Gmail: February 2008 Archives
You think? That's one of the stories out there right now. Makes sense to me: Amazon could definitely use Yahoo as both partner and source of revenue. Amazon could also conceivably tap Yahoo's pool of developers to help bolster the Amazon cloud computing initiative.
And tamping down any mojo that Microsoft might gain in the SAAS (software as a service) and overall cloud computing sector only helps Amazon's own foray into what many people think is the future of computing (though others think it's much ado about little).
Clearly it's good business for Microsoft to buy Yahoo and entrench itself as a firm No. 2 in search advertising. And ... while I'm touting the alleged skills of Yahoo's developers, Yahoo itself is way behind Google when it comes to Web-based applications. Yahoo has nothing like Google Docs and Spreadsheets, nor does it seem to have a Google-like plan to leverage Docs, Gmail and network storage as a fee-based service for the enterprise.
I still think Yahoo Mail has an edge over Gmail, excepting the fact that Gmail can run a totally secure session (which, nevertheless can be hacked into through unencrypted cookies) and Yahoo Mail cannot, but to me Yahoo Mail keeps that edge with usability and functionality ... but ... Gmail offers free POP mail, Yahoo charges for it, and Gmail is also rolling out IMAP, with no similar plan for Yahoo that I know about.
On the other hand, the latest rendition of Yahoo Mail, if run on fast-enough hardware, does an admirable job of mimicking a stand-alone e-mail client. It's the kind of app that makes me think Yahoo can develop a credible alternative to Google Docs if they wanted to do so.
Anyhow, back to business. One of the perils of being a publicly traded company without huge mounds of cash on hand is that somebody like Microsoft can swoop in and buy you when your stock is tanking.
Yahoo is a valuable brand with good core technologies. Given the time, they can manage their way out of this mess. But in today's world, time is scarce.
There are two kinds of tech companies out there: those who would love to be bought by Microsoft, and those who loathe it. OK, there's a third kind: those likely to be threatened with legal action by Microsoft, but I'm getting off-track here.
Remember this, Yahooligans: The Web isn't set in stone. If Yahoo is assimilated, you can always cash out and start something newer and better.
As for Microsoft, the company has never been shy about acquiring the technology and market share it needs in order to survive and grow. They've got the money, so this acquisition is a no-brainer for them. The clash-of-culture thing could be a problem, but for most people, if the checks keep coming (and they don't make people move to Seattle) and they see some kind of mission in their work, many will keep going. If it doesn't go so well, Microsoft parts with cash to crush the No. 2 player in search advertising and effectively assumes that mantle itself.
But letting anybody else -- especially someone with the scale and ambition of Amazon -- get Yahoo, that would only hurt Microsoft's search-ad, networked-application and plain-craven-moneymaking mojo. What's a big load of cash good for when you can't use it to crush your rivals?
Unless Yahoo can somehow find someone, somewhere with a bigger load of ready money or pricey stock, it looks like Redmond will win this round.
And whether the merger succeeds or fails, if it happens at all, it's huge-upside time for the folks in Redmond.
I've blogged before on how Gmail has an advantage over Yahoo Mail -- and most other Web-based e-mail services -- because you can choose to run a totally secure session (by entering the URL https://gmail.com instead of plain ol' http://gmail.com) and feel safe when reading and writing e-mail over public WiFi connections.
Seems it isn't so. According the Zero Day blog at ZDNet, somebody monitoring the radio traffic of your wireless connection can figure out your password through the use of unencrypted cookies with a technique called "sidejacking":
Sidejacking is a term (Robert) Graham uses to describe his session hijacking hack that can compromise nearly all Web 2.0 applications that rely on saved cookie information to seamlessly log people back in to an account without the need to reenter the password. By listening to and storing radio signals from the airwaves with any laptop, an attacker can harvest cookies from multiple users and go in to their Web 2.0 application. Even though the password wasn’t actually cracked or stolen, possession of the cookies acts as a temporary key to gain access to Web 2.0 applications such as Gmail, Hotmail, and Yahoo. The attacker can even find out what books you ordered on Amazon, where you live from Google maps, acquire digital certificates with your email account in the subject line, and much more.Gmail in SSL https mode was thought to be safe because it encrypted everything, but it turns out that Gmail’s JavaScript code will fall back to non-encrypted http mode if https isn’t available. This is actually a very common scenario anytime a laptop connects to a hotspot before the user signs in where the laptop will attempt to connect to Gmail if the application is opened but it won’t be able to connect to anything. At that point in time Gmail’s JavaScripts will attempt to communicate via unencrypted http mode and it’s game over if someone is capturing the data.
What’s really sad is the fact that Google Gmail is one of the “better” Web 2.0 applications out there and it still can’t get security right even when a user actually chooses to use SSL mode. Other applications like Microsoft’s MSN/Hotmail and Yahoo don’t even have SSL modes. The fact that they use SSL mode for first time authentication and sign-in is irrelevant because they all drop down to unencrypted mode right after the user authenticates.
I don't use my DSL Extreme Web mail as often as I should. It has a secure connection the whole time, and it's primitive enough -- I hope -- not to have these same vulnerabilities. Fastmail.fm, on which I also have a free account, will also do a secure session if you choose "secure login" when signing on.
I'm far from a security expert, but it seems to me that we'd be in better shape if we had the option of running a Web browser in secure-server mode all the time.




Recent Comments
Steven Rosenberg on The Debian Mac needs more memory: I'd love to see how OpenBSD does on this hardware, but I just can't se ...
Joe on Long-lost Click: Wolvix again: I don't know if this is completely related to your Slackware-Grub issu ...
ric storms on The Debian Mac needs more memory: I think there has to be something screwy in my system BIOS on my Power ...
Steven Rosenberg on LogMeIn Free: It could be my application of the year: LogMeIn Free does everything I need, and you can't beat free. ...
techoftheday on LogMeIn Free: It could be my application of the year: LogMeIn is an awesome tool, but the free version is limited in terms o ...
Steven Rosenberg on Installing Fedora 9 on the Power Mac G4/466 — Part 2: The biggest problems for Linux and the PowerPC are: No Flash No Java ...
Steven Rosenberg on Installing Fedora 9 on the Power Mac G4/466 — Part 2: This Power Mac G4 is pretty vanilla. Nothing added beyond the default ...
ric storms on Installing Fedora 9 on the Power Mac G4/466 — Part 2: I have all but given up on Linux for my PowerPC. I've tried both Etch ...
Steven Rosenberg on Debian Lenny: It's an up-and-down thing: Thanks for the info on the RAM. Those Macs seem pretty darn sensitive ...