<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.thestandard.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title></title>
 <link>http://www.thestandard.com/node/111935/comments</link>
 <description>comments feed.</description>
 <language>en</language>
<item>
 <title>Optional Gmail &quot;feature&quot; really an exploit fix</title>
 <link>http://www.thestandard.com/news/2008/08/19/optional-gmail-feature-really-bug-fix</link>
 <description>&lt;!--paging_filter--&gt;&lt;p&gt;&lt;!--paging_filter--&gt;
&lt;p&gt;&lt;!--paging_filter--&gt; &lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/sites/thestandard.com/files/u4993/Gmail_logo.jpg&quot; alt=&quot;Gmail logo image&quot; align=&quot;left&quot; border=&quot;0&quot; height=&quot;66&quot; hspace=&quot;10&quot; vspace=&quot;10&quot; width=&quot;143&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Last month, &lt;a href=&quot;http://blog.washingtonpost.com/securityfix/2008/07/gmail_gains_two_new_security_f_1.html?nav=rss_blog&quot;&gt;Google rolled out an SSL feature&lt;/a&gt; for Gmail to thwart an exploit brought to them a year ago and later publicly presented at the recent Defcon conference, &lt;a href=&quot;http://www.hungry-hackers.com/2008/08/gmail-account-hacking-tool.html&quot;&gt;according to Hacking Truths&lt;/a&gt;. There was no announcement for the new feature, and it was offered as an option, which I&#039;m willing to bet was largely ignored. &lt;/p&gt;
&lt;p&gt;Gmail is a perpetual beta, but should still bear some responsibility for its users&#039; security. If they really did have a year to issue a fix, and left it to an optional &amp;quot;feature&amp;quot; with no explanation to their users, they&#039;ve pushed that responsibility back to their users without even a basic explanation of the protection it provides. If you click the &amp;quot;&lt;a href=&quot;http://mail.google.com/support/bin/answer.py?hl=en&amp;amp;ctx=mail&amp;amp;answer=74765&quot;&gt;learn more&lt;/a&gt;&amp;quot; link, the text provided by Google actually sounds like it&#039;s discouraging users from enabling the feature, stating:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;i&gt;&amp;quot;Please note that selecting &#039;Always use https&#039; will prevent you from accessing Gmail via HTTP (Hypertext Transfer Protocol). In addition, it may make Gmail a bit slower. If you trust the security of your network, you can turn this feature off at any time.&amp;quot;&lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;&lt;img src=&quot;/sites/thestandard.com/files/u4993/GmailSSL_screenshot.jpg&quot; alt=&quot;Gmail SSL feature screenshot image&quot; height=&quot;55&quot; width=&quot;505&quot; /&gt; &lt;br clear=&quot;all&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;More news, commentary, and predictions from &lt;i&gt;The Industry Standard&lt;/i&gt;:&lt;/b&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Prediction: &lt;b&gt;&lt;a href=&quot;/predictions/gmail-announces-free-unlimited-storage-space&quot;&gt;Gmail announces free, unlimited storage space&lt;/a&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;News: &lt;b&gt;&lt;a href=&quot;/news/2008/08/13/gmail-outage-provides-weapon-cloud-haters&quot;&gt;GMail outage provides weapon for cloud-haters&lt;/a&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;News: &lt;b&gt;&lt;a href=&quot;/news/2008/08/12/google-mobile-app-iphone&quot;&gt;Google Mobile App for iPhone&lt;/a&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;a href=&quot;/news/2008/08/11/picture-gmail-down&quot;&gt;Picture this: Gmail is down&lt;/a&gt;&lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;
</description>
 <comments>http://www.thestandard.com/news/2008/08/19/optional-gmail-feature-really-bug-fix#comments</comments>
 <category domain="http://www.thestandard.com/taxonomy/term/778">co:google</category>
 <category domain="http://www.thestandard.com/taxonomy/term/6707">product:Gmail</category>
 <category domain="http://www.thestandard.com/taxonomy/term/5667">Software &amp;amp; Web</category>
 <category domain="http://www.thestandard.com/taxonomy/term/2514">The Industry Standard</category>
