Notices
The Basement Non-Honda/Acura discussion. Content should be tasteful and "primetime" safe.

Gmail users enter...

Thread Tools
 
Old Aug 19, 2008 | 09:15 AM
  #1  
thomas's Avatar
thomas
Thread Starter
pew pew pew
 
Joined: Jan 2005
Posts: 6,437
Likes: 0
From: teh az
Default Gmail users enter...

Saw this on slashdot

http://www.hungry-hackers.com/2008/0...king-tool.html

A tool that automatically steals IDs of non-encrypted sessions and breaks into Google Mail accounts has been presented at the Defcon hackers’ conference in Las Vegas.

Last week Google introduced a new feature in Gmail that allows users to permanently switch on SSL and use it for every action involving Gmail, and not only, authentication. Users who did not turn it on now have a serious reason to do so as Mike Perry, the reverse engineer from San Francisco who developed the tool is planning to release it in two weeks.

When you log in to Gmail the website sends a cookie (a text file) containing your session ID to the browser. This file makes it possible for the website to know that you are authenticated and keep you logged in for two weeks, unless you manually hit the sign out button. When you hit sign out this cookie is cleared.

Even though when you log in, Gmail forces the authentication over SSL (Secure Socket Layer), you are not secure because it reverts back to a regular unencrypted connection after the authentication is done. According to Google this behavior was chosen because of low-bandwidth users, as SLL connections are slower.

The problem lies with the fact that every time you access anything on Gmail, even an image, your browser also sends your cookie to the website. This makes it possible for an attacker sniffing traffic on the network to insert an image served from http://mail.google.com and force your browser to send the cookie file, thus getting your session ID. Once this happens the attacker can log in to the account without the need of a password. People checking their e-mail from public wireless hotspots are obviously more likely to get attacked than the ones using secure wired networks.

Perry mentioned that he notified Google about this situation over a year ago and even though eventually it made this option available, he is not happy with the lack of information. “Google did not explain why using this new feature was so important” he said. He continued and explained the implications of not informing the users, “This gives people who routinely log in to Gmail beginning with an https:// session a false sense of security, because they think they’re secure but they’re really not.”

If you are logging in to your Gmail account from different locations and you would like to benefit from this option only when you are using unsecured networks, you can force it by manually typing https://mail.google.com before you log in. This will access the SSL version of Gmail and it will be persistent over your entire session and not only during authentication.
you can force SSL always by going to settings and where it says browser connection switch it to "always use https"
Reply
Old Aug 19, 2008 | 09:18 AM
  #2  
RicoD's Avatar
RicoD
Pull my finger
 
Joined: Apr 2004
Posts: 41,423
Likes: 0
From: Arizona
Default

sweet
Reply
Old Aug 19, 2008 | 09:29 AM
  #3  
HawtPants's Avatar
HawtPants
the one and only
 
Joined: Dec 2000
Posts: 15,571
Likes: 0
From: Govenator Territory
Default

good info, repped :0
Reply
Old Aug 19, 2008 | 10:02 AM
  #4  
flipped cracka's Avatar
flipped cracka
BOOM goes the dynamite!
 
Joined: Mar 2003
Posts: 27,571
Likes: 1
From: in a van down by the rive
Default

setting changed. thanks.
Reply
Old Aug 19, 2008 | 10:07 AM
  #5  
R_Squared's Avatar
R_Squared
LEVEL UP
 
Joined: Sep 2004
Posts: 11,426
Likes: 1
From: Indianapolis
Default

Originally Posted by HawtPants
good info, repped :0
LOL, what he said. thanks.
Reply
Old Aug 19, 2008 | 10:25 AM
  #6  
Just Janna's Avatar
Just Janna
Cake or Death?
 
Joined: Jun 2003
Posts: 20,749
Likes: 0
From: NJ
Default




Nice looking out.
Reply
Old Aug 19, 2008 | 10:47 AM
  #7  
Dweezel's Avatar
Dweezel
d@weezel music
 
Joined: Jun 2002
Posts: 5,929
Likes: 0
Default

Thanks man, much appreciated.
Reply
Old Aug 19, 2008 | 10:51 AM
  #8  
M@rshy's Avatar
M@rshy
٩(̾●̮̮̃̾•̃̾)۶
 
Joined: Aug 2004
Posts: 21,807
Likes: 0
Default

Cool. Thanks. I'll be passing this around.
Reply
Old Aug 19, 2008 | 11:24 AM
  #9  
JCEN's Avatar
JCEN
Z0chicks
 
Joined: Oct 2004
Posts: 3,387
Likes: 0
From: PA
Default

Thank you just switched it
Reply
Old Aug 19, 2008 | 12:23 PM
  #10  
thomas's Avatar
thomas
Thread Starter
pew pew pew
 
Joined: Jan 2005
Posts: 6,437
Likes: 0
From: teh az
Default

Originally Posted by RicoD
sweet
Originally Posted by HawtPants
good info, repped :0
Originally Posted by flipped cracka
setting changed. thanks.
Originally Posted by red94teg
LOL, what he said. thanks.
Originally Posted by Just Janna



Nice looking out.
Originally Posted by Dweezel
Thanks man, much appreciated.
Originally Posted by MarshyTheKid
Cool. Thanks. I'll be passing this around.
Originally Posted by JCEN
Thank you just switched it
No problem
Reply



All times are GMT -8. The time now is 05:46 AM.