Sign up here to receive our top 10 email security hot tips

Frequently Asked Questions

We hope to answer any question you have through this page. If you need clarification on anything or have further queries please get in touch using the details on our contact page.

 

 

1. I can encrypt my files, what's wrong with that ?
Encrypting a file does not make it secure for sending via email. See our White Paper. In general, Email security = encryption + authentication.


top2. Why do other products require me to buy and register a Digital Certificate ?
These products use Public Key Cryptography and rely on a central agency (such as the certificate vendor) to perform the function of verifying your physical identity. Having done this the certificate binds your physical to your electronic identity. It also costs money. See White Paper.

In PTP there is no central agency. PTP provides a simple means for Secure Contact members to perform this function. The other functions required of a certificate are embedded in PTP but hidden from the user.


3. Why is PTP referred to as “Personal Software” ?
Because it doesn’t need to be “installed” which makes it easily portable. You can run it from a memory stick on any PC without installing anything on the PC.


top4. What if I want to send secure files to someone who doesn’t have PTP ?
Anyone wishing to receive encrypted files from you needs PTP and must have send you their 'MyPublicKey' file for you to encrypt for them. An unlimited number of decryptions (via Certify function) are possible with the Demo version.


5. Will PTP integrate with Outlook
Yes PTP can be fully integrated with Microsoft Outlook and Outlook Express. This means simply that you see an extra row of control buttons in Outlook to control the encryption and decryption of emails. The ability to fully integrate PTP with Outlook means that anyone who can use email can easily use encryption with minimal training.

Note that PTP runs on the users PC and not on the Exchange Server. This is because the encryption is literally “Person to Person”. It also means that there are no administrative overheads.


top6. When I have sent a secure email with PTP should I request a receipt ?
It is always good practice to send a receipt for a document whether you are using PTP or not. If it is important to know that the recipient has received the precise document that you sent, ask them to perform the Sign function on the document and send it back to you. You can then certify this and compare the result with your original file.


7. What's wrong with using Microsofts S/MIME ?
You should evaluate it for cost, ease of use, level of security and vulnerabilities. PTP has achieved major improvements in all these areas. One problem is that you need to purchase and register a Digital Certificate.


top8. What's preventing me from giving away licensed copies of PTP ?
Anyone receiving a licensed copy from you will have to use your exact User ID,which is pointless as it invalidates all your security. There are safeguards preventing two users with the same name from communicating with each other.


9. What are Privacy Groups in PTP ?
Secure Contacts in one Privacy Group cannot interact with those in another group. Privacy groups are reserved for individual customers who have special requirements. They are covered by bespoke software releases.


top10. Can I zip the encrypted files before sending ?
Yes. We recommend it if you want to email more than 5 files at once.


11. Can I use PTP from a memory stick ?
Yes. Just copy PTP.exe and the Data.ptp folder onto a blank memory stick. Use the Windows Run box to run it from the stick, e.g. E:\PTP.exe


top12. Are there any back doors to PTP ?
None. Not for the author or anyone else.


13. How strong is the encryption ?
The longest RSA (Public Key) key length in current internet use is 256 bits. The length used in PTP is 384 bits, better than a trillion trillion trillion times longer.The bulk of file encryption is carried out using a symmetric algorithm. As a comparison, AES uses a block length of 128 bits and a maximum key size of 256bits. PTP uses a block length of 512 bytes and a key size of 383 bits.


top14. Do you keep any information about the users of PTP ?
We will keep the barest possible information on users consistent with providing the contracted service. As part of the contract of sale, PTP suppliers undertake to use the information for no other purpose, nor disclose this information to any other party under the terms of the Data Protection Act.


15. Does PTP leave any trace of its activity on my PC ?
No intermediate plaintext files are created on disc. PTP does not access the Registry.If installed on a PC disc it PTP generates and maintains data in folders and subfolders encapsulated in the folder structure.If used with a memory stick, no files or data of any kind are written to the PC hard disc. On termination of a session, all traces of confidential data are removed from the PC RAM.


top16. What if I forget my password ?
You will have the start again with the Setup procedure and your new password. Each Secure Contact you send something to after this will be warned of a possible fraud and to contact you by phone or e-mail to reconfirm the link between your human and electronic identities. PTP provides a procedure for this.


