{"id":1137,"date":"2018-11-28T10:53:09","date_gmt":"2018-11-28T09:53:09","guid":{"rendered":"https:\/\/reddcrypt.hostpress.me\/?page_id=1137"},"modified":"2020-09-14T14:17:22","modified_gmt":"2020-09-14T12:17:22","slug":"technology","status":"publish","type":"page","link":"https:\/\/www.reddcrypt.com\/en\/technology\/","title":{"rendered":"Technical Overview \u2013 how REDDCRYPT works"},"content":{"rendered":"<div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-1 fusion-flex-container nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1040px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-0 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:15px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:15px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-1\"><h1 style=\"text-align: center;\"><span style=\"color: #cf000f;\">Technical overview<\/span><\/h1>\n<h2 style=\"text-align: center;\">\u00a0How REDDCRYPT works<\/h2>\n<p>REDDCRYPT is based on the PGP encryption method. This means that our solution works with a respective certificate pair &#8211; consisting of a private and a public key.\u00a0However we solve the biggest problem that the established standards have: they <strong>are not operable for a &#8220;normal&#8221; (non-technical) user!<\/strong><\/p>\n<p>The difference between REDDCRYPT and other solutions: The entire handling of the certificates takes place automatically in the background. No user ever has to deposit a certificate somewhere or even know how the technology works. And with this approach <strong>we make e-mail encryption usable for everyone<\/strong>!<\/p>\n<p>On this page we explain to you in detail and completely transparently how the encryption and decryption of REDDCRYPT works.<\/p>\n<\/div><\/div><\/div><\/div><\/div><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-2 fusion-flex-container nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-padding-top:1%;--awb-padding-bottom:2%;--awb-background-color:#172639;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1040px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-1 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-padding-top:30px;--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:15px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:15px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-2\"><h3 style=\"text-align: center;\"><span style=\"color: #ffffff;\">Quick overview: This happens at REDDCRYPT<\/span><\/h3>\n<\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-2 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:15px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:15px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-3\"><p><span style=\"color: #ffffff;\">REDDCRYPT automatically encrypts your emails on your device before they are being sent. Thus, your emails and their contents remain private. This way you can securely send sensitive information via email.<\/span><\/p>\n<\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-3 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:15px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:15px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-image-element \" style=\"--awb-caption-title-font-family:var(--h2_typography-font-family);--awb-caption-title-font-weight:var(--h2_typography-font-weight);--awb-caption-title-font-style:var(--h2_typography-font-style);--awb-caption-title-size:var(--h2_typography-font-size);--awb-caption-title-transform:var(--h2_typography-text-transform);--awb-caption-title-line-height:var(--h2_typography-line-height);--awb-caption-title-letter-spacing:var(--h2_typography-letter-spacing);\"><span class=\" fusion-imageframe imageframe-none imageframe-1 hover-type-none\"><img decoding=\"async\" width=\"1000\" height=\"278\" src=\"https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/04\/en_white_1.png\" alt class=\"img-responsive wp-image-2337\" srcset=\"https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/04\/en_white_1-200x56.png 200w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/04\/en_white_1-400x111.png 400w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/04\/en_white_1-600x167.png 600w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/04\/en_white_1-800x222.png 800w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/04\/en_white_1.png 1000w\" sizes=\"(max-width: 1024px) 100vw, (max-width: 640px) 100vw, 1000px\" \/><\/span><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-4 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:15px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:15px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-4\"><p><span style=\"color: #ffffff;\">You authenticate yourself on the REDDRYPT app with your email address and a password. A key pair comprising of public key and private key is automatically generated. Your private key is then encrypted with a password hash and uploaded to our servers together with your public key.<\/span><\/p>\n<p><span style=\"color: #ffffff;\">Sounds too complicated? Don&#8217;t worry as most of this happens in the background. You only need to enter your email address and choose a password to generate the key pair.