Snedd
Well-Known Member
One thing I'm seeing more and more is companies that I have to deal with either requesting or sending sensitive information via email. My view of email is that its the electronic equivalent of a post card in that its relatively insecure and easy to read as it passes through and gets stored on various mail routing devices on its way to your inbox.
For example I was recently trying to track down an old pension from my very first job. The company now administering the pension asked me to send various pieces of information including national insurance number and address history to prove I was who I said I was, via email. My attitude to this is that if it proves to them that I am me, then it can also be used by someone else to pretend to be me. I asked the company involved if they had a PGP or GPG key so I could encrypt the email. When they said no I ended up asking for a postal address instead.
I'm now in a situation where my accountant (I'm self employed) is going to start sending all monthly and quarterly documents out via email instead of post. This will include payslips, profit and loss statements, details of tax to be paid, etc. I'm think of making a fuss and insisting that they either:
ask me for a PGP/GPG key and encrypt the mail before sending it
or
allow me to opt out and continue to receive documents in the post
or
if none of the above I bin them and use a different accountants.
Am I being overly paranoid?
For example I was recently trying to track down an old pension from my very first job. The company now administering the pension asked me to send various pieces of information including national insurance number and address history to prove I was who I said I was, via email. My attitude to this is that if it proves to them that I am me, then it can also be used by someone else to pretend to be me. I asked the company involved if they had a PGP or GPG key so I could encrypt the email. When they said no I ended up asking for a postal address instead.
I'm now in a situation where my accountant (I'm self employed) is going to start sending all monthly and quarterly documents out via email instead of post. This will include payslips, profit and loss statements, details of tax to be paid, etc. I'm think of making a fuss and insisting that they either:
ask me for a PGP/GPG key and encrypt the mail before sending it
or
allow me to opt out and continue to receive documents in the post
or
if none of the above I bin them and use a different accountants.
Am I being overly paranoid?