Jeff Atwood's security blunder regarding email
fuscata.com
fuscata.com
Now if you want to take issue with his assumption, then go right ahead, but this is not an instance of Jeff Atwood misunderstanding how [eg]mail works.
The situation is a lot better than it was a handful of years ago. It's not quite the "don't ever do this!" it once was.
I am sure you can send email to GMail accounts with unencrypted SMTP. Just look at the incoming "Received" headers. If they do not contain a "cipher=" section, the connection was not encrypted.
I think what you mean is that GMail requires you to use https for their web interface.
gmail requires STARTTLS (or ssmtp) when an authenticated user submits outbound mail to them via SMTP (http://support.google.com/mail/bin/answer.py?hl=en&answe...), which is what he may have been mis-remembering. But, yes, it is incorrect that all mail sent to gmail.com addresses is TLS encrypted.
$ telnet smtp.gmail.com 587
Trying 173.194.67.108...
Connected to gmail-smtp-msa.l.google.com.
Escape character is '^]'.
220 mx.google.com ESMTP ea6sm27303065wib.5
HELO zwp
250 mx.google.com at your service
AUTH PLAIN [elided]
530 5.7.0 Must issue a STARTTLS command first. ea6sm27303065wib.5
$ telnet smtp.gmail.com 587
Trying 173.194.67.109...
Connected to gmail-smtp-msa.l.google.com.
Escape character is '^]'.
220 mx.google.com ESMTP ff2sm43397967wib.9
HELO zwp
250 mx.google.com at your service
MAIL FROM:<test@example.com>
530 5.7.0 Must issue a STARTTLS command first. ff2sm43397967wib.9[1] http://support.google.com/mail/bin/answer.py?hl=en&answe... [2] https://support.google.com/mail/bin/answer.py?hl=en&answ...
No it's not. First, it's does have to be Google to do something malicious with your mail. An exploit, e.g XSS, could be found for Gmail any day --there were several in the past.
Second, was does "has a secure enough network" means? Does he only ever log on to Gmail from one network? The assumption of "secure enough network" and the words "hacker-proof" do no go together well.
Not necessarily "malicious" - I wonder if I could set up some adwords targeting keywords out of the popular passwords from the various lists of exposed passwords (Gawker, Sony, RockYou, etc), and attempt to social engineer people to give me "just" their passwords on my landing pages... I wonder if I had an unusual password, perhaps "incandescent-frog", in my email archive - could an advertiser "detect" that from me clicking an ad?
[1] http://www.codinghorror.com/blog/2009/07/software-engineerin... [2] http://www.codinghorror.com/blog/2008/11/your-favorite-np-co...
I say unsupported, because if anyone actually read the supposed supporting links, there would at least be a discussion concerning the first link in these comments. At least, I don't see how the contents of that post disqualifies Atwood. I don't think upvoters are actually reviewing the evidence to see if they agree with this reason for disliking Atwood.
Concerning the second link: if you write off Atwood based on occasional mistakes, you are committing the fundamental attribution error [1]: thinking that someone, and therefore all his writing, must be worthless, simply because he sometimes writes nonsense. Never forget that smart and interesting people also make mistakes.
Atwood takes the time to air and explain his ideas about programming. He's not a great writer or a deep thinker [2], but that doesn't matter: he is one of us thinking about what it means to be one of us. I find all of his thoughts interesting, if only to see how someone can come to a different conclusion based on the same premises. They are interesting even if I disagree and even if he is wrong, because it shines a light on how colleagues may think about things. For instance, the second link clearly warns me that I can never take for granted that someone understands what NP-completeness means and have to verify it. That makes even that post worthwhile.
[1] http://en.wikipedia.org/wiki/Fundamental_attribution_error
[2] Though certainly not a bad writer or a shallow thinker
Each time I see some piece of writing from him, on a topic about which I am reasonably knowledgeable, I find some error. As a consequence, I tend to distrust anything from him on any topic about which I am not as familiar with.
This is a common but quite annoying misconception. The following is a perfectly valid deduction: 1. Authority A is correct on matters in subject X p percect of the time. 2. A claims Y regarding a matter in subject X. --> Therefore, Y is correct with probability p.
He's popular because he's high volume, reasonable quality. In the days when his blog was at it's prime, there was a reasonable article to read every day.
http://serverfault.com/questions/122627/how-secure-is-the-en...