 <pubDate>Wed, 20 Aug 2008 01:55:33 -0400</pubDate>
 <dc:creator>Cyndy Aleo-Carreira</dc:creator>
 <guid isPermaLink="false">111935 at http://www.thestandard.com</guid>
</item>
<item>
 <title>Optional Gmail &quot;feature&quot; really an exploit fix</title>
 <link>http://www.thestandard.com/news/2008/08/19/optional-gmail-feature-really-bug-fix</link>
 <description>&lt;!--paging_filter--&gt;&lt;p&gt;&lt;!--paging_filter--&gt;
&lt;p&gt;&lt;!--paging_filter--&gt; &lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/sites/thestandard.com/files/u4993/Gmail_logo.jpg&quot; alt=&quot;Gmail logo image&quot; align=&quot;left&quot; border=&quot;0&quot; height=&quot;66&quot; hspace=&quot;10&quot; vspace=&quot;10&quot; width=&quot;143&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Last month, &lt;a href=&quot;http://blog.washingtonpost.com/securityfix/2008/07/gmail_gains_two_new_security_f_1.html?nav=rss_blog&quot;&gt;Google rolled out an SSL feature&lt;/a&gt; for Gmail to thwart an exploit brought to them a year ago and later publicly presented at the recent Defcon conference, &lt;a href=&quot;http://www.hungry-hackers.com/2008/08/gmail-account-hacking-tool.html&quot;&gt;according to Hacking Truths&lt;/a&gt;. There was no announcement for the new feature, and it was offered as an option, which I&#039;m willing to bet was largely ignored. &lt;/p&gt;
&lt;p&gt;Gmail is a perpetual beta, but should still bear some responsibility for its users&#039; security. If they really did have a year to issue a fix, and left it to an optional &amp;quot;feature&amp;quot; with no explanation to their users, they&#039;ve pushed that responsibility back to their users without even a basic explanation of the protection it provides. If you click the &amp;quot;&lt;a href=&quot;http://mail.google.com/support/bin/answer.py?hl=en&amp;amp;ctx=mail&amp;amp;answer=74765&quot;&gt;learn more&lt;/a&gt;&amp;quot; link, the text provided by Google actually sounds like it&#039;s discouraging users from enabling the feature, stating:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;i&gt;&amp;quot;Please note that selecting &#039;Always use https&#039; will prevent you from accessing Gmail via HTTP (Hypertext Transfer Protocol). In addition, it may make Gmail a bit slower. If you trust the security of your network, you can turn this feature off at any time.&amp;quot;&lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;&lt;img src=&quot;/sites/thestandard.com/files/u4993/GmailSSL_screenshot.jpg&quot; alt=&quot;Gmail SSL feature screenshot image&quot; height=&quot;55&quot; width=&quot;505&quot; /&gt; &lt;br clear=&quot;all&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;More news, commentary, and predictions from &lt;i&gt;The Industry Standard&lt;/i&gt;:&lt;/b&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Prediction: &lt;b&gt;&lt;a href=&quot;/predictions/gmail-announces-free-unlimited-storage-space&quot;&gt;Gmail announces free, unlimited storage space&lt;/a&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;News: &lt;b&gt;&lt;a href=&quot;/news/2008/08/13/gmail-outage-provides-weapon-cloud-haters&quot;&gt;GMail outage provides weapon for cloud-haters&lt;/a&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;News: &lt;b&gt;&lt;a href=&quot;/news/2008/08/12/google-mobile-app-iphone&quot;&gt;Google Mobile App for iPhone&lt;/a&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;a href=&quot;/news/2008/08/11/picture-gmail-down&quot;&gt;Picture this: Gmail is down&lt;/a&gt;&lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;
</description>
 <comments>http://www.thestandard.com/news/2008/08/19/optional-gmail-feature-really-bug-fix#comments</comments>
 <category domain="http://www.thestandard.com/taxonomy/term/778">co:google</category>
 <category domain="http://www.thestandard.com/taxonomy/term/6707">product:Gmail</category>
 <category domain="http://www.thestandard.com/taxonomy/term/5667">Software &amp;amp; Web</category>
 <category domain="http://www.thestandard.com/taxonomy/term/2514">The Industry Standard</category>
 <pubDate>Wed, 20 Aug 2008 01:55:33 -0400</pubDate>
 <dc:creator>Cyndy Aleo-Carreira</dc:creator>
