On Tue, Jun 2, 2009 at 13:11, Disconnect <[email protected]> wrote:

>
> I haven't check gmail specifically yet but FYI calendar uses
> unencrypted http data over whatever connection is available (wifi,
> edge, carrier pigeon). "Encryption wasn't a requirement" is what I was
> told when i asked.
>

Bad... :-(

Even more since synchro is a background process that occurs now and then, on
all these unknown networks you may be connected to....
(anyway, even via 3G which is somehow encrypted I do not like to put my
trust in yet another third party to hold my unencrypted data. Giving trust
to google is already enough !)

I really want all these apps (mail, calendar, contacts, talk...) to be
secured...

Sniffing my personal info while synchronizing is a concern.
But in our case, can it be even worse and session impersonation is possible
? (so that access to your whole google account is "open"...) ?

I do not like weakness in this area where so much important info is on my
mails... and where google even hold my credit card infos in Checkout !
(and I hope I do not need to ask if Market transaction are secure......)

--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups 
"Android Discuss" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to 
[email protected]
For more options, visit this group at 
http://groups.google.com/group/android-discuss?hl=en
-~----------~----~----~----~------~----~------~--~---

Reply via email to