<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: The Wire: Google Security Edition</title>
	<atom:link href="http://krebsonsecurity.com/2010/01/the-wire-google-security-edition/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2010/01/the-wire-google-security-edition/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Sat, 11 Feb 2012 19:29:31 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: JCitizen</title>
		<link>http://krebsonsecurity.com/2010/01/the-wire-google-security-edition/comment-page-1/#comment-4458</link>
		<dc:creator>JCitizen</dc:creator>
		<pubDate>Thu, 25 Mar 2010 01:52:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=451#comment-4458</guid>
		<description>The news that Gmail is planning more secure &#039;always on&#039; https:\\ communication, is heartening, but they have a lot of work to do on that.

From what I understand, many of the hops a typical Gmail message takes are between servers that do not encrypt the messages.

If this is true, and Google plans on battening down the hatches; I applaud them. But all my clients plan on using encrypted attachments anyway. They have a healthy, &quot;wait and see&quot; attitude.</description>
		<content:encoded><![CDATA[<p>The news that Gmail is planning more secure &#8216;always on&#8217; https:\\ communication, is heartening, but they have a lot of work to do on that.</p>
<p>From what I understand, many of the hops a typical Gmail message takes are between servers that do not encrypt the messages.</p>
<p>If this is true, and Google plans on battening down the hatches; I applaud them. But all my clients plan on using encrypted attachments anyway. They have a healthy, &#8220;wait and see&#8221; attitude.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-4458" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('4458', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-4458-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-4458" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('4458', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-4458-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: M Henri Day</title>
		<link>http://krebsonsecurity.com/2010/01/the-wire-google-security-edition/comment-page-1/#comment-437</link>
		<dc:creator>M Henri Day</dc:creator>
		<pubDate>Fri, 15 Jan 2010 23:52:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=451#comment-437</guid>
		<description>Like Brian, I do hope that Google will make https encryption the default, if not mandatory, on all its many services ; myself, I turned the «always used https» feature on in my Gmail as soon as the bug that prevented the «Send to Gmail» feature on the Google Toolbar for Firefox from working with this setting. But let me say that this is not due to any suspicion that the Chinese government reads my email - those interested in doing so lie, I suspect, much closer to home....

With regard to Cpt Canuck&#039;s analysis of the possible advantages of using an email client rather than accessing one&#039;s email directly on the web, let me point out that email clients can also be targetted by the baddies, as we know from experience with Outlook. And that Gmail now offers an offline option, which means that, as in the case of an email client, already downloaded mail is available if your internet connexion fails....

Henri</description>
		<content:encoded><![CDATA[<p>Like Brian, I do hope that Google will make https encryption the default, if not mandatory, on all its many services ; myself, I turned the «always used https» feature on in my Gmail as soon as the bug that prevented the «Send to Gmail» feature on the Google Toolbar for Firefox from working with this setting. But let me say that this is not due to any suspicion that the Chinese government reads my email &#8211; those interested in doing so lie, I suspect, much closer to home&#8230;.</p>
<p>With regard to Cpt Canuck&#8217;s analysis of the possible advantages of using an email client rather than accessing one&#8217;s email directly on the web, let me point out that email clients can also be targetted by the baddies, as we know from experience with Outlook. And that Gmail now offers an offline option, which means that, as in the case of an email client, already downloaded mail is available if your internet connexion fails&#8230;.</p>
<p>Henri</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-437" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('437', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-437-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-437" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('437', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-437-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Tweets that mention The Wire: Google Security Edition — Krebs on Security -- Topsy.com</title>
		<link>http://krebsonsecurity.com/2010/01/the-wire-google-security-edition/comment-page-1/#comment-402</link>
		<dc:creator>Tweets that mention The Wire: Google Security Edition — Krebs on Security -- Topsy.com</dc:creator>
		<pubDate>Fri, 15 Jan 2010 02:09:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=451#comment-402</guid>
		<description>[...] This post was mentioned on Twitter by Security4all, briankrebs, Christen Gentile, designslinger, Isti and others. Isti said: RT @security4all: Gmail moves to &quot;always encrypted;&quot; cynics see ulterior motives in Google&#039;s hack disclosure: http://bit.ly/5aDniR (via ... [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by Security4all, briankrebs, Christen Gentile, designslinger, Isti and others. Isti said: RT @security4all: Gmail moves to &quot;always encrypted;&quot; cynics see ulterior motives in Google&#39;s hack disclosure: <a href="http://bit.ly/5aDniR" rel="nofollow">http://bit.ly/5aDniR</a> (via &#8230; [...]</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-402" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('402', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-402-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-402" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('402', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-402-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: BrianKrebs</title>
		<link>http://krebsonsecurity.com/2010/01/the-wire-google-security-edition/comment-page-1/#comment-400</link>
		<dc:creator>BrianKrebs</dc:creator>
		<pubDate>Fri, 15 Jan 2010 00:20:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=451#comment-400</guid>
		<description>Cpt Canuck is right. There&#039;s no security advantage to adding another app to checking your email. That said, newer versions of Outlook are much more secure than older Outlook and OE versions (for example, active scripting restrictions). And yes, Thunderbird is probably safer.</description>
		<content:encoded><![CDATA[<p>Cpt Canuck is right. There&#8217;s no security advantage to adding another app to checking your email. That said, newer versions of Outlook are much more secure than older Outlook and OE versions (for example, active scripting restrictions). And yes, Thunderbird is probably safer.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-400" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('400', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-400-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-400" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('400', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-400-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Captain Canuck</title>
		<link>http://krebsonsecurity.com/2010/01/the-wire-google-security-edition/comment-page-1/#comment-399</link>
		<dc:creator>Captain Canuck</dc:creator>
		<pubDate>Fri, 15 Jan 2010 00:03:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=451#comment-399</guid>
		<description>Outlook isn&#039;t the best email client there is in the security sense. Try Mozilla Thunderbird instead. 