17. Can I re-install PTP with a new User ID and the same licence key ?
This is only possible with the FREE License version. With the FULL License version you must use the exact User ID you provided at purchase.


top18. What happens if I change my password ?
You can change your password and there is a procedure for it. At next contact each Secure Contact will be prompted to contact you by phone or e-mail to confirm the link between your human and electronic identities.


19. Can the authors of PTP de-crypt my files ?
It is not possible to do this. This is a capability we do not want and the structure of the design makes it an absolute impossibility.


top20. What does “SIGN” do in PTP ?
SIGN means “Digitally Sign” the files in the InBox.ptp folder. Each file being signed is output to OutBox.ptp intact along with a Manifest file which contains the Digital Signature. At the other end the PTP user can prove that the files came from you. Signing also adds the sending correspondent to the list of secure contacts.


21. Does PTP write any data to my PC registry ?
No


top22. What DLL’s does PTP use ?
None on the 'Windows' version


23. What if my laptop is stolen with PTP on it ?
If your laptop was stolen while still switched on with PTP running you would be vulnerable . Otherwise there is no vulnerability: no secret keys or certificates of any kind are stored on the PC. If you have caught a key-logger virus and not followed anti-virus procedures, you might be at risk of disclosing your password.


top24. If I give someone my password can they de-crypt my files ?
You would have to set up the person with your Registration Code, your identity and your password. This person would replace you.


25. How does PTP compare with DES and AES ?
PTP uses a combination of Public Key and Symmetric Cryptography to achieve the objectives of a 'Public Key Infrastructure' for the secure transmission of e-mail attachments. Both DES and AES are Symmetric algorithms working on block sizes of 64 and 128 bits respectively. PTP uses a Symmetric Algorithm having a block size of 512 bits.


top26. How can I get maximum security from PTP ?
Choose a long password or passphrase with symbols and be sure to keep it safe. Think about using two or more random words as a password like apple engine. The fact that they are randomly selected makes the combination secure. Avoid any link to yourself.


27. How do I create a new secure contact ?
PTP will generate a signed file called 'MyPublicKey.txt'. Send this to your new Secure Contact with its Manifest.txt file. For the correspondent to be in your secure contacts list they must send you similar files.


top28. If I delete a secure contact how do I re-create them ?
Ask them to send you a 'MyPublicKet.txt' file and its Manifest.txt file.


29. What if two Secure Contacts have the same User Id ?
An Error will be flagged to the receiving correspondent and instructions displayed on how to resolve the issue.


top30. Is it best regularly to change my password ?
It should not be necessary to change you password for a very long time unless you suspect that someone else may know it. Changing your password involves some additional actions since all your Secure Contacts will know you have made a change.


31. Is it advisable to change my User Id frequently ?
You can't do it at all with the FULL License Version. You may experiment with the FREE version but it will cause confusion. Please consider the reasons for doing this.


top32. What is the best password length ?
The longest (32 maximum) and strongest you can remember. Use Upper and lower case characters, numbers, spaces and symbols, eg a phrase or a fictitious address. Spaces are accepted so you can have pass phrases.


33. Should my password contain numbers ?
Yes, it’s a good idea to stop it being guessed. Whole words and names alone can always be guessed more easily.


top34. Why are the encrypted files in text format ?
Firewall software is increasingly suspicious of files containing binary data or files which may contain macros. Although text files are longer it is apparent under examination that they are not harmful and therefore will be much less likely to be rejected or quarantined by firewalls. Also you can see for your self that the data is completely scrambled. Zipping it proves that the data distribution is flat as it always zips to the same 38% (approx) which is the limit for random data.


35. Can I just sign files and not encrypt ?
Yes. The files are not changed by this process. The signatures are contained in the Manifest file.


top36. Can I just encrypt files and not sign them ?
No. PTP insists on guaranteeing the integrity of a file by signing.


37. Can I encrypt my C: drive with PTP ?
No. PTP is primarily intended to encrypt files, a small number at a time, for transmission as e-mail attachments.
If you wish to encrypt files to keep on your PC you can select 'Myself' as the target from your Secure Contact List.
Please make sure you keep the file set from the OutBox for each operation (includes the Manifest file) together, either by making a dedicated folder or zipping them together.


top38. Can I encrypt an EXE (program) file ?
Yes. PTP outputs a text file which can be sent through firewalls and rebuilt by PTP at the other end. Its useful for getting binary files through to people in corporations who sit behind firewalls.


