Encryption is irrelevant when one party will give out the info for a price.
Google does not, nor have they ever, as far as I'm aware, sell personal user information to third parties. Google sells ads targeted at keywords and other interests, and while in an indirect way, this is profiting from user behavior, it is not the same as claiming they give out your personal info. Using third party hosted mail is a trade off, especially webmail. Unless you are using end-to-end encryption, intermediar…
Staying at the forefront of email security and reliability
11–20 of 42 posts
Re: Staying at the forefront of email security and reliability
#12Re: Staying at the forefront of email security and reliability
#13It is incredible that gmail even had HTTP enabled. It was an option in the gmail account settings. Honestly I am ashamed it took this long. Their documentation stated that by default HTTPS was enabled, but this wasn't the case for me. Mine was set to HTTP and all my emails were disclosed whenever I accessed them from firefox (which I guess doesn't have the pins for auto https in gmail like I'm assuming chrome does).
Re: Staying at the forefront of email security and reliability
#14It is incredible that gmail even had HTTP enabled. It was an option in the gmail account settings. Honestly I am ashamed it took this long. Their documentation stated that by default HTTPS was enabled, but this wasn't the case for me. Mine was set to HTTP and all my emails were disclosed whenever I accessed them from firefox (which I guess doesn't have the pins for auto https in gmail like I'm assuming chrome does).
You're ashamed it took this long for google, but not ashamed you didn't notice you were accessing with ssl?
Also, there isn't much you can do. You type in gmail.com, and on one browser I would be automatically taken to https for years. I switch to a different browser (I only use burp with firefox) and it is suddenly http. Easy OpSec failure to make.
Re: Staying at the forefront of email security and reliability
#15Nice to hear they're reacting to the revelations by Snowden. I guess the government will have a harder time eavesdropping mails at Google without them noticing.
[0] http://money.cnn.com/2013/11/04/technology/google-nsa-snowde...
Re: Staying at the forefront of email security and reliability
#16Email security? How do they do that when they are data-mining everyone's inbox? Most of us have a choice on using Gmail, some kids don't http://www.alternet.org/education/do-no-evil-google-sued-dat...
http://gawker.com/5637234/gcreep-google-engineer-stalked-tee...
Re: Staying at the forefront of email security and reliability
#17Email security? How do they do that when they are data-mining everyone's inbox? Most of us have a choice on using Gmail, some kids don't http://www.alternet.org/education/do-no-evil-google-sued-dat...
I guess the new changes are meant to guard against some external actors, while internal actors will continue to have unencrypted access like this fiasco from a while ago. http://gawker.com/5637234/gcreep-google-engineer-stalked-tee...
Re: Staying at the forefront of email security and reliability
#18Earlier quoted context omitted.
I guess the new changes are meant to guard against some external actors, while internal actors will continue to have unencrypted access like this fiasco from a while ago. http://gawker.com/5637234/gcreep-google-engineer-stalked-tee...
Google has long since implemented other measures to safeguard against internal bad actors.
Re: Staying at the forefront of email security and reliability
#19I know of Gandi and fastmail.fm [hosted in US though, so not much of an improvement].
Re: Staying at the forefront of email security and reliability
#20Earlier quoted context omitted.
I guess the new changes are meant to guard against some external actors, while internal actors will continue to have unencrypted access like this fiasco from a while ago. http://gawker.com/5637234/gcreep-google-engineer-stalked-tee...
Google has long since implemented other measures to safeguard against internal bad actors.