A couple of weeks ago i was about to post an article on my blog to make people aware of a possible security flaw in the gmail service. I then decided to let google know first before lettig anyone else know. It seemed ethical and right behaviour.
The following is what i intended to write
Has anyone noticed that you can be connected to googlemail either securely(over SSL / https ) or unsecurely (unencrypted http connecction)? Although the login pages them selfes are viewed over a secure ssl connection, once you are logged in to gmail, the connection redirects you back to an unsecure connection. You can manually change that by typing https:// google url here but not many people will notice or do that. Anyone with a network sniffer can see pages of your emails etc. There doesnt seem to be anyway of letting google know about this issue as there is no place where people can send feedback
After posting my email – request to google at 2 different feedback points, neither of which was to be used for technical feedback regarding problems with their service, but questions about things such as why people cant log in to their accounts(useful) or saying how great googlemail is (yeah.. right…). No feedback point exists for posting technical feedback regarding their service (overconfident arent they?? ). After waitting for a few days, i got a generic email reply letting me know my account was suspended due to security reasons. At that point i was furius! Trying to help them improve their service so that they can suspend my account? I couldnt believe it.
I calmed down and replied asking why my account was suspended as i was not in violation of the user agreement i agreed to when signing up for google (not using google for sharing illegal files et cetera) . After waitting for a few days and forgeting about it, i got an email 2 days ago basically giving me instructions on how to reset my password (can you believe this?) and telling me the following:
Also, regarding your first message, please note that because we are
testing Google Mail, there is some information we are unable to share. To
read more details about Google Mail, please visit:
http://mail.google.com/mail/help/about.html.
Indeed i have to agree with them. Google mail is still in beta, offers no guarantees of its service nor of the confidetiality, integrity and availability of our data. How many of us realise this though? Everyone is switching from microsoft’s email service to google’s one simply because it offers more space (in theory, i think they also dropped the 40 Gig space thing and just state how much space they “really” offer now, with some increase every day). Gmail does offer a simpler user interface, but does it offer enough for us to switch from using another email provider out there for our day to day emailing needs to go to gmail? I for one use microsoft’s hotmail service. It is not the greatest, it doesnt provide me with the assurance of confidentiality, as i dont have much trust over microsoft as a company, but it has proven to be reliable for my every day needs, including offering me with a secure connection to their end without expecting me to switch from one protocol to the other manually.
Isnt Google, the company of the future realising that this is simply a blow to its image? atleast to me. The idea of people being able to view the emails i am looking at, just by running a network sniffer on the network I am at, and not only, is not so nice. The solution to this issue is a very trivial one, all they have to do is redirect the traffic it self over https not only during the login page but through out the session, to allow the encrypted communication channel between us and google to be present.
Is this done so that google’s server load is not as much? SSL connections are resource consuming, i agree, but does google have that much of a problem that it is worried about its computing resources?? are they running low on cash? or are beta projects not that well funded?? OR is google monitoring traffic that comes and goes between us and its servers and having non encrypted connections makes it easier for them, and for other “organizations” to do so. (atleast if microsoft does it, it does it more discreatly). I guess this brings up the issue of being careful of what we save on gmail. After this i doubt there is much privacy offered by google’s services, or atleast not more than microsoft’s. Plenty of more to say here but i will leave it up to that. If you want me to post copies of the email correspondance feel free to ask me. Forgive my spelling mistakes