Custom Search
Search more than 150 trusted Websites for related information.

Alert: Enable "Always use https" setting in GMail

August 12, 2008 by Shanmuga  
Filed under Email Security, Featured

Google last week introduced a security setting designed to protect GMail users sessions from getting hijacked. The setting is provided as an option in the "settings" page of your GMail account. If you haven’t enabled the "Always use HTTPS" option, it’s time to do so now due to the emergence of an automated cookie stealing tool demonstrated at the Defcon hacker conference last week.

In the words of Brian Krebs "To put this attack in perspective, consider the following scenario. You log into your GMail account on a wireless hotspot at the local coffee bar, being careful to do so by clicking on a bookmark that sends you to https://mail.google.com. In between reading your e-mail, for example, you surf over to another trusted Web site. A bad guy who has hijacked the establishment’s network sees that you’ve requested a new Web page and appends a tiny image at htp://mail.google.com to the new page you requested. Bingo. Your browser will spit out the Gmail cookie with your credentials."

Google recommends selecting the ‘Always use HTTPS’ option in GMail any time your network may be non-secure. To secure your GMail "Sign in to your GMail account", Click "Settings" on top of the page menu and scroll down to "Browser connection"

gmail https setting Alert: Enable "Always use https" setting in GMail

Select "Always use https" Click "Save Changes" and reload.

Why Google has not made this as a default option is a mystery? Your mail browsing could become a bit slower through the SSL protocol, could that be the reason? or Google thinks every user logs in from a secure trusted network?

Better still use any modern secure email client that allows you to access your Webmail through SSL like Mozilla Thunderbird and you will be protected against cookie stealing attacks. Use the Webmail only when you don’t have access to your client like when you are on the road. When using the Webmail, always open a new browser window and remember to manually signout of your account and close the browser window.

  • StumbleUpon
  • Digg
  • Reddit
  • del.icio.us
  • Facebook
  • MySpace
  • TwitThis
  • Google
  • Yahoo! Buzz
  • Live
  • YahooMyWeb
  • E-mail this story to a friend!

If you enjoyed this post, make sure you subscribe to my RSS feed!

You may also like to read

Comments

2 Responses to “Alert: Enable "Always use https" setting in GMail”

  1. Websites tagged "setting" on Postsaver on August 29th, 2008 10:33 PM

    [...] - Alert: Enable "Always use https" setting in GMail saved by magneticlabs2008-08-22 - Of Pigeons & Peanut Butter saved by twoswallows2008-08-21 - [...]

  2. Prosumer News on October 16th, 2008 6:53 AM

    Gmail Always Use HTTPS…

    Gmail Always Use HTTPS

    There is however a setting in Gmail that is called Browser Connection (discovered via Sizlopedia) where the user can select to Always Use HTTPS when he connects to Gmail.

    Alert: Enable “Always use https” setting in …

  3. CAROL V WALKER on May 27th, 2009 8:55 PM

    Where is “settings” on the Gmail website?

Everyone has an Opinion...why don't you share yours and oh, if you want a pic to show with your comment, go get a gravatar! or you can even subscribe to our comments feed.

    Note:
  • All fields except the comments field are optional.
  • Real names aren't required, but please give us something to call you. Conversations among several people called "Anonymous" get too confusing.
  • All comments are pre-moderated, and will not appear on this site until approved by the site owner.





Tags

More News, Articles from elsewhere