Google Implements Forward Secrecy
Google is stepping up their security game in a big way for the second time this year: introducing a more secure browsing method known as forward secrecy in Gmail and a number of other Web-based services, according to a post on the GoogleOnlineSecurity blog.
In recent months, the Silicon Valley search giant addressed the immediate, implementing secure (HTTPS) browsing by default. Their latest move focuses on long-term data security, putting to rest almost any concerns that hackers could store encrypted communications then use improved technology in the future to crack it and view the contents.
“Forward secrecy requires that the private keys for a connection are not kept in persistent storage” explains Google Security Team member Adam Langley. “An adversary that breaks a single key will no longer be able to decrypt months’ worth of connections; in fact, not even the server operator will be able to retroactively decrypt HTTPS sessions.”
Editor's Pick
Sites operating in a non-forward secret fashion are vulnerable in that a malicious actor could record an email as it is delivered to your computer today. Then, years from now, that same person could harness increased computing power to break the server key and decrypt that message.
Among the services for which HTTPS forward secrecy is now live are Gmail, SSL Search, Docs, and Google+. Like in the case of default HTTPS adoption, the company is hopeful that others will follow their example, making forward secrecy the norm.
Commenting on this Article is closed.
Today's Most Popular
- Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops
- Dear Jailbreaker, Apple Wants to Have a Word with You
- ZTE Score M Android Phone Found to Have Backdoor Installed
- OPINION: Are Anonymous Members Forged in the Crucible of IT Compliance?
- New P2P Zeus Variant Targets Popular Sites with Bogus Offers
Most Commented Stories
-
Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops (5)
-
Spammers Targeting Pinterest Using Point-And-Click Tools (1)
-
White House Security Czar Howard Schmidt Retiring (3)
-
Hijacked Web Sites Among The Most Visited On Google's Black List (2)
-
New P2P Zeus Variant Targets Popular Sites with Bogus Offers (1)
Newsletter Sign-up
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.



