ARN

Google moves Gmail to more secure HTTPS service

The timing of the action is seen as a response to Chinese hacking attempts against the online mail service.

At the risk of inconveniencing some users, Google has moved its Gmail to a more secure protocol. The timing of the action is seen as a response to Chinese hacking attempts against the online mail service.

Google had previously offered HTTPS access to Gmail as an option, but Tuesday said it has become the default and would be rolled out to users over the next several weeks.

HTTPS, which encrypts Web traffic, is more resource intensive and thus more expensive for Google to offer. The change was announced on the company's official blog, though without a mention of Google's dispute with China over e-mail hacking attempts.

"Using HTTPS helps protect data from being snooped by third parties, such as in public Wi-Fi hotspots," wrote Sam Schillace, Gmail engineering director.

"We initially left the choice of using it up to you because there's a downside: HTTPS can make your mail slower since encrypted data doesn't travel across the web as quickly as unencrypted data. Over the last few months, we've been researching the security/latency tradeoff and decided that turning HTTPS on for everyone was the right thing to do."

HTTPS stands for Hypertext Transport Protocol Secure. It is intended to prevent eavesdropping and so-called man-in-the-middle attacks on information as it traverses the Internet.

Default HTTPS use on Gmail will protect confidential business information, which HTTP doesn't attempt to accomplish. This is important to business users, especially those Gmail users whose business includes campaigning for human rights in China.

HTTPS is the connection protocol already used by financial institutions and other organizations that require secure connections to Web pages and applications. URLs for these connections begin HTTPS://.

For most users, the change should be smooth and perhaps even go unnoticed. However, users that are setup to use Gmail while offline could face trouble.

"If you use offline Gmail over HTTP currently, the switch to HTTPS is likely to cause some problems," the company warned. It offered a link to a page offering instructions for working around the issue.

My take: Though Google's reputation is justifiably tarnished by its near clueless handling of the Nexus One smartphone introduction, it's handling of the China issue--and willingness to sacrifice perhaps billions in long-term revenue--shows Google takes protecting its customers most seriously.

The Nexus One flap will eventually blow over. But, among those who pay attention, Google's noble defense of its customers will be remembered for a very long time.

David Coursey has been writing about technology products and companies for more than 25 years. He tweets as @techinciter and may be contacted via his Web site.

Come socialise with us! Facebook | LinkedIn

More about: Google, Wikipedia
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the ARN comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: security, gmail
ARN Directory | Distributors relevant to this article
Aquion , Avnet Technology Solutions , Ingram Micro Australia
rhs_login_lockGet exclusive access to ARN's news, research and invitation only events.
ARN Distributor Directory
ARN Vendor Directory

iAsset is a channel management ecosystem that automates all major aspects of the entire sales,marketing and service process, including data tracking, integrated learning, knowledge management and product lifecycle management.