Security Basics mailing list archives

Re: newbie question


From: "Matt Davis" <stackinjection () gmail com>
Date: Thu, 7 Sep 2006 11:28:17 -0500

Freenigma stores the encryption keys on a server that the user doesn't
have control over.  Since the vendor has access to the keys, the
strength of the passphrase is of paramount importance.  Not to
mention, you're trusting that the company in question isn't doing
anything on their end that could jeopardize the key's strength.

On 9/6/06, Paul Rochford <elrocho () gmail com> wrote:
It does if you use the Firefox add-on CustomiseGoogle. The entire session is
encrypted while logged in. You CAN force Gmail to use SSL once logged in.

Failing that use www.freenigma.com


>
>
>
>
>
> On 06/09/06, Bora Dal <boradal () gmail com> wrote:
> > >>  I think GMail uses SSL (https://....) by default; it certainly
> > >>supports it.  If you can connect directly to Google, that's probably
> > >>good enough.
> >
> > Gmail does not use SSL in all phases of the your "mail experience". If
> > you take a look, SSL is used just in the initial login phase, sending
> > your credentials with SSL. The rest of the communication takes place
> > without the cover of encryption.
> >
> > In my opinion the safest gmail use is done through enabling POP3 and
> > SMTP with "delete the mail from gmail mailbox after its retrieved
> > option" set. The mail dropped into the local mailbox should be
> > secured, ofcourse thats another story :)
> >
> > Regards,
> >
> > Bora Dal, CISSP, CISA
> >
> >
> ---------------------------------------------------------------------------
> > This list is sponsored by: Norwich University
> >
> > EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
> > The NSA has designated Norwich University a center of Academic Excellence
> > in Information Security. Our program offers unparalleled Infosec
> management
> > education and the case study affords you unmatched consulting experience.
> > Using interactive e-Learning technology, you can earn this esteemed
> degree,
> > without disrupting your career or home life.
> >
> > http://www.msia.norwich.edu/secfocus
> >
> ---------------------------------------------------------------------------
> >
> >
>
>

---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence
in Information Security. Our program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------




--
email:  mjd [AT] mattdavis [DOT] biz
AIM:  MattJDavis  MSN:  Matt.J.Davis () hotmail com
ICQ:  4632557     G-Talk:  MatthewJDavis () gmail com

---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence in Information Security. Our program offers unparalleled Infosec management education and the case study affords you unmatched consulting experience. Using interactive e-Learning technology, you can earn this esteemed degree, without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------


Current thread: