lwood: (wizpod)
[personal profile] lwood
[Edit: I invite anyone reading this to dig through the comments for good ancillary advice, and some insightful commentary from [livejournal.com profile] fxchip]

Hello, folks--earlier this month, at a well-known conference, there was announced a tool that can hack into any GMail account, regardless of how good your password is, as long as the data is flitting around unencrypted.

That's bad, m'kay?

Google has always had it so that your login credentials flit around encrypted, but once that's done, drops you to an unencrypted session (for long reasons that work out to "it's cheaper that way" for several kinds of "cheaper"). This will leave you quite open to this tool when it's released into the wild at the end of the month.

However, there's help! Google has just made it so that you can choose to have all your GMail traffic encrypted, and I would recommend this to any GMail user, even if you think "oh, my e-mail isn't that important". It's really easy to fix this. Actually, they should fix the dodgamn underlying bug, but leaving that aside for now, here's what you can do:

Simply log into GMail, and click on the Settings link over in the top right corner. At the bottom of this screen is a section labelled "Browser Connection", which by default is set to "Don't always use https". Change this to "Always use https", then click the "Save changes" button directly below. That "should" keep you safe from people using this fascinating new toy.

Enjoy!

-- Lorrie
Page 1 of 2 << [1] [2] >>

Date: 2008-08-19 07:37 pm (UTC)
From: [identity profile] razorsharpblade.livejournal.com
Thanks for the heads up Lorrie! Do you mind if I link to this on my LJ??

Date: 2008-08-19 07:55 pm (UTC)
From: [identity profile] lwood.livejournal.com
You're welcome--please do!

-- Lorrie

Date: 2008-08-19 07:46 pm (UTC)
From: [identity profile] nicanthiel.livejournal.com
Thanks very much for the heads-up :)

Date: 2008-08-19 07:55 pm (UTC)
From: [identity profile] lwood.livejournal.com
You're welcome!

-- L

Date: 2008-08-19 07:48 pm (UTC)
From: [identity profile] ex-ciannait.livejournal.com
Thanks for the tip!!

Date: 2008-08-19 07:55 pm (UTC)
From: [identity profile] lwood.livejournal.com
You're welcome!

-- Lorrie

Date: 2008-08-19 07:52 pm (UTC)
From: [identity profile] netdancer.livejournal.com
Thanks for the heads-up, much appreciated. I'll pass this on to my Flist.

Date: 2008-08-19 07:56 pm (UTC)
From: [identity profile] lwood.livejournal.com
You're welcome!

-- L

Date: 2008-08-19 08:01 pm (UTC)
From: [identity profile] narfi.livejournal.com
Thanks. I'll make sure others know.

Date: 2008-08-19 09:56 pm (UTC)
From: [identity profile] lwood.livejournal.com
Excellent!

Date: 2008-08-19 08:13 pm (UTC)
From: [identity profile] erynn999.livejournal.com
I can has https. I shall pass the word.

Date: 2008-08-19 09:57 pm (UTC)
From: [identity profile] lwood.livejournal.com
Huzzah!

Date: 2008-08-19 08:48 pm (UTC)
From: [identity profile] knittingwoman.livejournal.com
I'll do this too. Gmail is my back up e-mail and the one I use for public stuff these days. I use a local freenet as well but it is a PITA sometimes and that's when I use gmail.
If I were looking for a different (free) web based e-mail are there are any others you would recommend?

Date: 2008-08-19 09:58 pm (UTC)
From: [identity profile] lwood.livejournal.com
Heh--I have owned my own e-mail for years, and give out accounts to anyone whom I trust reasonably who would like one. I don't charge, and I come with webmail access. So, I'd recommend me, but I don't have a lot of the kickass features that GMail has.

-- Lorrie

(no subject)

From: [identity profile] knittingwoman.livejournal.com - Date: 2008-08-20 06:02 pm (UTC) - Expand

Date: 2008-08-19 08:59 pm (UTC)
From: [identity profile] lishi3-complex.livejournal.com
Saw this on Lupa's LJ; thanks for the warning!

Date: 2008-08-19 09:59 pm (UTC)
From: [identity profile] lwood.livejournal.com
You're welcome!

Hi, I came here from Lupa's journal.

