Welcome Guest ( Log In | Register )



 
Reply to this topicStart new topic
> Something You've Need To Know About Gmail
shotgun
post Aug 17 2008, 07:42 AM
Post #1


Newbie [ Level 2 ]
Group Icon

Group: [HOSTED]
Posts: 29
Joined: 16-August 08
Member No.: 32,092



I was surprised the other day when I read about the types of security connections that you get when you use Gmail.
It seems when you use Gmail, Google uses https for authentication and http for everything else, I assume to save resources.

I guess my surprise was in that Google didn't maintain a secure session once logged in regardless if you entered the site via http or https. Yes, I may be a bit naive in assuming that this would be done by default.

To change this issue, you have to Log In to your mail account, and in Configurations, you have to go to the bottom part of the page, there you can select what type of connection do you want(obiously we are looking for https connection), so select it and then save changes.

I hope this was useful for you, greetings. wink.gif
Go to the top of the page
 
+Quote Post
wutske
post Aug 17 2008, 11:39 AM
Post #2


Way Out Of Control - You need a life :)
Group Icon

Group: [HOSTED]
Posts: 1,087
Joined: 2-August 05
From: Kapellen (Antwerp, Belgium)
Member No.: 7,585



I don't think gmail uses non secure connections when you sign in via https.
If check the help about this option you'll see this line:
QUOTE
Please note that selecting 'Always use https' will prevent you from accessing Gmail via HTTP (Hypertext Transfer Protocol). In addition, it may make Gmail a bit slower. If you trust the security of your network, you can turn this feature off at any time.


"Always use https" just means that you can't sign in via the normal (not-secured) http protocol, thus forcing you to use the https protocol.
Go to the top of the page
 
+Quote Post
turbopowerdmaxst...
post Aug 17 2008, 09:37 PM
Post #3


Premium Member
Group Icon

Group: [HOSTED]
Posts: 410
Joined: 16-February 06
From: Kolkata, India
Member No.: 11,322
myCENTs:82.69



I agree with wutske on that one. Always use https, is a must for people who access the Internet from Cyber cafes. While, those that have a connection at home, can use the non secure protocol to speed things up. I rarely use https because my 128 Kbps connection is quite slow.
Go to the top of the page
 
+Quote Post
wutske
post Aug 18 2008, 11:05 AM
Post #4


Way Out Of Control - You need a life :)
Group Icon

Group: [HOSTED]
Posts: 1,087
Joined: 2-August 05
From: Kapellen (Antwerp, Belgium)
Member No.: 7,585



QUOTE(turbopowerdmaxsteel @ Aug 17 2008, 11:37 PM) *
I agree with wutske on that one. Always use https, is a must for people who access the Internet from Cyber cafes. While, those that have a connection at home, can use the non secure protocol to speed things up. I rarely use https because my 128 Kbps connection is quite slow.


I prefer https, even if it slows things down, I realy don't like that my passwords and other personal stuff are sent out in the clear. Even tough nobody might be interested in it, I still think it's a got habbit to check and use security measurements that are available (I always use https when signing in at hotmail too smile.gif ).
Go to the top of the page
 
+Quote Post
FirefoxRocks
post Aug 19 2008, 03:20 AM
Post #5


Super Member
Group Icon

Group: [HOSTED]
Posts: 749
Joined: 12-July 06
From: Ontario, Canada
Member No.: 14,464



The Always use HTTPS option only appeared recently:
QUOTE("Wikipedia")
As of July 2008, it is possible to configure Gmail for HTTPS access only through the Settings option - this prevents any unsecure access via HTTP. POP3 and IMAP access uses Transport Layer Security, or TLS.


Before that, authentication (sign in) always used HTTPS, same with Windows Live Hotmail. Of course I prefer using HTTPS, it is more secure and I use it if it is available. I do not notice the speed difference.
Go to the top of the page
 
+Quote Post
Quatrux
post Aug 19 2008, 09:17 PM
Post #6


the Q
Group Icon

Group: [HOSTED]
Posts: 1,124
Joined: 13-July 05
From: Lithuania, Vilnius
Member No.: 7,059
myCENTs:4.06



I don't use HTTPS for GMail, I have this feature off I guess, I didn't really check it, it's much faster with HTTP for me that's why I prefer it, I try to avoid connecting to anything from other computers, especially at public places like library or university, but sometimes I have to, but as there really aren't anything special, just privacy stuff.. not a paypal or bank account or something, but still if someone would have hacked my gMail account it would be disappointed, I wish my ISP would be much faster when using HTTPS connections tongue.gif
Go to the top of the page
 
