440Forums  |  MacMusic.org  |  PcMusic.org  |  440tv  |  Zicos  |  AudioLexic
letter   {key13}


Security Experts Urge Google to Secure All Sessions

TidBITS

Friday June 19, 2009. 10:27 PM
TidBITS

Google has been name-checked on security. A letter sent on 16-Jun-09 to Google CEO Eric Schmidt strongly urges the company to make a secure connection the default method for Web applications. Among the 38 signatories to the letter are a host of well-known security experts, researchers, and advocates, including Ronald Rivest (the R of RSA), Bruce Schneier, Jon Callas, Eugene Spafford, Peter G. Neumann, William Cheswick, and Steven Bellovin.

Two years ago, Google's use of unsecured connections came to the fore with the discovery of sidejacking, a technique for grabbing the authentication cookies that Google uses to identify users during an unsecured session and inserting them into a browser under the sidejacker's control. Sidejacking can be performed anywhere there's an open Wi-Fi hotspot or an untrusted Ethernet network in which traffic is mingled and sniffable. (See "Sidejack Attack Jimmies Open Gmail, Other Services," 2007-08-27.)

Google has taken some steps to derail sidejacking, including marking the Gmail authentication cookie with a secure flag that should keep it from being sent without encryption even if https isn't used. Google also added an option to require https (SSL/TLS secured) connections for Gmail. (See "Google Gmail Adds Secure Session Option," 2008-07-28.) The researchers noted that other services, like Google Docs and Google Calendar, support https as well, although there's no way to set that level of security as a default.

The letter sent to Google claims that acquiring a Google authentication cookie from Docs or Calendar would allow access to Gmail, but one of Google's security team members, Alma Whitten, said in a blog entry that it wouldn't be possible for such a cookie to be intercepted.

The security experts urge that https sessions become the default for all Web-based services. The letter acknowledges that this lack is a widespread problem, and is even worse at Microsoft Hotmail, Yahoo Mail, Facebook, and MySpace because those services don't offer a secure option. We expect that the security experts are starting with Google because of Google's existing optional support for secure connections, and if they can convince Google to make the switch, they'll move on to these other companies.

They note that because Google apps are designed to work asynchronously, queuing and performing tasks at the server and then updating the browser without a page reload, any latency introduced by the additional user or server computational load for encryption won't make the experience of using these applications worse.

Google's response, in Whitten's blog entry, is that Google remains concerned that there's not enough known about whether specific computer configurations, networks, or parts of the world would suffer far worse performance in an all-https world. Whitten also said that Google is planning a trial that moves small sets of Gmail customers who haven't explicitly requested https-only sessions to that option. Copyright © 2009 Glenn Fleishman. TidBITS is copyright © 2009 TidBITS Publishing Inc. If you're reading this article on a Web site other than TidBITS.com, please let us know, because if it was republished without attribution, by a commercial site, or in modified form, it violates our Creative Commons License.

WebCrossing Neighbors Creates Private Social NetworksCreate a complete social network with your company or group'sown look. Scalable, extensible and extremely customizable.Take a guided tour today <http://www.webcrossing.com/tour>

 
Google been name-checked security. letter sent 16-Jun-09 Google Eric Schmidt stro Security Experts Urge Google Secure Sessions
Security Experts Urge Google to Secure All Sessions Read more at TidBITS
feedproxy.google.com/~r/tidbits_main/~3/rSjU9osmv7E/10364

 

 Related News 
No Java fix in OS X 10.5.7 leaves Macs vulnerable, claim secu... No Java fix in OS X 10.5.7 leaves Macs vulnerable, claim secu...
 Macworld UK 05/20/09 01 PM 
Google Making Gmail More Secure, Dan Knight, Mac Musings Google Making Gmail More Secure, Dan Knight, Mac Musings
 Low End Mac 06/17/09 03 PM 
US senators urge FCC to review exclusive deals between carrie... US senators urge FCC to review exclusive deals between carrie...
 Mac Daily News 06/15/09 10 PM 
Google to try more security on Gmail Google to try more security on Gmail
 Mac Central 06/17/09 12 AM 
Google fixes 'critical' security hole in Chrome Google fixes 'critical' security hole in Chrome
 Mac Central 06/23/09 06 PM 
Google fixes 'critical' security hole in Chrome Google fixes 'critical' security hole in Chrome
 Macworld UK 06/24/09 08 AM 
Google urged to improve Gmail privacy and security risks Google urged to improve Gmail privacy and security risks
 Macworld UK 06/17/09 08 AM 
Do You Still Believe the Experts? Do You Still Believe the Experts?
 TheMacNightOwl 06/23/09 02 AM 
Apple should disclose CEO Steve Jobs? liver transplant, some ... Apple should disclose CEO Steve Jobs? liver transplant, some ...
 Mac Daily News 06/22/09 09 PM 
Citrix?s ?XenClient for the Mac? promises faster, more secure... Citrix?s ?XenClient for the Mac? promises faster, more secure...
 Mac Daily News 05/11/09 02 PM 
Kingston Technology Adds Mac Compatibility to DataTraveler Va... Kingston Technology Adds Mac Compatibility to DataTraveler Va...
 AppleLinks 05/12/09 06 AM 
Zevrix releases Instant Backup 1.6 for Secure On-line and Loc... Zevrix releases Instant Backup 1.6 for Secure On-line and Loc...
 Mac Megasite 06/24/09 02 AM 
Mac OSX 10.4 Tiger gets security updates Mac OSX 10.4 Tiger gets security updates
 Macworld UK 05/13/09 08 AM 
Tiger gets security updates Tiger gets security updates
 Mac Central 05/12/09 11 PM 
Safari 3.2.3 improves security Safari 3.2.3 improves security
 Mac Central 05/12/09 10 PM 
Mac OS X 10.4 Tiger gets security updates Mac OS X 10.4 Tiger gets security updates
 Macworld UK 05/13/09 08 AM 
Apple Releases Mac OS X 10.5.7 and Security Updates Apple Releases Mac OS X 10.5.7 and Security Updates
 Mac Bidouille 05/12/09 05 AM 
Security Update 2009-002 (OS X Tiger) Security Update 2009-002 (OS X Tiger)
 AccelerateYourMac 05/12/09 08 PM 
Security improvements punctuate iPhone 3.0 Security improvements punctuate iPhone 3.0
 Mac Central 06/17/09 07 PM 
The Myths of Security - New from O’Reilly The Myths of Security - New from O’Reilly
 AppleLinks 07/01/09 06 AM 
Apple lags on Java security fix in OS X Apple lags on Java security fix in OS X
 Mac Central 05/20/09 04 PM 

Search

Mac Zicos
Fri March 19, 01:16 PM
letter   {key13}