<\/span><\/p>\n<\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-5 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:15px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:15px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-separator fusion-full-width-sep\" style=\"align-self: center;margin-left: auto;margin-right: auto;width:100%;\"><div class=\"fusion-separator-border sep-shadow\" style=\"--awb-height:20px;--awb-amount:20px;--awb-sep-color:#ffffff;background:radial-gradient(ellipse at 50% -50% , #ffffff 0px, rgba(255, 255, 255, 0) 80%) repeat scroll 0 0 rgba(0, 0, 0, 0);background:-webkit-radial-gradient(ellipse at 50% -50% , #ffffff 0px, rgba(255, 255, 255, 0) 80%) repeat scroll 0 0 rgba(0, 0, 0, 0);background:-moz-radial-gradient(ellipse at 50% -50% , #ffffff 0px, rgba(255, 255, 255, 0) 80%) repeat scroll 0 0 rgba(0, 0, 0, 0);background:-o-radial-gradient(ellipse at 50% -50% , #ffffff 0px, rgba(255, 255, 255, 0) 80%) repeat scroll 0 0 rgba(0, 0, 0, 0);\"><\/div><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-6 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:15px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:15px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-image-element \" style=\"--awb-caption-title-font-family:var(--h2_typography-font-family);--awb-caption-title-font-weight:var(--h2_typography-font-weight);--awb-caption-title-font-style:var(--h2_typography-font-style);--awb-caption-title-size:var(--h2_typography-font-size);--awb-caption-title-transform:var(--h2_typography-text-transform);--awb-caption-title-line-height:var(--h2_typography-line-height);--awb-caption-title-letter-spacing:var(--h2_typography-letter-spacing);\"><span class=\" fusion-imageframe imageframe-none imageframe-2 hover-type-none\"><img decoding=\"async\" width=\"1000\" height=\"353\" src=\"https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/04\/en_white_2.png\" alt class=\"img-responsive wp-image-2339\" srcset=\"https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/04\/en_white_2-200x71.png 200w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/04\/en_white_2-400x141.png 400w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/04\/en_white_2-600x212.png 600w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/04\/en_white_2-800x282.png 800w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/04\/en_white_2.png 1000w\" sizes=\"(max-width: 1024px) 100vw, (max-width: 640px) 100vw, 1000px\" \/><\/span><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-7 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:15px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:15px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-5\"><p><span style=\"color: #ffffff;\">Writing an email happens locally on your device. Why is this important you may ask? Because only you can read the contents of the email as the process happens locally. Before sending the email it is automatically encrypted on your device.<\/span><\/p>\n<p><span style=\"color: #ffffff;\">If the recipient is also a REDDCRYPT user, the encryption takes place with the public key of the recipient. This means that you don&#8217;t have to take action, as everything happens automatically in the background.<\/span><\/p>\n<p><span style=\"color: #ffffff;\">If the recipient is not a user of REDDCRYPT yet, you will have to define a passphrase <strong>for this first mail<\/strong> with which the recipient can decrypt the mail. To make sure that only the intended recipient can read your email. you can disclose this passphrase to the recipient e.g. via sms or phone call.<\/span><\/p>\n<\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-8 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:15px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:15px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-separator fusion-full-width-sep\" style=\"align-self: center;margin-left: auto;margin-right: auto;width:100%;\"><div class=\"fusion-separator-border sep-shadow\" style=\"--awb-height:20px;--awb-amount:20px;--awb-sep-color:#ffffff;background:radial-gradient(ellipse at 50% -50% , #ffffff 0px, rgba(255, 255, 255, 0) 80%) repeat scroll 0 0 rgba(0, 0, 0, 0);background:-webkit-radial-gradient(ellipse at 50% -50% , #ffffff 0px, rgba(255, 255, 255, 0) 80%) repeat scroll 0 0 rgba(0, 0, 0, 0);background:-moz-radial-gradient(ellipse at 50% -50% , #ffffff 0px, rgba(255, 255, 255, 0) 80%) repeat scroll 0 0 rgba(0, 0, 0, 0);background:-o-radial-gradient(ellipse at 50% -50% , #ffffff 0px, rgba(255, 255, 255, 0) 80%) repeat scroll 0 0 rgba(0, 0, 0, 0);\"><\/div><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-9 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:15px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:15px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-image-element \" style=\"--awb-caption-title-font-family:var(--h2_typography-font-family);--awb-caption-title-font-weight:var(--h2_typography-font-weight);--awb-caption-title-font-style:var(--h2_typography-font-style);--awb-caption-title-size:var(--h2_typography-font-size);--awb-caption-title-transform:var(--h2_typography-text-transform);--awb-caption-title-line-height:var(--h2_typography-line-height);--awb-caption-title-letter-spacing:var(--h2_typography-letter-spacing);\"><span class=\" fusion-imageframe imageframe-none imageframe-3 hover-type-none\"><img decoding=\"async\" width=\"1000\" height=\"340\" src=\"https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/04\/en_white_3.png\" alt class=\"img-responsive wp-image-2343\" srcset=\"https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/04\/en_white_3-200x68.png 200w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/04\/en_white_3-400x136.png 400w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/04\/en_white_3-600x204.png 600w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/04\/en_white_3-800x272.png 800w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/04\/en_white_3.png 1000w\" sizes=\"(max-width: 1024px) 100vw, (max-width: 640px) 100vw, 1000px\" \/><\/span><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-10 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:15px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:15px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-image-element \" style=\"--awb-caption-title-font-family:var(--h2_typography-font-family);--awb-caption-title-font-weight:var(--h2_typography-font-weight);--awb-caption-title-font-style:var(--h2_typography-font-style);--awb-caption-title-size:var(--h2_typography-font-size);--awb-caption-title-transform:var(--h2_typography-text-transform);--awb-caption-title-line-height:var(--h2_typography-line-height);--awb-caption-title-letter-spacing:var(--h2_typography-letter-spacing);\"><span class=\" fusion-imageframe imageframe-none imageframe-4 hover-type-none\"><img decoding=\"async\" width=\"1000\" height=\"539\" src=\"https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/04\/en_white_4.png\" alt class=\"img-responsive wp-image-2345\" srcset=\"https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/04\/en_white_4-200x108.png 200w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/04\/en_white_4-400x216.png 400w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/04\/en_white_4-600x323.png 600w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/04\/en_white_4-800x431.png 800w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/04\/en_white_4.png 1000w\" sizes=\"(max-width: 1024px) 100vw, (max-width: 640px) 100vw, 1000px\" \/><\/span><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-11 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:15px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:15px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-6\"><p><span style=\"color: #ffffff;\">To be able to read the email the recipient authenticates on the REDDCRYPT app, as well. If he already has access and the email has been encrypted with this public key, then the recipient can open, read and answer your mail right away. If he didn&#8217;t have access yet, he will have to generate his own key pair to through his email address and a chosen password. Afterwards he can see your encrypted email which can be encrypted by entering the passphrase you have disclosed to the recipient earlier (e.g. via sms or phone call).<\/span><\/p>\n<p><span style=\"color: #ffffff;\">This passphrase is only necessary for the decryption of the first email. With every email that comes afterwards the encryption and decryption process takes places automatically in the background. Highest user comfort and highest security &#8211; this is REDDCRYPT.<\/span><\/p>\n<\/div><\/div><\/div><\/div><\/div><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-3 nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-background-position:left top;--awb-border-sizes-top:0px;--awb-border-sizes-bottom:0px;--awb-border-sizes-left:0px;--awb-border-sizes-right:0px;--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-padding-top:1%;--awb-padding-bottom:2%;--awb-background-color:#ffffff;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-12 fusion_builder_column_1_1 1_1 fusion-one-full fusion-column-first fusion-column-last\" style=\"--awb-padding-top:30px;--awb-bg-size:cover;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-column-wrapper-legacy\"><div class=\"fusion-text fusion-text-7\"><h3 style=\"text-align: center;\"><span style=\"color: #cf000f;\">In detail <\/span><\/h3>\n<h3 style=\"text-align: center;\">Creating a key pair at the beginning<\/h3>\n<\/div><div class=\"fusion-clearfix\"><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-13 fusion_builder_column_1_1 1_1 fusion-one-full fusion-column-first fusion-column-last fusion-animated\" style=\"--awb-padding-top:20px;--awb-padding-right:20px;--awb-padding-bottom:20px;--awb-padding-left:20px;--awb-bg-size:cover;--awb-margin-top:20px;\" data-animationType=\"fadeInUp\" data-animationDuration=\"0.7\" data-animationOffset=\"top-into-view\"><div class=\"fusion-column-wrapper fusion-flex-column-wrapper-legacy\"><div class=\"fusion-text fusion-text-8\"><p>Every REDDCRYPT user generates a key pair when first using REDDCRYPT. This RSA key pair consists of a private and a public key and is generated from the combination of the user&#8217;s email address and a chosen password.<\/p>\n<p>The generation of the key pair takes place locally on your device.<\/p>\n<p><img decoding=\"async\" class=\"alignnone wp-image-2765 size-large\" src=\"https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/Register-Keypair-1-1024x585.png\" alt=\"Register Keypair\" width=\"1024\" height=\"585\" srcset=\"https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/Register-Keypair-1-200x114.png 200w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/Register-Keypair-1-300x171.png 300w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/Register-Keypair-1-400x229.png 400w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/Register-Keypair-1-600x343.png 600w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/Register-Keypair-1-768x439.png 768w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/Register-Keypair-1-800x457.png 800w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/Register-Keypair-1-1024x585.png 1024w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/Register-Keypair-1-1200x686.png 1200w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/Register-Keypair-1.png 1402w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p>After confirming that the User is the owner of the email address, he\/she assigns his\/her personal password. <strong>This password is used to encrypt the users private key<\/strong> and at the same time <strong>a password hash<\/strong> is generated from this password via a key derivation.<\/p>\n<p>The <em>password hash\u00a0<\/em>is necessary to authenticate the user in the REDDCRYPT app. We use a hash value so that the actual password of the user is never transferred and not stored in our database. Furthermore, a hash value is much more secure as it has higher entropy &#8211; more randomness &#8211; compared to passwords in plain text.