PaulDotCom mailing list archives

Can a sys admin see a gmail account


From: cmerkel at gmail.com (Chris Merkel)
Date: Mon, 14 Dec 2009 15:52:24 -0600

If you're using a corporate asset, a sysadmin could install software to
record all of your screen actions, keystrokes, copy everything off your HDD
without you knowing, monitor all your network traffic, etc. Worrying about
SSL in that context would be a bit silly.

My recommendation, if you're really concerned about it, would to bring your
own netbook + EVDO card to work if you need any semblance of privacy.

- Chris

On Mon, Dec 14, 2009 at 2:30 PM, Shawn McGovern <26mcgovern at gmail.com>wrote:

Ok so my question was posted in a forum and someone gave me and answer but
didnt explain it and then the forum post was when closed on me.  So I will
ask here for clarity and try not to kill me for this, I am trying to learn.

So if someone uses a corporate network to check a Gmail (using SSL).  If
they check to make sure that they have a secure connection -- once connected
-- and then they check the certificate to see if the cert hierarchy has been
tampered with.  Everything looks fine.  Are any admin or whomever able to
see you emails?  Forget about software on the computer you are using, only
through the network monitoring.

I was told in the forum that they could use a monitoring program like
wireshark to view them.  In the wireshark forum I read that you would need
the private key to decrypt the messages and in the forum they said that a
sys admin can get the private key?  Is that information correct?  and if so
how would they be able to get the private key?


Thanks in advance

_______________________________________________
Pauldotcom mailing list
Pauldotcom at mail.pauldotcom.com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com




-- 
- Chris Merkel
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mail.pauldotcom.com/pipermail/pauldotcom/attachments/20091214/a61ccd25/attachment.htm 


Current thread: