Encryption details
Orders from the bookshop are being sent over a secure connection (SSL with 1024 bit RSA and AES-256). On the server, the order is being encrypted using Bluefish and a randomly generated 256-bit one-time key and stored in a database. The one-time key is in its turn encrypted using 1024-bit RSA and stored on the server. The private RSA-key which is being used for reading the order is stored in encrypted form. We have got the password and it is never stored on the server.
In this way the information is being sent encrypted in all stages and stored encrypted on the server. The only weak link would be if somebody could monitor the server the very moment when the order is being re-encrypted (from SSL to the form in which it is being stored and vice verse) which supposes physical access to the computers of the web hotel Loopia. Thus, hacking into the database would not be enough to break security.
In order to be even more assured that electronic communication with us (in both directions) remains unread by unauthorised persons, we recommend that you send PGP encrypted emails using the GNU Privacy Guard. As a suggestion you can use the email client Mozilla Thunderbird together with the extension module Enigmail. More information on encryption solutions can preferably be found on the world wide web.
To the bookstore
|