Live data from Hacker News

Staying at the forefront of email security and reliability

googleenterprise.blogspot.com

1–10 of 42 posts

Re: Staying at the forefront of email security and reliability

#3
It is incredible that gmail even had HTTP enabled. It was an option in the gmail account settings. Honestly I am ashamed it took this long.

Their documentation stated that by default HTTPS was enabled, but this wasn't the case for me. Mine was set to HTTP and all my emails were disclosed whenever I accessed them from firefox (which I guess doesn't have the pins for auto https in gmail like I'm assuming chrome does).

Re: Staying at the forefront of email security and reliability

#9
post #4

Encryption is irrelevant when one party will give out the info for a price.

Or to avoid going to jail (assuming that they give out the info to the US government in the first place).

The word "price hints money, but I guess you don't mean that; it would need a lot of money for that company to risk jeopardize it's reputation.

Probably the best pressure the US government could do is to actually threaten important people in the company some jail time if they cooperate. So here "price" means personal freedom. Nobody would like to go to jail just because his job right?

In any case, yes there is no guarantee that nobody would treat your data with no interference. If you use another mail provider, the government could grab their https certificate, or with cooperation of a cert authority perform a man in the middle attack. (Which ironically google can to some extent be protected from because of cert pinning in chrome).

Still, in your comment you are hinting that it's easier to just "buy" it from Google because Google is just fine with selling your data to anybody for a "price". I find it hard to believe. Not saying anybody should trust Google more than any other service, but I don't see neither any proof that we should trust them less.

Re: Staying at the forefront of email security and reliability

#10
post #4

Encryption is irrelevant when one party will give out the info for a price.

Google does not, nor have they ever, as far as I'm aware, sell personal user information to third parties. Google sells ads targeted at keywords and other interests, and while in an indirect way, this is profiting from user behavior, it is not the same as claiming they give out your personal info.

Using third party hosted mail is a trade off, especially webmail. Unless you are using end-to-end encryption, intermediary servers will need plaintext access, not only to route the email, but to present it, to permit search, filtering, and other operations users value in the webmail client.

Google is taking steps to ensure all data is encrypted-at-rest and encrypted-in-flight. That's not a perfect defense, but it is an improvement. What is to be gained by bashing them for taking positive steps that everyone in the industry, we hope, are also taking?

Post reply on HN