öλÔÓéÀֵǼÈë¿ÚÏÂÔØ

Ó¢Óï¿ÆÆÕÎÄÑ¡£ºÈçºÎ½¨Á¢°²È«µÄµç×ÓÓʼþ

ÍøÂç×ÊÔ´ Freekaoyan.com/2008-04-17

¡¡¡¡ unencrypted messages can be hijacked in transit and read or altered£®if the mail is not digitally signed£¬you can¡¯t be sure where it came from£®
¡¡¡¡Î´¼ÓÃܵÄÐÅÏ¢¿ÉÄÜÔÚ´«ÊäÖб»½Ø»ñ¡¢Íµ¿´»ò´Ü¸Ä¡£Èç¹ûÓʼþ²»ÊÇÊý×ÖÇ©ÃûµÄ£¬Äã¾Í²»Äܿ϶¨ÓʼþÊÇ´ÓÄÄÀïÀ´µÄ¡£
¡¡¡¡there are many options for securing e-mail£¬all with a few strengths and probably more weaknesses£®
¡¡¡¡È·±£µç×ÓÓʼþµÄ°²È«ÓжàÖÖÑ¡Ôñ£¬ËüÃǶ¼ÓÐЩ³¤´¦£¬µ«ÓпÉÄÜ´æÔÚ¸ü¶àÈõµã¡£
¡¡¡¡let¡¯s take care of the easy decisions£®secure/multipurpose internet mail extensions(s/mime)should be the message encryption and digital signature format because it¡¯s the accepted standard and is built into leading e-mail clients such as microsoft outlook 98/2000 and lotus notes r5£®yet a standard such as s/mime only takes you so far£®each vendor has implemented its own interpretation of s/mime£¬which makes interoperability problematic£®this drawback is exacerbated by the emergence of s/mime version 3 in the newest e-mail clients£¬which again could create interoperability issues£®
¡¡¡¡ÈÃÎÒÃÇÏȹØ×¢Ò»ÏÂÈÝÒ××öµÄ¾ö¶¨£¬°²È«/¶àÓÃ;ÒòÌØÍøÓʼþÀ©Õ¹(s/mime)Ó¦¸ÃÊÇÐÅÏ¢¼ÓÃܺÍÊý×ÖÇ©ÃûµÄ¸ñʽ£¬ÒòΪËüÊÇÒѱ»ÈϿɵıê×¼£¬±»×ö½øÁËÖ÷ÒªµÄµç×ÓÓʼþ¿Í»§¶ËÈí¼þÖУ¬Èç΢ÈíµÄoutlook 98/2000ºÍÁ«»¨¹«Ë¾µÄnotes r5¡£Æù½ñΪֹ£¬ÄãÖ»ÄÜÓÃs/mimeÒ»ÀàµÄ±ê×¼¡£Ã¿¼Ò¹©Ó¦É̶¼ÓÐ×Ô¼º¶Ôs/mimeµÄ½âÊÍ£¬Õâ¾ÍÒý³ö ÁË»¥ÓÃÐÔÎÊÌ⣬×îеĵç×ÓÓʼþ¿Í»§¶ËÈí¼þÖÐs/mimeÈý°æµÄ³öÏÖ£¬¼ÓÖØÁËÕâ¸öȱÏÝ£¬ËüÔٴοÉÄÜ´øÀ´»¥ÓÃÐÔÎÊÌâ¡£
¡¡¡¡the path of least resistance is to get an e-mail security gateway£¬ which is analogous to a firewall for e-mail£®every message going in or out pases through the gateway£¬allowing security policies to be enforced (where and when messages can be sent)£¬virus checking to be performed£¬and messages to be signed and encrypted£® one drawback of the gateway approach is that it doesn¡¯t provide user-based security£®for example£¬the gateway encrypts outbound messages so recipients can verify they came from your company£¬but recipients can¡¯t prove from whom they came£®
¡¡¡¡×èÁ¦×îСµÄµÀ·¾ÍÊDzÉÓõç×ÓÓʼþ°²È«Íø¹Ø£¬ËüÏ൱ÓÚµç×ÓÓʼþµÄ·À»ðǽ¡£½ø³öµÄÿһÌõÐÅÏ¢¶¼Òª¾­¹ýÍø¹Ø£¬Íø¹Ø¿ÉÒÔʵʩ°²È«Õþ²ß(ÐÅÏ¢ÔںΠʱÏòºÎµØ·¢ËÍ)¡¢Ö´Ðв¡¶¾¼ì²é²¢¸øÐÅϢǩÃûºÍ¼ÓÃÜ¡£ÕâÖÖÍø¹Ø·½·¨µÄÒ»¸öȱÏݾÍÊÇËü²» ÄÜÌṩ»ùÓÚÓû§µÄ°²È«ÐÔ¡£ÀýÈç£¬Íø¹Ø¶ÔÏòÍâ·¢µÄÐÅÏ¢½øÐмÓÃÜ£¬Òò¶ø½ÓÊÕ·½ÄÜÑéÖ¤Ëü ÃÇÀ´×ÔÄãµÄ¹«Ë¾£¬µ«½ÓÊÕ·½²»ÄÜÖ¤Ã÷ËüÃÇÀ´×ÔÄĸöÈË¡£
¡¡¡¡client-based methods use your private key to sign messages(proving it came from you)£¬which is a more granular level of security£¬but they have weaknesses as well£®they need to be configured on each desktop£¬which includes issuing a digital certificate to each user (for encryption and digital signature)£¬and ensuring that a proper security profile is configured within the e-mail client£®
¡¡¡¡»ùÓÚ¿Í»§¶ËµÄ·½·¨²ÉÓÃÄã˽ÈËÃÜÔ¿À´Ç©ÊðÐÅÏ¢(Ö¤Ã÷Ëü³ö×ÔÓÚÄã)£¬ÕâÊǸüϸ»¯µÄ°²È«µÈ¼¶£¬µ«ËüÃÇÒ²ÓÐÈõµã¡£ËüÃÇÐèÒªÅäÖõ½Ã¿¸ö×ÀÃæÏµÍ³£¬°üÀ¨Ïòÿ¸öÓû§·¢Êý×ÖÖ¤Êé(ÓÃÓÚ¼ÓÃܺÍÊý×ÖÇ©Ãû)£¬²¢È·±£ÔÚÿ¸öµç×ÓÓʼþ¿Í»§¶Ë¶¼ÅäÖÃÁ˺ÏÊʵݲȫÅäÖÃÎļþ¡£
¡¡¡¡there are also a number of web-based secure mail services that keep all messages within their environment at all times to ensure security£®you use a secure site on the internet to compose a message£®once you hit¡°send¡±£¬the site encrypts and stores the message on its site£¬and sends the recipient an e-mail notification that a secure message is waiting£®the recipient links to the site£¬ provides a shared secret for authentication£¬and accesses the message via secure sockets layer£® unfortunately£¬this method does not work with existing enterprise e-mail systems£®

