Computer Security and Cyber LawUnit 1211 min read
Email Security Protocols: Encryption, Spoofing, Phishing & Secure Transactions
Unit 12 of Computer Security and Cyber Law explores email security threats (phishing, spoofing, malware), encryption protocols (S/MIME, PGP, TLS), secure email standards (SMTP, IMAP), and real-world applications like eSewa transaction alerts and WhatsApp end-to-end encryption. Learn how to design secure email systems,
TAKEAWAYS:
- Email threats like phishing (fake eSewa login pages) and spoofing (Ncell SMS scams) exploit human trust—always verify sender addresses and links.
- TLS/SSL (used by Gmail, WhatsApp) encrypts emails in transit, while S/MIME and PGP add digital signatures for non-repudiation in legal contracts.
- SMTP (port 25) and IMAP (port 143) handle delivery and storage, but DMARC/DKIM prevent spoofing in Kathmandu traffic route notifications.
- Secure email design requires multi-factor authentication (like Daraz OTPs), message integrity checks, and proactive password policies.
- Exam focus: Trace TLS handshakes, compare S/MIME vs. PGP, and explain how denial-of-receipt (e.g., "read receipts" in WhatsApp) fails in cyber law.
- Real-world tie: NEPSE stock alerts use signed emails to prevent fraud; a spoofed "NEPSE update" could crash share prices if clicked.
1. Why Email Security Matters: Threats in Nepal’s Digital Life
Email is the #1 attack vector for cybercrime in Nepal. 90% of data breaches start with a phishing email (IBM 2023). Even eSewa, Khalti, and Ncell face spoofed SMS/email scams daily. Let’s break down the risks:
A. Common Email Attacks (With Nepali Examples)
Key red flags in Nepali scams:
- Urgent action: "Your Khalti account will be suspended in 24 hours!"
- Mismatched URLs: Hover over links—does
khalti.com.ne.scamappear? - Generic greetings: "Dear User" instead of your name.
- Attachments: Never open
.exeor.zipfiles from unknown senders.
2. Email Security Protocols: How Gmail, WhatsApp, and Banks Protect You
Protocols are the "locks" on email. Here’s how they work in real systems:
A. Transport Layer Security (TLS/SSL)
What it does: Encrypts emails in transit (like a sealed envelope). Used by Gmail, WhatsApp, and eSewa. How it works:
- Handshake: Your device and the server agree on an encryption key (like shaking hands before a secret meeting).
- Encryption: Data is scrambled using symmetric keys (AES-256).
- Integrity check: A hash (like a fingerprint) ensures no one tampered with the email.
Worked Example: WhatsApp End-to-End Encryption
- Scenario: You send a Daraz order confirmation to your friend.
- Without TLS: Hackers on public Wi-Fi (e.g., at Thamel cafés) can read your order details.
- With TLS: Even if intercepted, the message appears as gibberish:
Original: "Your order #12345 is shipped via Ncell." Encrypted: "🔒 7F#9K$L2!@#QWERTY... 🔒"
B. S/MIME vs. PGP: Digital Signatures for Legal Emails
| Feature | S/MIME (Used by Outlook, Yahoo) | PGP/GPG (Used by journalists, lawyers) |
|---|---|---|
| Encryption | Symmetric (AES) + RSA | Asymmetric (RSA) + Symmetric (AES) |
| Key Management | Certificates (like a digital ID card) | Public/Private key pairs (you manage) |
| Use Case | Business emails (e.g., NEPSE reports) | Secure messaging (e.g., whistleblowers) |
| Ease of Use | Built into email clients | Requires manual setup (e.g., GPG tools) |
Worked Example: NEPSE Shareholder Alerts
- Problem: A hacker spoofs an email from NEPSE saying "Your dividend is delayed—click to claim."
- Solution: Use S/MIME-signed emails:
- NEPSE’s server signs the email with its private key.
- Your email client verifies the signature using NEPSE’s public key.
- If the signature fails → scam alert!
3. Secure Email Delivery: SMTP, IMAP, and DMARC
A. Protocols for Sending and Receiving Emails
| Protocol | Port | Role | Security Risk | Fix |
|---|---|---|---|---|
| SMTP | 25 | Sends emails | Spoofing, open relays | Use DMARC |
| IMAP | 143 | Downloads emails | Man-in-the-middle | TLS encryption |
| POP3 | 110 | Downloads emails | No sync, insecure | Avoid; use IMAP |
B. DMARC, DKIM, and SPF: Stopping Spoofed Emails
- SPF: Lists authorized servers (e.g.,
v=spf1 include:_spf.khalti.com ~all). - DKIM: Adds a digital signature to prove the email wasn’t altered.
- DMARC: Tells servers what to do if SPF/DKIM fails (e.g., "Quarantine this email").
Worked Example: Ncell SMS Spoofing
- Attack: Scammer sends "Your Ncell bill is ₹5000—pay here: [fake link]" from
ncell@bill.com. - Defense:
- SPF check: Is
ncell@bill.comauthorized to send emails for Ncell? → No → Block. - DKIM check: Does the email have Ncell’s signature? → No → Quarantine.
