Major University Dumps Gmail Over Security Concerns
mashable.com
mashable.com
A legitimate reason to not use Google is their history of less than perfect customer service; they excel in technology, not in customer service.
Google's sophisticated systems have already been compromised by unsophisticated hackers in China.
A house with 5 doors is less secure than a house with 1 door. A house with no windows is more secure than a house with windows.
EDIT: meastham makes a good point and he/she could definitely be right about generating hashes of all slight variations of each password. In response to what fname said, I'm wondering if there are any security concerns about being able to find similarities in hashes for similar passwords.
I think many people are misunderstanding what you're saying i.e., they think you're saying that similarities between hashes correspond to similarities between passwords.
EDITed to add: There's some logic to detect how close a new password is to an old one. Mainly, it's looking for consistencies between the 2.
Your comment solely addresses security, but privacy concerns are not necessarily the same as security concerns
I do have an interest in this: I'm about to move a campus to Gmail. I have no evidence it's less secure than the Exchange/Postfix systems it will be replacing, and I suspect in many ways it is more secure. I would welcome evidence to the contrary but the OP doesn't have any. This sounds like a bunch of people who don't understand "hacking" making loud about how the cloud just has to be less secure than their in-house systems.
My employer uses a hosted Exchange service, and I've not heard anyone raise a peep about privacy concerns. I suspect, however, that if we decided to move to Google Mail, people would raise the same sort of concerns.
Keep in mind that, as with any IT department in a large organization, there are vested interests to protect and outsourcing infrastructure can often be seen as a threat.
Holding up privacy as the showstopper is bit of a straw man. I could easily list a bunch of reasons why keeping mail service local has major downsides and security concerns.
I'm not assuming that the IT dept in question had covert motives in this, just noting that we certainly aren't getting all the information in this situation.
The only reason I don't pump it through my Gmail account is the level of crap that gets sent on mailing lists.
While I understand they do use my information for advertising purposes, is that the extent of it? Am I just misguided? I don't really think there is anything to worry about, but I don't trust them. Should I?
There are several options, so there is no need to subject yourself to those concerns.