Up until recently, I had always used GMail by typing http://gmail.com into my browser. At some point, however, I started asking myself questions about security and wondered if an https flavor was available. It turns out that it had been there all along and so began the era of more secure GMail for me.
Given that it’s so darn easy to sniff packets these days with tools like ethereal, I recommend you folks update your bookmarks and remember that last ’s’ as well. It’s just plain silly not to.


FYI... this is available for lots of Google services such as the 'ig' homepage, calendar, etc...
In some/many browsers, just type "gmail" and you'll end up at a https log in page, which takes you to http://mail.google.com, but if you change that page (your Gmail page) to https://mail.google.com etc. it sitll works. Not sure what that means.
If you use firefox, you can use greasemonkey http-to-https redirector user script!
encryption... tooo slooowwww.....
If you have sensitive data in your email, why on earth are you using a 3rd party web based system in the first place?
@machineman: Personally, I just don't like giving folks the free opportunity to eavesdrop on me, my appointments, whereabouts, etc. -- whether it is *sensitive* data or not. Besides, there's a lot of non-sensitive data that a psyco-stalker type could put together into something more meaningful if they wanted, I'd think. Using https is a freebie, so why not take advantage of it?
@Justin: A quick search turned up what you were referring to: http://diveintogreasemonkey.org/casestudy/gmailsecure.html
The Firefox CustomizeGoogle extension has an option to always use HTTPS, and a whole load of other cool features besides.
http://www.customizegoogle.com/
and don't forget that Google Notifier does not use encryption when connecting to Gmail / gCal
@dsjkvf: Excellent catch. I didn't think of that. Is that documented somewhere?
I did a quick dump of the strings for the binary and here's what came up:
Goliath-2:/Applications/Google Notifier.app/Contents/MacOS matthew$ strings Google\ Notifier | grep http
https://www.google.com/tools/service/update
http://www.corp.google.com/~oster/Demos/notifier.txt
https://www.google.com/accounts/NewServiceAccount?service=cl
http://www.google.com/googlecalendar/tour.html
https://www.google.com/accounts/NewServiceAccount?service=mail
http://www.google.com/calendar/
http://mail.google.com/mail
http://mail.google.com/a
http://www.google.com/support/calendar
http:
https:
http://mail.google.com/support
httpGetMemo
https
http
httpFetcherWithRequest:
https://www.google.com/accounts
http://t/dacz
httpGetMemo_
httpGetMemo non nil
I may do some tinkering around and see if any of those strings can be edited to point to https:// destinations. I'll also send in a request to Google to provide an option for choosing SSL with Google Notifier.
@Andy Smith: Awesome. Thanks for that link.
Nice catch!!
I do not want to pretend I am smarter than the rest, but from the very beginning I noticed that GMail could be accessed both by standard HTTP and Secure HTTP. In fact that was one of the reasons that convinced me to move to GMail.
Additionaly, the POP3 of GMail could be also acessed over SSL, so this makes GMail a great choice for people that has to use not fully trustable connections.
@xmanoel: And I would even submit that any connection over http is never "trustable" since anyone with trivial knowledge could sniff and reconstruct the packets using freely available tools out there. When you're viewing a webpage, maybe it doesn't matter...but when communicating with a specific person about a specific topic, I'd always want https "just because".
http://gmail.com/ and https://gmail.com/ both automatically redirect you to https://www.google.com/accounts/ServiceLogin?service=mail (etc etc)... The point is that even if you use http instead of https, you are always redirected to the same secure login page.
@anonymous: yes, the login page is https, but if you hit gmail via http://gmail.com, you're http after you log in, whereas if you hit it via https, you're still https after you log in.
Yes, I knew this. However, I usually use a mail client program with GMail -
http://mail.google.com/support/bin/topic.py?topic=1555
- again over SSL, and only go into the web interface periodically in order to clean out the "Sent" folder.
Firefox's Gmail Notifier extension (here: https://addons.mozilla.org/firefox/173/) directs you via the secure site by default. I'm not sure if it does the email checks via the secure connection. But at least when you click on it to go to the site, you don't have to bother.
@ptwobrussell
thanks, that would be really nice, since their notifier is very handy :).
as for me, i've just inspected it with Little Snitch (http://www.obdev.at/products/littlesnitch/index.html), and blocking 80 port has caused Notifier to stop working (since it couldn't connect). that's why i've assumed that it does not use SSL.
however, looking forward to hear from you (and Google) soon. and thanks once again for your help and ineterst :).
