Gmail improves its encryption in response to government snooping
Gmail comes up with improved encryption, but there are still limited opportunities for government spies and others to snoop on private e-mail messages
March 25, 2014 at 05:25 AM
10 minute read
The original version of this story was published on Law.com
There is a renewed effort by Google to ensure Gmail is secure from government snooping or from other outsiders with nefarious intentions.
The latest move helps private companies and other organizations concerned about protecting their own or their customers' privacy, but it definitely has limits.
First, Google announced in a blog post last week that Gmail as of now “will always use an encrypted HTTPS connection when you check or send email.” HTTPS is a secure communications protocol.
Also, the messages will be encrypted while they move internally through the Google system. “This ensures that your messages are safe not only when they move between you and Gmail's servers, but also as they move between Google's data centers,” Nicolas Lidzborski, Gmail Security Engineering lead, said.
“Today's change means that no one can listen in on your messages as they go back and forth between you and Gmail's servers—no matter if you're using public Wi-Fi or logging in from your computer, phone or tablet,” he added.
The move comes soon after a California judge rejected a class action lawsuit against Google for alleged privacy violations. The proposed class action targeted how Gmail collects data from users and uses it to send them relevant ads. It is a key revenue source for the company. There are still other individual lawsuits pending on the issue.
Meanwhile, experts have told the media that the beefed up encryption by Google will go a long way to prevent snooping into e-mails by government spies, such as the National Security Agency (NSA). The agency may still be able to reach inside for mass surveillance, but it becomes much harder for them. It also restricts any efforts by hackers or even employers watching their employees.
“That should be effective,” Mikko Hypponen, a tech security specialist based in Finland, told CNN about the beefed-up security. “By protecting the connection between you and Google servers, they protect you against tons of attackers.”
“I wouldn't call it NSA-proofing,” Eugene H. Spafford, a computer scientist at Purdue University, also told CNN. “But they're doing something reasonable to protect against that and any other similar kind of eavesdropping.”
In fact, Lidzborski said the changes by Google were in response to the recent U.S. government surveillance efforts. “This ensures that your messages are safe … something we made a top priority after last summer's revelations,” Lidzborski adds.
It was reported last year the NSA searched fiber-optic cables operating among data centers belonging to tech companies for data that was of interest.
The issue was of concern for the attorneys representing tech companies – and they are no doubt involved in finding ways to minimize the risk of any controversial surveillance from taking place. Also, in response to revelations about the NSA spying methods, several tech companies have joined “Reform Government Surveillance” – which wants to improve privacy rights and limit government surveillance. The companies include: Google, Facebook, Yahoo, AOL, LinkedIn, Twitter and Microsoft.
Companies such as Microsoft and Yahoo still have not implemented encryption between email providers, Christopher Soghoian, a technologist for the American Civil Liberties Union, told CNN.
And even with Google's latest move, there are some limitations to users' privacy, according to a blog post from The Washington Post. Google's machines will still look through user messages in order to send them relevant ads. And remember that Gmail is only secure while in Google's network.
“Not every e-mail provider has agreed to support the technology that's required,” The Post explains. “To make absolutely sure that your e-mails are fully shielded — even if your recipient is using a different e-mail service — encrypt your e-mail yourself, and make sure your friends do, too.” That is something both a business and individuals could do relatively easily.
And attorneys working for businesses may want to advise the company to consider such a move – especially if a breach of privacy could negatively impact the company, through potential legal action or by a loss of business or loss of company secrets.
Related stories:
There is a renewed effort by
The latest move helps private companies and other organizations concerned about protecting their own or their customers' privacy, but it definitely has limits.
First,
Also, the messages will be encrypted while they move internally through the
“Today's change means that no one can listen in on your messages as they go back and forth between you and Gmail's servers—no matter if you're using public Wi-Fi or logging in from your computer, phone or tablet,” he added.
The move comes soon after a California judge rejected a class action lawsuit against
Meanwhile, experts have told the media that the beefed up encryption by
“That should be effective,” Mikko Hypponen, a tech security specialist based in Finland, told CNN about the beefed-up security. “By protecting the connection between you and
“I wouldn't call it NSA-proofing,” Eugene H. Spafford, a computer scientist at Purdue University, also told CNN. “But they're doing something reasonable to protect against that and any other similar kind of eavesdropping.”
