<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Protect yourself now if you use Gmail</title>
	<atom:link href="http://shawnwilsher.com/archives/171/feed" rel="self" type="application/rss+xml" />
	<link>http://shawnwilsher.com/archives/171</link>
	<description></description>
	<lastBuildDate>Mon, 05 Dec 2011 17:26:04 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Ian M</title>
		<link>http://shawnwilsher.com/archives/171/comment-page-1#comment-3047</link>
		<dc:creator>Ian M</dc:creator>
		<pubDate>Mon, 18 Aug 2008 13:38:00 +0000</pubDate>
		<guid isPermaLink="false">http://shawnwilsher.com/?p=171#comment-3047</guid>
		<description>This isn&#039;t available for people who use Google Apps, although the paid-for Premier Edition will have it.</description>
		<content:encoded><![CDATA[<p>This isn&#8217;t available for people who use Google Apps, although the paid-for Premier Edition will have it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gmail et attaques HDM &#171; Stemp</title>
		<link>http://shawnwilsher.com/archives/171/comment-page-1#comment-3038</link>
		<dc:creator>Gmail et attaques HDM &#171; Stemp</dc:creator>
		<pubDate>Sat, 16 Aug 2008 15:46:19 +0000</pubDate>
		<guid isPermaLink="false">http://shawnwilsher.com/?p=171#comment-3038</guid>
		<description>[...] Shawn Wilsher : Protect yourself now if you use Gmail [...]</description>
		<content:encoded><![CDATA[<p>[...] Shawn Wilsher : Protect yourself now if you use Gmail [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Peng&#8217;s links for Saturday, 16 August &#171; I&#8217;m Just an Avatar</title>
		<link>http://shawnwilsher.com/archives/171/comment-page-1#comment-3037</link>
		<dc:creator>Peng&#8217;s links for Saturday, 16 August &#171; I&#8217;m Just an Avatar</dc:creator>
		<pubDate>Sat, 16 Aug 2008 14:48:22 +0000</pubDate>
		<guid isPermaLink="false">http://shawnwilsher.com/?p=171#comment-3037</guid>
		<description>[...] Wilsher: Protect yourself now if you use Gmail. I thought I had posted this when I came across it elsewhere recently, but it looks like I posted [...]</description>
		<content:encoded><![CDATA[<p>[...] Wilsher: Protect yourself now if you use Gmail. I thought I had posted this when I came across it elsewhere recently, but it looks like I posted [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Frank Hecker</title>
		<link>http://shawnwilsher.com/archives/171/comment-page-1#comment-3036</link>
		<dc:creator>Frank Hecker</dc:creator>
		<pubDate>Sat, 16 Aug 2008 12:27:24 +0000</pubDate>
		<guid isPermaLink="false">http://shawnwilsher.com/?p=171#comment-3036</guid>
		<description>A couple of points worth noting: First, to my knowledge this capability is not yet available for people (like me) who use Google Apps instead of regular Gmail. (I don&#039;t see the new setting when using my Google Apps account, but do see it using my old Gmail account.)

Second, if you want additional confirmation that you are connected via SSL and using the right domain, use about:config and change the setting for browser.identity.ssl_domain_display from 0 (the default) to 1. This will cause the domain &quot;google.com&quot; to be displayed in the area to the left of the location bar when you are connected to Gmail via SSL.

When you connect to other SSL sites you&#039;ll see their domains as well. Also, if Google had spent a little more money on an Extended Validation SSL certificate, you&#039;d see a green identity button with &quot;Google, Inc. (US)&quot; (similar to what you see if you connect to PayPal), and you wouldn&#039;t have had to mess with about:config.</description>
		<content:encoded><![CDATA[<p>A couple of points worth noting: First, to my knowledge this capability is not yet available for people (like me) who use Google Apps instead of regular Gmail. (I don&#8217;t see the new setting when using my Google Apps account, but do see it using my old Gmail account.)</p>
<p>Second, if you want additional confirmation that you are connected via SSL and using the right domain, use about:config and change the setting for browser.identity.ssl_domain_display from 0 (the default) to 1. This will cause the domain &#8220;google.com&#8221; to be displayed in the area to the left of the location bar when you are connected to Gmail via SSL.</p>
<p>When you connect to other SSL sites you&#8217;ll see their domains as well. Also, if Google had spent a little more money on an Extended Validation SSL certificate, you&#8217;d see a green identity button with &#8220;Google, Inc. (US)&#8221; (similar to what you see if you connect to PayPal), and you wouldn&#8217;t have had to mess with about:config.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steve Lee</title>
		<link>http://shawnwilsher.com/archives/171/comment-page-1#comment-3035</link>
		<dc:creator>Steve Lee</dc:creator>
		<pubDate>Sat, 16 Aug 2008 10:59:58 +0000</pubDate>
		<guid isPermaLink="false">http://shawnwilsher.com/?p=171#comment-3035</guid>
		<description>Strange it&#039;s not there for me (or anywhere in the settings); google mail (UK) in google apps.
