<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: The Wire: Google Security Edition</title> <atom:link href="http://krebsonsecurity.com/2010/01/the-wire-google-security-edition/feed/" rel="self" type="application/rss+xml" /><link>http://krebsonsecurity.com/2010/01/the-wire-google-security-edition/</link> <description>In-depth security news and investigation</description> <lastBuildDate>Fri, 30 Jul 2010 04:29:12 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.0</generator> <item><title>By: JCitizen</title><link>http://krebsonsecurity.com/2010/01/the-wire-google-security-edition/#comment-4458</link> <dc:creator>JCitizen</dc:creator> <pubDate>Thu, 25 Mar 2010 01:52:25 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=451#comment-4458</guid> <description>The news that Gmail is planning more secure &#039;always on&#039; https:\\ communication, is heartening, but they have a lot of work to do on that.From what I understand, many of the hops a typical Gmail message takes are between servers that do not encrypt the messages.If this is true, and Google plans on battening down the hatches; I applaud them. But all my clients plan on using encrypted attachments anyway. They have a healthy, &quot;wait and see&quot; attitude.</description> <content:encoded><![CDATA[<p>The news that Gmail is planning more secure &#8216;always on&#8217; https:\\ communication, is heartening, but they have a lot of work to do on that.</p><p>From what I understand, many of the hops a typical Gmail message takes are between servers that do not encrypt the messages.</p><p>If this is true, and Google plans on battening down the hatches; I applaud them. But all my clients plan on using encrypted attachments anyway. They have a healthy, &#8220;wait and see&#8221; attitude.</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-4458" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('4458', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-4458-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-4458" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('4458', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-4458-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: M Henri Day</title><link>http://krebsonsecurity.com/2010/01/the-wire-google-security-edition/#comment-437</link> <dc:creator>M Henri Day</dc:creator> <pubDate>Fri, 15 Jan 2010 23:52:28 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=451#comment-437</guid> <description>Like Brian, I do hope that Google will make https encryption the default, if not mandatory, on all its many services ; myself, I turned the «always used https» feature on in my Gmail as soon as the bug that prevented the «Send to Gmail» feature on the Google Toolbar for Firefox from working with this setting. But let me say that this is not due to any suspicion that the Chinese government reads my email - those interested in doing so lie, I suspect, much closer to home....With regard to Cpt Canuck&#039;s analysis of the possible advantages of using an email client rather than accessing one&#039;s email directly on the web, let me point out that email clients can also be targetted by the baddies, as we know from experience with Outlook. And that Gmail now offers an offline option, which means that, as in the case of an email client, already downloaded mail is available if your internet connexion fails....Henri</description> <content:encoded><![CDATA[<p>Like Brian, I do hope that Google will make https encryption the default, if not mandatory, on all its many services ; myself, I turned the «always used https» feature on in my Gmail as soon as the bug that prevented the «Send to Gmail» feature on the Google Toolbar for Firefox from working with this setting. But let me say that this is not due to any suspicion that the Chinese government reads my email &#8211; those interested in doing so lie, I suspect, much closer to home&#8230;.</p><p>With regard to Cpt Canuck&#8217;s analysis of the possible advantages of using an email client rather than accessing one&#8217;s email directly on the web, let me point out that email clients can also be targetted by the baddies, as we know from experience with Outlook. And that Gmail now offers an offline option, which means that, as in the case of an email client, already downloaded mail is available if your internet connexion fails&#8230;.</p><p>Henri</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-437" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('437', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-437-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-437" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('437', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-437-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: Tweets that mention The Wire: Google Security Edition — Krebs on Security -- Topsy.com</title><link>http://krebsonsecurity.com/2010/01/the-wire-google-security-edition/#comment-402</link> <dc:creator>Tweets that mention The Wire: Google Security Edition — Krebs on Security -- Topsy.com</dc:creator> <pubDate>Fri, 15 Jan 2010 02:09:40 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=451#comment-402</guid> <description>[...] This post was mentioned on Twitter by Security4all, briankrebs, Christen Gentile, designslinger, Isti and others. Isti said: RT @security4all: Gmail moves to &quot;always encrypted;&quot; cynics see ulterior motives in Google&#039;s hack disclosure: http://bit.ly/5aDniR (via ... [...]</description> <content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by Security4all, briankrebs, Christen Gentile, designslinger, Isti and others. Isti said: RT @security4all: Gmail moves to &quot;always encrypted;&quot; cynics see ulterior motives in Google&#39;s hack disclosure: <a
href="http://bit.ly/5aDniR" rel="nofollow">http://bit.ly/5aDniR</a> (via &#8230; [...]</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-402" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('402', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-402-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-402" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('402', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-402-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: BrianKrebs</title><link>http://krebsonsecurity.com/2010/01/the-wire-google-security-edition/#comment-400</link> <dc:creator>BrianKrebs</dc:creator> <pubDate>Fri, 15 Jan 2010 00:20:32 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=451#comment-400</guid> <description>Cpt Canuck is right. There&#039;s no security advantage to adding another app to checking your email. That said, newer versions of Outlook are much more secure than older Outlook and OE versions (for example, active scripting restrictions). And yes, Thunderbird is probably safer.</description> <content:encoded><![CDATA[<p>Cpt Canuck is right. There&#8217;s no security advantage to adding another app to checking your email. That said, newer versions of Outlook are much more secure than older Outlook and OE versions (for example, active scripting restrictions). And yes, Thunderbird is probably safer.</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-400" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('400', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-400-up" style="font-size:12px; color:#009933;">2</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-400" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('400', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-400-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: Captain Canuck</title><link>http://krebsonsecurity.com/2010/01/the-wire-google-security-edition/#comment-399</link> <dc:creator>Captain Canuck</dc:creator> <pubDate>Fri, 15 Jan 2010 00:03:18 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=451#comment-399</guid> <description>Outlook isn&#039;t the best email client there is in the security sense. Try Mozilla Thunderbird instead.Security-wise, I can think of two advantages for using an email client instead of the web interface:- cuts out your middleman (your browser) incase it has any security issues
