As Yahoo makes encryption standard for email, weak implementation seen

The company's HTTPS implementation still needs some improvements, an SSL expert said

Yahoo has started to automatically encrypt connections between users and its email service, adding an important security layer that rival Gmail has had for almost four years, but its implementation needs work, according to at least one security expert.

Yahoo Mail had support for full-session HTTPS -- SSL/TLS encryption over HTTP -- since late 2012, but users had to opt in to use the feature. Tuesday, the company delivered on a promise that it made in October to enable encryption for everyone by default by January 8.

"Anytime you use Yahoo Mail -- whether it's on the web, mobile web, mobile apps, or via IMAP, POP or SMTP -- it is 100% encrypted by default and protected with 2,048 bit certificates," said Jeff Bonforte, senior vice-president of communication products at Yahoo, in a blog post. "This encryption extends to your emails, attachments, contacts, as well as Calendar and Messenger in Mail."

While this is a great step, the company's HTTPS implementation appears to be inconsistent across servers and even technically insecure in some cases, according to Ivan Ristic, director of application security research at security firm Qualys, which runs the SSL Labs and SSL Pulse projects.

For example, some of Yahoo's HTTPS email servers use RC4 as the preferred cipher with most clients. "RC4 is considered weak, which is why we advise that people either don't use it, or if they feel they must, use it as a last resort," Ristic said.

Other servers, like login.yahoo.com, primarily use the AES cipher, but do not have mitigations for known attacks like BEAST and CRIME, the latter targeting a feature called TLS compression that login.yahoo.com still has enabled.

None of the servers checked by Ristic support forward secrecy, a feature that makes decryption of previously captured SSL traffic impossible even if the server's private key is compromised in the future. This is a property of the Diffie-Hellman Ephemeral (DHE or ECDHE) key agreement protocols. Instead, the Yahoo servers use traditional RSA key exchange.

Google's SSL configuration for Gmail supports forward secrecy since 2011 and Facebook and Twitter have also implemented it.

Because of various theoretical and practical attacks demonstrated against SSL in recent years, security experts also recommend the use of ciphers that function in Galois/Counter Mode (GCM). These are only available in TLS 1.2, the latest version of the protocol, but not all of Yahoo's servers support TLS 1.2.

"I think we should accept that Yahoo needs time to get their servers in order when it comes to encryption, but perhaps they need to be more transparent about what they're planning and doing," Ristic said. "For example, I would have preferred to see something along the lines of: 'We haven't done these other things yet, but here's our schedule for addressing them'."

Yahoo's move comes after repeated calls over the years from security experts and privacy advocates for the company to enable HTTPS for email. The recent revelations of mass Internet surveillance by the U.S. National Security Agency and U.K. Government Communications Headquarters that painted a picture of Yahoo being a primary target for user data collection by intelligence agencies have likely added to the pressure as well.

One top-secret document leaked by former NSA contractor Edward Snowden showed that in a single day in 2012, the NSA collected over 440,000 e-mail address books from Yahoo, compared to around 100,000 from Hotmail, 82,000 from Facebook and 33,000 from Gmail.

Gmail has had HTTPS by default since 2010, Microsoft's Outlook.com email service launched in July 2012 that eventually replaced Hotmail had this feature from the beginning, and Facebook started rolling out HTTPS by default to users in November 2012. All companies supported full-session HTTPS on an opt-in basis for some time before making it the standard setting.

The media reports about NSA's data collection programs have also prompted Yahoo to expand its encryption efforts beyond email. The company plans to encrypt information moving between its data centers and to offer users the option to encrypt all data flows to and from Yahoo by the end of the first quarter of 2014, Yahoo CEO Marissa Mayer announced in November.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags Internet-based applications and servicesonline safetydata protectioninternetprivacyqualysFacebookYahooGoogleMicrosoftsecurityMailencryptiontwitter

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Lucian Constantin

IDG News Service
Show Comments

Cool Tech

Breitling Superocean Heritage Chronographe 44

Learn more >

SanDisk MicroSDXC™ for Nintendo® Switch™

Learn more >

Toys for Boys

Family Friendly

Panasonic 4K UHD Blu-Ray Player and Full HD Recorder with Netflix - UBT1GL-K

Learn more >

Stocking Stuffer

Razer DeathAdder Expert Ergonomic Gaming Mouse

Learn more >

Christmas Gift Guide

Click for more ›

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

David Coyle

Brother PocketJet PJ-773 A4 Portable Thermal Printer

I rate the printer as a 5 out of 5 stars as it has been able to fit seamlessly into my busy and mobile lifestyle.

Kurt Hegetschweiler

Brother PocketJet PJ-773 A4 Portable Thermal Printer

It’s perfect for mobile workers. Just take it out — it’s small enough to sit anywhere — turn it on, load a sheet of paper, and start printing.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?