Yes
After getting warnings about "the security certificate presented by this website was issued for a different website's address", a search of Gmail's help forum yielded this URL:
https://mail.google.com/mail/s/
Hello, this is a question rather than comment. I saw here you and others deal with gmail very knowledgeably and wonder if I may ask if you and/or others here know whether gmail accepts sending my messages to my list of about 250 names (or a little more) all at once? I tried Yahoo but my friends on my list don't like the idea of having to subscribe, etc. (I don't like them very much either!) I also burned my eyes on listservs' websites trying to find something I can use but I have difficulty understanding all those techi words, etc. If you know of a provider who won't charge an arm and a leg to do my so-called bulk emailing...would you be so very kind as to let me know? I'mjust an individual doing charity work. Thanks ever so very much!!! Adela Pisar, nuevadela2@rcn.com
@Adela: I haven't tried GMail to send to that many people, so I can say one way or the other....but what I will say is that you could get your own mail server from a hosting company for a negligible fee these days. A quick Google search for "email hosting" showed many vendors who will hook you up for ~$5/month.
I contacted the author of the Google Notifier for Mac and asked him about using an SSL connection instead of the usual http used by default. His answer was simple, just set SecureAlways to: 1.
I just switched to Mac, so forgive me if that's not the proper way of setting up the preferences.
Edit your GoogleNotifier file: Library/Preferences/com.google.GmailNotifier.plist
Add a New Sibling called SecureAlways, setup as Boolean and with a value of 1.
I verified with Little Snitch and everything worked fine. Two things you need to know though: the calendar notifier uses port 80 and the link to your inbox is still using http.
But, well, you can now check on your inbox using SSL.
Matt
its a nice thing to use
The tip by Matt about adding a 'SecureAlways' string to the plist file works solidly. For me and my girlfriend, the link to the gmail inbox is also over ssl (blocking port 80 on my router confirms this). I've been getting leery of using gmail notifier recently, so this comes as a relief, because the interface is simple and slick.
The developers are likely holding off on this option as a preference because of the increased overhead of the https protocol. I'm sure the bandwidth adds up pretty quickly for a site like google.
html:/groupt gmail@yahoo.com/
hile/pp.spdd@aol.com/"yellow"/bllu carch 1260p
code:/machelen "USA" COIOUGGIERO@bOSTLK US.COM
I can't connect gmail to mail. Can you tell me what i need to do to get a connection?
TOP TIP
Pull down the Notifier menu (either Calendar or Gmail), hold down Command and Option, and click Preferences on the menu. You'll see a hidden settings editor. Enter 'SecureAlways' in the Key field (upper and lower case must be entered as shown) and 1 in the Value field, then click Set. Quit Notifier and start it up again. From now on all connections with both Gmail & Gcal will be https. Enjah
Interesting comments.. :D
I believe this one applies "Unless each man prodiuses more than he receives, increases his output, there will be less for him than all the others", doesn't it?
This one makes sence "One's first step in wisdom is to kuesstion everything - and one's last is to come to terms with everything."
how to access my gmail account without useing gamil website.Because it blocked in my office.
MANJANUTH: The other way to check Gmail is to configure your email client to retrieve it.
When checking mail in a browser that will actually let you, go to Settings, click on the Forwarding and POP tab, then the Configuration Settings link will give you instructions on setting up your email client. Just make sure that POP is enabled.
Another thing - I found that the tip for making the Notifier secure (using SecureAlways) only work with the Google Notifier, not the Gmail notifier.
HElP - I changed my password at night - forgot it in the morning! Don't know how I managed that only to say that my short term memory must be going (quicker than I thought.) Does ANYONE have a clue how I can get back into my gmail account without a password? I have tried EVERYTHING - I need a hacker. Never thought I'd promote this concept but here I am. Can anyone help me?
his good
not bad
Mba lis gi ngapain ni imel nyampe ga?
How does Gmail SSL Login works ???
I recently downloaded the GMail application on my cell phone... any issues with security there I should be aware of?
Thanks for the tips on the https://mail.google.com, I just heard about it from a friend last night.
Hello.
Iwould like to contact with my friend using this mail.
I got gmail and then deleted it because of all the "junk" mail. still getting like 25 a day. I want it to stop , NOW.
sandra_sword1@verizon.net
systeman24@gmail.org
Plz Send Me your Web Pictures And Vidio Plzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz
just hoped to find another way to get into my account. Have tried several attempts and think my computer is stuffed full of spam. Not sure what to do.
I cannot access my account. It appear a message: "The name of the user and the "contrasenia" do not coincide"
i would like to joine with gmail.com staff in Afghanistan