slowfox: Slowfox' default icon (Default)
[personal profile] slowfox
You've probably known this for a long while, but since I've only just got around to doing it, I thought I'd mention...

As this Wired article explains, although gMail asks for your initial log on password via HTTPS (the nice, secure protocol), the rest of your session, under the default settings, is plain HTTP. Which is potentially a problem if you're checking email from a WiFi hotspot or whatever.

Changing this is easy enough, once you know where to look.

Go to Settings (upper right hand side of the screen), and from there you should be on the 'General' tab.

Right at the bottom of the page is a section headed 'Browser Connection', and, as above, the default is 'Don't always use HTTPS'. I've changed my settings to 'always use https', and haven't (yet) noticed any drawbacks.

Now, because HTTPS is encrypted, it does mean that encryption/decryption has to take place at both the client (your machine) and the server (Google's kit), so, in theory, using HTTPS all the time will slow things down a bit.

On the other hand, not using HTTPS means that the communication twixt you and Google's cloud is all in the clear, and is much easier to eavesdrop/snoop on. Especially since a tool was announced at DEFCON last year which made such snooping 'relatively easy'.

So, the general advice (from Wired, above, The Register, here, Mashable, here and the good old Beeb, here) is to always use HTTPS.

Date: 2009-06-19 10:33 pm (UTC)
estel: (avatar)
From: [personal profile] estel
Thanks, I did not know about this.

However, I usually use gmail from my mail client. I'm guessing that might still be going unencrypted.

Date: 2009-06-19 11:02 pm (UTC)
anotherpenguin: (Default)
From: [personal profile] anotherpenguin
I had no idea, so thanks !

Although, when I checked, none of the radio buttons were actually default-checked. Weird.

Date: 2009-06-19 11:30 pm (UTC)
alicit: Cheshire cat pointing to your right (Default)
From: [personal profile] alicit
I have been using the "always use https" option for years and haven't had any trouble with it.

Date: 2009-06-20 01:23 am (UTC)
aome: (Default)
From: [personal profile] aome
You need to add "PSA" to your tags. :D

Profile

slowfox: Slowfox' default icon (Default)
slowfox

Style Credit

Expand Cut Tags

No cut tags
Page generated Jul. 7th, 2025 10:07 am
Powered by Dreamwidth Studios