Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

We block the draft from going up to Gmail's servers. Gmail only sees the encrypted version of the body.


Gmail can just edit your code if they want.

In a comment on encrypting gtalk, I explained how this can be done: https://news.ycombinator.com/item?id=5858375


If Google decides to change how they save drafts you're compromised. They also have complete control of the page so any key press or mouse movement you do they can catch.


Yup, you're right. I tried to inspect and intercept every XHR call that gmail was making to ensure we weren't missing any holes. But it's entirely possible that there's analytics/tracking data that got passed.

Like we said, this is a starting point. It's open source. As with any type of security product that has a hope of being good, try and break it and let's fix it together :)


You could hash the code delivered by Google and throw up a big warning if it has changed.

I believe that Google does releases of the entire application at once so this method should detect when a roll-out has occured.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: