IT225 Computer Security and Cyber Law

Computer Security and Cyber LawUnit 1211 min read

Email Security Protocols: Encryption, Spoofing, Phishing & Secure Transactions

Unit 12 of Computer Security and Cyber Law explores email security threats (phishing, spoofing, malware), encryption protocols (S/MIME, PGP, TLS), secure email standards (SMTP, IMAP), and real-world applications like eSewa transaction alerts and WhatsApp end-to-end encryption. Learn how to design secure email systems,

TAKEAWAYS:

  • Email threats like phishing (fake eSewa login pages) and spoofing (Ncell SMS scams) exploit human trust—always verify sender addresses and links.
  • TLS/SSL (used by Gmail, WhatsApp) encrypts emails in transit, while S/MIME and PGP add digital signatures for non-repudiation in legal contracts.
  • SMTP (port 25) and IMAP (port 143) handle delivery and storage, but DMARC/DKIM prevent spoofing in Kathmandu traffic route notifications.
  • Secure email design requires multi-factor authentication (like Daraz OTPs), message integrity checks, and proactive password policies.
  • Exam focus: Trace TLS handshakes, compare S/MIME vs. PGP, and explain how denial-of-receipt (e.g., "read receipts" in WhatsApp) fails in cyber law.
  • Real-world tie: NEPSE stock alerts use signed emails to prevent fraud; a spoofed "NEPSE update" could crash share prices if clicked.

1. Why Email Security Matters: Threats in Nepal’s Digital Life

Email is the #1 attack vector for cybercrime in Nepal. 90% of data breaches start with a phishing email (IBM 2023). Even eSewa, Khalti, and Ncell face spoofed SMS/email scams daily. Let’s break down the risks:

A. Common Email Attacks (With Nepali Examples)

Fake login pages (e.g., eSewa, Ncell)Urgent 'verify account' emails (e.g., 'Your NEPSE dividend iExample: 'Your eSewa balance is locked!' (with fake NTC logoPhishingFake sender address (e.g., 'ntc@gov.np' → 'ntc@gov.np.scam')Example: 'Ncell: Your SIM is blocked' from unknown senderLookalike domains (e.g., 'esewa.com.ne' → 'esewa.com.ne.scamSpoofingMalicious attachments (PDFs, EXEs, DOCX with macros)Example: 'Tax refund form.docx' (fake NEPSE dividend slip)Drive-by downloads (e.g., 'Click here to unlock your accountMalwareFake 'read receipts' (e.g., 'Your email was read at 3 AM')Example: WhatsApp 'last seen' spoof (e.g., 'You were seen tySocial engineering: 'Your boss sent this at midnight!'Denial of ReceiptCommon Email Attacks in Nepal
Hierarchy of common email attacks with Nepali-specific examples (simplified for clarity)

Key red flags in Nepali scams:

  • Urgent action: "Your Khalti account will be suspended in 24 hours!"
  • Mismatched URLs: Hover over links—does khalti.com.ne.scam appear?
  • Generic greetings: "Dear User" instead of your name.
  • Attachments: Never open .exe or .zip files from unknown senders.

2. Email Security Protocols: How Gmail, WhatsApp, and Banks Protect You

Protocols are the "locks" on email. Here’s how they work in real systems:

A. Transport Layer Security (TLS/SSL)

What it does: Encrypts emails in transit (like a sealed envelope). Used by Gmail, WhatsApp, and eSewa. How it works:

  1. Handshake: Your device and the server agree on an encryption key (like shaking hands before a secret meeting).
  2. Encryption: Data is scrambled using symmetric keys (AES-256).
  3. Integrity check: A hash (like a fingerprint) ensures no one tampered with the email.
1995SSL 2.0(deprecated, vulnerabl1996SSL 3.0 (weak,replaced by TLS)1999TLS 1.0 (firstsecure version)2018TLS 1.3 (currentstandard, faster, more2023Nepal banks adoptTLS 1.3 (e.g., NMB, Gl
Evolution of TLS/SSL protocols and adoption in Nepal

Worked Example: WhatsApp End-to-End Encryption

  • Scenario: You send a Daraz order confirmation to your friend.
  • Without TLS: Hackers on public Wi-Fi (e.g., at Thamel cafés) can read your order details.
  • With TLS: Even if intercepted, the message appears as gibberish:
    Original: "Your order #12345 is shipped via Ncell."
    Encrypted: "🔒 7F#9K$L2!@#QWERTY... 🔒"
    
Feature S/MIME (Used by Outlook, Yahoo) PGP/GPG (Used by journalists, lawyers)
Encryption Symmetric (AES) + RSA Asymmetric (RSA) + Symmetric (AES)
Key Management Certificates (like a digital ID card) Public/Private key pairs (you manage)
Use Case Business emails (e.g., NEPSE reports) Secure messaging (e.g., whistleblowers)
Ease of Use Built into email clients Requires manual setup (e.g., GPG tools)

Worked Example: NEPSE Shareholder Alerts

  • Problem: A hacker spoofs an email from NEPSE saying "Your dividend is delayed—click to claim."
  • Solution: Use S/MIME-signed emails:
    1. NEPSE’s server signs the email with its private key.
    2. Your email client verifies the signature using NEPSE’s public key.
    3. If the signature fails → scam alert!

3. Secure Email Delivery: SMTP, IMAP, and DMARC

A. Protocols for Sending and Receiving Emails

Protocol Port Role Security Risk Fix
SMTP 25 Sends emails Spoofing, open relays Use DMARC
IMAP 143 Downloads emails Man-in-the-middle TLS encryption
POP3 110 Downloads emails No sync, insecure Avoid; use IMAP

B. DMARC, DKIM, and SPF: Stopping Spoofed Emails

  • SPF: Lists authorized servers (e.g., v=spf1 include:_spf.khalti.com ~all).
  • DKIM: Adds a digital signature to prove the email wasn’t altered.
  • DMARC: Tells servers what to do if SPF/DKIM fails (e.g., "Quarantine this email").

Worked Example: Ncell SMS Spoofing

  • Attack: Scammer sends "Your Ncell bill is ₹5000—pay here: [fake link]" from ncell@bill.com.
  • Defense:
    1. SPF check: Is ncell@bill.com authorized to send emails for Ncell? → No → Block.
    2. DKIM check: Does the email have Ncell’s signature? → No → Quarantine.

4. Secure Email Design: Principles for IT Managers

To build a secure email system (like for a bank or e-commerce site), follow these 5 principles:

mindmap
  root((Secure Email Design))
    Principle1[(Multi-Factor Authentication)]
      Example: eSewa OTP + Fingerprint
    Principle2[(Message Integrity)]
      Tools: Hashing (SHA-256), Digital Signatures (S/MIME)
    Principle3[(Encryption in Transit)]
      Protocol: TLS 1.3
    Principle4[(Proactive Password Policies)]
      Rules: 12+ chars, no reuse, 90-day expiry
    Principle5[(User Training)]
      Example: Simulate phishing attacks (like NTC’s cybersecurity drills)

Worked Example: Daraz Order Queue System

  • Problem: A hacker intercepts your order confirmation email and changes the shipping address.
  • Solution:
    1. TLS: Encrypts the email in transit.
    2. S/MIME: Daraz’s server signs the email with its private key.
    3. OTP: Your order confirmation includes a one-time password (e.g., DARAZ-12345) that must be entered on Daraz’s website to confirm.

5. Email Security in Nepal: Case Studies

A. eSewa Transaction Alerts

  • Protocol Used: TLS 1.2 (for encryption) + SMS OTP (for authentication).
  • Why It Works:
    • Your transaction details (e.g., "₹500 sent to XYZ") are encrypted.
    • The OTP ensures even if the email is intercepted, the hacker can’t complete the transaction.

B. WhatsApp Business (for Pathao Drivers)

  • Protocol Used: End-to-End Encryption (E2EE) + Signal Protocol.
  • Why It Matters:
    • Pathao drivers receive ride requests securely.
    • Even WhatsApp employees can’t read your messages.

C. NEPSE Shareholder Communications

  • Protocol Used: S/MIME-signed emails + DMARC policies.
  • Why It’s Critical:
    • Prevents spoofed "dividend claim" emails.
    • Investors can verify the email came from NEPSE’s official server.

6. Common Exam Questions & How to Answer Them

Q1: "Define denial of receipt. How does it relate to email security?"

Answer: Denial of receipt is a cyber law concept where the sender claims the recipient never received an email (e.g., "I never got your WhatsApp message!").

  • Problem: Hard to prove in court (no digital receipt).
  • Solution: Use read receipts (IMAP) + timestamps (but these can be spoofed).
  • Real Example: A Daraz seller claims "I never got your cancellation request!" → S/MIME-signed emails can prove the email was sent.

Q2: "Compare S/MIME and PGP for email security."

Use the table above, then add:

  • S/MIME is easier for businesses (integrated with Outlook).
  • PGP is better for privacy (no central certificate authority).

Q3: "Illustrate the SSL/TLS handshake protocol."

Answer:

  1. ClientHello: Your browser sends supported encryption methods to the server (e.g., TLS_AES_256_GCM_SHA384).
  2. ServerHello: The server picks a method (e.g., TLS_RSA_WITH_AES_128_CBC_SHA) and sends its digital certificate.
  3. Key Exchange: Client and server generate a symmetric session key using RSA.
  4. Secure Session: All future messages are encrypted with AES-256.

## In the Real World

  1. eSewa Transaction Emails

    • Protocol: TLS 1.2 + S/MIME
    • How it’s used: When you transfer ₹1000 to a friend, eSewa sends an encrypted email with:
      • Sender: no-reply@esewa.com (verified via DMARC).
      • Subject: "₹1000 sent to [Friend’s Name]".
      • Signature: S/MIME proves it’s from eSewa (not a scammer).
  2. WhatsApp Business for Pathao Drivers

    • Protocol: End-to-End Encryption (E2EE)
    • How it’s used: When a customer books a ride, the request appears as:
      🔒 [Customer Name] → You: "Pick me up from Thapathali, ₹300"
      
    • Why it matters: Even Pathao’s servers can’t read your messages.
  3. NEPSE Shareholder Alerts

    • Protocol: S/MIME + DMARC
    • How it’s used: When NEPSE sends a dividend notice:
      • The email has a digital signature (verified via NEPSE’s public key).
      • If the signature fails → scam alert (DMARC blocks it).

## Exam Tip

  1. For protocol questions (TLS, S/MIME, PGP):

    • Draw a 3-step flowchart (e.g., TLS handshake).
    • Mention ports (SMTP: 25, IMAP: 143, TLS: 443).
  2. For real-world examples:

    • Always tie to Nepali companies (eSewa, Ncell, NEPSE).
    • Example: "Like how Daraz uses OTPs in emails to prevent address spoofing..."
  3. For threats (phishing, spoofing):

    • List 3 red flags (e.g., mismatched URLs, urgent language).
    • Compare with DMARC/SPF fixes.
  4. For secure design:

    • Use the 5 principles (MFA, integrity, encryption, passwords, training).
    • Example: "A bank’s email system should use TLS for transit + S/MIME for signatures + DMARC to block spoofed alerts."

## Quick Revision Table

Concept Key Idea Example in Nepal
TLS Encrypts emails in transit Gmail, WhatsApp, eSewa
S/MIME Digital signatures for emails NEPSE shareholder reports
PGP Asymmetric encryption Journalists, lawyers
DMARC Stops spoofed emails Ncell, NTC alerts
Phishing Fake emails to steal data "Your Khalti account is locked"
Spoofing Fake sender addresses "ntc@gov.np" → scammer

Based on the TU BITM syllabus for Computer Security and Cyber Law (IT225), unit 12.

Discussion

Loading…