Ïà¹Ø»°Ìâ/

  • ÁìÏÞʱ´ó¶îÓÅ»Ýȯ,Ïí±¾Õ¾Õý°æöλÔÓéÀֵǼÈë¿ÚÏÂÔØöλÔÓéÀÖ¹Ù·½appÏÂÔØ!
    ´ó¶îÓÅ»Ýȯ
    ÓÅ»ÝȯÁìÈ¡ºó72СʱÄÚÓÐЧ£¬10ÍòÖÖ×îÐÂöλÔÓéÀֵǼÈë¿ÚÏÂÔØ¿¼Ö¤Ààµç×Ó´òÓ¡öλÔÓéÀÖ¹Ù·½appÏÂÔØÈÎÄãÑ¡¡£º­¸ÇÈ«¹ú500ÓàËùԺУöλÔÓéÀÖ¹Ù·½appÏÂÔØöλÔÓéÀֵǼÈë¿ÚÏÂÔØ¿Î¡¢200¶àÖÖÖ°Òµ×ʸñöλÔÓéÀֵǼÈë¿ÚÏÂÔØ¡¢1100¶àÖÖ¾­µä½Ì²Ä£¬²úÆ·ÀàÐͰüº¬µç×ÓÊé¡¢Ìâ¿â¡¢È«Ì×öλÔÓéÀÖ¹Ù·½appÏÂÔØÒÔ¼°ÊÓÆµ£¬ÎÞÂÛÄúÊÇöλÔÓéÀÖ¹Ù·½appÏÂÔØ¸´Ï°¡¢¿¼Ö¤Ë¢Ì⣬»¹ÊÇ¿¼Ç°³å´ÌµÈ£¬²»Í¬ÀàÐ͵IJúÆ·¿ÉÂú×ãÄúѧϰÉϵIJ»Í¬ÐèÇó¡£ ...
    öλÔÓéÀֵǼÈë¿ÚÏÂÔØÓÅ»Ýȯ ±¾Õ¾Ð¡±à FreeÒ¼°Û·ÖÑ§Ï°Íø 2022-09-19
öλÔÓéÀÖ(xinhui)¹Ù·½ÍøÕ¾_öλÔÓéÀÖappÏÂÔØÈë¿Ú