Live data from Hacker News

Staying at the forefront of email security and reliability

googleenterprise.blogspot.com

11–20 of 42 posts

Re: Staying at the forefront of email security and reliability

#11
post #4

Encryption is irrelevant when one party will give out the info for a price.

Google does not, nor have they ever, as far as I'm aware, sell personal user information to third parties. Google sells ads targeted at keywords and other interests, and while in an indirect way, this is profiting from user behavior, it is not the same as claiming they give out your personal info. Using third party hosted mail is a trade off, especially webmail. Unless you are using end-to-end encryption, intermediar…

So you don't think that Google sells and buys user data from data brokers to correlate with their usage data?

Re: Staying at the forefront of email security and reliability

#13
post #3

It is incredible that gmail even had HTTP enabled. It was an option in the gmail account settings. Honestly I am ashamed it took this long. Their documentation stated that by default HTTPS was enabled, but this wasn't the case for me. Mine was set to HTTP and all my emails were disclosed whenever I accessed them from firefox (which I guess doesn't have the pins for auto https in gmail like I'm assuming chrome does).

You're ashamed it took this long for google, but not ashamed you didn't notice you were accessing with ssl?

Re: Staying at the forefront of email security and reliability

#14
post #3

It is incredible that gmail even had HTTP enabled. It was an option in the gmail account settings. Honestly I am ashamed it took this long. Their documentation stated that by default HTTPS was enabled, but this wasn't the case for me. Mine was set to HTTP and all my emails were disclosed whenever I accessed them from firefox (which I guess doesn't have the pins for auto https in gmail like I'm assuming chrome does).

You're ashamed it took this long for google, but not ashamed you didn't notice you were accessing with ssl?

Clearly I did notice otherwise I wouldn't have a personal story about how I noticed.

Also, there isn't much you can do. You type in gmail.com, and on one browser I would be automatically taken to https for years. I switch to a different browser (I only use burp with firefox) and it is suddenly http. Easy OpSec failure to make.

Re: Staying at the forefront of email security and reliability

#15

Nice to hear they're reacting to the revelations by Snowden. I guess the government will have a harder time eavesdropping mails at Google without them noticing.

They were "shocked" and "outraged" at the NSA datacenter hack [0]

[0] http://money.cnn.com/2013/11/04/technology/google-nsa-snowde...

Re: Staying at the forefront of email security and reliability

#16
post #12

Email security? How do they do that when they are data-mining everyone's inbox? Most of us have a choice on using Gmail, some kids don't http://www.alternet.org/education/do-no-evil-google-sued-dat...

I guess the new changes are meant to guard against some external actors, while internal actors will continue to have unencrypted access like this fiasco from a while ago.

http://gawker.com/5637234/gcreep-google-engineer-stalked-tee...

Re: Staying at the forefront of email security and reliability

#17
post #12

Email security? How do they do that when they are data-mining everyone's inbox? Most of us have a choice on using Gmail, some kids don't http://www.alternet.org/education/do-no-evil-google-sued-dat...

I guess the new changes are meant to guard against some external actors, while internal actors will continue to have unencrypted access like this fiasco from a while ago. http://gawker.com/5637234/gcreep-google-engineer-stalked-tee...

Google has long since implemented other measures to safeguard against internal bad actors.

Re: Staying at the forefront of email security and reliability

#18
post #17

Earlier quoted context omitted.

I guess the new changes are meant to guard against some external actors, while internal actors will continue to have unencrypted access like this fiasco from a while ago. http://gawker.com/5637234/gcreep-google-engineer-stalked-tee...

Google has long since implemented other measures to safeguard against internal bad actors.

I wouldn't give them too much credit on this. Gmail started in 2004, so a fix in 2010 still means that gmail had this vuln for most of its existence.

Re: Staying at the forefront of email security and reliability

#20
post #17

Earlier quoted context omitted.

I guess the new changes are meant to guard against some external actors, while internal actors will continue to have unencrypted access like this fiasco from a while ago. http://gawker.com/5637234/gcreep-google-engineer-stalked-tee...

Google has long since implemented other measures to safeguard against internal bad actors.

So if Larry Page wants to read my email, he cannot? I somehow doubt that.
Post reply on HN