Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi all,
Vanilla are planning an update to the site on April 24th (next Wednesday). It is a major PHP8 update which is expected to boost performance across the site. The site will be down from 7pm and it is expected to take about an hour to complete. We appreciate your patience during the update.
Thanks all.

Gmail Account Hacking [** PLEASE READ **]

Options
  • 25-08-2008 11:18am
    #1
    Registered Users Posts: 43,774 ✭✭✭✭


    Sorry if has been posted already but..

    Very interesting!
    Earlier this month, at a well-known conference, there was announced a tool that can hack into any GMail account, regardless of how good your password is, as long as the data is flitting around unencrypted.

    ..

    Google has always had it so that your login credentials flit around encrypted, but once that's done, drops you to an unencrypted session (for long reasons that work out to "it's cheaper that way" for several kinds of "cheaper"). This will leave you quite open to this tool when it's released into the wild at the end of the month.

    However, there's help! Google has just made it so that you can choose to have all your GMail traffic encrypted, and I would recommend this to any GMail user, even if you think "oh, my e-mail isn't that important". It's really easy to fix this. Actually, they should fix the dodgamn underlying bug, but leaving that aside for now, here's what you can do:

    Simply log into GMail, and click on the Settings link over in the top right corner. At the bottom of this screen is a section labelled "Browser Connection", which by default is set to "Don't always use https". Change this to "Always use https", then click the "Save changes" button directly below. That "should" keep you safe from people using this fascinating new toy.


Comments

  • Registered Users Posts: 8,225 ✭✭✭Ciaran500


    How does it work? Is it installed on a Gmail users computer or is it remote?


  • Closed Accounts Posts: 1,910 ✭✭✭barnicles


    What little f*cker did that?:mad::mad::mad::mad::mad::mad::mad::mad::mad::mad::mad::mad::mad:


  • Registered Users Posts: 43,774 ✭✭✭✭Basq


    To be honest, I think it's unbelievable that Gmail isn't encrypted anyways.

    I always thought it was judging by the login page but when viewing your Inbox / Sent Items folders (etc), it's all unencrypted.


  • Moderators, Regional Midwest Moderators Posts: 11,054 Mod ✭✭✭✭MarkR


    Just changed my settings, thanks.


  • Registered Users Posts: 339 ✭✭dbs_sailor


    basquille wrote: »
    To be honest, I think it's unbelievable that Gmail isn't encrypted anyways.

    I always thought it was judging by the login page but when viewing your Inbox / Sent Items folders (etc), it's all unencrypted.

    Well, more security can only be a good thing! :D I've got ridiculous amounts of personal data on my Gmail account. I may do a cleanout.

    It'll be interesting to see how this tool works.


  • Advertisement
  • Registered Users Posts: 18,484 ✭✭✭✭Stephen


    Funny how they always require encryption when you use their imap/smtp service but not their web mail service.


  • Closed Accounts Posts: 17,208 ✭✭✭✭aidan_walsh


    Ciaran500 wrote: »
    How does it work? Is it installed on a Gmail users computer or is it remote?
    Its local, based on an flag that is usually not set in the cookie of an SSL-connected site. Google have fixed the issue so the new cookie will block the exploit.

    So the new entry to your Buzzword Bingo cards these days is "Surfjacking" (link contains a video demo).


  • Moderators, Technology & Internet Moderators Posts: 11,005 Mod ✭✭✭✭yoyo


    Changed setting to https just there cheers

    Nick


  • Registered Users Posts: 8,361 ✭✭✭Gadgetman496


    Cheers for the heads up.

    -

    "Everybody is a genius. But if you judge a fish by its ability to climb a tree, it will live its whole life believing that it is stupid."



  • Registered Users Posts: 171 ✭✭ajmull


    Thanks for that tip. I have changed my settings.


  • Advertisement
  • Registered Users Posts: 81,630 ✭✭✭✭Overheal


    yes yes. That is part of the argument behind restructuring the web, for all of the poor security protocols. but thats not something they can just change overnight, is it.


  • Registered Users Posts: 2,593 ✭✭✭Soundman


    Anyone else using the taskbar Gmail Notifier? Once I changed my settings in my Gmail account, I can no longer connect to the Gmail account with my notifier....

    Anyone else notice this?

    Edit: Just changed the setting back and immediately I can connect to my Gmail account with Gmail notifier.


