Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In fairness, if you're e-mailing yourself, chances are it's not going out over the public internet at any point. In Gmail, it's likely not even going anywhere except straight into Google's database.


It's still stored unencrypted, which is not the ideal state for a password at rest.


Absolutely. I use 1password, and it's hard to beat - encrypted, well organized (certainly better than searching Gmail for e-mails from myself!), and it syncs the encrypted store to Dropbox so I can have it on multiple computers.


Your password is 1password too?


Why do you assume that messages in a gmail box are stored unencrypted?



That adds nothing but poorly contrived speculation.

Further, the general notion that email is predominately insecure is often wrong-

-TLS is used for most transports now.

-Email seldom transits through intermediaries (in the less connected world most had layers of smarthosts that were intermediate steps. Now almost all email is sent from origin organization directly to the destination organization, only diverging for highly secure intermediary like Erado).

I still wouldn't ever imagine emailing yourself passwords (email yourself an encrypted spreadsheet sure...to refute another comment, encryption in Office 2007+ is more than adequate) and the like, but just needed to address the hysterics about email.


gmail has been revamped so that China, with a fuck-ton of resources and desire, cannot get into it. they hired the NSA to help them. maybe it's no longer secure from the NSA, but it is from everyone else.


I didn't know the NSA was available to hire.


http://rt.com/usa/news/nsa-epic-foia-court-413/

FWIW, I know security folks at Google and NSA. Google definitely wins the talent war.


My objection was principally to the notion that the NSA is just some 3rd party security consultancy one calls up. Whether there was or was not a partnership that can or cannot be confirmed or denied, who knows, but lacking verifiable evidence, I'm just as likely to believe the NSA's advice was along the lines of "use a firewall and an IDS".


>My objection was principally to the notion that the NSA is just some 3rd party security consultancy one calls up.

When one is Google, it is. Not to mention that NSA very much cares for the trillions of information Google has to offer them and their continuing compliance.


Source?

It's very hard for me to imagine truly trusting that China cannot get into Gmail. Even if you have a great source. :-P


In late 2009, China tried to get into Gmail. According to the forensics done at the time, they managed to compromise 2 accounts. And even then they only managed to read subject lines but not email contents for those accounts.

Google detected them, locked them out, identified over 20 other companies that had been compromised and notified all of them. Furthermore getting compromised was a wake-up call - they immediately took a lot of steps to improve their own security.

See http://techcrunch.com/2010/01/12/google-china-attacks/ for verification of some of this.

So China went after the easier target - users. Users are easy to compromise.

Therefore in 2011 Google notified hundreds of users (including many members of the government) that their accounts had been compromised by China. See http://www.foxnews.com/scitech/2011/06/01/gmail-compromised-... for verification.

Note that this time Google's infrastructure was not targeted. Just end users and still Google tracked it down and notified people.

No system is perfect. I guarantee that Google knows this. But Gmail has a far better claim than any other email system I know of to claim to being able to beat Chinese hackers. (That said, I'm sure that China has not given up.)


But, these are just the incidents we know about. Plus, if the email isn't encrypted, many Google employees potentially have access, which throws the door very wide open.

Also, wasn't Google tracking everyone's movement everywhere, on Android? This is not a company I trust.


From TC link: "We are telling you this because we are committed to transparency, accountability, and maintaining your trust."

You'd think, if that were true, Google would indicate somewhere that, yes indeed, they do encrypt your email.


Have you thought of the operational costs of both encrypting email and still being able to support efficient searching of said email?

It really makes more sense to store unencrypted, and then secure access. The difficulty that motivated and well-prepared attackers have had in getting access demonstrates that they have done a very good job of securing access.


this didn't happen that long ago.

gmail was broken into by someone representing the chinese government. google fully admitted to this. this admittance did not seem to hurt their rep. they would probably admit to it if it had happened again.

google soon thereafter asked the nsa to help them out with security.

http://www.washingtonpost.com/wp-dyn/content/article/2010/02...

http://www.nytimes.com/2010/02/05/science/05google.html

I am not saying that it's impossible for China to get in, but I'm sure it's a whole lot harder


Google is on the public internet, you know.


