  PeeWee Premium join:2001-10-21 Clovis, CA clubs:
·Pacific Bell - SBC
·Comcast
| Gmail, encryption, more secure?
I notice that gmail is using certain type of encryption. (I don't pretend to know anything about it) So I ask is this a logical step toward safer communication? If so, why aren't more set up that way? Or is it an option we always have had with any service? -- Nemo me impune lacessit. [No one provokes me with impunity] -- Motto of the Crown of Scotland |
|
  PeeWee Premium join:2001-10-21 Clovis, CA clubs: | Maybe an encryted connection is not the same thing? |
|
  Daniel Premium,MVM join:2000-06-26 Pleasanton, CA clubs: 
| reply to PeeWee said by PeeWee :I notice that gmail is using certain type of encryption. Well, Gmail is using TLS with 256-bit AES encryption. TLS is an improvement on SSL, which is the standard for communication between users and websites. Here are a couple of links for you:
SSL »en.wikipedia.org/wiki/Secure_Sockets_Layer
TLS »en.wikipedia.org/wiki/Transport_···Security -- grep understanding knowledge |
|
  Daniel Premium,MVM join:2000-06-26 Pleasanton, CA clubs: 
2 edits | reply to PeeWee said by PeeWee :Maybe an encryted connection is not the same thing? SSL/TLS creates an encrypted connection between you and the website you are visiting -- in this case the Gmail login page. Note that once you login you are changed to an unencrypted session; the only thing that's secured is the passing of your credentials. -- grep understanding knowledge |
|
 leeb00
join:2001-08-09
| I've noticed that if I access gmail using »https://www.gmail.com that the entire session is SSL.
Of course, this encryption only exists between your PC and the gmail server. Emails sent to/received from outside of gmail are unencrypted. This seems to be commonly misunderstood. SSL email is desireable, but not entirely secure. |
|
 nonymous
join:2003-09-08 Glendale, AZ
| said by leeb00 :I've noticed that if I access gmail using » https:// www.gmail.com that the entire session is SSL. no it is not |
|
 Raphion
join:2000-10-14 Samsara | Try it and see, just put the S in there and it will ALL be 256bit SSL. |
|
 Raphion
join:2000-10-14 Samsara
| reply to PeeWee The SSL encryption does make it secure against a hacker running a sniffer somewhere on your line. But I have no idea whether the messages are stored on the servers using any encryption at all though. That seems a little nervous making, seeing how as Google's server clusters are spread far and wide, and guarded under who knows how little security. I'd like to see Google encrypt the user's email using the user;s passphrase, so that in the event someone gets access to the servers contents, they wouldn't actually gain access to the messages. |
|
  Daniel Premium,MVM join:2000-06-26 Pleasanton, CA clubs: 
| reply to nonymous said by nonymous :said by leeb00 :I've noticed that if I access gmail using » https:// www.gmail.com that the entire session is SSL. no it is not It is. You have to manually change back to https once you are moved to http upon login. -- dmiessler.com - grep understanding knowledge |
|