• HOME
  • NEWS
  • EXPLORE
    • CAREER
      • Companies
      • Jobs
    • EVENTS
    • iGEM
      • News
      • Team
    • PHOTOS
    • VIDEO
    • WIKI
  • BLOG
  • COMMUNITY
    • FACEBOOK
    • INSTAGRAM
    • TWITTER
Tuesday, August 26, 2025
BIOENGINEER.ORG
No Result
View All Result
  • Login
  • HOME
  • NEWS
  • EXPLORE
    • CAREER
      • Companies
      • Jobs
        • Lecturer
        • PhD Studentship
        • Postdoc
        • Research Assistant
    • EVENTS
    • iGEM
      • News
      • Team
    • PHOTOS
    • VIDEO
    • WIKI
  • BLOG
  • COMMUNITY
    • FACEBOOK
    • INSTAGRAM
    • TWITTER
  • HOME
  • NEWS
  • EXPLORE
    • CAREER
      • Companies
      • Jobs
        • Lecturer
        • PhD Studentship
        • Postdoc
        • Research Assistant
    • EVENTS
    • iGEM
      • News
      • Team
    • PHOTOS
    • VIDEO
    • WIKI
  • BLOG
  • COMMUNITY
    • FACEBOOK
    • INSTAGRAM
    • TWITTER
No Result
View All Result
Bioengineer.org
No Result
View All Result
Home NEWS Science News Science

New app can secure all your saved emails

Bioengineer by Bioengineer
March 26, 2019
in Science
Reading Time: 5 mins read
0
Share on FacebookShare on TwitterShare on LinkedinShare on RedditShare on Telegram

IMAGE

Credit: John S. Koh/Columbia Engineering

New York, NY–March 26, 2019–While an empty email inbox is something many people strive for, most of us are not successful. And that means that we probably have stored away hundreds, even thousands, of emails that contain all kinds of personal information we would prefer to keep private.

Current defenses, such as Pretty Good Privacy (PGP) and Secure/Multipurpose Internet Mail Extensions (S/MIME), rely on public key cryptography that uses pairs of public and private keys generated by cryptographic algorithms. Because these systems are too technical and difficult for the average user, most people don’t use them. As a result, many email accounts have been hacked, including such high profile cases as the phishing attack on Hillary Clinton’s top campaign advisor John Podesta and the 2016 email hack of one of Vladimir Putin’s top aides.

In response to these kinds of widespread attacks, computer scientists at Columbia Engineering have built Easy Email Encryption (E3), an application for secure, encrypted email that is easy to manage even for non-technical users. Now in beta test mode, E3 automatically and invisibly encrypts email as soon as it is received on any trusted device, including smartphones, laptops, and tablets. It works on a variety of platforms including Android, Windows, Linux, and Google Chrome, and with popular mail services such as Gmail, Yahoo, AOL, and more.

The team–Professors Jason Nieh and Steve Bellovin and their PhD student John S. Koh–presented its study today at EuroSys ’19 in Dresden, Germany, one of the world’s top forums focused on computer systems software research and development.

“Email privacy grows ever more critical as our email inboxes increase in size,” notes Koh, the paper’s lead author. “Thanks to free and widely popular mail services like Gmail, users are keeping more and more emails, thus providing a one-stop shop for hackers who can compromise all of a user’s emails with a single successful attack.”

Ever since 1999, when the seminal “Why Johnny Can’t Encrypt” paper showed how extraordinarily hard it was for people to send encrypted email, researchers have been trying to design encryption systems that are easier for the average user to manage. The problem is that they have stayed focused on end-to-end encryption solutions, where only the original sender and recipient can read the messages. Third-parties, including telecommunications and Internet providers, cannot eavesdrop as they cannot access the cryptographic keys to decrypt the conversation. While these solutions certainly work and offer the most security, PGP and S/MIME, the encryption solutions most favored by experts, are so complex that they are impractical, almost unusable, for a non-technical user.

“The field of email security is just begging for improvement,” Koh notes. “For 20 years, the research community was fixated on end-to-end security. We took a different tack, positing that end-to-end encryption for email is not needed in the 21st century. Internet connections are increasingly protected by default using encryption. Our insight is that email needs to be protected when it’s stored in our inboxes, not when it’s being sent over the Internet, because hackers are mainly just trying to log into your email account. We thus apply an ‘encrypt on receipt’ model that provides excellent real-world security while being far more usable than end-to-end encryption.”

Over the past three years, the Columbia Engineering team refined E3, trying many different approaches before finding a method that checked all the boxes they needed. They have been testing the app with a couple dozen study participants, many of whom were not particularly tech-savvy. All agreed that E3 is significantly easier to use than the state-of-the-art systems for secure email, to the point where E3 is almost as easy to use as a regular email client.