Security-wise, I can think of two advantages for using an email client instead of the web interface:

   - cuts out your middleman (your browser) incase it has any security issues
  - if your email server&#039;s go offline, you have backups on your computer.</description>
		<content:encoded><![CDATA[<p>Outlook isn&#8217;t the best email client there is in the security sense. Try Mozilla Thunderbird instead. </p>
<p>Security-wise, I can think of two advantages for using an email client instead of the web interface:</p>
<p>   &#8211; cuts out your middleman (your browser) incase it has any security issues<br />
  &#8211; if your email server&#8217;s go offline, you have backups on your computer.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-399" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('399', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-399-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-399" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('399', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-399-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: JohnJ</title>
		<link>http://krebsonsecurity.com/2010/01/the-wire-google-security-edition/comment-page-1/#comment-397</link>
		<dc:creator>JohnJ</dc:creator>
		<pubDate>Thu, 14 Jan 2010 22:20:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=451#comment-397</guid>
		<description>When using a webmail service, is there any security difference between logging on at the e-mail web site, and sending/retrieving your mail using Outlook?</description>
		<content:encoded><![CDATA[<p>When using a webmail service, is there any security difference between logging on at the e-mail web site, and sending/retrieving your mail using Outlook?</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-397" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('397', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-397-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-397" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('397', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-397-down" style="font-size:14px; color:#990033;">2</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Google, China, and Lawful Intercept &#124; nothing important, just security ...</title>
		<link>http://krebsonsecurity.com/2010/01/the-wire-google-security-edition/comment-page-1/#comment-396</link>
		<dc:creator>Google, China, and Lawful Intercept &#124; nothing important, just security ...</dc:creator>
		<pubDate>Thu, 14 Jan 2010 22:19:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=451#comment-396</guid>
		<description>[...] about it. I&#8217;m sure that more details will come out over the next few weeks. Brian Krebs has an excellent summary article posted; I hope he&#8217;ll continue to update it. For the moment, though, my tentative conclusions are [...]</description>
		<content:encoded><![CDATA[<p>[...] about it. I&#8217;m sure that more details will come out over the next few weeks. Brian Krebs has an excellent summary article posted; I hope he&#8217;ll continue to update it. For the moment, though, my tentative conclusions are [...]</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-396" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('396', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-396-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-396" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('396', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-396-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: f</title>
		<link>http://krebsonsecurity.com/2010/01/the-wire-google-security-edition/comment-page-1/#comment-392</link>
		<dc:creator>f</dc:creator>
		<pubDate>Thu, 14 Jan 2010 20:18:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=451#comment-392</guid>
		<description>Could you explain to me the effect this is having on Symantecs Norton Anti Virus 2010?I have noticed a change in the way Norton is working.Am I still protected while using Norton?What should I do?Thank you very much.</description>
		<content:encoded><![CDATA[<p>Could you explain to me the effect this is having on Symantecs Norton Anti Virus 2010?I have noticed a change in the way Norton is working.Am I still protected while using Norton?What should I do?Thank you very much.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-392" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('392', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-392-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-392" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('392', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-392-down" style="font-size:14px; color:#990033;">5</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: d</title>
		<link>http://krebsonsecurity.com/2010/01/the-wire-google-security-edition/comment-page-1/#comment-387</link>
		<dc:creator>d</dc:creator>
		<pubDate>Thu, 14 Jan 2010 17:52:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=451#comment-387</guid>
		<description>Yea, for Google! I was about ready to dump them. Their lack of providing constant encryption has always bothered me. So much so, that I still have yet to  try their other products. Much like the poll you just conducted Brian, some people don&#039;t care what&#039;s lurking out there and some do. I have been a user of NoScript and took your advice about RequestPolicy. Lately, every time I log in to gmail there seems to be yet another cookie. Giving their cookies a short expiration date would be another step in the right direction.</description>
		<content:encoded><![CDATA[<div style="background-color:#FFFFCC !important"><p>Yea, for Google! I was about ready to dump them. Their lack of providing constant encryption has always bothered me. So much so, that I still have yet to  try their other products. Much like the poll you just conducted Brian, some people don&#8217;t care what&#8217;s lurking out there and some do. I have been a user of NoScript and took your advice about RequestPolicy. Lately, every time I log in to gmail there seems to be yet another cookie. Giving their cookies a short expiration date would be another step in the right direction.</p>
</div><div class="CommentRating">Well-loved. Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-387" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('387', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-387-up" style="font-size:14px; color:#009933;">5</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-387" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('387', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-387-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 2/16 queries in 0.008 seconds using memcached
Object Caching 877/882 objects using memcached

Served from: krebsonsecurity.com @ 2012-02-11 23:15:51 -->
