligence community have privatized their expertise, fax and data interception has become a relatively common practice.
It is also a relatively cheap and easy way to get detailed insider knowledge. At a recent demonstration, senior executives from a Canadian petroleum company were shocked by the ease with which a fax transmission can be “tapped.” Like most business people, the executives believed their fax transmissions were somehow electronically scrambled and difficult to reassemble. Unfortunately, the open communications standards that are required for compatibility also make it easy for anyone to monitor most electronic transmissions.
For example, all that is needed to steal a fax is an induction coil purchased over the counter from a local electronics supplies outlet. The induction coil can intercept the electromagnetic signal carrying the message and relay it to an ordinary fax machine that prints the fax, as if it were the intended receiver.
With faxes transmitted over a public telephone network, their information can be intercepted at various strategic points along the transmission route, which can be by land-line, land-based microwave or satellite. Anyone with the motive, and the right equipment, can intercept signals.
Sure, it’s illegal, but you have to know they’re there before you can catch them. The incidence of interception is vastly understated since the intruder is not often detected. And the victims usually don’t like to admit that they have been compromised.
Data encryption has changed since the Cold War days of espionage. High-speed computers have made it simple to break encryption methods that were long believed secure.
Today, several encryptors are available which can protect the security of fax transmissions. These small pieces of hardware use complex mathematical algorithms to encrypt information at the fax transmission point and unscramble it at the receiver. These encryptors work with modern fax machines and PC fax cards.
The best encryption devices allow transparent operation of your fax machines: there are no complex codes to push at both ends. The primary discriminator among the better systems is their cryptographic system — is it a public key or a private key system? Ironically, the public key system is the more secure of the two.
With private key encryption, each user has his or her unique “keys” (which are random numbers in the electronic world) to encrypt and decrypt information. In a network of users, there must be as many keys as there are combinations of users. This becomes cumbersome and expensive once the network grows beyond a handful of users. Worse, the disclosure of keys in one unit compromises all of the others.
Public key systems use sophisticated mathematical algorithms to eliminate the weakness of private key systems. Public key technology allows the creation of “digital signatures,” or strings of data that can prove the identity or integrity of data.
— The author is president of Mobius Encryption Technologies of Mississauga, Ont.
Be the first to comment on "FACTS & FIGURES — Securing your fax messages"