Your GMail account CAN be hacked over insecure WiFi

Today The Next Web posted an episode of BBC Watchdog where it was demonstrated how a GMail account was hacked through insecure (WEP) WiFi.

https_gmail_url

For those of you still wondering, I’d like to confirm that it is indeed possible to hack a GMail account over insecure WiFi: GMail does indeed always send your password through secure HTTP (SSL) so that this can’t be directly hacked, BUT, by default, the rest of your session happens through normal clear-text HTTP.  The Watchdog episode of course gives absolutely no technical details, but it’s most probably the “sidejacking” attack first published by Robert Graham, where the attacker reads the cookies of the post-authentication HTTP traffic and uses them to fool GMail into thinking that they are in fact the legitimate owners attacked GMail account.  This attack works on other webmail and -service providers too.

In short, if you EVER use a network connection that you don’t trust, simply change the “http:” in your URL bar to “https:”, or, even better, change your browser connection to “Always use https” on the GMail Settings – General page.   With both of these solutions, the whole connection will use secure HTTPS (SSL), and cookies can’t be sidejacked.

The drawback of the secure setting is that your GMail access will be slightly slower than usual:  The encryption costs more compute time at both ends, and the transmission of data is slightly less efficient.

Related posts:

  1. GMail Favour
  2. Even more GMail (also for domains) storage for free!
  3. GMail I love you dearly
  4. My GMAIL experiment comes to an end
  5. all your mail belongs to us

3 Responses to Your GMail account CAN be hacked over insecure WiFi

  1. Pingback: Charl Botha

  2. “Always use https” is now the default setting for a gmail account.

    http://gmailblog.blogspot.com/2010/01/default-https-access-for-gmail.html

  3. Pingback: flipangle » Blog Archive » FB security *yawn* – Firesheep *hmmm sounds interesting* – and the opt in option for https on Facebook *yawn*

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>