Security Basics mailing list archives
RE: Gmail and https
From: "Murda Mcloud" <murdamcloud () bigpond com>
Date: Tue, 12 Feb 2008 14:34:39 +1000
I seem to remember something to do with sidejacking and ssl gmail sessions too-will see if I can find the link. So your ssl session is as secure as the wireless session is. Here is the link-watch the wrap, people. http://arstechnica.com/news.ars/post/20080201-report-google-mail-vulnerable- to-sidejacking-despite-ssl.html -----Original Message----- From: listbounce () securityfocus com [mailto:listbounce () securityfocus com] On Behalf Of Mike Hale Sent: Tuesday, February 12, 2008 4:12 AM To: Albert R. Campa Cc: Mohammad Tina; security-basics () securityfocus com Subject: Re: Gmail and https You guys should confirm that it actually is using SSL. Run wireshark and see if you can catch any plain text. If I remember correctly, someone ran some tests a while back and confirmed that even though it was SSL for some portions of the page, your email was still in plain text. - Mike On 2/11/08, Albert R. Campa <abcampa () gmail com> wrote:
I believe it is. Although with gmail Manager firefox addon, there is an option to use secure connection, so my url always says https. On Feb 8, 2008 1:49 PM, Mohammad Tina <mohammad.tina () googlemail com>
wrote:
Hi, I notices recently that gmail after you logon the header in the address bar is http not https? is that normal? -- /Mohammad N. Tina
-- 09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0
Current thread:
- Gmail and https Mohammad Tina (Feb 11)
- Re: Gmail and https Albert R. Campa (Feb 11)
- Re: Gmail and https Mike Hale (Feb 11)
- RE: Gmail and https Murda Mcloud (Feb 12)
- Re: Gmail and https Mike Hale (Feb 11)
- Message not available
- Re: Gmail and https Mohammad Tina (Feb 11)
- RE: Gmail and https Joe Klein (Feb 11)
- Re: Gmail and https Warren Myers (Feb 11)
- Re: Gmail and https Mohammad Tina (Feb 11)
- Re: Gmail and https Albert R. Campa (Feb 11)
- RE: Gmail and https Joe Klein (Feb 11)
- RE: Gmail and https Ben de Bont (Feb 11)
- RE: Gmail and https Murda Mcloud (Feb 12)
- RE: Gmail and https Joe Klein (Feb 12)
- Re: Gmail and https Security Basic (Feb 13)
- RE: Gmail and https Ben de Bont (Feb 11)
- Re: Gmail and https Steven D. Ellison (Feb 11)