Tag Archives: organisations

Welche Dienste Firmen besser nutzen und welche nicht

Im privaten Leben nutzen in der Schweiz nach Schätzungen der Neuen Zürcher Zeitung rund sechs Millionen Menschen der acht Millionen Einwohner den Nachrichtendienst Whatsapp. In Deutschland und Österreich werden die Werte wohl ähnlich hoch sein. Diese Art der Kommunikation ist so selbstverständlich, dass immer mehr auch Unternehmen mit ihren Mitarbeitern und Kunden über Whatsapp kommunizieren möchten: Bildnachrichten einer zu reparierenden Stelle, Details zu einem gebuchten Flug oder auch Direktwerbung.

Der bekannte Nachrichtendienst erlaubt die betriebliche Nutzung explizit und bietet für KMU eine Business-Version und für Grossunternehmen eine Schnittstelle (API) an. Die Liste der Vorteil ist lang: unkompliziert, direkt, kürzere Entscheidungswege, kostengünstiger Kundenservice, etc. – was will man noch mehr? Doch seit 2017 verbieten immer mehr Unternehmen ihren Mitarbeitern Whatsapp zu benutzen, denn im Geltungsbereich der EU-Datenschutzgrundverordnung gilt, dass personenbezogene Daten ohne Einwilligung der betroffenen Person weder erhoben noch verarbeitet werden dürfen. Die drohenden Bussen in der Höhe von mehreren Millionen Euro, will sich keine Firma leisten.

Das Problem liegt in der Betriebsweise des Nachrichtendienstes. Er liest regelmässig die Adressbücher seiner Nutzer aus, um diese mit seiner Datenbank abzugleichen. So kann er Kontakte, die neu den Dienst nutzen anzeigen. Nur eine Einwilligung haben die nie gegeben. Ergo handelt es sich um einen Verstoss gegen die Datenschutzgrundverordnung, welche auch für Unternehmen gilt, die nur einen einzigen Kontakt in der EU haben. Wenn es sich entweder um ein Diensttelefon handelt oder um ein privates, auf dem mit Einwiligung der Firma Geschäftskontakte gespeichert sind, haftet die Firma. Wenn die Mitarbeiter ihr eigenes Gerät im Geschäft nutzen, darf keine Synchronisation mit den Datenverarbeitungssystemen stattfinden. So verarbeitet der Mitarbeiter ohne Erlaubnis des Arbeitgebers personenbezogene Daten und ist dann selber für mögliche Gesetzesverstösse haftbar.

Möchte man den Nachrichtendienst datenschutzkonform nutzen, müsste man zwei getrennte Adressbücher haben, ein internes, indem sich ausschliesslich Personen befinden, die nachweislich der Weitergabe ihrer personenbezogenen Daten an Whatsapp zugestimmt haben. Die Neue Zürcher Zeitung schrieb dazu: “Eine weitere Möglichkeit ist der Einsatz eines DSGVO-konformen Messengers im Unternehmen. Der Nachteil dieser Lösung ist allerdings, dass solche Messenger bis zum jetzigen Zeitpunkt noch nicht weit verbreitet sind und damit im Kontakt zu Kunden kaum einsetzbar sind.”

Und die Lösung? Sie entspricht der Quadratur des Kreises und ist etwa so einfach wie die Browserintegration von CAcert in den nächsten 12 Monaten. Trotzdem lohnt es sich, sich gerade im Jahr 2026 damit zu beschäftigen, wie man in seiner Firma mit personenbezogenen Daten umgeht. Die ersten Unternehmen, die praktikable und einfach umsetzbare Lösungen finden können sich so einen Wettbewerbsvorteil erarbeiten, denn “Sicherheit ist nicht alles, aber ohne Sicherheit ist alles nichts.” (Schopenhauer)

Mit der Datenschutzgrundverordnung konforn ist der Versand verschlüsselter und signierter e-Mails. Mit der Organisations-Assurance bietet CAcert für Firmen eine einfach und praktisch umsetzbare Lösung an. Der systematische Versand digitale signierter e-Mails bietet den Kunden die Möglichkeit, die Nachrichten klar von Spam und Phishing zu unterscheiden. Die Verschlüsselung interner e-Mails erhöht die Sicherheit und ist technisch einfach umzusetzen, indem die IT-Abteilung die entsprechenden Zertifikate ausrollt.

