As Yahoo makes encryption standard for email, weak implementation seen

The company's HTTPS implementation still needs some improvements, an SSL expert said

Yahoo has started to automatically encrypt connections between users and its email service, adding an important security layer that rival Gmail has had for almost four years, but its implementation needs work, according to at least one security expert.

Yahoo Mail had support for full-session HTTPS -- SSL/TLS encryption over HTTP -- since late 2012, but users had to opt in to use the feature. Tuesday, the company delivered on a promise that it made in October to enable encryption for everyone by default by January 8.

"Anytime you use Yahoo Mail -- whether it's on the web, mobile web, mobile apps, or via IMAP, POP or SMTP -- it is 100% encrypted by default and protected with 2,048 bit certificates," said Jeff Bonforte, senior vice-president of communication products at Yahoo, in a blog post. "This encryption extends to your emails, attachments, contacts, as well as Calendar and Messenger in Mail."

While this is a great step, the company's HTTPS implementation appears to be inconsistent across servers and even technically insecure in some cases, according to Ivan Ristic, director of application security research at security firm Qualys, which runs the SSL Labs and SSL Pulse projects.

For example, some of Yahoo's HTTPS email servers use RC4 as the preferred cipher with most clients. "RC4 is considered weak, which is why we advise that people either don't use it, or if they feel they must, use it as a last resort," Ristic said.

Other servers, like login.yahoo.com, primarily use the AES cipher, but do not have mitigations for known attacks like BEAST and CRIME, the latter targeting a feature called TLS compression that login.yahoo.com still has enabled.

None of the servers checked by Ristic support forward secrecy, a feature that makes decryption of previously captured SSL traffic impossible even if the server's private key is compromised in the future. This is a property of the Diffie-Hellman Ephemeral (DHE or ECDHE) key agreement protocols. Instead, the Yahoo servers use traditional RSA key exchange.

Google's SSL configuration for Gmail supports forward secrecy since 2011 and Facebook and Twitter have also implemented it.

Because of various theoretical and practical attacks demonstrated against SSL in recent years, security experts also recommend the use of ciphers that function in Galois/Counter Mode (GCM). These are only available in TLS 1.2, the latest version of the protocol, but not all of Yahoo's servers support TLS 1.2.

"I think we should accept that Yahoo needs time to get their servers in order when it comes to encryption, but perhaps they need to be more transparent about what they're planning and doing," Ristic said. "For example, I would have preferred to see something along the lines of: 'We haven't done these other things yet, but here's our schedule for addressing them'."

Yahoo's move comes after repeated calls over the years from security experts and privacy advocates for the company to enable HTTPS for email. The recent revelations of mass Internet surveillance by the U.S. National Security Agency and U.K. Government Communications Headquarters that painted a picture of Yahoo being a primary target for user data collection by intelligence agencies have likely added to the pressure as well.

One top-secret document leaked by former NSA contractor Edward Snowden showed that in a single day in 2012, the NSA collected over 440,000 e-mail address books from Yahoo, compared to around 100,000 from Hotmail, 82,000 from Facebook and 33,000 from Gmail.

Gmail has had HTTPS by default since 2010, Microsoft's Outlook.com email service launched in July 2012 that eventually replaced Hotmail had this feature from the beginning, and Facebook started rolling out HTTPS by default to users in November 2012. All companies supported full-session HTTPS on an opt-in basis for some time before making it the standard setting.

The media reports about NSA's data collection programs have also prompted Yahoo to expand its encryption efforts beyond email. The company plans to encrypt information moving between its data centers and to offer users the option to encrypt all data flows to and from Yahoo by the end of the first quarter of 2014, Yahoo CEO Marissa Mayer announced in November.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags privacyMicrosoftinternetGoogleFacebooktwitterdata protectionMailYahooonline safetyqualysInternet-based applications and services

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.
Lucian Constantin

Lucian Constantin

IDG News Service
Show Comments

Cool Tech

Toys for Boys

Skywatcher Dobsonian 8″ Collapsible Telescope

Learn more >

Family Friendly

Whodunnit™ Duo-Scope MFL-007 Microscope Kit

Learn more >

Stocking Stuffer

Logitech Ultimate Ears Wonderboom 2 Bluetooth Speaker

Learn more >

Christmas Gift Guide

Click for more ›

Brand Post

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Tom Sellers

MSI P65

This smart laptop was enjoyable to use and great to work on – creating content was super simple.

Lolita Wang

MSI GT76

It really doesn’t get more “gaming laptop” than this.

Jack Jeffries

MSI GS75

As the Maserati or BMW of laptops, it would fit perfectly in the hands of a professional needing firepower under the hood, sophistication and class on the surface, and gaming prowess (sports mode if you will) in between.

Taylor Carr

MSI PS63

The MSI PS63 is an amazing laptop and I would definitely consider buying one in the future.

Christopher Low

Brother RJ-4230B

This small mobile printer is exactly what I need for invoicing and other jobs such as sending fellow tradesman details or step-by-step instructions that I can easily print off from my phone or the Web.

Aysha Strobbe

Microsoft Office 365/HP Spectre x360

Microsoft Office continues to make a student’s life that little bit easier by offering reliable, easy to use, time-saving functionality, while continuing to develop new features that further enhance what is already a formidable collection of applications

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?