Slashdot Mirror


Gmail Messages Are Vulnerable To Interception

Michael Wally writes "GMail messages are vulnerable to interception. An attacker has only to transmit malformed test messages to himself, and information left over in memory, from previous messages destined for other people, will appear with the test messages, in the attacker's inbox. Sometimes, this information may include usernames and passwords... Do you use GMail? Are your communications private? Should they be? Well, here's what we figured out about the issue, that may or may not help you - or perhaps GMail, if anyone can get ahold of their developers, to tell them about it." Update: 01/12 22:21 GMT by T : Good news for Gmail users; those malformed messages are no longer being accepted; read below for a message from Chris DiBona.

chrisd writes "Just so you know, at 10:15am PST mails with the problematic formatting as described in your previous story stopped being accepted into Gmail. Previous emails that had this problem will also no longer will be accessible. If you don't mind, I'd like to take the time to remind Slashdot readers that they can send bugs that may have a security aspect into security@google.com. If they like, they should feel free to cc me at cdibona@google.com. We appreciate your patience and we're sorry about the bug."

17 of 460 comments (clear)

  1. Wow by bperkins · · Score: 4, Funny

    Did any of this "left over" information happen to be spurious commas?

    1. Re:Wow by TedCheshireAcad · · Score: 4, Funny

      ,,,, no, ret,u,rn to yo,ur work. ,,
      ,do,not,,worry abou,t t,he com,mas.

  2. Comment removed by account_deleted · · Score: 4, Funny

    Comment removed based on user account deletion

  3. Well hey.. by sinner0423 · · Score: 5, Funny

    Google = best & brightest, right?

    I mean, their aptitude tests & hiring policies makes me believe they've got a few nobel prize winners working there..

    Shouldn't they be able to fix this during lunch break?

    1. Re:Well hey.. by Anonymous Coward · · Score: 1, Funny

      I mean, their aptitude tests & hiring policies makes me believe they've got a few nobel prize winners working there..

      Yes, but they are busy playing with colored balls and rolling around on Segway-scooters.

      The real work is done by 4$/h student-workers.

      This is no lie, believe me.

  4. Re:One Key Word by Anonymous Coward · · Score: 5, Funny

    Next up on Slashdot: the Google apologists vs. the Apple apologists in a brown nose-off...

  5. end of the world is coming!! by jxyama · · Score: 4, Funny
    headless $500 Mac and $99 iPod...

    now Google messes up...

    with all the natural disasters happening, i cannot think of a good reason why the world wouldn't end the day after tomorrow.

  6. Re:Are you communications private? by American+AC+in+Paris · · Score: 1, Funny
    I don't even know where to start with this one!!!!>

    Simple.

    All you communications are belong to them.

    --

    Obliteracy: Words with explosions

  7. Re:Security Category in Gmail Bugs List? by Anonymous Coward · · Score: 1, Funny

    #include

  8. Re:Are you communications private? by Anonymous Coward · · Score: 1, Funny

    Are you communications private?

    I don't even know where to start with this one!!!! Editors? You out there???


    He's talking to the communications. Example:

    "Are you guys ready?"
    "Are you folks hungry?"

  9. Yawn... by revery · · Score: 2, Funny

    I already read about this in a newsletter that I received in the "Reply To" field of an email.

    --
    Was it the sheep climbing onto the altar, or the cattle lowing to be slain,
    or the Son of God hanging dead and bloodied on a cross that told me this was a world condemned, but loved and bought with blood.

  10. Re:A Darker Shade of Grey Hat by cakestick · · Score: 2, Funny

    Sorry to bother you, Microsoft. It won't happen again.

    --
    I'm not here. This isn't happening.
  11. Re:Security Category in Gmail Bugs List? by Anonymous Coward · · Score: 1, Funny

    1:44: std/security_through_obscurity.h: No such file or directory

  12. or rather by apparently · · Score: 5, Funny
    #include <std/security_through_obscurity_rant.h hey moms, it's big poppa here! be looking to fly with you 2nite an' get a little stank on mah hanglow, dig-it?! It's gonna be a <B
  13. need invite by Anonymous Coward · · Score: 1, Funny

    Please send an gmail invite. the last one got intercepted...

  14. Did anyone else see this? by Lank · · Score: 2, Funny

    At the bottom of TFA:

    Screen Capture #5
    Jack Rabbit Vibrator Features

    This message describes the features of one "Jack Rabbit Vibrator," a 7.5" Multi-Speed toy of sorts.


    What are the odds of finding that?

    --
    Gotta get me one of these!
  15. You Win An Award by rho · · Score: 3, Funny

    Most Humorously Appropriate Usage of the Word "Festoon" In A Slashdot Post.

    --
    Potato chips are a by-yourself food.