In fact, Lidzborski said the changes by
It was reported last year the NSA searched fiber-optic cables operating among data centers belonging to tech companies for data that was of interest.
The issue was of concern for the attorneys representing tech companies – and they are no doubt involved in finding ways to minimize the risk of any controversial surveillance from taking place. Also, in response to revelations about the NSA spying methods, several tech companies have joined “Reform Government Surveillance” – which wants to improve privacy rights and limit government surveillance. The companies include:
Companies such as
And even with
“Not every e-mail provider has agreed to support the technology that's required,” The Post explains. “To make absolutely sure that your e-mails are fully shielded — even if your recipient is using a different e-mail service — encrypt your e-mail yourself, and make sure your friends do, too.” That is something both a business and individuals could do relatively easily.
And attorneys working for businesses may want to advise the company to consider such a move – especially if a breach of privacy could negatively impact the company, through potential legal action or by a loss of business or loss of company secrets.
Related stories:
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2024 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllAI Adoption, Data Center Building Boom Opening More Doors for Cybercriminals, Many of Them Teenagers
Another Senior Boeing Attorney Exits, This One for CLO Post at Jet-Maintenance Company
3 minute readTrending Stories
Who Got The Work
Michael G. Bongiorno, Andrew Scott Dulberg and Elizabeth E. Driscoll from Wilmer Cutler Pickering Hale and Dorr have stepped in to represent Symbotic Inc., an A.I.-enabled technology platform that focuses on increasing supply chain efficiency, and other defendants in a pending shareholder derivative lawsuit. The case, filed Oct. 2 in Massachusetts District Court by the Brown Law Firm on behalf of Stephen Austen, accuses certain officers and directors of misleading investors in regard to Symbotic's potential for margin growth by failing to disclose that the company was not equipped to timely deploy its systems or manage expenses through project delays. The case, assigned to U.S. District Judge Nathaniel M. Gorton, is 1:24-cv-12522, Austen v. Cohen et al.
Who Got The Work
Edmund Polubinski and Marie Killmond of Davis Polk & Wardwell have entered appearances for data platform software development company MongoDB and other defendants in a pending shareholder derivative lawsuit. The action, filed Oct. 7 in New York Southern District Court by the Brown Law Firm, accuses the company's directors and/or officers of falsely expressing confidence in the company’s restructuring of its sales incentive plan and downplaying the severity of decreases in its upfront commitments. The case is 1:24-cv-07594, Roy v. Ittycheria et al.
Who Got The Work
Amy O. Bruchs and Kurt F. Ellison of Michael Best & Friedrich have entered appearances for Epic Systems Corp. in a pending employment discrimination lawsuit. The suit was filed Sept. 7 in Wisconsin Western District Court by Levine Eisberner LLC and Siri & Glimstad on behalf of a project manager who claims that he was wrongfully terminated after applying for a religious exemption to the defendant's COVID-19 vaccine mandate. The case, assigned to U.S. Magistrate Judge Anita Marie Boor, is 3:24-cv-00630, Secker, Nathan v. Epic Systems Corporation.
Who Got The Work
David X. Sullivan, Thomas J. Finn and Gregory A. Hall from McCarter & English have entered appearances for Sunrun Installation Services in a pending civil rights lawsuit. The complaint was filed Sept. 4 in Connecticut District Court by attorney Robert M. Berke on behalf of former employee George Edward Steins, who was arrested and charged with employing an unregistered home improvement salesperson. The complaint alleges that had Sunrun informed the Connecticut Department of Consumer Protection that the plaintiff's employment had ended in 2017 and that he no longer held Sunrun's home improvement contractor license, he would not have been hit with charges, which were dismissed in May 2024. The case, assigned to U.S. District Judge Jeffrey A. Meyer, is 3:24-cv-01423, Steins v. Sunrun, Inc. et al.
Who Got The Work
Greenberg Traurig shareholder Joshua L. Raskin has entered an appearance for boohoo.com UK Ltd. in a pending patent infringement lawsuit. The suit, filed Sept. 3 in Texas Eastern District Court by Rozier Hardt McDonough on behalf of Alto Dynamics, asserts five patents related to an online shopping platform. The case, assigned to U.S. District Judge Rodney Gilstrap, is 2:24-cv-00719, Alto Dynamics, LLC v. boohoo.com UK Limited.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250