3 ms·
I have to agree with this. I hadn't read Jeff's post yet since, really, I haven't regularly read his stuff in probably two or three years, but I just did. The
by AgentConundrum 14y ago
I have to agree with this. I hadn't read Jeff's post yet since, really, I haven't regularly read his stuff in probably two or three years, but I just did.
The only mention of emailing things to yourself is wholly contained in the following paragraph:
> The upside is that once you enable this, your email becomes extremely secure, to the point that you can (and I regularly do) email yourself highly sensitive data like passwords and logins to other sites you visit so you can easily retrieve them later.
To me, that's really dangerous advice. It relies on the assumption that you're only emailing things from your own gmail account, to your own gmail account. This means that the only transfer happens between you and Google over a secure HTTPS connection. Your data is transferred securely, stored on Google's servers, and securely transferred back to you when you request it.
At no point is this specific assumption pointed out, nor are the problems with it discussed.
First, although I can't think of a particular reason why gmail-to-gmail emails would be routed outside of Google's servers, that doesn't mean it doesn't happen. If someone could point a blog post discussing it, I would appreciate it.
Second, All bets are off if you use a separate provider. One example might be work email. If you're signed in to a work account already, you might be more inclined to just use that to toss an email at yourself for later. I've certainly done that before, even though I could sign into gmail from work. People could make the mistake of thinking he's saying "send an email to yourself from anywhere" which isn't correct. Incidentally, activating two-factor auth makes it more likely that someone would do work-to-home emailing since there's now an extra barrier to just logging into gmail.
Finally, this seems to rely on the assumption that you're only using the web client to access gmail. If you're using POP3 or IMAP to access your account, you could still be at risk, since I think (though admittedly I'm unsure since I only use the web interface) that these protocols aren't encrypted by default.
- tantalor 14y ago> At no point is this specific assumption pointed out, nor are the problems with it discussed. To "email yourself" implies using the same service. > If you're using POP3 or IMAP to access your account, you could still be at risk, since I think (though admittedly I'm unsure since I only use the web interface) that these protocols aren't encrypted by default. Gmail IMAP requires SSL: http://support.google.com/mail/bin/answer.py?hl=en&answer=78799 http://support.google.com/mail/bin/answer.py?hl=en&answe...
- AgentConundrum 14y ago> Gmail IMAP requires SSL Good to know. I did specify that I never used it, so my understanding could be flawed. > To "email yourself" implies using the same service. To you, but not necessarily to everyone. People do have multiple accounts (gmail, personal domain, work, even Facebook gives you an email address you can send things to), and it's really easy to conflate "email yourself" with "send an email to your account", or even to abstract "sending an email to yourself is secure" to "email is secure". My point was simply that if you make an argument about something as important as security, it's vital that you spell out the limitations to your advice. "Email yourself" is ambiguous enough that it needs a proper disclaimer. Admittedly, the audience for Coding Horror is mostly people who know this stuff already, but it's certainly not limited to those people exclusively. I started reading his blog midway through college, and it's amazing to me, looking back now, just how naive I was about a lot of things back then.
- ColinWright 14y ago> To "email yourself" implies > using the same service. I would take exactly the opposite interpretation. I regularly email stuff to myself, and it's pretty much never on the same service.