- if your email server&#039;s go offline, you have backups on your computer.</description> <content:encoded><![CDATA[<p>Outlook isn&#8217;t the best email client there is in the security sense. Try Mozilla Thunderbird instead.</p><p>Security-wise, I can think of two advantages for using an email client instead of the web interface:</p><p> &#8211; cuts out your middleman (your browser) incase it has any security issues<br
/> &#8211; if your email server&#8217;s go offline, you have backups on your computer.</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-399" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('399', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-399-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-399" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('399', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-399-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: JohnJ</title><link>http://krebsonsecurity.com/2010/01/the-wire-google-security-edition/#comment-397</link> <dc:creator>JohnJ</dc:creator> <pubDate>Thu, 14 Jan 2010 22:20:12 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=451#comment-397</guid> <description>When using a webmail service, is there any security difference between logging on at the e-mail web site, and sending/retrieving your mail using Outlook?</description> <content:encoded><![CDATA[<p>When using a webmail service, is there any security difference between logging on at the e-mail web site, and sending/retrieving your mail using Outlook?</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-397" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('397', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-397-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-397" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('397', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-397-down" style="font-size:12px; color:#990033;">1</span></p>]]></content:encoded> </item> <item><title>By: Google, China, and Lawful Intercept &#124; nothing important, just security ...</title><link>http://krebsonsecurity.com/2010/01/the-wire-google-security-edition/#comment-396</link> <dc:creator>Google, China, and Lawful Intercept &#124; nothing important, just security ...</dc:creator> <pubDate>Thu, 14 Jan 2010 22:19:06 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=451#comment-396</guid> <description>[...] about it. I&#8217;m sure that more details will come out over the next few weeks. Brian Krebs has an excellent summary article posted; I hope he&#8217;ll continue to update it. For the moment, though, my tentative conclusions are [...]</description> <content:encoded><![CDATA[<p>[...] about it. I&#8217;m sure that more details will come out over the next few weeks. Brian Krebs has an excellent summary article posted; I hope he&#8217;ll continue to update it. For the moment, though, my tentative conclusions are [...]</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-396" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('396', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-396-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-396" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('396', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-396-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: f</title><link>http://krebsonsecurity.com/2010/01/the-wire-google-security-edition/#comment-392</link> <dc:creator>f</dc:creator> <pubDate>Thu, 14 Jan 2010 20:18:12 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=451#comment-392</guid> <description>Could you explain to me the effect this is having on Symantecs Norton Anti Virus 2010?I have noticed a change in the way Norton is working.Am I still protected while using Norton?What should I do?Thank you very much.</description> <content:encoded><![CDATA[<p>Could you explain to me the effect this is having on Symantecs Norton Anti Virus 2010?I have noticed a change in the way Norton is working.Am I still protected while using Norton?What should I do?Thank you very much.</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-392" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('392', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-392-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-392" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('392', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-392-down" style="font-size:12px; color:#990033;">3</span></p>]]></content:encoded> </item> <item><title>By: d</title><link>http://krebsonsecurity.com/2010/01/the-wire-google-security-edition/#comment-387</link> <dc:creator>d</dc:creator> <pubDate>Thu, 14 Jan 2010 17:52:07 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=451#comment-387</guid> <description>Yea, for Google! I was about ready to dump them. Their lack of providing constant encryption has always bothered me. So much so, that I still have yet to  try their other products. Much like the poll you just conducted Brian, some people don&#039;t care what&#039;s lurking out there and some do. I have been a user of NoScript and took your advice about RequestPolicy. Lately, every time I log in to gmail there seems to be yet another cookie. Giving their cookies a short expiration date would be another step in the right direction.</description> <content:encoded><![CDATA[<div
style="background-color:#FFFFCC !important"><p>Yea, for Google! I was about ready to dump them. Their lack of providing constant encryption has always bothered me. So much so, that I still have yet to  try their other products. Much like the poll you just conducted Brian, some people don&#8217;t care what&#8217;s lurking out there and some do. I have been a user of NoScript and took your advice about RequestPolicy. Lately, every time I log in to gmail there seems to be yet another cookie. Giving their cookies a short expiration date would be another step in the right direction.</p></div><p>Well-loved. Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-387" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('387', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-387-up" style="font-size:12px; color:#009933;">4</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-387" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('387', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-387-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using memcached
Page Caching using memcached (user agent is rejected)
Database Caching 4/9 queries in 0.002 seconds using memcached

Served from: krebsonsecurity.com @ 2010-07-30 05:28:27 -->