Quelle: NZZ, 31.12.2018

Security is not everything, but without security everything is nothing

According to estimates, around six million people of the eight million inhabitants in Switzerland use the Whatsapp news service in their private lives. In Germany and Austria, the figures will probably be similarly high. This type of communication is so self-evident that more and more companies want to communicate with their employees and customers with Whatsapp: Picture messages of a place to be repaired, details of a booked flight or even direct advertising.

The well-known news service explicitly allows operational use and offers a business version for SMEs and an interface (API) for large companies. The list of advantages is long: uncomplicated, direct, shorter decision paths, cost-effective customer service, etc. – what more do you want? Since 2017, however, more and more companies have prohibited their employees from using Whatsapp, as the basic EU data protection regulation stipulates that personal data may neither be collected nor processed without the consent of the person concerned. No company wants to afford the imminent fines of several million euros.

The problem lies in the way the messsanger service operates. It regularly reads the address books of its users in order to compare them with its database. In this way he can display contacts that are new to the service. They have never given their consent. This is therefore a violation of the general data protection regulation, which also applies to companies that have only one contact in the EU. If it is either a service telephone or a private one on which business contacts are stored with the consent of the company, the company is liable. If the employees use their own device in the company, no synchronization with the data processing systems may take place. Thus, the employee processes personal data without the employer’s permission and is then liable for possible violations of the law.

If the intelligence service is to be used in compliance with data protection regulations, there must be two separate address books, one internal, with only those persons who have given their consent to the transfer of their personal data to Whatsapp. Another possibility is the use of a GDPR-compliant messenger in the company. The disadvantage of this solution, however, is that such messengers have not yet become widespread and can therefore hardly be used in contact with customers.

And the solution? It corresponds to squaring the circle and is about as simple as the browser integration of CAcert in the next 12 months. Nevertheless, it is worthwhile, especially in the year 2019, to deal with how one deals with personal data in one’s company. The first companies to find practicable and easily implementable solutions can gain a competitive advantage, because “Security is not everything, but without security everything is nothing”. (Schopenhauer)

The sending of encrypted and signed e-mails is in compliance with the general data protection regulation. With the Organisation Assurance Programme, CAcert offers companies a simple and practical solution. The systematic sending of digitally signed e-mails offers customers the opportunity to clearly distinguish messages from spam and phishing. The encryption of internal e-mails increases security and is technically easy to implement, as the IT department rolls out the corresponding certificates.

Source: NZZ, 31.12.2018

Donate the running costs of allmost one day (5€)     Donate as much as you want                     Donate the running costs of one week (50€)                                                                                    IBAN DE50 2019 0003 0008 5478 07 “CAcert”

Creating client certificates with CSR now possible for Org Accounts

A fix for a long standing issue has recently been installed at the CAcert main server: Now finally it’s possible to create a client certificate from a Certificate Signing Request (CSR) in the user interface for Organisation (Org) Accounts.

For those who don’t have an idea what I am talking about, an Org Account is a user interface for administrators of companies and other organisations who got themselves assured with a CAcert Org Assurance.

Until recently, client certificates in an Org Account could only be created by using the browser feature to create a key pair and signing request in one go. This usually has the consequence that the administrator has access to the private key of the certificate, and has to send the private key and a password (hopefully secure) to the user the certificate is intended for.

While this is not that unusual in an organisation environment, it is not considered a clean solution.

The new feature to create a certificate from a CSR now allows much better solutions. Not only that the administrator does not need access to the end user’s private key at all, it’s now possible to create solutions where an organisation end user can create her own keys and CSR at the organisation’s website, while the administrator only confirms the validity of the request, gets the certificate from CAcert and posts it on a website for the user to download into her browser.

Especially in company settings CAcert certificates can productively used even though the root certificate is not included in browsers by default. Many companies use private CAs, for example to issue certificates which allow employees to securely log on to web applications. Now it’s possible to outsource the CA management to CAcert and just use an Org Account to issue certificates.

In my opinion CSR certificate creation is an important step to make CAcert certificates much more practical to use in company settings! Thanks to everyone involved in implementing this feature!