Interception Modernisation Programme

Chris Edwards ukcrypto at chiark.greenend.org.uk
Thu, 9 Oct 2008 15:51:52 +0100 (BST)


On Thu, 9 Oct 2008, Richard Clayton wrote:

| Hotmail is an example of a webmail service that runs in HTTP once the
| sign-on is completed....

Ah - I stand corrected!

Have checked, and it seems the services I cited - hotmail/yahoo/gmail 
*all* seem to fallback to HTTP after sign-on.

This is presumably a resource saving measure.

Google provide an "Always use HTTPS" option, which I suspect Roland has 
enabled.  (Presumably google are banking on few people using it).  As far 
as I can see, neither hotmail nor yahoo provide similar, at least in their 
free offerings.