I deposit money in my bank. My bank is located in Bank Street. Therefore, I have dumped my money in the street.


In bank street. You have dumped the money in bank street. yes.

The huge difference between Internet and the street- and by street i actually mean the safe of the bank, is the ease to steal from the Internet undetected.

Good luck stealing from the bank undetected. You see, they'd have to sneak in and still for example, 0.1cts from random accounts.

Easy electronically. Impossible physically.

The Internet is not nearly as well protected as the physical world AND it doesn't leave traces.

It's like making an analogy to everything + cars. It just doesn't make any sense. Sorry.


>In fairness, if you're e-mailing yourself, chances are it's not going out over the public internet at any point.

I beg to differ:

  traceroute gmail.com 
Or on windows:

  tracert gmail.com
Now do correct me if I'm wrong. But those commands seem to show my packets being routed over the public Internet.

EDIT: While the point about SSL is valid, see my post below.

EDIT2: And as stated above, having your passwords plaintext anywhere, espicially in the cloud, isn't ideal.


If you are using an e-mail client, you will be connecting to the gmail server using STARTTLS, so your e-mails will not be transferred over the public internet in plain text.

If you use the web client, everything is over HTTPS, and, like the gp stated, probably goes nowhere beyond the database, although merely a supposition.


If you're using a client your mail is probably delivered to a local smtp server, might bounce around for a while, and is then delivered to gmail server. You don't know that the last step uses ssl/tsl. Even if it does, what about the 3 other servers it touched? Was it logged somewhere? Did the anti-spam store it? Was it even removed from the spool at all?

My point is, email was not designed to be "secure" (i.e., secret), and is not though that way. Therefore ppl do not work very hard to secure email, and one little band-aid doesn't magically make the whole system "secure".

Your mail could turn up in a log file 5 years from now.


The packets are routed over the public Internet, but if you're using HTTPS, they'll look like encrypted garbage to anyone who doesn't have Google's SSL private key.


Though once again in all fairness, the security of SSL is not a guarantee.

(See: http://googleonlinesecurity.blogspot.com/2011/08/update-on-a...)


The DigiNotar case was an anomaly where the certificate provider was compromised. This is a rare case.


It's nowhere near as rare as you think. There are sub-CA certs issued to private companies all the time, allowing them to MITM any default browser config.

The PKI is now totally broken.


http://www.infoworld.com/t/authentication/weaknesses-in-ssl-...

Seems to happen often enough.

(Then again, 2011 seems to have been something of an unlucky year for security professionals. Just ask RSA.)


Well you got to trust someone... else you should just unplug your computer from the internet :)


I have a feeling he was referring to e-mailing yourself with g-mail's web interface (which you connection to is, typically, SSL Encrypted). However, as the data is still stored unencrypted on google's servers so... yeah, still sucks.


Really curious, how do you guys know that google's servers store our data unencrypted?


Since email generally traverses the internet unencrypted, the consensus is that it's already insecure. There's little to be gained by encrypting it after the fact.

Besides that, what key would they encrypt it with? Something from your password? What do they do with email you get while not logged in? How do you build a search index? I'm actually building something similar, and even after a lot of effort, there's tons of corner cases that simply cannot be protected, so it seems a reasonable guess that gmail does nothing special to encrypt your data.

[edit to add that once you include oauth in the picture, I think the encryption story starts getting really fuzzy.]


Even if the data is stored encrypted, Google can always decrypt it on an as needed basis (since they serve ads based on the content of the email messages.)


When talking about passwords, best to assume the worst case.


It doesn't really matter. Any method of server-side encryption for email (and many other) systems as we currently understand them has inherent flaws.

The simple fact is that key material is accessible in RAM, and even if it weren't, the data still must be decrypted at some point, and once the server is compromised, you can likely capture that decrypted data.

That's not to say you shouldn't do it -- it helps prevent accidents like unwiped drives getting out, and might be a reasonably effective obfuscation against some attacks, but it just isn't secure in the same way that real end-to-end encryption can be.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: