HTTPS encryption increased for Gmail and Google+

November 27, 2011

Google already offers HTTPS as default for Gmail and encrypted search. Google has now moved on and is now enabling "forward secrecy" by default. Forward secrecy (or PFS) ensures that a session key cannot be compromised if a long term private key is compromised in the future. What this means is, forward secrecy doesn't allow persistent stored private keys to be used for connections and helps stop hackers (using ECDHE encryption) from snooping on your HTTPS network connection.

If a private single key is broken a hacker will be unable to decrypt your connection history - in fact it makes it almost impossible to decrypt HTTPS sessions. Google is planning ahead because in the future computer systems will be much faster and could break a servers private key and decrypt email traffic. As for supporting TLS 1.1/1.2 Google says not right now but plans too in the future. Read more...

Recommended From Hakin9

Security firm RSA Security breached

Security firm RSA Security breached

RSA Security is one of the biggest players in the enterprise security landscape, featuring advanced ....

Notify of

This site uses Akismet to reduce spam. Learn how your comment data is processed.

1 Comment
Oldest Most Voted
Inline Feedbacks
View all comments
© HAKIN9 MEDIA SP. Z O.O. SP. K. 2023
What certifications or qualifications do you hold?
Max. file size: 150 MB.

What level of experience should the ideal candidate have?
What certifications or qualifications are preferred?

Download Free eBook

Step 1 of 4


We’re committed to your privacy. Hakin9 uses the information you provide to us to contact you about our relevant content, products, and services. You may unsubscribe from these communications at any time. For more information, check out our Privacy Policy.