Gmail (aka Google Mail) and secure cookies

Ask for help about NoScript, no registration needed to post
Guest

Gmail (aka Google Mail) and secure cookies

Post by Guest »

I added google.com to the list for "Force encryption for all cookies set over HTTPS by the following sites". However, even though I only log in over the https interface, one of the cookies I receive is still insecure, according to CS Lite. Additionally, even when I visit one of Google's unencrypted search pages, Google still sees me as logged in.

Why?
Mozilla/5.0 Gecko/20070713 Firefox/2.0.0.0
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: Gmail (aka Google Mail) and secure cookies

Post by Giorgio Maone »

Did you tick the "Automatic secure cookie management" checkbox?
Also, are you sure the insecure cookie is from gmail.google.com and not from google.com?
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.0.10) Gecko/2009042316 Firefox/3.0.10 (.NET CLR 3.5.30729)
Guest

Re: Gmail (aka Google Mail) and secure cookies

Post by Guest »

Giorgio Maone wrote:Did you tick the "Automatic secure cookie management" checkbox?
Yes, the box is ticked.
Giorgio Maone wrote:Also, are you sure the insecure cookie is from gmail.google.com and not from google.com?
It is a google.com cookie, but I placed both google.com and mail.google.com on the force secure cookies list.

Also, I did not temporarily allow google.com to put cookies on my computer, using CS Lite, until I reached the https login page, so it was not a pre-existing cookie. And apparently the single unsecure cookie was enough for Google to recognise me even on the non-https search page.
Mozilla/5.0 Gecko/20070713 Firefox/2.0.0.0
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: Gmail (aka Google Mail) and secure cookies

Post by Giorgio Maone »

May I know the name of the cookie? I've got some suspects...
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.0.10) Gecko/2009042316 Firefox/3.0.10 (.NET CLR 3.5.30729)
Guest

Re: Gmail (aka Google Mail) and secure cookies

Post by Guest »

Giorgio Maone wrote:May I know the name of the cookie? I've got some suspects...
Name: SID
Domain: .google.com
Path: /
Secure: No
Expiration: Session

GAUSR and LSID (from HOST: http://www.google.com) are both marked as secure, as is everything from mail.google.com.
Mozilla/5.0 Gecko/20070713 Firefox/2.0.0.0
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: Gmail (aka Google Mail) and secure cookies

Post by Giorgio Maone »

SID is set by http://www.google.com, which you're not enforcing HTTPS cookies on (are you?)
Just add http://www.google.com or even better *.google.com (beware, though, that some Google services which are not HTTPS enabled might cease to work).
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.0.10) Gecko/2009042316 Firefox/3.0.10 (.NET CLR 3.5.30729)
Guest

Re: Gmail (aka Google Mail) and secure cookies

Post by Guest »

Giorgio Maone wrote:SID is set by http://www.google.com, which you're not enforcing HTTPS cookies on (are you?)
Just add http://www.google.com or even better *.google.com (beware, though, that some Google services which are not HTTPS enabled might cease to work).
I had the following on the list:
google.com
mail.google.com

(No wildcard characters.)

I added the wildcard character, but now I can't login at all.
Mozilla/5.0 Gecko/20070713 Firefox/2.0.0.0
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: Gmail (aka Google Mail) and secure cookies

Post by Giorgio Maone »

Well, I told you preventing that cookie from being set could break something.
However, you probably don't need this.
Just try to delete the secure cookies and check if you can still login. If you cannot, you're safe.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.0.10) Gecko/2009042316 Firefox/3.0.10 (.NET CLR 3.5.30729)
Guest

Re: Gmail (aka Google Mail) and secure cookies

Post by Guest »

Giorgio Maone wrote:Well, I told you preventing that cookie from being set could break something.
However, you probably don't need this.
Just try to delete the secure cookies and check if you can still login. If you cannot, you're safe.
You are right.

The insecure cookie seems to be insufficient to get into Google Mail with. It looks like all an attacker could do with the insecure cookie is impersonate me while searching Google and look at my Web History, which is empty because I don't let Google run scripts. So I suppose someone could frame me by searching for illegal material with my cookie, but at least my mail can't be compromised that way.
Mozilla/5.0 Gecko/20070713 Firefox/2.0.0.0
User avatar
GµårÐïåñ
Lieutenant Colonel
Posts: 3369
Joined: Fri Mar 20, 2009 5:19 am
Location: PST - USA
Contact:

Re: Gmail (aka Google Mail) and secure cookies

Post by GµårÐïåñ »

I was using Gmail through the website today and it logged me in and then when I changed folder, it pops up saying that it appears you have logged out or someone else has logged on to this machine, so you need to log back in and takes me away to the login page. I was pissed and so tried to log back in and this time it just sits on that loading page and bar goes to 100 and it just sits there doing abso-freakin-lutely nothing. Whatever the problem was, is back.
~.:[ Lï£ê ï§ å Lêmðñ åñÐ Ì Wåñ† M¥ Mðñê¥ ßå¢k ]:.~
________________ .: [ Major Mike's ] :. ________________
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
Post Reply