<\/p>\n<p>The encrypted private key is transferred to REDDCRYPT together with the public key.<\/p>\n<\/div><div class=\"fusion-clearfix\"><\/div><\/div><\/div><\/div><\/div><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-4 nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-background-position:left top;--awb-border-sizes-top:0px;--awb-border-sizes-bottom:0px;--awb-border-sizes-left:0px;--awb-border-sizes-right:0px;--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-padding-top:1%;--awb-padding-bottom:2%;--awb-background-color:#172639;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-14 fusion_builder_column_1_1 1_1 fusion-one-full fusion-column-first fusion-column-last\" style=\"--awb-padding-top:30px;--awb-bg-size:cover;\"><div class=\"fusion-column-wrapper fusion-flex-column-wrapper-legacy\"><div class=\"fusion-text fusion-text-9\"><h3 style=\"text-align: center;\"><span style=\"color: #ffffff;\">Data protection: What data we store and how we protect it<\/span><\/h3>\n<\/div><div class=\"fusion-clearfix\"><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-15 fusion_builder_column_1_1 1_1 fusion-one-full fusion-column-first fusion-column-last fusion-animated\" style=\"--awb-padding-top:20px;--awb-padding-right:20px;--awb-padding-bottom:20px;--awb-padding-left:20px;--awb-bg-size:cover;--awb-margin-top:20px;\" data-animationType=\"fadeInUp\" data-animationDuration=\"0.7\" data-animationOffset=\"top-into-view\"><div class=\"fusion-column-wrapper fusion-flex-column-wrapper-legacy\"><div class=\"fusion-text fusion-text-10\"><p><span style=\"color: #ffffff;\">Fundamentally, the REDDOXX App serves to store and transfer encrypted emails. For our service to work smoothly and on different devices we have to store some data.<\/span><\/p>\n<p><strong><span style=\"color: #ffffff;\">Email Address<\/span><br \/>\n<\/strong><span style=\"color: #ffffff;\">The email address is required to log in to the REDDCRYPT app.<\/span><\/p>\n<p><span style=\"color: #ffffff;\"><strong>Public Key<\/strong><\/span><br \/>\n<span style=\"color: #ffffff;\">We store your public key unencrypted. This is uncritical as public keys don&#8217;t contain any sensitive information. It is in their nature to be unencrypted so that other users can use them to send you encrypted emails.<\/span><\/p>\n<p><span style=\"color: #ffffff;\"><strong>Private Key<\/strong><\/span><br \/>\n<span style=\"color: #ffffff;\">Your private key has already been encrypted locally on your device with your password. This encrypted private key is transferred to us and stored securely.<\/span><\/p>\n<p><span style=\"color: #ffffff;\"><strong>Password Hash<\/strong><\/span><br \/>\n<span style=\"color: #ffffff;\">In order to encrypt and decrypt an email the REDDCRYPT user&#8217;s password is mandatory. This password has already been hashed on your device and is hashed again on our servers.<\/span><\/p>\n<p><span style=\"color: #ffffff;\"><strong>Encrypted Email<\/strong><br \/>\nTo improve the user experience we store encrypted mails on our servers. This allows recipients to access and read emails instantly from any device via web browser. Emails have already been encrypted in a container on your device before being transferred to us.<\/span><\/p>\n<\/div><div class=\"fusion-reading-box-container reading-box-container-1\" style=\"--awb-title-color:#515b69;--awb-margin-top:34px;--awb-margin-bottom:84px;\"><div class=\"reading-box\" style=\"background-color:#e3e3e3;border-width:1px;border-color:#cf000f;border-bottom-width:3px;border-bottom-color:var(--primary_color);border-style:solid;\"><h2>What if REDDCRYPT were hacked?<\/h2><div class=\"reading-box-description fusion-reading-box-additional\"><b>The simple answer: nothing!<\/b> As all data on our servers is additionally encrypted potential attackers would only be able to see your email adress and 'waste data'. It is impossible to restore or calculate the real plain text password from the password hash stored on our servers. This ensures that a hacker would be unable to read the encrypted emails because he would require a user's password to decrypt the private key (and the emails respectively).<\/div><div class=\"fusion-clearfix\"><\/div><\/div><svg style=\"opacity:0.70;\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" width=\"100%\" viewBox=\"0 0 600 28\" preserveAspectRatio=\"none\"><g clip-path=\"url(#a)\"><mask id=\"b\" style=\"mask-type:luminance\" maskUnits=\"userSpaceOnUse\" x=\"0\" y=\"0\" width=\"600\" height=\"28\"><path d=\"M0 0h600v28H0V0Z\" fill=\"#fff\"\/><\/mask><g filter=\"url(#c)\" mask=\"url(#b)\"><path d=\"M16.439-18.667h567.123v30.8S438.961-8.4 300-8.4C161.04-8.4 16.438 12.133 16.438 12.133v-30.8Z\" fill=\"#000\"\/><\/g><\/g><defs><clipPath id=\"a\"><path fill=\"#fff\" d=\"M0 0h600v28H0z\"\/><\/clipPath><filter id=\"c\" x=\"5.438\" y=\"-29.667\" width=\"589.123\" height=\"52.8\" filterUnits=\"userSpaceOnUse\" color-interpolation-filters=\"sRGB\"><feFlood flood-opacity=\"0\" result=\"BackgroundImageFix\"\/><feBlend in=\"SourceGraphic\" in2=\"BackgroundImageFix\" result=\"shape\"\/><feGaussianBlur stdDeviation=\"5.5\" result=\"effect1_foregroundBlur_3983_183\"\/><\/filter><\/defs><\/svg><\/div><div class=\"fusion-clearfix\"><\/div><\/div><\/div><\/div><\/div><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-5 nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-background-position:left top;--awb-border-sizes-top:0px;--awb-border-sizes-bottom:0px;--awb-border-sizes-left:0px;--awb-border-sizes-right:0px;--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-padding-top:1%;--awb-padding-bottom:2%;--awb-background-color:#ffffff;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-16 fusion_builder_column_1_1 1_1 fusion-one-full fusion-column-first fusion-column-last\" style=\"--awb-padding-top:30px;--awb-bg-size:cover;\"><div class=\"fusion-column-wrapper fusion-flex-column-wrapper-legacy\"><div class=\"fusion-text fusion-text-11\"><h3 style=\"text-align: center;\">Zero knowledge \u2013 Full control over your emails<\/h3>\n<\/div><div class=\"fusion-clearfix\"><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-17 fusion_builder_column_1_1 1_1 fusion-one-full fusion-column-first fusion-column-last fusion-animated\" style=\"--awb-padding-top:20px;--awb-padding-right:20px;--awb-padding-bottom:20px;--awb-padding-left:20px;--awb-bg-size:cover;--awb-margin-top:20px;\" data-animationType=\"fadeInUp\" data-animationDuration=\"0.7\" data-animationOffset=\"top-into-view\"><div class=\"fusion-column-wrapper fusion-flex-column-wrapper-legacy\"><div class=\"fusion-text fusion-text-12\"><p>REDDCRYPT is a so-called <strong>zero-knowledge provider<\/strong>. All private and sensitive information are fully encrypted before being transferred to REDDCRYPT. The important thing about about the zero-knowledge\u00a0technique is the fact that we neither know your password\u00a0 nor is it being transferred to us at any point. Thus, we do not have access to your emails.<\/p>\n<p><strong>The encryption and decryption of your emails happens 100% locally on your device.<br \/>\n<\/strong><\/p>\n<p>Every decryption starts with the user&#8217;s password which is necessary to decrypt the private key, which &#8211; again &#8211; is necessary to decrypt the encrypted email.<br \/>\nThis is further evidence of the zero-knowledge technique as your keys, despite being stored on our servers, can only be used in combination with your password.<\/p>\n<p>Only your public key is stored unencrypted on our servers so that other REDDCRYPT users can use it to send you encrypted emails.<\/p>\n<\/div><div class=\"fusion-clearfix\"><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-18 fusion_builder_column_1_1 1_1 fusion-one-full fusion-column-first fusion-column-last\" style=\"--awb-bg-size:cover;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-column-wrapper-legacy\"><div class=\"fusion-text fusion-text-13\"><h3>Security &#8211; Your password stays with you<\/h3>\n<\/div><div class=\"fusion-clearfix\"><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-19 fusion_builder_column_1_1 1_1 fusion-one-full fusion-column-first fusion-column-last fusion-animated\" style=\"--awb-padding-top:20px;--awb-padding-right:20px;--awb-padding-bottom:20px;--awb-padding-left:20px;--awb-bg-size:cover;--awb-margin-top:20px;\" data-animationType=\"fadeInUp\" data-animationDuration=\"0.7\" data-animationOffset=\"top-into-view\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-column-wrapper-legacy\"><div class=\"fusion-text fusion-text-14\"><p>As mentioned, the encryption and decryption of the emails only works if you authenticate with your email address and password in the REDDCRYPT App. <strong>Your password never leaves your device. <\/strong>As part of the zero-knowledge technique<\/p>\n<p>Your password is needed in two cases: To authenticate in the REDDCRYPT app and to decrypt your private key. As part of the zero-knowledge technique a<strong>\u00a0password hash<\/strong> is generated from your password through key derivation.<\/p>\n<p>When logging in to the REDDCRYPT app a password hash is derived from the combination of your email address and a password and then transferred to us. If the hash value matches the hash value stored on our servers, access to your encrypted emails will be granted. If the hash value does not match access will be denied.<\/p>\n<p>In order for the emails to be automatically decrypted on your device the password is used.<\/p>\n<\/div><div class=\"fusion-clearfix\"><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-20 fusion_builder_column_1_1 1_1 fusion-one-full fusion-column-first fusion-column-last\" style=\"--awb-bg-size:cover;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-column-wrapper-legacy\"><div class=\"fusion-text fusion-text-15\"><h3 style=\"text-align: center;\">The authentication process for accessing the REDDCRYPT app<\/h3>\n<\/div><div class=\"fusion-clearfix\"><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-21 fusion_builder_column_1_1 1_1 fusion-one-full fusion-column-first fusion-column-last fusion-animated\" style=\"--awb-padding-top:20px;--awb-padding-right:20px;--awb-padding-bottom:20px;--awb-padding-left:20px;--awb-bg-size:cover;--awb-margin-top:20px;\" data-animationType=\"fadeInUp\" data-animationDuration=\"0.7\" data-animationOffset=\"top-into-view\"><div class=\"fusion-column-wrapper fusion-flex-column-wrapper-legacy\"><div class=\"fusion-text fusion-text-16\"><p>If a user accesses the REDDCRYPT app, the following happens:<\/p>\n<ol>\n<li>A password hash is derived from the password entered on the user&#8217;s device<\/li>\n<li>The entered email address and password hash are sent to the REDDCRYPT server<\/li>\n<li>The password hash is hashed again on the server<\/li>\n<li>On the server the hashed password hash is compared to the hash value stored in our database. If both values match, the entered password is correct and the user&#8217;s authentication is successful.<\/li>\n<\/ol>\n<p>If the user&#8217;s authentication is successful he is granted access to the encrypted emails. To decrypt these emails the private key is needed which is automatically downloaded in the background to your device and decrypted with the password.