Lessons learned while protecting Gmail
googleresearch.blogspot.com
googleresearch.blogspot.com
I run several email newsletters. One of them consistently gets marked as a "phishing" attempt by Gmail. They do not get marked as phishing if the email includes no links – but if I include a link, it immediately gets marked as phishing. This disables all of the links in the emails. I regularly get emails from subscribers complaining that the links do not work.
I once sent an email to all of the Gmail subscribers, asking them to explicitly mark my emails as trusted. Many of them did. But, it did not help – they still get marked as phishing attempts. I've implemented SPF and DKIM. It still didn't help.
The problem: Once an email is flagged as "phishing", the links are not clickable. On mobile, there is no way to make them clickable. Most users don't know how to make them clickable, even when it is possible.
All of the emails come from the same domain and the links are always to the same domain. All of them have the same basic format. Other email from this IP address gets through no problem. Google's Postmaster tools give the IP address a 100% reputation. I tried switching to a new sending service, to no avail. Nothing seems to work – no matter what I do, Gmail marks my emails as phishing.
I've contacted Google's postmaster, to no avail.
Basically, Gmail has made it very difficult for people to read the content I send them. There seems to be no way to convince Gmail that my emails are not phishing.
> Safe Browsing has not recently seen malicious content on
Every couple of months, Gmail starts depositing any email from my users into spam. No warning, no rejection, just a vague yellow banner on the recipient's view that says "this message has the characteristics of spam." The message could be in plain text with no links, still the same. I have SPF, DKIM, and rDNS all configured. I send from a single IPv4 and single IPv6 address with matching records. No RBL entries. Even the headers on a "spam" message say that everything passes and is fine.
Oh, and it isn't a domain reputation problem: only one of the domains I host even has a web site and all of them are at least five years old. Two of my domains predate Google itself. :P
The real kicker? I can't use their postmaster site, either. Why? We don't generate enough email to rank a report!
Meanwhile, no problems at all from any other receiving hosts. I have to log into several Gmail accounts and click "this is not spam" on some test messages and then it is fine for another 50 days. After that, back to the bit bucket.
Grr.
I have this problem sending through:
* An email service such as Mailchimp
* My own server with SPF / DKIM and good reputation / deliverability for other domains
* Amazon AWS Simple Email Service
I think it is something on the domain level – perhaps they've flagged the domain.
If the answer is yes, is it viable to sue Gmail of lost business/job?
p.s. if talking about the topic, I have also seen quite drastic measures on emails which are not Google's and pray to god if you CC bunch of GMail addresses. You can be flagged as spam, phishing or whatever pretty quick.
Exactly.
> If the answer is yes, is it viable to sue Gmail of lost business/job?
In my case definitely not, it is the job I currently have :) Everything worked out after I had an epiphany and checked the spam folder.
It worries me, though, that they're willing to accommodate novices to such a degree that they open up advanced users to targeted attacks. For example, Gmail bugs you quite a bit to set a "recovery phone number," but doesn't make it clear that this isn't like 2-factor auth. The phone number is actually a single factor that can be used to reset your password. It even works if you have "traditional" 2-factor enabled.
Thus, the attack looks like this:
1. Look up target's social security number. This is easy with certain online services that were meant for private investigators, but actually let anyone get an account.
2. Contact their cell phone provider. If you don't know which one, guess. There are only a handful of common providers and you'll hit on it eventually. Impersonate the target, say you're going on vacation and need your calls and texts forwarded, and give them the SSN from step 1 to verify.
3. Go to Gmail and say you forgot your password. Opt for the phone based reset, and wait for the text with a reset token to come in. Ideally, do this while the target is asleep to give yourself time to work.
High profile individuals have actually been hit this way, and I think Gmail should offer greater protection to sophisticated users who do everything right, don't fall for phishing, and would never forget their password, but can fall victim to highly targeted attacks.
[1]: http://krebsonsecurity.com/2015/12/2016-reality-lazy-authent...
[2]: https://medium.com/@espringe/amazon-s-customer-service-backd...
https://youtu.be/bjYhmX_OUQQ?t=2m30s
A phone provider's key goal is to continue to provide charged-for services to their customers, not to secure your bank account or dns registrar account... They'll do whatever's needed to allow paying customers to pay or pay more.
Alhough as a customer, I'd like my phones not to be redirect to anybody asking for it, but I understand they don't have the security measures a bank should have.
It's a password that you reuse everywhere and never change.
"The SSA may assign a new Social Security numberto you if you are being harassed, abused, or are in grave danger when using the original number, or if you can prove that someone has stolen your number and is using it."
Unfortunately, maintaining and securing a private email server can be a big job. Google already does that job, and their data centers are much more secure than the VPS provider where you'll host your private email server.
All I'm asking for -- and I don't think this is unreasonable -- is to rely on their world-class technical security, while being able to disable all password recovery methods, which are vulnerable to social engineering.
All the target knows is, his phone has been forwarded and his Gmail password changed. Even assuming the police are willing to help (which is unlikely), all they'll discover is that your phone number is forwarding to a disposable cell phone which was bought with cash.
Things like "You are only strong as your weakest link," "There is no silver bullet," and "Never stop improving" are essentially meaningless platitudes. I would, however, love to see data on headings like "Attacks come in bursts."
Is there a link to something that delves more into each topic?
edit: Saw the links to the slides and video talk. Looks much more comprehensive!
Interesting how that works only one way. If you are in need for some support from Google, then good luck trying to contact them.
I'm looking for a job, and after sending out resumes (and often a URL to my resume) for over a month I realized practically no one was getting my emails. I was being flagged as a spammer.
The only way around this was to signup for a GMail account.
I won't feel very protected losing the roof over my head, GMail. Please fix this.
shrug
Ehh. If you're running a URL shortener, case-sensitive URLs let your URLs stay short longer. Ditto for things like YouTube's video IDs.
But you're right, you have do click on them, any transfer requiring typing is susceptible to losing case.
Does this mean they encrypt customer e-mails at rest on their server?
If you think about it, the files Gmail backends need to access are fairly small: even the upper limit is just couple of tens of megabytes. This is true regardless of whether you get to use hardware acceleration or not. (And in case of modern Xeon servers, you certainly do!)
Servers will spend more time waiting for disk seeks to complete than they do decrypting the data once it's read.
You can even test it yourself: just run "openssl speed aes". My puny laptop does 85MB/s at the most unoptimal settings (AES-256 with 16B blocks), and 92MB/s with conservative settings at same security level (AES-256 with 1kB blocks).
A decent server system can do multiples of that. And once you add hardware acceleration, we're talking about crypto throughput of several hundreds of MB/s. Google servers are connected to top-of-rack switches, and I can make an educated guess that the per-server bandwidth is 1Gb, or roughly ~120MB/s.
For hilarious comparison, even my RPi 2 can do 16MB/s.
So: if we're talking about on-disk storage, crypto will never be your performance bottleneck.
>diverse team
Adding diversity makes the weakest link weaker (and the strongest link stronger). The point of diversity is to increase variance in multiple areas so that a team's "strongest" member in any area is strong. Does not make sense as a solution to weak links.
It just occurred to me that diverse could mean "skilled in different forms of security", and then it's just saying to hire domain experts in as many security domains as you can. That would make diversity a direct solution to the weakest link problem.