Date: 2008-08-19 09:33 pm (UTC)
From: [identity profile] tlttlotd.livejournal.com
There are also a couple of Firefox plugins that automatically turn on SSL support with Google services (like CustomizeGoogle (https://addons.mozilla.org/en-US/firefox/addon/743) and Gmail Manager (https://addons.mozilla.org/en-US/firefox/addon/1320)). You can also throw https:// in front of most Google URLs. The services that support SSL will use it, the ones that don't will redirect you to the non-encrypted verison of the site.

Also beware of other applications that don't use SSL or TLS to access Google services when they use your credentials, like Mozilla Sunbird (a calendaring application with Google Calendar support; it caches your username and password if you let it) and various e-mail applications (SSL support for POP3 and IMAP can be turned on when accessing your Gmail account but many people forget that sending e-mail through their relays also requires your credentials, and forget to turn on TLS support in their outgoing SMTP server settings).

No matter how you cut it, if your login credentials go over an untrusted network and someone's running a packet sniffer, it's game over.

Re: Hi, I came here from Lupa's journal.

Date: 2008-08-20 02:55 am (UTC)
From: [identity profile] sleepingwolf.livejournal.com
Also here via Lupa and, as a reminder, [livejournal.com profile] triskele, though I stop in here now and then.

https:// helps, but the problem is that the cookie isn't properly secured. Without the cookie being secured, it's possible for the "fascinating new toy" to tell your browser temporarily that it is going to http://www.gmail.com/ to retrieve an image, and your browser will helpfully supply your cookie, even if you're using https.

(ETA [livejournal.com profile] triskele's role in reminding me to take care of this.)
Edited Date: 2008-08-20 02:59 am (UTC)

Date: 2008-08-19 09:38 pm (UTC)
From: [identity profile] abhasana.livejournal.com
*@)#$! I don't even like gmail in the first place.

Date: 2008-08-20 06:54 am (UTC)
From: [identity profile] lwood.livejournal.com
I had a libertarian crankyfit when it was made known that my e-mail was being parsed for ad value. Still...I worked at Hotmail for nigh unto two years, and someone's got to pay for all this stuff.

So I own my own e-mail server and installed a webmail package there instead. 8-)

-- Lorrie

Date: 2008-08-19 09:42 pm (UTC)

Date: 2008-08-20 06:54 am (UTC)
From: [identity profile] lwood.livejournal.com
welcome!

Date: 2008-08-19 09:45 pm (UTC)
ardaniel: photo of Ard in her green hat (Default)
From: [personal profile] ardaniel
Do note that you've got to log out and back in for the change to take effect, or at least I did. Just clicking the button doesn't make you any safer.

Also, MobileMe, the Apple version of same, doesn't even have a *way* to let you always use SSL on the web app-- so if you've got a me.com email address, you want to stick to using Mail.app instead of the MobileMe webmail.

Date: 2008-08-19 10:11 pm (UTC)
From: [identity profile] lwood.livejournal.com
It sorted me when I reloaded the page, actually, but relogging is a good idea in any case.

-- L

Date: 2008-08-19 09:54 pm (UTC)
From: [identity profile] fireba11.livejournal.com
Thanks for the info - I just applied the "fix" on my own account.

And... I didn't get to see you this time (was just out in SF for a few days), but would very much like to the next time I'm out!

Date: 2008-08-19 10:16 pm (UTC)
From: [identity profile] lwood.livejournal.com
Excellent all around!

Date: 2008-08-19 10:00 pm (UTC)
From: [identity profile] thorn-and-calyx.livejournal.com
Thanks, sweetling! I'm all snuggled in well-armoured https goodness. *hugs*

Date: 2008-08-19 10:16 pm (UTC)
From: [identity profile] lwood.livejournal.com
Hoorah! *hugs*

Date: 2008-08-19 10:02 pm (UTC)
From: [identity profile] brownkitty.livejournal.com
Done, and thank you :)

Date: 2008-08-19 10:16 pm (UTC)
From: [identity profile] lwood.livejournal.com
You're welcome!

Date: 2008-08-19 10:03 pm (UTC)
From: [identity profile] faeryl.livejournal.com
Thank you muchly! :-) Account settings have been changed.

Date: 2008-08-19 10:17 pm (UTC)
From: [identity profile] lwood.livejournal.com
You're welcome!

