Default HTTPS access for Gmail
gmailblog.blogspot.com
Default HTTPS access for Gmail
1–10 of 31 posts
Re: Default HTTPS access for Gmail
#2Re: Default HTTPS access for Gmail
#3This whole incident seems to have put the fear of god in them.
Re: Default HTTPS access for Gmail
#4This whole incident seems to have put the fear of god in them.
Where I find it funny in relation to email is that email passes over the internet in plain text and without Google adding PGP or something to Gmail the benefits for this aren't great.
Considering the current incident with China, and the hacking in December. https for gmail will prevent snooping of gmail, but wouldn't prevent the email being intercepted if sent to or CC'd anyone on any other domain where the traffic crossed China (ot it could offer low-hanging fruit in other countries as relays may not be as secure).
It does help increase intra-Gmail security (as using the web to author would author it being visible before being sent) but it wouldn't wholly secure the entire transaction end to end which surely should be the goal.
I'd love to see Google take steps to offer a public key encryption system for Gmail that could secure the email even as it passed over other systems and to recipients in potential hot-zones.
Re: Default HTTPS access for Gmail
#5This whole incident seems to have put the fear of god in them.
I like this idea though, indeed I like the idea of the web being https by default. Where I find it funny in relation to email is that email passes over the internet in plain text and without Google adding PGP or something to Gmail the benefits for this aren't great. Considering the current incident with China, and the hacking in December. https for gmail will prevent snooping of gmail, but wouldn't prevent the email…
However, using a secure link from the client to the mail server cuts down on the area of vulnerability significantly. Now your personal system needs to be compromised, or the backbone internet links between mail servers used by people who contact you need to be compromised. This is a significantly higher bar. Granted, if you want to maximize email security then public/private key encryption is the way to go, but the simple step of using https between the client and the server is a very significant improvement.
Re: Default HTTPS access for Gmail
#6This is old news for people who know (or care) about https. But it is new news in terms of the Goog vs. China cyber war. The winners in all this will most certainly be Google customers outside of China because Google will continue hardening their defenses which will make computing with Google safer for the end user. Will it help users in China? Time will tell...
Re: Default HTTPS access for Gmail
#7This whole incident seems to have put the fear of god in them.
I like this idea though, indeed I like the idea of the web being https by default. Where I find it funny in relation to email is that email passes over the internet in plain text and without Google adding PGP or something to Gmail the benefits for this aren't great. Considering the current incident with China, and the hacking in December. https for gmail will prevent snooping of gmail, but wouldn't prevent the email…
So that proxies become useless, the connection gets slower, data traffic increases, firefox users are plagued with warnings because people don't have proper certificats etc.
At least 95% of the web-pages people are viewing are pointless bullshit anyway. It's not as if the casual internet user were using the potential freedom of the internet for anything good.
Messaging and similar services should be private of course.
Re: Default HTTPS access for Gmail
#8Earlier quoted context omitted.
I like this idea though, indeed I like the idea of the web being https by default. Where I find it funny in relation to email is that email passes over the internet in plain text and without Google adding PGP or something to Gmail the benefits for this aren't great. Considering the current incident with China, and the hacking in December. https for gmail will prevent snooping of gmail, but wouldn't prevent the email…
> I like the idea of the web being https by default. So that proxies become useless, the connection gets slower, data traffic increases, firefox users are plagued with warnings because people don't have proper certificats etc. At least 95% of the web-pages people are viewing are pointless bullshit anyway. It's not as if the casual internet user were using the potential freedom of the internet for anything good. Messa…
In fact Google already have a whitepaper published for their SPDY protocol and that uses SSL everywhere: http://www.chromium.org/spdy/spdy-whitepaper
Re: Default HTTPS access for Gmail
#9This whole incident seems to have put the fear of god in them.
I like this idea though, indeed I like the idea of the web being https by default. Where I find it funny in relation to email is that email passes over the internet in plain text and without Google adding PGP or something to Gmail the benefits for this aren't great. Considering the current incident with China, and the hacking in December. https for gmail will prevent snooping of gmail, but wouldn't prevent the email…
Re: Default HTTPS access for Gmail
#10This whole incident seems to have put the fear of god in them.
I like this idea though, indeed I like the idea of the web being https by default. Where I find it funny in relation to email is that email passes over the internet in plain text and without Google adding PGP or something to Gmail the benefits for this aren't great. Considering the current incident with China, and the hacking in December. https for gmail will prevent snooping of gmail, but wouldn't prevent the email…
Many servers have it configured, and if it's available on the destination almost all MTAs will use it to send mail to other servers, even if they don't support receipt of mail in this way.