Wincrypt 2.0 encryption software review
Originally published in GP magazine .
Written for GP magazine around 2002. This is the version I submitted - the published article may have been edited.
Wincrypt 2.0 (£29.95 from www.wincrypt.com) is a newly released British encryption utility that is being marketed as especially useful for doctors in the UK.
Encryption scrambles your files so that no one without the correct password can read them. The software is based upon the US government approved Advanced Encryption Standard (AES) algorithm, which uses a 256-bit key (very large). In official reports it is suggested that even with a supercomputer it would require several thousand billion years to break.
You have to download the software off the internet, as there isn’t a version available in the shops. There is a free cut-down version available for testing. On buying, you are given codes that when entered activate the product fully. You have to ring the makers to discuss bulk purchasing. It is easy to install and only takes a few minutes.
The software has a simple, easy to use interface and allows you to run either the encryption or decryption sides of the program. You can choose to create a copy of a file that is encrypted or encrypt an existing file. You can elect to compress a file to make it smaller, and you can create a self-decoding file that doesn’t need the recipient to have the software to decode it.
The main use of the program is to encrypt files on your hard disk. You can encode any file of any sort or size. The advertising makes a lot of the fact that email is insecure and in theory people can intercept and read your email. The software allows you to encrypt any file that you send as an attachment, though you have to do this beforehand; I would prefer to be able to do it while composing the email.
The ability to send a file that will decode itself with the right password means that you don’t have to check that the recipients have the same software. I can see several situations where this may be very useful. Our health authority wasn’t keen on the idea of practices saving computer records to disk for forwarding on when a patient had transferred out, as the data was insecure. This software would allow you to encrypt the file and then only release the password to the new GP practice. Some practices I know give, for a small payment, a copy of all a patient’s records on CD on request. Again it would be sensible to encrypt the data with a password the patient knows, such that if the CD was ever lost or stolen nobody else would be able to access the data. My practice prints off computer-generated insurance reports, which we post. It would seem sensible to email the report as an encrypted attachment, possibly only releasing the password once the invoice had been paid!
There are however several limitations to the software. The encrypted files aren’t recognised by any other software, and more seamless integration would seem worthwhile. I would prefer it if, when you tried to open a document in for example Word, it automatically ran the decryption program and prompted you for the password. It can be a bit laborious to decrypt and save the file, then open it, and then when finished re-encrypt it. It seems therefore more suited to archival material rather than documents you use every day.
The software also doesn’t solve the problem of email text being readable, and so wouldn’t make email consultations any more secure if you wanted to do those. It also doesn’t interact with current GP clinical software in any way, though I could see that there is a possible market there if it could be integrated to provide additional security.
On the downside, I did find several minor bugs when reviewing it, and more worryingly, while attempting to decrypt one file I had encoded, my computer crashed repeatedly and refused to decrypt the file. When purchasing the program you do get free technical support and free upgrades for one year. I am also puzzled, as there is no advice on what type of password you should use other than that it has to be five letters. Although the algorithm used is inherently strong against what are called brute force attacks, most people use a password that is easily guessable, and this would make it less secure.
In summary, this is a very affordable, easy to use piece of software that has several potential uses in general practice, though you need to be clear what you need it for, and hopefully it will be even better in future versions.