securing your gmail

Wednesday, 20 August 2008 10:36 am by noel
posted in tech | tags: , , , , ,

there exist a tool that can “automaticaly steal ids of non-encrypted sessions and breaks into google mail accounts” and it will be released to the public in a few weeks. the tool was presented in the recent hackers’ conference in las vegas called defcon. click on the link above if you want more technical details.

essentially what the tool does is to allow a hacker (unsuspecting or otherwise) to get into your gmail account and do what s/he pleases — like change the password. scary stuff.

the solution is simple enough — encrypt your entire gmail session and not just the login portion. to do that both the server (google mail) and the client (your browser) have to talk to each other via ssl (secure sockets layer) all the time. fortunately, google was informed of the vulnerability about a year ago so they took steps to implement ssl on their side of the fence. browsers has ssl-support built in.

all you have to is to add an “s” to the “http” portion of the google mail address making it look like “https” (without the quotes of course) and you’re done. preferably, you should do this at the start of your gmail session when you log in.

related posts

4 Responses to “securing your gmail”

  1. freddie Says:

    hi noel. you know i am not a techie so i tried your instructions but cannot make anything out of it. i have at least 6 accounts with gmail. all my blogs are based on them. it’s scary to think that something might happen to them or to my accounts. do keep in touch and i’ll try my best, maybe with the help of my computer maintenance person, to help me out with this. best regards.

  2. noel Says:

    okay. let’s walk through it. when you try to access gmail you would point your browser to

    http://mail.google.com/

    to activate a secure session with your gmail account point your browser to

    https://mail.google.com/

    don’t worry. i’ll likely visit the city before september ends and i’ll show you more tricks. ;-)

  3. Gemma Batoon Says:

    see me too, noy ok. walk me through it as well…

  4. noel Says:

    ey gems, i just wrote up a simpler one.. here.

leave a reply