How to Use Your Sub Rosa Email Account

The best way to use your Sub Rosa email account will depend on your particular situation and requirements. What we present below is some general advice, a list of features, and how to use each one.

Security Begins at Home

The most important, and perhaps the most painful place to implement security, is on your personal computer. It is the weakest link in the security chain. Unless you do everything you can to minimize your vulnerabilities at that point, all your other efforts will not make you safe.

Please see our page on computer security for information on the threats to your computer and "How to Keep a Secret" for a starting point on how to counter them.

The Sub Rosa Server

Email stored on the Sub Rosa server is as secure as it can be.

Your account is anonymous. We do not know who you are and we do not track your activity beyond what is needed for spam prevention.

Your emails are encrypted while on our server. Should someone break in to the server, they would not be able to read any emails stored there, even if they were not encrypted by the sender.

Our server is in an off-shore legal jurisdiction. What little information that could be recovered, cannot be subpeonaed by US or European courts.

We use Transport Layer Security to prevent eavsdropping on your email during transmission between your computer and our server.

Connecting to the Server

There are two ways of connecting to our email server: through an email client such as Thunderbird, or, through a web interface. Using an email client is prefered because it allows you to encrypt your messages more easily and securely.

Email Client

You may use any email client that supports the IMAP protocol. We recommend Thunderbird which is free, opensource, runs on most computers and operating systems, and is more secure than many other clients. Many computer attacks have used email so employing a secure email client is important to your overall computer security.

We assume you already have an email client installed. If not, download and install one according to the supplier's instructions. Again, we recommend Thunderbird.

Next, you need to configure an account. The account may be configured to use either the POP3 or IMAP protocols. POP3 will automatically download your emails to your computer. IMAP will, by default, leave them on the server until you delete them. We think IMAP is more secure but, the choice is yours.

The following steps assume you are using Thunderbird as an email client. The imformation you need will be the same for any client but the order of the steps may be different.

Your account has been setup in Thunderbird. Click on the "Inbox" link to read your messages. You will be asked for your password.

All other settings may be set to your personal preferences.

When you first login to your new email account you will be asked for your password. You should also get a message about the SSL certificate. Our certificate is self generated. You should select "Accept Always".

The Web Interface

A web based email client will always be less secure than one running on your own computer. That said, under some circumstances, it may be the best you can do.

The web interface is avaialbe at https://www.novo-ordo.com/webmail. Note this is https not http. This means the webmail interface is communicating over an encrypted link to ensure your privacy.

When you log into the web interface your user name is your full email address, i.e. mymail@novo-ordo.com.

The interface allows you to encrypt and decrypt messages as you would on a local email client. However, there is an important difference. Using the webmail interface, the encyption and decryption occur on our server rather than on your computer. This means we have copies of your keys. Although we pledge to do everything in our power to keep your private key safe, you must determine for yourself if your security requirements allow you to trust us.

To setup encryption through the webmail client, after logging in, select "GPG Pluggin Options" from the "Options" link at the top of your screen. Read the documentation and follow the instructions you find there.

Setting up Encryption

If your email client is Thunderbird, SeaMonkey, or Mozilla, download the Enigmail pluggin.

Traffic Obfuscation

Details on how to use the traffic obfuscation feature of Sub Rosa will be sent by email to you new account.

Help

If there is anything you do not understand or are having difficulty with regarding your Sub Rosa email account, you may always ask by sending email to: SubRosaHelp@Novo- Ordo.com