4 ms·
I think what you mean is that GMail requires you to use https for their web interface. gmail requires STARTTLS (or ssmtp) when an authenticated user submits ou
by mct 14y ago
I think what you mean is that GMail requires you to use https for their web interface.
gmail requires STARTTLS (or ssmtp) when an authenticated user submits outbound mail to them via SMTP (http://support.google.com/mail/bin/answer.py?hl=en&answer=13287 http://support.google.com/mail/bin/answer.py?hl=en&answe...), which is what he may have been mis-remembering. But, yes, it is incorrect that all mail sent to gmail.com addresses is TLS encrypted.
- bigiain 14y agoI feel kinda dirty sticking up for Jeff here - but that means if you _know_ your outbound mail always uses TLS when available, then maybe the security-in-transit concerns are eliminated. (I don't even know where I'd start trying to find out if all my possible ways of sending myself mail can be conclusively determined to be using TLS though.)
- garethadams 14y agoThat would be a perfect counter argument, except the point mentioned in the article specifically related to getting passwords sent to you from other services.