39. Can I protect my memory stick with PTP ?
This provides a useful way to manage tour confidential information. If you have PTP installed on a memory stick you can encrypt files, storing them in folders also on the stick. Large numbers of files can be zipped and the zip file can be encrypted onto the memory stick. You can then use any PC wherever you are and use PTP to recover the files without having to install anything on the PC. If you lose the memory stick no-one can recover you secret data.


top40. What affects the speed of encryption ?
The larger the file, the longer it takes to encrypt. PTP is pretty fast.


41. How many bits are used in the encryption ?
The Symmetric algorithm uses a 383-bit key, randomly selected for each file. This key is protected by an RSA key of 384 bits.


top42. Is the encryption algorithm published ?
The Public Key Cryptography RSA algorithm we use is an international specification.The PTP Symmetric algorithm uses techniques standard in the industry: Substitution, Permutation, Multiple Rounds, Cypher Block Chaining, Initialisation Vector.The Copyright for this algorithm was time-lined in 1985. It is not published because there is no intention of inter-operating with any party outside PTP. Another strong reason is that it presents another barrier in the security defense, not least involving reverse-engineering of the software, a significant additional barrier.


43. Has the encryption algorithm been tested ?
Yes over 20 years in real-life applications. The RSA encryption implementation has been used in the Payment Card Industries Chip and PIN programme. As such it has been certified after testing to EMV (Europay, MasterCard, Visa) Level 2 by laboratories approved by the banking authorities. The PTP Symmetric Algorithm has been subjected to similar quality
assurance procedures in-house.


top44. Is PTP compiled or interpreted code ?
PTP.exe is a Windows Dialog application compiled using the Microsoft C++ development platform. The intensive nature of cryptographic computation make it unfeasible to use interpretive code such as C# or Java.


45. What if my correspondents want to purchase PTP ?
They can buy direct or you can be a reseller to them and obtain a discount which you can elect to share with them if you wish.


top46. Is support included with the licence ?
Yes, for a small annual cost


47. Do I get software and documentation updates ?
Yes If you hold a current support and update contract


top48. Does PTP work on all Windows operating systems ?
Yes, from Windows 95 to Vista


49. Will PTP work on my palmtop PC ?
PTP is not currently supported on Windows Mobile or CE platforms.


top50. Can I share the use of PTP with a colleague ?
No, they will need their own copy. If they just want to RECEIVE from you they can use the FREE licence, otherwise they must purchase a FULL licence.


51. Can I keep re-installing PTP to take advantage of the initial demo period ?
It would be pointless in practice because each new install would create a different Public Key.


top52. What is the file limit which can be encrypted ?
PTP has been tested to a maximum of 1GB per file in the InBox.ptp for encryption. The ability to handle large file sizes means that PTP can be used to encrypt files for storing and transporting on CD/DVD. A 1GB file takes approximately 1 Hr to encrypt. Encryption is computationally intensive and the cpu is fully utilised during this process.


53. Why is the maximum number of InBox files 5 ?
Five files is regarded as a typical maximum for normal attachments. Also using a large number of files could lead to management problems and hence detract from the security. There is nothing to stop you zipping a number of files into one and processing this. Bear in mind any restrictions by email service providers on file sizes. The file size limit is 1 GB if you want to transport or store the encrypted files on CD or DVD.


top54. What if I want to move PTP and my Secure Contacts list ?
If you copy PTP.exe and the Data.ptp folder to a memory stick you transfer your licence details and your secure contacts list. We recommend that you have PTP in two locations – on your main PC and on a usb memory stick for traveling. Secure Contacts are added to the main PC copy and are easily transferred to the memory stick by copying the Data.ptp folder over.


55. Why does the application appear to freeze when encrypting long files?
Many applications, notably some anti-virus services, which do not allow you to do anything with the application while installing new data files. This is to prevent any of a number of unsatisfactory outcomes including a half-updated database which appears OK. PPT adopts the same policy. If you wish to encrypt very large files you are able to do so but you must be assured that the outcome is a guaranteed secure result. You will be able to use other PC applications while PTP operates although the PTP window will not re-paint until the function is complete.


top56. What are Privacy Groups ?
Privacy Groups are groups of PTP users who can communicate with each other using PTP but no-one outside the group can read their files. Privacy Group 1 is “the world” and is the default setting. To have a different privacy group we have to compile a special edition of the software at additional cost. This is often done by companies who want all their secured files to stay “in house”.

 

© 2012 Taktik Solutions Ltd. All rights reserved. All trademarks acknowledged.