Next Question
RSS
YES .
It really all depends on what type of network you are on.
And who has access to your computer.
Watch these videos
http://en.wikibooks.org/wiki/Metasploit/VideoTutorials
Especially with the existence of SSL and XSS man in the middle attacks using metasploit, and/or milw0rm, and now that "hackers" have created a hole OS around wireless injection, cracking and cookie stealing.
On the other hand however.
If you can make sure that handshake information between you and your mail provider (In this case google) isn't exchanged for more than the time you first login, then this actually might help in a sense.
Like i said...
It really all depends on what type of network you are on.
And who has access to your computer.
I would seriously start looking into OpenID they are revolutionizing the way people log into web sites, get their data, and keep it safe.
Kind Regards,
XDS
Source(s):
ISC2 Certs.
Experience.
Permalink | Report
I think your talking about a cross site scripting exploit. It happened a long time back and has since been fixed.(And seems to be removed from google's brain.)
If you use firefox and NoScript plug-in such things have no success.
Hope that helps!
Source(s):
Me. I'm in IT. I do this stuff all day.
Permalink | Report
I'm sure the security risk they mean is a stranger getting into your email so it's more who owns the computer and where it is rather than just the sole fact of leaving gmail logged on.
Permalink | Report
But on a theoretical level, the best security practice is to close it whenever you're not using it. If you have to ask whether or not you need to be "theoretical" about email security, you probably don't.
Permalink | Report
Answered Question
M$1
April 23, 2009 02:23 PM
Is it dangerous or risky to leave Gmail open in a web browser throughout the day?
I've heard that a potential security risk is involved in doing this, but cannot locate the source of that info.
It would be better for me (less work) to leave Gmail open all day long instead of constantly reloading it.
It would be better for me (less work) to leave Gmail open all day long instead of constantly reloading it.
RSS
Best Answer Chosen by Asker
| April 23, 2009 06:42 PM |
It really all depends on what type of network you are on.
And who has access to your computer.
Watch these videos
http://en.wikibooks.org/wiki/Metasploit/VideoTutorials
Especially with the existence of SSL and XSS man in the middle attacks using metasploit, and/or milw0rm, and now that "hackers" have created a hole OS around wireless injection, cracking and cookie stealing.
On the other hand however.
If you can make sure that handshake information between you and your mail provider (In this case google) isn't exchanged for more than the time you first login, then this actually might help in a sense.
Like i said...
It really all depends on what type of network you are on.
And who has access to your computer.
I would seriously start looking into OpenID they are revolutionizing the way people log into web sites, get their data, and keep it safe.
Kind Regards,
XDS
Source(s):
ISC2 Certs.
Experience.
| Asker's Rating: |
• Thanks for the wealth of detail. You went beyond the assumption that my question (not as specific with details as it could have been) was primarily about whether another human had physical access to my computer to the ins and outs of scripting and software.
Permalink | Report
Other Answers (3)
April 23, 2009 02:33 PM
If there is physical access to your computer & you have something you need/want to protect in that mail account then of course the answer is yes. I think your talking about a cross site scripting exploit. It happened a long time back and has since been fixed.(And seems to be removed from google's brain.)
If you use firefox and NoScript plug-in such things have no success.
Hope that helps!
Source(s):
Me. I'm in IT. I do this stuff all day.
Permalink | Report
April 23, 2009 07:15 PM
What are the pros and cons of the NoScript plug-in?
Does it disable stuff that you might want to allow as well as exploits?
Report
Does it disable stuff that you might want to allow as well as exploits?
April 25, 2009 02:16 AM
Yes and No. You can okay an entire site. So if you know a site is safe. IE google.com amazon.com...
But in this case were talking about cross site scripting. If a site employs this I would simply not use it. It's such bad form that they could be causing a problem even if they are not meaning to intentionally.
Report
But in this case were talking about cross site scripting. If a site employs this I would simply not use it. It's such bad form that they could be causing a problem even if they are not meaning to intentionally.
April 23, 2009 02:34 PM
If anything, the security risk is present if you leave it on all day on a computer that other people can access. But if you leave it on all day on your own personal computer in your house or private office, i don't see the problem. I'm sure the security risk they mean is a stranger getting into your email so it's more who owns the computer and where it is rather than just the sole fact of leaving gmail logged on.
Permalink | Report
April 23, 2009 02:35 PM
If you leave it open, anyone who can use your computer (either physically or remotely) would have access to your Gmail account. That's the big concern. You shouldn't worry about cross site scripting or similar issues if you use an up to date web browser. But on a theoretical level, the best security practice is to close it whenever you're not using it. If you have to ask whether or not you need to be "theoretical" about email security, you probably don't.
Permalink | Report
Answer this Question
Related Questions
Anyone have any examples of slick, web-based scrolling of images/items? Fluid like sc...
Feeling very cold and weak... I know, not like me at all. Any tips? Home remedies per...
have been Dx. with Auto Immune Urticaria, Please Help. For the last year I have been ...
I have been Dx. with Autoimmune Urticria, Please Help. For the last year I have been ...
Feeling very cold and weak... I know, not like me at all. Any tips? Home remedies per...
have been Dx. with Auto Immune Urticaria, Please Help. For the last year I have been ...
I have been Dx. with Autoimmune Urticria, Please Help. For the last year I have been ...
Ask a Question
Buy Mahalo Dollars with Credit Card or PayPal
Top Members
Most Popular Tags
Categories
- Anonymous
- Arts & Design
- Beauty & Style
- Books & Authors
- Business
- Cars & Transportation
- Consumer Electronics
- Coupons Deals
- Education
- Entertainment
- Environment
- Fitness
- Food & Drink
- From Email
- From Iphone
- From Twitter
- Health
- History
- Hobbies
- Home & Garden
- How Tos
- Humor
- Jobs
- Legal
- Local
- Love & Relationships
- Mahalo Answers Community
- Money
- Music
- News
- NSFW
- Parenting
- Pets
- Science & Mathematics
- Services
- Shopping
- Social Science
- Society & Culture
- Sports
- Technology & Internet
- Travel
- Video Games
Welcome New Members
- thanzawa, December 04, 2009 02:36 AM
- letsgohalves, December 04, 2009 02:35 AM
- lovelydog88, December 04, 2009 02:32 AM
- fruition, December 04, 2009 02:30 AM
- k8eelegg, December 04, 2009 02:28 AM
Mahalo Dollars are the currency of Mahalo Answers.
Each Mahalo Dollar costs $1.
Once you earn more than 40 Mahalo Dollars, you can request to be paid via PayPal. Each Mahalo Dollar is currently worth $0.75 when paid out via PayPal. Learn More
http://sce.uhcl.edu/yang/teaching/csci5234WebSecuritySpring2008/secure%20Sockets%20Layer%20(SSL)%20Man-in-the-middle%20Attack.htm
There is no way to really protect against these type of attacks if you are using a wireless network unless you are using WPA2 with A Radius based encrypted key that changes daily and is longer than 25 characters.
These certs can be just plucked out of the air without you even knowing.
Combining this with cookie stealing and the UNSUB will have your completely handshake to access your account.
Here are some screenshots from the WiFiZoo program available in backtrack
(which is a security based OS currently based on debian)
Scary stuff.
And to end the mood I give you cluster one. =P
http://www.youtube.com/watch?v=6b7Jcw4B3hc