There is a known flaw that Office uses (used? I believe it's unfixed) the same RC4 stream for multiple versions of a document, which could be bad news if you used the same password for them and an attacker has old revisions, but even so, that may be hard to leverage if the doc in question is just a list of passwords. [nm, it's been fixed for a while. thanks, nhebb.]
I beg to differ:
traceroute gmail.com
Or on windows: tracert gmail.com
Now do correct me if I'm wrong. But those commands seem to show my packets being routed over the public Internet.EDIT: While the point about SSL is valid, see my post below.
EDIT2: And as stated above, having your passwords plaintext anywhere, espicially in the cloud, isn't ideal.
Besides that, what key would they encrypt it with? Something from your password? What do they do with email you get while not logged in? How do you build a search index? I'm actually building something similar, and even after a lot of effort, there's tons of corner cases that simply cannot be protected, so it seems a reasonable guess that gmail does nothing special to encrypt your data.
[edit to add that once you include oauth in the picture, I think the encryption story starts getting really fuzzy.]
The simple fact is that key material is accessible in RAM, and even if it weren't, the data still must be decrypted at some point, and once the server is compromised, you can likely capture that decrypted data.
That's not to say you shouldn't do it -- it helps prevent accidents like unwiped drives getting out, and might be a reasonably effective obfuscation against some attacks, but it just isn't secure in the same way that real end-to-end encryption can be.
(See: http://googleonlinesecurity.blogspot.com/2011/08/update-on-a...)
Seems to happen often enough.
(Then again, 2011 seems to have been something of an unlucky year for security professionals. Just ask RSA.)
The PKI is now totally broken.
If you use the web client, everything is over HTTPS, and, like the gp stated, probably goes nowhere beyond the database, although merely a supposition.
My point is, email was not designed to be "secure" (i.e., secret), and is not though that way. Therefore ppl do not work very hard to secure email, and one little band-aid doesn't magically make the whole system "secure".
Your mail could turn up in a log file 5 years from now.
It's very hard for me to imagine truly trusting that China cannot get into Gmail. Even if you have a great source. :-P
gmail was broken into by someone representing the chinese government. google fully admitted to this. this admittance did not seem to hurt their rep. they would probably admit to it if it had happened again.
google soon thereafter asked the nsa to help them out with security.
http://www.washingtonpost.com/wp-dyn/content/article/2010/02...
http://www.nytimes.com/2010/02/05/science/05google.html
I am not saying that it's impossible for China to get in, but I'm sure it's a whole lot harder
Google detected them, locked them out, identified over 20 other companies that had been compromised and notified all of them. Furthermore getting compromised was a wake-up call - they immediately took a lot of steps to improve their own security.
See http://techcrunch.com/2010/01/12/google-china-attacks/ for verification of some of this.
So China went after the easier target - users. Users are easy to compromise.
Therefore in 2011 Google notified hundreds of users (including many members of the government) that their accounts had been compromised by China. See http://www.foxnews.com/scitech/2011/06/01/gmail-compromised-... for verification.
Note that this time Google's infrastructure was not targeted. Just end users and still Google tracked it down and notified people.
No system is perfect. I guarantee that Google knows this. But Gmail has a far better claim than any other email system I know of to claim to being able to beat Chinese hackers. (That said, I'm sure that China has not given up.)
You'd think, if that were true, Google would indicate somewhere that, yes indeed, they do encrypt your email.
It really makes more sense to store unencrypted, and then secure access. The difficulty that motivated and well-prepared attackers have had in getting access demonstrates that they have done a very good job of securing access.
Also, wasn't Google tracking everyone's movement everywhere, on Android? This is not a company I trust.
FWIW, I know security folks at Google and NSA. Google definitely wins the talent war.
When one is Google, it is. Not to mention that NSA very much cares for the trillions of information Google has to offer them and their continuing compliance.
Further, the general notion that email is predominately insecure is often wrong-
-TLS is used for most transports now.
-Email seldom transits through intermediaries (in the less connected world most had layers of smarthosts that were intermediate steps. Now almost all email is sent from origin organization directly to the destination organization, only diverging for highly secure intermediary like Erado).
I still wouldn't ever imagine emailing yourself passwords (email yourself an encrypted spreadsheet sure...to refute another comment, encryption in Office 2007+ is more than adequate) and the like, but just needed to address the hysterics about email.
The huge difference between Internet and the street- and by street i actually mean the safe of the bank, is the ease to steal from the Internet undetected.
