Live data from Hacker News

Staying at the forefront of email security and reliability

googleenterprise.blogspot.com

31–40 of 42 posts

Re: Staying at the forefront of email security and reliability

#31
post #28
post #24

So how does this work when the CA's are less than reputable, Google has to comply with various homeland security acts, they didn't notice people tapping their fibre, have had numerous problems with their own staff and they have done evil before? Sounds like marketing fluff to me.

They have addressed and/or solved some of those issues: >So how does this work when the CA's are less than reputable Chrome has been using certificate pinning for Gmail for quite some time. Not sure what has been implemented in other browsers yet. >Google has to comply with various homeland security acts That's a legislative issue, and not something Google can fix. I would argue their track record on pushing for new…

> Traffic passing between their DCs is now being encrypted (well, it's been confirmed for Gmail.)

Encrypted how? With what keys? There's still a single point of failure to capture a huge amount of GMail traffic and an aggressive adversary who has penetrated Google's networks before. Google could be saying this and still handling over the keys to the gov't. The key is increasing the cost of bulk surveillance. This doesn't help. The only acceptable solution is one where I encrypt my data with my own keys.

> That's a legislative issue, and not something Google can fix.

Yes, but technical architecture changes what it means for Google to comply. If all they have is my encrypted data, that's all they can hand over.

Re: Staying at the forefront of email security and reliability

#32

Nice to hear they're reacting to the revelations by Snowden. I guess the government will have a harder time eavesdropping mails at Google without them noticing.

I'm inclined to think they're doing this for public perception and they're not actually making it significantlly harder for the government to eavesdrop.

Re: Staying at the forefront of email security and reliability

#34

> In 2013, Gmail was available 99.978% of the time, which averages to less than two hours of disruption for a user for the entire year. Does anyone understand why they use the term "averages" in this statement? What is being averaged? Isn't it just 0.022% * minutes in a year.

I think this means not all outages tracked affected all users equally. Some users would have seen more or less downtime than the 2 hours mentioned.

Re: Staying at the forefront of email security and reliability

#36
post #28

Earlier quoted context omitted.

They have addressed and/or solved some of those issues: >So how does this work when the CA's are less than reputable Chrome has been using certificate pinning for Gmail for quite some time. Not sure what has been implemented in other browsers yet. >Google has to comply with various homeland security acts That's a legislative issue, and not something Google can fix. I would argue their track record on pushing for new…

> Traffic passing between their DCs is now being encrypted (well, it's been confirmed for Gmail.) Encrypted how? With what keys? There's still a single point of failure to capture a huge amount of GMail traffic and an aggressive adversary who has penetrated Google's networks before. Google could be saying this and still handling over the keys to the gov't. The key is increasing the cost of bulk surveillance. This doe…

Sure, that's a valid point. That's something that is true for any email provider though. Google isn't stopping you from encrypting your mail, and you can't really expect them to force their users to do that, because sadly, the majority doesn't care and would switch to other providers who wouldn't annoy them with that whole encryption stuff.

Re: Staying at the forefront of email security and reliability

#37
post #36

Earlier quoted context omitted.

> Traffic passing between their DCs is now being encrypted (well, it's been confirmed for Gmail.) Encrypted how? With what keys? There's still a single point of failure to capture a huge amount of GMail traffic and an aggressive adversary who has penetrated Google's networks before. Google could be saying this and still handling over the keys to the gov't. The key is increasing the cost of bulk surveillance. This doe…

Sure, that's a valid point. That's something that is true for any email provider though. Google isn't stopping you from encrypting your mail, and you can't really expect them to force their users to do that, because sadly, the majority doesn't care and would switch to other providers who wouldn't annoy them with that whole encryption stuff.

That's the point: Google has their own interests, and they're not aligned with my privacy or security, except to not be embarrassed. There is a lot they could do besides forcing encryption on everyone, but I honestly think they have other priorities.

Re: Staying at the forefront of email security and reliability

#39
post #14

Earlier quoted context omitted.

You're ashamed it took this long for google, but not ashamed you didn't notice you were accessing with ssl?

Clearly I did notice otherwise I wouldn't have a personal story about how I noticed. Also, there isn't much you can do. You type in gmail.com, and on one browser I would be automatically taken to https for years. I switch to a different browser (I only use burp with firefox) and it is suddenly http. Easy OpSec failure to make.

Gmail has defaulted to an encrypted connection for over four years years now, including redirecting if you attempt to access over http (yes, even in Firefox). Really the only way that setting could have been made is if you made it at some point. Everyone else was opted in to https access.

"We are currently rolling out default https for everyone. If you've previously set your own https preference from Gmail Settings, nothing will change for your account. If you trust the security of your network and don't want default https turned on for performance reasons, you can turn it off at any time by choosing "Don't always use https" from the Settings menu."

And seriously, you accessed your email for years over an http connection and never even searched to find out why that was happening?

http://gmailblog.blogspot.com/2010/01/default-https-access-f...

Re: Staying at the forefront of email security and reliability

#40
post #14

Earlier quoted context omitted.

Clearly I did notice otherwise I wouldn't have a personal story about how I noticed. Also, there isn't much you can do. You type in gmail.com, and on one browser I would be automatically taken to https for years. I switch to a different browser (I only use burp with firefox) and it is suddenly http. Easy OpSec failure to make.

Gmail has defaulted to an encrypted connection for over four years years now, including redirecting if you attempt to access over http (yes, even in Firefox). Really the only way that setting could have been made is if you made it at some point. Everyone else was opted in to https access. "We are currently rolling out default https for everyone. If you've previously set your own https preference from Gmail Settings,…

You clearly did not understand what I said. I wrote that I used chrome, which I assume has a pin for google sites because even when you allow HTTP in your Gmail account, you would be taken to the HTTPS site.

Then, when going to firefox, It would take me to gmail over http. This is because my account was set to http (by default) and chrome doesn't allow connections to gmail over anything but https.

I accessed gmail one time over http in firefox (when I was connected to burp) before I realized there was a problem. My account had been set to "Allow Connection of HTTP" for years, but chrome will only connect with https.

Despite what they say was default, a few of my friends and I experienced a bug where ours was set to "Allow HTTPS" but we didn't realize it since we were using chrome.

Post reply on HN