-- L

Date: 2008-08-19 11:25 pm (UTC)
From: [identity profile] sk4p.livejournal.com
Another friend of Lupa's: much appreciated.

Date: 2008-08-20 06:55 am (UTC)
From: [identity profile] lwood.livejournal.com
You're welcome!

-- Lorrie

Date: 2008-08-19 11:25 pm (UTC)
From: [identity profile] djedet.livejournal.com
Followed a link to this! Thank you so much!

Date: 2008-08-20 06:58 am (UTC)
From: [identity profile] lwood.livejournal.com
You're welcome!

Date: 2008-08-20 01:16 am (UTC)
From: [identity profile] emberleo.livejournal.com
Ah! Good to know. I have implemented the recommended change in both my accounts.

Danke!

--Ember--

Date: 2008-08-20 06:59 am (UTC)
From: [identity profile] lwood.livejournal.com
Bitte!

Date: 2008-08-20 01:22 am (UTC)
From: [identity profile] synabetic.livejournal.com
I, too, followed a link to this. Done and thank you!!!1 :)

Cheers,
Steve

Date: 2008-08-20 07:00 am (UTC)
From: [identity profile] lwood.livejournal.com
You're welcome! Nice icon!

-- L

thanks, and a question

Date: 2008-08-20 02:30 am (UTC)
From: [identity profile] anne-jumps.livejournal.com
This seems to render the Gmail Notifier inoperable -- is there a way around that or is it just a tough break?

Re: thanks, and a question

Date: 2008-08-20 02:56 am (UTC)
From: [identity profile] sleepingwolf.livejournal.com
There is a workaround (http://mail.google.com/support/bin/answer.py?hl=en&answer=9429).

Re: thanks, and a question

From: [identity profile] lwood.livejournal.com - Date: 2008-08-20 07:01 am (UTC) - Expand

Re: thanks, and a question

From: [identity profile] anne-jumps.livejournal.com - Date: 2008-08-20 12:27 pm (UTC) - Expand

Notifier still works on Macs :)

From: [identity profile] rhrsoulmates.livejournal.com - Date: 2008-08-24 01:31 am (UTC) - Expand

Date: 2008-08-20 03:42 am (UTC)
ext_15463: (alice advice)
From: [identity profile] illuviel.livejournal.com
Thanks for the heads-up. Posting a link here, if you don't mind.

Date: 2008-08-20 07:01 am (UTC)
From: [identity profile] lwood.livejournal.com
No worries, please do.

-- L

Date: 2008-08-20 03:55 am (UTC)
From: [identity profile] averysmallthing.livejournal.com
Thanks. Going to regurgitate the info in my LJ with credit.

Date: 2008-08-20 07:02 am (UTC)
From: [identity profile] lwood.livejournal.com
Excellent!

Date: 2008-08-20 06:27 am (UTC)
From: [identity profile] sabethea.livejournal.com
Thank you for this. [livejournal.com profile] lupabitch linked to it, and as I have three gmail accounts I am particularly grateful (and going to link to it myself, as I see you don't mind that happening. If for some reason a total stranger linking to this post makes you hugely angry, please tell me and I'll remove it).

Date: 2008-08-20 07:03 am (UTC)
From: [identity profile] lwood.livejournal.com
You're welcome, please do, no, I am a grownup and besides, more "thanks!" comments are more ego-boo. *grin*

-- Lorrie

(no subject)

From: [identity profile] keristor.livejournal.com - Date: 2008-08-20 10:09 am (UTC) - Expand

(no subject)

From: [identity profile] rhrsoulmates.livejournal.com - Date: 2008-08-24 01:36 am (UTC) - Expand

Another gmail user

Date: 2008-08-20 11:24 am (UTC)
From: (Anonymous)
I have a gmail account so when someone on my FTH listserve sent me your link I checked it out immediately. Thanks much. I'd like to post your link on my blog.

Re: Another gmail user

Date: 2008-08-29 06:06 am (UTC)
From: [identity profile] lwood.livejournal.com
You're welcome--please do!

-- Lorrie
Page 1 of 2 << [1] [2] >>

Profile

lwood: (Default)
lwood

February 2011

S M T W T F S
  12345
6789 101112
13141516171819
20212223242526
2728     

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Feb. 12th, 2026 06:47 pm
Powered by Dreamwidth Studios