Shame as I often wonder if AJAX connections are https or not as the browser doesn&#039;t give you much of a clue there.</description>
		<content:encoded><![CDATA[<p>Strange it&#8217;s not there for me (or anywhere in the settings); google mail (UK) in google apps.<br />
Shame as I often wonder if AJAX connections are https or not as the browser doesn&#8217;t give you much of a clue there.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wladimir Palant</title>
		<link>http://shawnwilsher.com/archives/171/comment-page-1#comment-3034</link>
		<dc:creator>Wladimir Palant</dc:creator>
		<pubDate>Sat, 16 Aug 2008 10:42:30 +0000</pubDate>
		<guid isPermaLink="false">http://shawnwilsher.com/?p=171#comment-3034</guid>
		<description>The really important thing about this option is that it will flag the cookies so that they will only be sent over HTTPS. If you &quot;only&quot; use https://mail.google.com/ as your entry point for GMail without setting this option, you access everything via HTTPS as well - but a MITM can easily inject an image linking to http://mail.google.com/ on some unrelated (and unencrypted) page which will give him the cookies in clear text. So he will still be able to hijack your session.</description>
		<content:encoded><![CDATA[<p>The really important thing about this option is that it will flag the cookies so that they will only be sent over HTTPS. If you &#8220;only&#8221; use <a href="https://mail.google.com/" rel="nofollow">https://mail.google.com/</a> as your entry point for GMail without setting this option, you access everything via HTTPS as well &#8211; but a MITM can easily inject an image linking to <a href="http://mail.google.com/" rel="nofollow">http://mail.google.com/</a> on some unrelated (and unencrypted) page which will give him the cookies in clear text. So he will still be able to hijack your session.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chaz6</title>
		<link>http://shawnwilsher.com/archives/171/comment-page-1#comment-3033</link>
		<dc:creator>Chaz6</dc:creator>
		<pubDate>Sat, 16 Aug 2008 09:43:58 +0000</pubDate>
		<guid isPermaLink="false">http://shawnwilsher.com/?p=171#comment-3033</guid>
		<description>This option does not seem to be available for Google Apps for Domains users :-(</description>
		<content:encoded><![CDATA[<p>This option does not seem to be available for Google Apps for Domains users :-(</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jesse Ruderman</title>
		<link>http://shawnwilsher.com/archives/171/comment-page-1#comment-3032</link>
		<dc:creator>Jesse Ruderman</dc:creator>
		<pubDate>Sat, 16 Aug 2008 08:38:44 +0000</pubDate>
		<guid isPermaLink="false">http://shawnwilsher.com/?p=171#comment-3032</guid>
		<description>You should select this setting even if you&#039;re careful to always access Gmail using the https URL.  The reason is that it makes your login cookie https-only.  I wish Google made this more clear.  See http://voices.washingtonpost.com/securityfix/2008/08/new_tool_automates_cookie_stea.html</description>
		<content:encoded><![CDATA[<p>You should select this setting even if you&#8217;re careful to always access Gmail using the https URL.  The reason is that it makes your login cookie https-only.  I wish Google made this more clear.  See <a href="http://voices.washingtonpost.com/securityfix/2008/08/new_tool_automates_cookie_stea.html" rel="nofollow">http://voices.washingtonpost.com/securityfix/2008/08/new_tool_automates_cookie_stea.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gordon P. Hemsley</title>
		<link>http://shawnwilsher.com/archives/171/comment-page-1#comment-3031</link>
		<dc:creator>Gordon P. Hemsley</dc:creator>
		<pubDate>Sat, 16 Aug 2008 08:05:48 +0000</pubDate>
		<guid isPermaLink="false">http://shawnwilsher.com/?p=171#comment-3031</guid>
		<description>That must be a new feature. I don&#039;t recall seeing that setting before, and I didn&#039;t already have a preference selected when I went to look for it. (Both radio buttons were empty.)</description>
		<content:encoded><![CDATA[<p>That must be a new feature. I don&#8217;t recall seeing that setting before, and I didn&#8217;t already have a preference selected when I went to look for it. (Both radio buttons were empty.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Da Scritch</title>
		<link>http://shawnwilsher.com/archives/171/comment-page-1#comment-3030</link>
		<dc:creator>Da Scritch</dc:creator>
		<pubDate>Sat, 16 Aug 2008 07:10:39 +0000</pubDate>
		<guid isPermaLink="false">http://shawnwilsher.com/?p=171#comment-3030</guid>
		<description>I tryed, but pidgin lost instantly all access to Gtalk/Jabber. Google seems to have lot of works for doing this not-to-late conversion</description>
		<content:encoded><![CDATA[<p>I tryed, but pidgin lost instantly all access to Gtalk/Jabber. Google seems to have lot of works for doing this not-to-late conversion</p>
]]></content:encoded>
	</item>
</channel>
</rss>

