Are email links to access secure messages without a password secure? How?
The purpose of encryption to protect your data against a data breach (data theft).
The link to access a message (without a password) expires after 4 days (or the number of days you set under your compliance settings). So if your clients’ email data is stolen (e.g. if the server or a computer storing their emails is stolen), most such links would have expired by then. Only the most recent messages will be vulnerable.
- Even for those unexpired messages, the secure message content and files are not included in the email data. So automated software tools that data thieves use to extract sensitive data such as SSNs or financial account details from the stolen email data will not find it.
- Each link only gives access to one message and not all messages received by that client. This limits the amount of data leaked.
There is often a trade-off between security and ease of use. Depending on the nature of threats and data involved, you have to decide where you draw the line. Making secure messages too difficult for your users may also cause some users to revert to just using email and losing the protection from encryption altogether.
Can I Tighten Security?
If you are not comfortable with the above, consider the following options:
- Disable access without passwords: see Require Recipients to Use a Password.
- Make the message access links expire sooner: see Change Expiry Duration.
Related articles
-
How can I change my username or email?
How do I change my email address? Changing the email address changes: the email address you use as your username for login, the email address used in case...
-
Why are secure message links sent via email secure?
If you have received an email with a link to access secure files and are wondering: How does using the link protect your data (even though no password is a...
-
Can I login to two Encyro accounts at the same time?
Yes. When logged in with one account, you will see the current email address used for login near the top right corner of the Encyro web page (on a mobile ...
-
Can't create an account in Safari?
I cannot create an account in Safari, why? My client tried to access their message in Safari but nothing showed up. It is likely that you or your client we...
-
Change My Email Address
I ended up using an email address different from what I would like. Can I change that? I am moving from a free email address to a new email address on my ...
-
Can I Avoid Having to Login Each Time?
If you are being asked to login every time you visit your Encyro account, it is likely that you or your organization's compliance settings have enforced au...
-
What is Email Verification?
Email verification helps ensure that someone using an email address to sign up for an Encyro account also has access to that email account. This helps prev...
-
Why can't my recipients open my secure messages?
Some of the people that I send Encyro messages to keep saying that they cannot open my secure message. It seems to work for some others. What is going on? ...
-
Can my client reply securely to my secure message?
If I send a secure message to someone, can they send me an encrypted response? Can my recipients send an encrypted message to me? If I send an encrypted em...