<\/p>\n<\/div><div class=\"fusion-reading-box-container reading-box-container-2\" style=\"--awb-title-color:#515b69;--awb-margin-top:34px;--awb-margin-bottom:84px;\"><div class=\"reading-box\" style=\"background-color:#e3e3e3;border-width:1px;border-color:#cf000f;border-bottom-width:3px;border-bottom-color:var(--primary_color);border-style:solid;\"><h2>Why happens when clicking the 'Forgot Password' option?<\/h2><div class=\"reading-box-description fusion-reading-box-additional\">Since your password does not leave your device and is completely unknown to us there is no way we can recover your password. So what happens if you generate a new password via \"Forgot password\"?\n\nWhen you generate a new password you will be treated like a new user and new certificates (including password hash and password key) will be generated for you - of course fully automated.\n\nPlease note that you can no longer decrypt your old emails when new certificates are generated.<\/div><div class=\"fusion-clearfix\"><\/div><\/div><svg style=\"opacity:0.70;\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" width=\"100%\" viewBox=\"0 0 600 28\" preserveAspectRatio=\"none\"><g clip-path=\"url(#a)\"><mask id=\"b\" style=\"mask-type:luminance\" maskUnits=\"userSpaceOnUse\" x=\"0\" y=\"0\" width=\"600\" height=\"28\"><path d=\"M0 0h600v28H0V0Z\" fill=\"#fff\"\/><\/mask><g filter=\"url(#c)\" mask=\"url(#b)\"><path d=\"M16.439-18.667h567.123v30.8S438.961-8.4 300-8.4C161.04-8.4 16.438 12.133 16.438 12.133v-30.8Z\" fill=\"#000\"\/><\/g><\/g><defs><clipPath id=\"a\"><path fill=\"#fff\" d=\"M0 0h600v28H0z\"\/><\/clipPath><filter id=\"c\" x=\"5.438\" y=\"-29.667\" width=\"589.123\" height=\"52.8\" filterUnits=\"userSpaceOnUse\" color-interpolation-filters=\"sRGB\"><feFlood flood-opacity=\"0\" result=\"BackgroundImageFix\"\/><feBlend in=\"SourceGraphic\" in2=\"BackgroundImageFix\" result=\"shape\"\/><feGaussianBlur stdDeviation=\"5.5\" result=\"effect1_foregroundBlur_3983_183\"\/><\/filter><\/defs><\/svg><\/div><div class=\"fusion-clearfix\"><\/div><\/div><\/div><\/div><\/div><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-6 nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-background-position:left top;--awb-border-sizes-top:0px;--awb-border-sizes-bottom:0px;--awb-border-sizes-left:0px;--awb-border-sizes-right:0px;--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-padding-top:1%;--awb-padding-bottom:2%;--awb-background-color:#172639;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-22 fusion_builder_column_1_1 1_1 fusion-one-full fusion-column-first fusion-column-last\" style=\"--awb-padding-top:30px;--awb-bg-size:cover;\"><div class=\"fusion-column-wrapper fusion-flex-column-wrapper-legacy\"><div class=\"fusion-text fusion-text-17\"><h3 style=\"text-align: center;\"><span style=\"color: #ffffff;\">Functionality: Client-side encryption<\/span><\/h3>\n<\/div><div class=\"fusion-clearfix\"><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-23 fusion_builder_column_1_1 1_1 fusion-one-full fusion-column-first fusion-column-last whitefont fusion-animated\" style=\"--awb-padding-top:20px;--awb-padding-right:20px;--awb-padding-bottom:20px;--awb-padding-left:20px;--awb-bg-size:cover;--awb-margin-top:20px;\" data-animationType=\"fadeInUp\" data-animationDuration=\"0.7\" data-animationOffset=\"top-into-view\"><div class=\"fusion-column-wrapper fusion-flex-column-wrapper-legacy\"><div class=\"fusion-text fusion-text-18\"><p>After successful authentication a random session key is generated on the user&#8217;s device with which the email is encrypted for the first time. To make sure that nobody else besides the recipient gains access to the email&#8217;s content, the session key is also encrypted.<\/p>\n<p><strong>Recipient is already REDDCRYPT user<br \/>\n<\/strong>Upon entering the recipient&#8217;s email address a request is send to REDDCRYPT&#8217;s key server. If the recipient is already a user of REDDCRYPT, his public key is already stored on our servers and is downloaded to encrypt the session key.<\/p>\n<p><img decoding=\"async\" class=\"alignnone wp-image-2767 size-large\" src=\"https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_public-key-1-1024x586.png\" alt=\"If the recipient is already a user of REDDCRYPT, his public key is already stored on our servers and is downloaded to encrypt the session key\" width=\"1024\" height=\"586\" srcset=\"https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_public-key-1-200x114.png 200w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_public-key-1-300x172.png 300w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_public-key-1-400x229.png 400w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_public-key-1-600x343.png 600w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_public-key-1-768x439.png 768w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_public-key-1-800x458.png 800w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_public-key-1-1024x586.png 1024w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_public-key-1-1200x686.png 1200w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_public-key-1.png 1402w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p><strong>Recipient is not yet a REDDCRYPT user<br \/>\n<\/strong>If no public key is available for the entered email address the sender has to define a random passphrase with which the session key is encrypted.