- SPF check: Is
4. Secure Email Design: Principles for IT Managers
To build a secure email system (like for a bank or e-commerce site), follow these 5 principles:
mindmap
root((Secure Email Design))
Principle1[(Multi-Factor Authentication)]
Example: eSewa OTP + Fingerprint
Principle2[(Message Integrity)]
Tools: Hashing (SHA-256), Digital Signatures (S/MIME)
Principle3[(Encryption in Transit)]
Protocol: TLS 1.3
Principle4[(Proactive Password Policies)]
Rules: 12+ chars, no reuse, 90-day expiry
Principle5[(User Training)]
Example: Simulate phishing attacks (like NTC’s cybersecurity drills)Worked Example: Daraz Order Queue System
- Problem: A hacker intercepts your order confirmation email and changes the shipping address.
- Solution:
- TLS: Encrypts the email in transit.
- S/MIME: Daraz’s server signs the email with its private key.
- OTP: Your order confirmation includes a one-time password (e.g.,
DARAZ-12345) that must be entered on Daraz’s website to confirm.
5. Email Security in Nepal: Case Studies
A. eSewa Transaction Alerts
- Protocol Used: TLS 1.2 (for encryption) + SMS OTP (for authentication).
- Why It Works:
- Your transaction details (e.g., "₹500 sent to XYZ") are encrypted.
- The OTP ensures even if the email is intercepted, the hacker can’t complete the transaction.
B. WhatsApp Business (for Pathao Drivers)
- Protocol Used: End-to-End Encryption (E2EE) + Signal Protocol.
- Why It Matters:
- Pathao drivers receive ride requests securely.
- Even WhatsApp employees can’t read your messages.
C. NEPSE Shareholder Communications
- Protocol Used: S/MIME-signed emails + DMARC policies.
- Why It’s Critical:
- Prevents spoofed "dividend claim" emails.
- Investors can verify the email came from NEPSE’s official server.
6. Common Exam Questions & How to Answer Them
Q1: "Define denial of receipt. How does it relate to email security?"
Answer: Denial of receipt is a cyber law concept where the sender claims the recipient never received an email (e.g., "I never got your WhatsApp message!").
- Problem: Hard to prove in court (no digital receipt).
- Solution: Use read receipts (IMAP) + timestamps (but these can be spoofed).
- Real Example: A Daraz seller claims "I never got your cancellation request!" → S/MIME-signed emails can prove the email was sent.
Q2: "Compare S/MIME and PGP for email security."
Use the table above, then add:
- S/MIME is easier for businesses (integrated with Outlook).
- PGP is better for privacy (no central certificate authority).
Q3: "Illustrate the SSL/TLS handshake protocol."
Answer:
- ClientHello: Your browser sends supported encryption methods to the server (e.g.,
TLS_AES_256_GCM_SHA384). - ServerHello: The server picks a method (e.g.,
TLS_RSA_WITH_AES_128_CBC_SHA) and sends its digital certificate. - Key Exchange: Client and server generate a symmetric session key using RSA.
- Secure Session: All future messages are encrypted with AES-256.
## In the Real World
eSewa Transaction Emails
- Protocol: TLS 1.2 + S/MIME
- How it’s used: When you transfer ₹1000 to a friend, eSewa sends an encrypted email with:
- Sender:
no-reply@esewa.com(verified via DMARC). - Subject: "₹1000 sent to [Friend’s Name]".
- Signature: S/MIME proves it’s from eSewa (not a scammer).
- Sender:
WhatsApp Business for Pathao Drivers
- Protocol: End-to-End Encryption (E2EE)
- How it’s used: When a customer books a ride, the request appears as:
🔒 [Customer Name] → You: "Pick me up from Thapathali, ₹300" - Why it matters: Even Pathao’s servers can’t read your messages.
NEPSE Shareholder Alerts
- Protocol: S/MIME + DMARC
- How it’s used: When NEPSE sends a dividend notice:
- The email has a digital signature (verified via NEPSE’s public key).
- If the signature fails → scam alert (DMARC blocks it).
## Exam Tip
For protocol questions (TLS, S/MIME, PGP):
- Draw a 3-step flowchart (e.g., TLS handshake).
- Mention ports (SMTP: 25, IMAP: 143, TLS: 443).
For real-world examples:
- Always tie to Nepali companies (eSewa, Ncell, NEPSE).
- Example: "Like how Daraz uses OTPs in emails to prevent address spoofing..."
For threats (phishing, spoofing):
- List 3 red flags (e.g., mismatched URLs, urgent language).
- Compare with DMARC/SPF fixes.
For secure design:
- Use the 5 principles (MFA, integrity, encryption, passwords, training).
- Example: "A bank’s email system should use TLS for transit + S/MIME for signatures + DMARC to block spoofed alerts."
## Quick Revision Table
| Concept | Key Idea | Example in Nepal |
|---|---|---|
| TLS | Encrypts emails in transit | Gmail, WhatsApp, eSewa |
| S/MIME | Digital signatures for emails | NEPSE shareholder reports |
| PGP | Asymmetric encryption | Journalists, lawyers |
| DMARC | Stops spoofed emails | Ncell, NTC alerts |
| Phishing | Fake emails to steal data | "Your Khalti account is locked" |
| Spoofing | Fake sender addresses | "ntc@gov.np" → scammer |
Based on the TU BITM syllabus for Computer Security and Cyber Law (IT225), unit 12.
Discussion
Loading…