Good luck stealing from the bank undetected. You see, they'd have to sneak in and still for example, 0.1cts from random accounts.
Easy electronically. Impossible physically.
The Internet is not nearly as well protected as the physical world AND it doesn't leave traces.
It's like making an analogy to everything + cars. It just doesn't make any sense. Sorry.
Even better - don't put it online and don't even save it digitally if you can avoid it (is anyone that steals your wallet or burgles your house going to really bother trying to figure out what a hand-scribbled series of characters might mean?).
Remember him getting his knickers in a twist over AES ECB? Or more recently conflating secure hashes with hashes for other purposes? Or back-peddling on, well, everything?!
I love his writing and read every blog entry. But I shudder if we hold him up as an expert in recommending how to secure passwords and such!
Imagine someone using Hushmail in the same way. It should be a lot more secure. Hushmail uses strong encryption, but has in the past served specially crafted Java applications to the customer because they were cooperating with law enforcement.
Admittedly, if you have law enforcement after you then you need to start being a lot more careful with everything.
Emailing yourself sensitive data unencrypted is simply dumb.
The only mention of emailing things to yourself is wholly contained in the following paragraph:
> The upside is that once you enable this, your email becomes extremely secure, to the point that you can (and I regularly do) email yourself highly sensitive data like passwords and logins to other sites you visit so you can easily retrieve them later.
To me, that's really dangerous advice. It relies on the assumption that you're only emailing things from your own gmail account, to your own gmail account. This means that the only transfer happens between you and Google over a secure HTTPS connection. Your data is transferred securely, stored on Google's servers, and securely transferred back to you when you request it.
At no point is this specific assumption pointed out, nor are the problems with it discussed.
First, although I can't think of a particular reason why gmail-to-gmail emails would be routed outside of Google's servers, that doesn't mean it doesn't happen. If someone could point a blog post discussing it, I would appreciate it.
Second, All bets are off if you use a separate provider. One example might be work email. If you're signed in to a work account already, you might be more inclined to just use that to toss an email at yourself for later. I've certainly done that before, even though I could sign into gmail from work. People could make the mistake of thinking he's saying "send an email to yourself from anywhere" which isn't correct. Incidentally, activating two-factor auth makes it more likely that someone would do work-to-home emailing since there's now an extra barrier to just logging into gmail.
Finally, this seems to rely on the assumption that you're only using the web client to access gmail. If you're using POP3 or IMAP to access your account, you could still be at risk, since I think (though admittedly I'm unsure since I only use the web interface) that these protocols aren't encrypted by default.
To "email yourself" implies using the same service.
> If you're using POP3 or IMAP to access your account, you could still be at risk, since I think (though admittedly I'm unsure since I only use the web interface) that these protocols aren't encrypted by default.
Gmail IMAP requires SSL: http://support.google.com/mail/bin/answer.py?hl=en&answe...
Good to know. I did specify that I never used it, so my understanding could be flawed.
> To "email yourself" implies using the same service.
To you, but not necessarily to everyone. People do have multiple accounts (gmail, personal domain, work, even Facebook gives you an email address you can send things to), and it's really easy to conflate "email yourself" with "send an email to your account", or even to abstract "sending an email to yourself is secure" to "email is secure".
My point was simply that if you make an argument about something as important as security, it's vital that you spell out the limitations to your advice. "Email yourself" is ambiguous enough that it needs a proper disclaimer.
Admittedly, the audience for Coding Horror is mostly people who know this stuff already, but it's certainly not limited to those people exclusively. I started reading his blog midway through college, and it's amazing to me, looking back now, just how naive I was about a lot of things back then.
> To "email yourself" implies
> using the same service.
I would take exactly the opposite interpretation. I regularly email stuff to myself, and it's pretty much never on the same service.Is it possible to use GMail without HTTPS? Somehow I can't imagine Google would enable that?
And now you have to trust the server.
Don't trust anything else.
(OK, technically there are cases where you should trust other stuff, but if you can recognize it you are probably a professional cryptographer).
Or do you carry your GPG key around on your smartphone?
This solution, while technically pure, does not work. Those of us that live in the Real World send our regards.
Oh, and my email isn't GPG encrypted. I just don't store sensitive data in my email.
Gmail indexes messages, which makes it incredibly fast to find a note that I sent to myself. I also use it to remind myself about something important to eventually remember, but I can't work on it right now.