Do You Use GMail? If so, please read:
Aug. 19th, 2008 12:15 pm[Edit: I invite anyone reading this to dig through the comments for good ancillary advice, and some insightful commentary from
fxchip]
Hello, folks--earlier this month, at a well-known conference, there was announced a tool that can hack into any GMail account, regardless of how good your password is, as long as the data is flitting around unencrypted.
That's bad, m'kay?
Google has always had it so that your login credentials flit around encrypted, but once that's done, drops you to an unencrypted session (for long reasons that work out to "it's cheaper that way" for several kinds of "cheaper"). This will leave you quite open to this tool when it's released into the wild at the end of the month.
However, there's help! Google has just made it so that you can choose to have all your GMail traffic encrypted, and I would recommend this to any GMail user, even if you think "oh, my e-mail isn't that important". It's really easy to fix this. Actually, they should fix the dodgamn underlying bug, but leaving that aside for now, here's what you can do:
Simply log into GMail, and click on the Settings link over in the top right corner. At the bottom of this screen is a section labelled "Browser Connection", which by default is set to "Don't always use https". Change this to "Always use https", then click the "Save changes" button directly below. That "should" keep you safe from people using this fascinating new toy.
Enjoy!
-- Lorrie
Hello, folks--earlier this month, at a well-known conference, there was announced a tool that can hack into any GMail account, regardless of how good your password is, as long as the data is flitting around unencrypted.
That's bad, m'kay?
Google has always had it so that your login credentials flit around encrypted, but once that's done, drops you to an unencrypted session (for long reasons that work out to "it's cheaper that way" for several kinds of "cheaper"). This will leave you quite open to this tool when it's released into the wild at the end of the month.
However, there's help! Google has just made it so that you can choose to have all your GMail traffic encrypted, and I would recommend this to any GMail user, even if you think "oh, my e-mail isn't that important". It's really easy to fix this. Actually, they should fix the dodgamn underlying bug, but leaving that aside for now, here's what you can do:
Simply log into GMail, and click on the Settings link over in the top right corner. At the bottom of this screen is a section labelled "Browser Connection", which by default is set to "Don't always use https". Change this to "Always use https", then click the "Save changes" button directly below. That "should" keep you safe from people using this fascinating new toy.
Enjoy!
-- Lorrie
no subject
Date: 2008-08-19 07:37 pm (UTC)no subject
Date: 2008-08-19 07:55 pm (UTC)-- Lorrie
no subject
Date: 2008-08-19 07:46 pm (UTC)no subject
Date: 2008-08-19 07:55 pm (UTC)-- L
no subject
Date: 2008-08-19 07:48 pm (UTC)no subject
Date: 2008-08-19 07:55 pm (UTC)-- Lorrie
no subject
Date: 2008-08-19 07:52 pm (UTC)no subject
Date: 2008-08-19 07:56 pm (UTC)-- L
no subject
Date: 2008-08-19 08:01 pm (UTC)no subject
Date: 2008-08-19 09:56 pm (UTC)no subject
Date: 2008-08-19 08:13 pm (UTC)no subject
Date: 2008-08-19 09:57 pm (UTC)no subject
Date: 2008-08-19 08:48 pm (UTC)If I were looking for a different (free) web based e-mail are there are any others you would recommend?
no subject
Date: 2008-08-19 09:58 pm (UTC)-- Lorrie
(no subject)
From:no subject
Date: 2008-08-19 08:59 pm (UTC)no subject
Date: 2008-08-19 09:59 pm (UTC)Hi, I came here from Lupa's journal.
Date: 2008-08-19 09:33 pm (UTC)Also beware of other applications that don't use SSL or TLS to access Google services when they use your credentials, like Mozilla Sunbird (a calendaring application with Google Calendar support; it caches your username and password if you let it) and various e-mail applications (SSL support for POP3 and IMAP can be turned on when accessing your Gmail account but many people forget that sending e-mail through their relays also requires your credentials, and forget to turn on TLS support in their outgoing SMTP server settings).
No matter how you cut it, if your login credentials go over an untrusted network and someone's running a packet sniffer, it's game over.
Re: Hi, I came here from Lupa's journal.
Date: 2008-08-20 02:55 am (UTC)https:// helps, but the problem is that the cookie isn't properly secured. Without the cookie being secured, it's possible for the "fascinating new toy" to tell your browser temporarily that it is going to http://www.gmail.com/ to retrieve an image, and your browser will helpfully supply your cookie, even if you're using https.
(ETA
Re: Hi, I came here from Lupa's journal.
From:Re: Hi, I came here from Lupa's journal.
From:no subject
Date: 2008-08-19 09:38 pm (UTC)no subject
Date: 2008-08-20 06:54 am (UTC)So I own my own e-mail server and installed a webmail package there instead. 8-)
-- Lorrie
no subject
Date: 2008-08-19 09:42 pm (UTC)no subject
Date: 2008-08-20 06:54 am (UTC)no subject
Date: 2008-08-19 09:45 pm (UTC)Also, MobileMe, the Apple version of same, doesn't even have a *way* to let you always use SSL on the web app-- so if you've got a me.com email address, you want to stick to using Mail.app instead of the MobileMe webmail.
no subject
Date: 2008-08-19 10:11 pm (UTC)-- L
no subject
Date: 2008-08-19 09:54 pm (UTC)And... I didn't get to see you this time (was just out in SF for a few days), but would very much like to the next time I'm out!
no subject
Date: 2008-08-19 10:16 pm (UTC)no subject
Date: 2008-08-19 10:00 pm (UTC)no subject
Date: 2008-08-19 10:16 pm (UTC)no subject
Date: 2008-08-19 10:02 pm (UTC)no subject
Date: 2008-08-19 10:16 pm (UTC)no subject
Date: 2008-08-19 10:03 pm (UTC)no subject
Date: 2008-08-19 10:17 pm (UTC)-- L
no subject
Date: 2008-08-19 11:25 pm (UTC)no subject
Date: 2008-08-20 06:55 am (UTC)-- Lorrie
no subject
Date: 2008-08-19 11:25 pm (UTC)no subject
Date: 2008-08-20 06:58 am (UTC)no subject
Date: 2008-08-20 01:16 am (UTC)Danke!
--Ember--
no subject
Date: 2008-08-20 06:59 am (UTC)no subject
Date: 2008-08-20 01:22 am (UTC)Cheers,
Steve
no subject
Date: 2008-08-20 07:00 am (UTC)-- L
thanks, and a question
Date: 2008-08-20 02:30 am (UTC)Re: thanks, and a question
Date: 2008-08-20 02:56 am (UTC)Re: thanks, and a question
From:Re: thanks, and a question
From:Notifier still works on Macs :)
From:no subject
Date: 2008-08-20 03:42 am (UTC)no subject
Date: 2008-08-20 07:01 am (UTC)-- L
no subject
Date: 2008-08-20 03:55 am (UTC)no subject
Date: 2008-08-20 07:02 am (UTC)no subject
Date: 2008-08-20 06:27 am (UTC)no subject
Date: 2008-08-20 07:03 am (UTC)-- Lorrie
(no subject)
From:(no subject)
From:Another gmail user
Date: 2008-08-20 11:24 am (UTC)Re: Another gmail user
Date: 2008-08-29 06:06 am (UTC)-- Lorrie