  • Registered Users Posts: 43,774 ✭✭✭✭Basq


    Soundman wrote: »
    Anyone else using the taskbar Gmail Notifier? Once I changed my settings in my Gmail account, I can no longer connect to the Gmail account with my notifier....

    Anyone else notice this?

    Edit: Just changed the setting back and immediately I can connect to my Gmail account with Gmail notifier.
    Yeah, this was noted on the original blogpost in one of the comments alright.

    Small price to pay to be honest.

    Does it still work if you use Google Talk?


  • Registered Users Posts: 2,593 ✭✭✭Soundman


    I don't use Google Talk, so I don't know I'm afraid.


  • Moderators, Education Moderators, Home & Garden Moderators Posts: 8,104 Mod ✭✭✭✭Jonathan


    Still no sign of forcing ssl on education google hosted mail. :(


  • Closed Accounts Posts: 2,987 ✭✭✭Auvers


    demo on how another tool does a similar job

    http://www.0x000000.com/index.php?i=628&bin=1001110100


  • Closed Accounts Posts: 64 ✭✭scotsmarc


    Maybe this is why you should always go with a quality mail provider.


  • Closed Accounts Posts: 3,119 ✭✭✭Wagon


    Cheers for that one!


  • Registered Users Posts: 68,317 ✭✭✭✭seamus


    Soundman wrote: »
    Anyone else using the taskbar Gmail Notifier? Once I changed my settings in my Gmail account, I can no longer connect to the Gmail account with my notifier....

    Anyone else notice this?

    Edit: Just changed the setting back and immediately I can connect to my Gmail account with Gmail notifier.
    I'm using the plugin for Firefox and my Gmail account was disabled this morning, I'm assuming by the plugin attempting to connect. Just re-enabled it and bingo-bango.


  • Moderators, Education Moderators, Home & Garden Moderators Posts: 8,104 Mod ✭✭✭✭Jonathan


    scotsmarc wrote: »
    Maybe this is why you should always go with a quality mail provider.
    Like who? :rolleyes:


  • Advertisement
  • Registered Users Posts: 990 ✭✭✭rosboy


    There's a patch for Gmail Notifier to fix the problem created when you turn on "Always use HTTP" setting


  • Closed Accounts Posts: 16,339 ✭✭✭✭tman


    basquille wrote: »
    Yeah, this was noted on the original blogpost in one of the comments alright.

    Small price to pay to be honest.

    Does it still work if you use Google Talk?

    Google talk is still working fine for me after enabling that setting.
    Thanks for the heads up, I'll pass this on


  • Registered Users Posts: 43,774 ✭✭✭✭Basq


    tman wrote: »
    Google talk is still working fine for me after enabling that setting.
    Thanks for the heads up, I'll pass this on
    No worries tman. Assumed Google Talk would work alright.

    I wouldn't normally post this stuff.. but work with computing and developing websites is one of the primary areas I work in, and to leave your mail possibly compromised in an unsecured session is unforgivable really.
    rosboy wrote: »
    There's a patch for Gmail Notifier to fix the problem created when you turn on "Always use HTTP" setting
    Cheers for that rosboy.


  • Registered Users Posts: 27 thebandito600


    cheers i just changed mine there


  • Registered Users Posts: 3,871 ✭✭✭Conor108


    I've done this but I still get spam mail sent from me to me? Why is from me? I've changed my password and always log in via https. Anyone know?


  • Closed Accounts Posts: 1,910 ✭✭✭barnicles


    ta


  • Registered Users Posts: 2,593 ✭✭✭Soundman


    Thanks for that rosboy. Worked a treat.


  • Registered Users Posts: 895 ✭✭✭brav


    I just checked my gmail account and all my pages are using https, also I couldn't see the option to use https in the settings.(see attachment)

    I also installed Better Gmail 2.0 and it has an option to force https, which is unticked but gmail is already using https

    Is there something I'm missing?


    UPDATE: I just realised I'm using Coporate Gmail or something(www.google.com/a/) and it seems this is always https, thus the reason I don't have the option to turn it off.
    Checked a normal gmail account it had the option.
    I use Gmail manager to get notifications in the status bar in Firefox and it works OK with Gmail corporate/apps(or whatever they are calling it)


  • Registered Users Posts: 314 ✭✭Alzar


    Updated my settings.

    Thanks!


  • Advertisement
Advertisement