<\/p>\n<p><img decoding=\"async\" class=\"alignnone wp-image-2769 size-large\" src=\"https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_passphrase-1-1024x586.png\" alt=\"If no public key is available for the entered email address the sender has to define a random passphrase\" width=\"1024\" height=\"586\" srcset=\"https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_passphrase-1-200x114.png 200w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_passphrase-1-300x172.png 300w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_passphrase-1-400x229.png 400w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_passphrase-1-600x343.png 600w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_passphrase-1-768x439.png 768w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_passphrase-1-800x458.png 800w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_passphrase-1-1024x586.png 1024w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_passphrase-1-1200x686.png 1200w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_passphrase-1.png 1402w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p><strong>On Sending<\/strong><br \/>\nWhen the REDDCRYPT user clicks <em>send<\/em> the encrypted email and the encrypted session key are bundled in a container which is then transferred to the REDDCRYPT server.<\/p>\n<\/div><div class=\"fusion-clearfix\"><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-24 fusion_builder_column_1_1 1_1 fusion-one-full fusion-column-first fusion-column-last\" style=\"--awb-bg-size:cover;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-column-wrapper-legacy\"><div class=\"fusion-text fusion-text-19\"><h3 style=\"text-align: center;\"><span style=\"color: #ffffff;\">Functionality: Client-side decryption<\/span><\/h3>\n<\/div><div class=\"fusion-clearfix\"><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-25 fusion_builder_column_1_1 1_1 fusion-one-full fusion-column-first fusion-column-last fusion-animated\" style=\"--awb-padding-top:20px;--awb-padding-right:20px;--awb-padding-bottom:20px;--awb-padding-left:20px;--awb-bg-size:cover;--awb-margin-top:20px;\" data-animationType=\"fadeInUp\" data-animationDuration=\"0.7\" data-animationOffset=\"top-into-view\"><div class=\"fusion-column-wrapper fusion-flex-column-wrapper-legacy\"><div class=\"fusion-text fusion-text-20\"><p><span style=\"color: #ffffff;\">How the email is decrypted depends on whether the recipient has already been a REDDCRYPT user at the time of the email&#8217;s sending.<\/span><\/p>\n<p><span style=\"color: #ffffff;\"><strong>The recipient is already a REDDCRYPT user and has a key pair<\/strong><\/span><br \/>\n<span style=\"color: #ffffff;\">After the recipient&#8217;s successful authentication on the REDDCRYPT app the private key and container are downloaded. Afterwards, the private key is decrypted with the password. The password is now used to to decrypt the session key.<\/span><\/p>\n<p><span style=\"color: #ffffff;\">The decrypted session key is used to decrypt the encrypted email. The complete process takes place in the background and the email opens automatically afterwards.<\/span><\/p>\n<p><img decoding=\"async\" class=\"alignnone wp-image-2771 size-large\" src=\"https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_mail-decrypted-1-1024x560.png\" alt=\"Mail is decrypted\" width=\"1024\" height=\"560\" srcset=\"https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_mail-decrypted-1-200x109.png 200w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_mail-decrypted-1-300x164.png 300w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_mail-decrypted-1-400x219.png 400w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_mail-decrypted-1-600x328.png 600w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_mail-decrypted-1-768x420.png 768w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_mail-decrypted-1-800x438.png 800w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_mail-decrypted-1-1024x560.png 1024w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_mail-decrypted-1-1200x656.png 1200w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_mail-decrypted-1.png 1402w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p><span style=\"color: #ffffff;\"><strong>The recipient is not a REDDCRYPT user yet and does not have a key pair<\/strong><\/span><br \/>\n<span style=\"color: #ffffff;\">The user generates a key pair for authentication on the REDDCRYPT app. This process is similar to a traditional registration process for the user. Afterwards the user authenticates on the REDDCRYPT app and the container is downloaded in the background.<\/span><\/p>\n<p><span style=\"color: #ffffff;\">As the session key has not been encrypted with a public key but with a passphrase this passphrase is needed for decryption. After the passphrase is correctly entered the decrypted session key is used to decrypt the email.<\/span><\/p>\n<p><img decoding=\"async\" class=\"alignnone wp-image-2773 size-large\" src=\"https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_passphrase-decrypt-1-1024x560.png\" alt=\"Enter passphrase for decryption\" width=\"1024\" height=\"560\" srcset=\"https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_passphrase-decrypt-1-200x109.png 200w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_passphrase-decrypt-1-300x164.png 300w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_passphrase-decrypt-1-400x219.png 400w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_passphrase-decrypt-1-600x328.png 600w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_passphrase-decrypt-1-768x420.png 768w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_passphrase-decrypt-1-800x438.png 800w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_passphrase-decrypt-1-1024x560.png 1024w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_passphrase-decrypt-1-1200x656.png 1200w, https:\/\/www.reddcrypt.com\/wp-content\/uploads\/2019\/05\/EN_passphrase-decrypt-1.png 1402w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<\/div><div class=\"fusion-clearfix\"><\/div><\/div><\/div><\/div><\/div><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-7 fusion-flex-container nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1040px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-26 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:15px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:15px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-21\"><h2 style=\"text-align: center;\">REDDCRYPT Business and the Master-Key<\/h2>\n<p>Administrators of REDDCRYPT Business can create a master key for their organisation and thus protect their own company against data loss.<\/p>\n<p>Because this master key enables the decryption of all emails of the own company, a requirement that occurs again and again, especially after employees have left the company. The master key also enables employees to create a new password if they forget their old one.<\/p>\n<h3 style=\"text-align: center;\">This is changed by the Master-Key<\/h3>\n<p>If an organisation has a master key users&#8217; private keys are no longer encrypted directly with the users password.<\/p>\n<p>From the user&#8217;s entered password &#8211; from which the password hash was derived at the beginning &#8211; a further hash value is now determined: <strong>a password key<\/strong>. In the future the users private key will be encrypted with this password key instead of the password.<\/p>\n<h3 style=\"text-align: center;\">The creation of the Master-Key<\/h3>\n<p>If a Master-Key is created basically the same happens as when creating a REDDCRYPT account: If the administrator creates a master key it is created locally on the administrators device.<\/p>\n<p>In addition the administrator defines a password from which a password key is derived here as well. With this password key the master key is encrypted and transferred to our servers in encrypted format.<\/p>\n<p>Again without the password defined by the administrator the master key cannot be used. This is an essential part of the Zero-Knowledge technology and does not differ from the process described above which is applied to the user keys. Since the defined password is never transmitted to us only you can use the master key.<\/p>\n<h3 style=\"text-align: center;\">This is how the Master-Key works&#8230;<\/h3>\n<p>If an organisation has a master key the users password key is additionally encrypted with this master key. So in the future there will be two ways to decrypt the users private key: By the users password input and by the master key.<\/p>\n<p><strong>&#8230;if emails should be decrypted<\/strong><\/p>\n<p>For example if e-mails from employees who have left the company need to be decrypted this can be done using the master key.<\/p>\n<ol>\n<li>To do this the master key has to be decrypted using the password created by the administrators<\/li>\n<li>Afterwards the decrypted master key is used to decrypt the users password key<\/li>\n<li>The decrypted password key is used to decrypt the users private key<\/li>\n<li>The decrypted private key is used to decrypt the email.<\/li>\n<\/ol>\n<p>We have described how the complete process looks like in practice in our Knowledge Base: <a href=\"https:\/\/www.reddcrypt.com\/en\/knowledge-base\/decrypt-emails-of-former-employees-with-the-master-key\/\">https:\/\/www.reddcrypt.com\/en\/knowledge-base\/decrypt-emails-of-former-employees-with-the-master-key\/<\/a><\/p>\n<p><strong>&#8230; if passwords are forgotten<\/strong><\/p>\n<p>If a user has forgotten their password they can generate a new password without losing access to previously encrypted emails. During the development phase it was important for us that the administrators do not know the user passwords so we developed a process that allows the user to define his new password on his own.<\/p>\n<p>To do this the user creates a new password using the &#8220;Forgot Password&#8221; function which is first stored temporarily in encrypted form. To use the new password the users private key must be decrypted and then re-encrypted with the new password.<\/p>\n<ol>\n<li>The administrator enters the password of the master key to decrypt it<\/li>\n<li>With the decrypted Master-Key the (old) password key of the user is decrypted<\/li>\n<li>The decrypted password key is used to decrypt the users private key<\/li>\n<li>A new password key is generated from the users new password<\/li>\n<li>The users private key is encrypted with the new password key<\/li>\n<li>The password key is encrypted with the master key<\/li>\n<li>The process is finished and the new password can be used for login from now on<\/li>\n<\/ol>\n<p>How the whole process looks like in practice we have described in our Knowledge Base: <a href=\"https:\/\/www.reddcrypt.com\/en\/knowledge-base\/resetting-password-with-master-key\/\">https:\/\/www.reddcrypt.com\/en\/knowledge-base\/resetting-password-with-master-key\/<\/a><\/p>\n<\/div><\/div><\/div><\/div><\/div>","protected":false},"excerpt":{"rendered":"","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"100-width.php","meta":{"footnotes":""},"class_list":["post-1137","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/www.reddcrypt.com\/en\/wp-json\/wp\/v2\/pages\/1137","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.reddcrypt.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.reddcrypt.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.reddcrypt.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.reddcrypt.com\/en\/wp-json\/wp\/v2\/comments?post=1137"}],"version-history":[{"count":11,"href":"https:\/\/www.reddcrypt.com\/en\/wp-json\/wp\/v2\/pages\/1137\/revisions"}],"predecessor-version":[{"id":5194,"href":"https:\/\/www.reddcrypt.com\/en\/wp-json\/wp\/v2\/pages\/1137\/revisions\/5194"}],"wp:attachment":[{"href":"https:\/\/www.reddcrypt.com\/en\/wp-json\/wp\/v2\/media?parent=1137"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}