The team’s new approach simplifies email encryption and improves its usability by implementing receiver-controlled encryption. Newly received messages are transparently downloaded and encrypted to a locally generated key and the original message is then replaced. A major problem was how to handle multiple devices, especially important these days as most people read email on several devices. Rather than moving private keys around, which is hard to do securely and puts great demands on the user, the researchers used per-device key pairs. With this approach, only public keys need to be synchronized via a simple verification step. Hackers who successfully attack an email account or server can only gain access to encrypted emails. All emails encrypted prior to a breach are protected.

In E3, public keys are never shared with other people. They are self-generated and self-signed, and require no public key infrastructure for the user to understand. Previous work has shown that users find it confusing to correctly obtain and use public keys. In contrast, an E3 user needs only self-signed keys, and any public key exchanges among the user’s devices are automated.

The researchers note that they do not intend E3 to be an end-to-end, maximum security solution, but rather a major improvement over the norm that is easy to deploy and use. Says Koh, “We traded perfection–end-to-end, sender-controlled encryption–for a significant increase in usability and the ability to protect what we now know is the real problem for most people.”

The team is refining E3 and making its implementations–the actual applications–even easier to use by trying new approaches applicable to the modern user. They plan to make it available in the near future for Android users as an app freely available in the Google Play Store. An iOS version is also in the works.

###

About the Study

The study is titled “Why Joanie Can Encrypt: Easy Email Encryption with Easy Key Management.”

Authors are: John S. Koh, Steven M. Bellovin, and Jason Nieh, Department of Computer Science, Columbia Engineering.

This work was supported in part by National Science Foundation grant CNS-1717801.

LINKS:

Paper: https://www.cs.columbia.edu/~koh/papers/koh-eurosys19-e3_easy_email_encryption-final.pdf

DOI: https: //doi.org/10.1145/3302424.3303980

http://www.cs.columbia.edu/

http://engineering.columbia.edu/

https://www.cs.columbia.edu/~koh/

http://www.cs.columbia.edu/~nieh/

https://engineering.columbia.edu/faculty/steven-bellovin

https://www.eurosys2019.org/

Columbia Engineering

Columbia Engineering, based in New York City, is one of the top engineering schools in the U.S. and one of the oldest in the nation. Also known as The Fu Foundation School of Engineering and Applied Science, the School expands knowledge and advances technology through the pioneering research of its more than 220 faculty, while educating undergraduate and graduate students in a collaborative environment to become leaders informed by a firm foundation in engineering. The School’s faculty are at the center of the University’s cross-disciplinary research, contributing to the Data Science Institute, Earth Institute, Zuckerman Mind Brain Behavior Institute, Precision Medicine Initiative, and the Columbia Nano Initiative. Guided by its strategic vision, “Columbia Engineering for Humanity,” the School aims to translate ideas into innovations that foster a sustainable, healthy, secure, connected, and creative humanity.

Media Contact
Holly Evarts
[email protected]

Related Journal Article

http://dx.doi.org/10.1145/3302424.3303980

Tags: Computer ScienceTechnology/Engineering/Computer Science
Share12Tweet8Share2ShareShareShare2

Related Posts

Five or more hours of smartphone usage per day may increase obesity

July 25, 2019
IMAGE

NASA’s terra satellite finds tropical storm 07W’s strength on the side

July 25, 2019

NASA finds one burst of energy in weakening Depression Dalila

July 25, 2019

Researcher’s innovative flood mapping helps water and emergency management officials

July 25, 2019
Please login to join discussion

POPULAR NEWS

  • blank

    Breakthrough in Computer Hardware Advances Solves Complex Optimization Challenges

    147 shares
    Share 59 Tweet 37
  • Molecules in Focus: Capturing the Timeless Dance of Particles

    142 shares
    Share 57 Tweet 36
  • New Drug Formulation Transforms Intravenous Treatments into Rapid Injections

    115 shares
    Share 46 Tweet 29
  • Neuropsychiatric Risks Linked to COVID-19 Revealed

    81 shares
    Share 32 Tweet 20

About

We bring you the latest biotechnology news from best research centers and universities around the world. Check our website.

Follow us

Recent News

Unveiling Genomic Insights for Glycemic Trait Drug Repurposing

New lncRNA PICSAR Drives Thyroid Cancer Progression

Transforming Patient Encounters with Relationship-Centered Care

  • Contact Us

Bioengineer.org © Copyright 2023 All Rights Reserved.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Homepages
    • Home Page 1
    • Home Page 2
  • News
  • National
  • Business
  • Health
  • Lifestyle
  • Science

Bioengineer.org © Copyright 2023 All Rights Reserved.