HTTPS encryption increased for Gmail and Google+

November 27, 2011

Google already offers HTTPS as default for Gmail and encrypted search. Google has now moved on and is now enabling “forward secrecy” by default. Forward secrecy (or PFS) ensures that a session key cannot be compromised if a long term private key is compromised in the future. What this means is, forward secrecy doesn’t allow persistent stored private keys to be used for connections and helps stop hackers (using ECDHE encryption) from snooping on your HTTPS network connection.

If a private single key is broken a hacker will be unable to decrypt your connection history – in fact it makes it almost impossible to decrypt HTTPS sessions. Google is planning ahead because in the future computer systems will be much faster and could break a servers private key and decrypt email traffic. As for supporting TLS 1.1/1.2 Google says not right now but plans too in the future. Read more…Comments

Tagged with:

Leave a Comment

Please keep in mind that comments are moderated and rel="nofollow" is in use. So, please do not use a spammy keyword or a domain as your name, or it will be deleted. Let us have a personal and meaningful conversation instead.

You must be logged in to post a comment.

IT MAGAZINES: Hakin9 Magazine | Pentest Magazine | eForensics Magazine | Software Developer's Journal | Hadoop Magazine | Java Magazine
IT Blogs: Hakin9 Magazine Blog | Pentest Magazine Blog | eForensics Magazine Blog | Software Developer's Journal Blog | Hadoop Magazine Blog | Java Magazine Blog
IT ONLINE COURSES: Pentest Laboratory
JOB OFFERS FOR IT SPECIALIST: Jobs on Hakin9 Magazine | Jobs on Pentest Magazine | Jobs on eForensics Magazine | Jobs on Software Developer's Journal | Jobs on Java Magazine | Jobs on Hadoop Magazine
Hakin9 Media Sp. z o.o. Sp. komandytowa ul. Postępu 17D, 02-676 Warszawa