 <guid isPermaLink="false">111935 at http://www.thestandard.com</guid>
</item>
<item>
 <title>Optional Gmail &quot;feature&quot; really an exploit fix</title>
 <link>http://www.thestandard.com/news/2008/08/19/optional-gmail-feature-really-bug-fix</link>
 <description>&lt;!--paging_filter--&gt;&lt;p&gt;&lt;!--paging_filter--&gt;
&lt;p&gt;&lt;!--paging_filter--&gt; &lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/sites/thestandard.com/files/u4993/Gmail_logo.jpg&quot; alt=&quot;Gmail logo image&quot; align=&quot;left&quot; border=&quot;0&quot; height=&quot;66&quot; hspace=&quot;10&quot; vspace=&quot;10&quot; width=&quot;143&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Last month, &lt;a href=&quot;http://blog.washingtonpost.com/securityfix/2008/07/gmail_gains_two_new_security_f_1.html?nav=rss_blog&quot;&gt;Google rolled out an SSL feature&lt;/a&gt; for Gmail to thwart an exploit brought to them a year ago and later publicly presented at the recent Defcon conference, &lt;a href=&quot;http://www.hungry-hackers.com/2008/08/gmail-account-hacking-tool.html&quot;&gt;according to Hacking Truths&lt;/a&gt;. There was no announcement for the new feature, and it was offered as an option, which I&#039;m willing to bet was largely ignored. &lt;/p&gt;
&lt;p&gt;Gmail is a perpetual beta, but should still bear some responsibility for its users&#039; security. If they really did have a year to issue a fix, and left it to an optional &amp;quot;feature&amp;quot; with no explanation to their users, they&#039;ve pushed that responsibility back to their users without even a basic explanation of the protection it provides. If you click the &amp;quot;&lt;a href=&quot;http://mail.google.com/support/bin/answer.py?hl=en&amp;amp;ctx=mail&amp;amp;answer=74765&quot;&gt;learn more&lt;/a&gt;&amp;quot; link, the text provided by Google actually sounds like it&#039;s discouraging users from enabling the feature, stating:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;i&gt;&amp;quot;Please note that selecting &#039;Always use https&#039; will prevent you from accessing Gmail via HTTP (Hypertext Transfer Protocol). In addition, it may make Gmail a bit slower. If you trust the security of your network, you can turn this feature off at any time.&amp;quot;&lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;&lt;img src=&quot;/sites/thestandard.com/files/u4993/GmailSSL_screenshot.jpg&quot; alt=&quot;Gmail SSL feature screenshot image&quot; height=&quot;55&quot; width=&quot;505&quot; /&gt; &lt;br clear=&quot;all&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;More news, commentary, and predictions from &lt;i&gt;The Industry Standard&lt;/i&gt;:&lt;/b&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Prediction: &lt;b&gt;&lt;a href=&quot;/predictions/gmail-announces-free-unlimited-storage-space&quot;&gt;Gmail announces free, unlimited storage space&lt;/a&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;News: &lt;b&gt;&lt;a href=&quot;/news/2008/08/13/gmail-outage-provides-weapon-cloud-haters&quot;&gt;GMail outage provides weapon for cloud-haters&lt;/a&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;News: &lt;b&gt;&lt;a href=&quot;/news/2008/08/12/google-mobile-app-iphone&quot;&gt;Google Mobile App for iPhone&lt;/a&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;a href=&quot;/news/2008/08/11/picture-gmail-down&quot;&gt;Picture this: Gmail is down&lt;/a&gt;&lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;
</description>
 <comments>http://www.thestandard.com/news/2008/08/19/optional-gmail-feature-really-bug-fix#comments</comments>
 <category domain="http://www.thestandard.com/taxonomy/term/778">co:google</category>
 <category domain="http://www.thestandard.com/taxonomy/term/6707">product:Gmail</category>
 <category domain="http://www.thestandard.com/taxonomy/term/5667">Software &amp;amp; Web</category>
 <category domain="http://www.thestandard.com/taxonomy/term/2514">The Industry Standard</category>
 <pubDate>Wed, 20 Aug 2008 01:55:33 -0400</pubDate>
 <dc:creator>Cyndy Aleo-Carreira</dc:creator>
 <guid isPermaLink="false">111935 at http://www.thestandard.com</guid>
</item>
</channel>
</rss>