+Quote Post
xerxes
post Sep 6 2008, 06:46 PM
Post #7


Member [ Level 2 ]
Group Icon

Group: [HOSTED]
Posts: 72
Joined: 8-May 07
From: Poland
Member No.: 21,854
myCENTs:41.66



Quatrux,

Have you though of somebody taking over your account and using it while impersonating yourself? If somebody does that, they can contact your friends, perhaps co-workers and do some moral damage. Also remember that gmail stores all your mail, so such a person would also have access to any passwords or logins erbsites often send to their users. More than that, they could find out which sites you're using and reset your passwords on them (correct e-mail address usually being enough), gaining access to more of your private information and disrupting your access to those resources. You're using services that you would not admit using in public? How about somebody sending your last invoice from a sex-toys website to your boss (radical example but still...). All this is quite easy if you're using an unsecured connection in a public place, in fact man-in-the-middle attacks are quite often. Please keep that in mind.
Go to the top of the page
 
+Quote Post
shood
post Nov 16 2008, 07:03 PM
Post #8


Newbie [ Level 1 ]
Group Icon

Group: Members
Posts: 6
Joined: 16-November 08
Member No.: 35,146



Thanks for the information. I am learning more on this forum about Gmail that I never knew before. I do not believe that I will be answering my email in a public place. However one way to prevent people from getting into your email is to be sure and sign out each and every session. This can prevent a lot of problems.

If there is a problem with gmail like someone getting into it be sure and report it to gmail. There is also a Federal Agency in the USA to report mail fraud. Other countries have similar agencies so it is wise to contact your countries goverment too to let them know what is going on.

I really do not see how the https:// connection would help if you are using a public connection anymore than using http: and signing out. The most important thing is to sign out. Then go to tools in the browser or how ever the particular browser of your ISP of the computer you are using and get rid of the search history and cookies. Never click on the remember my password at a public computer.

Remember to always clean out the browsing history, etc. and cookies after each session. That really is the best protection.

QUOTE(wutske @ Aug 18 2008, 05:05 AM) *
I prefer https, even if it slows things down, I realy don't like that my passwords and other personal stuff are sent out in the clear. Even tough nobody might be interested in it, I still think it's a got habbit to check and use security measurements that are available (I always use https when signing in at hotmail too smile.gif ).

Go to the top of the page
 
+Quote Post
wutske
post Nov 17 2008, 08:29 AM
Post #9


Way Out Of Control - You need a life :)
Group Icon

Group: [HOSTED]
Posts: 1,087
Joined: 2-August 05
From: Kapellen (Antwerp, Belgium)
Member No.: 7,585



QUOTE(shood @ Nov 16 2008, 08:03 PM) *
I really do not see how the https:// connection would help if you are using a public connection anymore than using http: and signing out. The most important thing is to sign out. Then go to tools in the browser or how ever the particular browser of your ISP of the computer you are using and get rid of the search history and cookies. Never click on the remember my password at a public computer.


The https connection encrypts all the information you send over this public connection, including your username, password and all the mails you have in your inbox. People that are monitoring the lines (or the signals if it's wifi) won't be able to see your password and all your private information, same goes for virusses that look for transmitted passwords (it however won't protect you if the virus just monitors keyboard input ... ).
It's like using an anti-conceptive, it doesn't protect you in rougly 5% of the cases ... but for the other 95% you are safe, you just have to hope you're in that 95% tongue.gif
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic

Collapse

> Similar Topics

Topics Topics
  1. Secure Gmail Client!(19)
  2. Gmail To Sms(6)
  3. Gmail Dangerous?(45)
  4. Gmail Notifier Keeps Asking Me Password Upon Each Reboot(6)
  5. Free Gmail Invite!(2)
  6. Gmail No Longer Beta(26)
  7. Is It Worth It To Get Gmail ? Is Gmail Good?(92)
  8. Gmail Has Launched Antivirus Service(33)
  9. Free Gmail Account!(28)
  10. Goodbye Gmail, Hello Googlemail?(67)
  11. Gmail Paper :: Free Physical Copy Of Any Message With The Click Of A Button(8)
  12. Goolge Gmail Now Often Can`t Be Used In China(4)
  13. Gmail As Smtp(12)
  14. The New Gmail Video And Voice Chat Plug-in(4)
  15. Gmail Security Flaw(3)


 



- Lo-Fi Version Time is now: 2nd December 2008 - 12:39 PM