Question for the technical people on email headers

Employment Law Clinic

Free Member
Aug 10, 2009
3,557
1,667
London
employmentlawclinic.com
I'm curious about an argument from a local authority regarding using names in the "subject line" of an email - they suggest their choice is based on security - so would welcome any input on the validity of their argument.

An email is sent from a local authority to a resident; this is not from a central government office using gsi, just a standard email from [email protected], and to a standard gmail account. The body of the email & addressee both clearly identify the subject matter - the former with the full name in various parts of the email, the latter being the parent of said child, so it would be clear to anyone that intercepted the title & addressee of the email if they were so inclined.

The explanation for this behaviour - an abbreviation in the title only - is for security: "When emails are sent we avoid using children's names in the title of the emails for security purposes."

But the full name of the child is in the body of the email, and the abbreviations of their name in the subject line only. (In this instance, it was PO; the full name appears in the body of the email, and any attached documents.)

I just want to know, so would appreciate comments, on whether there is something special in the "subject line" that has a lower level of security to the actual body of the email, or if there is any sense to the argument made.


Thanks,


Karl Limpert
 
Councils. Lol.

the subject element of the plain text email is no different to the body. The point of the subject is so the email client can display it differently, if so desired. Its all plain text.

if the body is html its still just text that anyone who intercepts it will be able to read.
 
Upvote 0
in fact, many clients and web based email show the first line of the email alongside the subject, so maybe the councils should ban using the childs name too high in in the body!
 
Upvote 0
This is definitely wrong.

The only instance where this might not be the case is if you are encrypting the email which generally encrypts the body of the email but leaves the subject line unencrypted. Since they aren't even bothering to encrypt the email I wouldn't take any notice of what they say since anyone can read the body of the email as it is just sent as plain text (or HTML but that is human readable as well).
 
Upvote 0
No security benefit at all. If you can read the header then you can read the body.

The correct secure way of handling personal information is not to transmit it by email but to notify the recipient that there is a secure message waiting for them. If you have online banking you will understand how they do it.
 
Upvote 0
No security benefit at all. If you can read the header then you can read the body.

The correct secure way of handling personal information is not to transmit it by email but to notify the recipient that there is a secure message waiting for them. If you have online banking you will understand how they do it.

Not entirely true as you can encrypt the message as I said which you can use to send secure information via email but since they aren't doing this then it isn't an issue in this case.
 
Upvote 0
Wow, I'm often finding this place to be quiet these days, but so many responses so quickly is a positive.


When I read the argument, it sounded most odd to me, but I didn't want to argue the point until I had a second (and many more now) opinion.

Thanks all, it's appreciated.


Karl Limpert
 
Upvote 0
Due to the comments about the best way of sending/receiving these communications, I'll observe that the recipient of the emails doesn't object at all to receiving the communications by email, regardless of the security; it's actually convenient to her, as it allows a wide circulation of correspondence, back & forth.

Offence has simply been taken by the laziness of the council officers, referring to her daughter only by abbreviations in the title, something that was explained as for "security purposes", which didn't appear a valid argument, and the above seems to confirm my suspicions.


Edit: Paragraphs make the text much easier to read!

Karl Limpert
 
Upvote 0
@Cromulent I composed my post while you were writing yours, but I genuinely had never heard of email body encryption, I have always thought that you can encrypt in transit but that was that.

And that is me having been working in IT for 35 years and been using internet email since it was invented, so I assume that either it isn't widely known or that I have had selective hearing.

That said, I have just read up on it, and it appears that major email clients automatically handle encryption, including Gmail as per theOPs reciever.

I would say that I didn't notice the OP mentioning that the council DID NOT encrypt the body in their clients or webserver.

So, the argument that the subject is less secure stands, in my opinion, contrary to my first post.

Learn something new everyday.

Of course, the value of that security will depend on whether the clients receiving device is inherently secure (access controlled and encrypted on disk)
 
Upvote 0
Confirm that the subject line thing is BS.

Frankly I find it shocking that a Local Authority will discuss a child through anything other than a fully secure channel. I guess it does depend a bit on what the content is, but it does not seem right.
 
Upvote 0
@Cromulent I composed my post while you were writing yours, but I genuinely had never heard of email body encryption, I have always thought that you can encrypt in transit but that was that.

And that is me having been working in IT for 35 years and been using internet email since it was invented, so I assume that either it isn't widely known or that I have had selective hearing.

That said, I have just read up on it, and it appears that major email clients automatically handle encryption, including Gmail as per theOPs reciever.

I would say that I didn't notice the OP mentioning that the council DID NOT encrypt the body in their clients or webserver.

So, the argument that the subject is less secure stands, in my opinion, contrary to my first post.

Learn something new everyday.

Of course, the value of that security will depend on whether the clients receiving device is inherently secure (access controlled and encrypted on disk)

Encrypting email is a pain in the arse. You'd know instantly if they were sending encrypted email because you'd need to have their public key and they would need to have your public key and you'd probably hear people talking about S/MIME or GPG.

Most people think that if they use SSL/TLS to connect to their SMTP server their email is safe. This is false since when your SMTP server sends the email on to another SMTP server (probably the SMTP server of the recipient of your email but there could be other SMTP servers that forward it on first) there is no guarantee that the SMTP servers will use SSL/TLS to communicate with each other. Thus anyone can snoop on the communications between SMTP servers and access all of your sent email.

The only 100% sure way to protect your email is to encrypt it. Oh and also you need to make sure that your private key is kept absolutely secure otherwise anyone with access to it can decrypt your emails.
 
Upvote 0
May I check my understanding is correct.

LA sends an email to parent.

Email content discusses child and names child. Email subject refers to child by their initials.

Parent objects to laziness. Council cites security as the reason the name is abbreviated in the subject?

If so then the security reason does, for me, hold some water as you are of course obscuring the full name if the email is not opened.

However - as alluded to by everyone technical - as soon as you open the email then the entire security argument falls over. Ditto the case where the data is intercepted as the message headers and body are basically the same text file so if you have one, you have the other.

That said, I can see *some* merit in not naming in the subject. In fact I'd go so far as to know use the initials there either? Unless there's a strong case for disambiguating the email to the parent prior to them opening it.

However - and this is the big one one for me - are the council acting inside of the principle 7 DP obligations? I'd be significantly more worried that you have an unlawful disclosure waiting to happen if this is routine procedure by the LA. Moreover, and I may be incorrect here but that data may also constitute sensitive data for the purposes of section 2 which gives the LA further responsibilities to ensure its integrity.

Parent being happy to receive is rather academic.
 
Upvote 0
As much as I agree that there isn't a massive difference between the subject and the email. There is a difference - especially when managing IT security on an organisation basis.

Security is very subjective, and must take into account human factors and real life scenarios.

In this scenario it may not matter that the child's name is in the subject, but in some more sensitive cases it may. And as soon as you start having flexible rules, someone will put the name on a very sensitive case.

For example an organisation may have a mobile device management system in place that will only show the subject when a phone/tablet is locked when an email comes in, so if 3rd parties see a subject on an employees phone during a meeting there is no problem. Whereas if the name is in the subject this would be disclosed.

It could be that email subjects are viewable by admin or IT staff when archived, and they don't need to see the name, or 100 other reasons that it impacts on security outside of the simple email exchange.
 
Upvote 0

Latest Articles