<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: PSA: https and gmail</title>
	<atom:link href="http://ericgar.com/2008/01/19/psa-https-and-gmail/feed/" rel="self" type="application/rss+xml" />
	<link>http://ericgar.com/2008/01/19/psa-https-and-gmail/</link>
	<description></description>
	<pubDate>Fri, 05 Dec 2008 09:40:13 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.5</generator>
		<item>
		<title>By: Eric</title>
		<link>http://ericgar.com/2008/01/19/psa-https-and-gmail/#comment-220</link>
		<dc:creator>Eric</dc:creator>
		<pubDate>Mon, 21 Jan 2008 21:38:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.ericgar.com/2008/01/19/psa-https-and-gmail/#comment-220</guid>
		<description>That's all true, but I think those are tangential problems that don't concern gmail.</description>
		<content:encoded><![CDATA[<p>That&#8217;s all true, but I think those are tangential problems that don&#8217;t concern gmail.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Casey</title>
		<link>http://ericgar.com/2008/01/19/psa-https-and-gmail/#comment-219</link>
		<dc:creator>Casey</dc:creator>
		<pubDate>Mon, 21 Jan 2008 21:16:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.ericgar.com/2008/01/19/psa-https-and-gmail/#comment-219</guid>
		<description>While it's probably cost issues, there are even more problems.  First of all, distributing certificates to thousands of internet-facing servers still isn't perfectly solved.  Also, because SSL encrypts *everything*, you have to present the certificate before the browser sends the Host: field.  This means you can't use VHosts for SSL.</description>
		<content:encoded><![CDATA[<p>While it&#8217;s probably cost issues, there are even more problems.  First of all, distributing certificates to thousands of internet-facing servers still isn&#8217;t perfectly solved.  Also, because SSL encrypts *everything*, you have to present the certificate before the browser sends the Host: field.  This means you can&#8217;t use VHosts for SSL.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eric</title>
		<link>http://ericgar.com/2008/01/19/psa-https-and-gmail/#comment-218</link>
		<dc:creator>Eric</dc:creator>
		<pubDate>Sun, 20 Jan 2008 22:49:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.ericgar.com/2008/01/19/psa-https-and-gmail/#comment-218</guid>
		<description>I don't know why they do that. I surmise that it's because encryption is expensive. For every packet sent back and forth, a non-trivial amount of computation has to take place in order to encrypt it. While your desktop probably has available cycles to do this, they have to do this for all users. 

That gets expensive very quickly. There are a lot of variables, but performance impact can be an order of magnitude or more.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t know why they do that. I surmise that it&#8217;s because encryption is expensive. For every packet sent back and forth, a non-trivial amount of computation has to take place in order to encrypt it. While your desktop probably has available cycles to do this, they have to do this for all users. </p>
<p>That gets expensive very quickly. There are a lot of variables, but performance impact can be an order of magnitude or more.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Somudro Gupta</title>
		<link>http://ericgar.com/2008/01/19/psa-https-and-gmail/#comment-217</link>
		<dc:creator>Somudro Gupta</dc:creator>
		<pubDate>Sun, 20 Jan 2008 20:21:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.ericgar.com/2008/01/19/psa-https-and-gmail/#comment-217</guid>
		<description>Hey, it still says 0 comments!  I demand my previous comment, as well as this one, to be heard.</description>
		<content:encoded><![CDATA[<p>Hey, it still says 0 comments!  I demand my previous comment, as well as this one, to be heard.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Somudro Gupta</title>
		<link>http://ericgar.com/2008/01/19/psa-https-and-gmail/#comment-216</link>
		<dc:creator>Somudro Gupta</dc:creator>
		<pubDate>Sun, 20 Jan 2008 20:18:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.ericgar.com/2008/01/19/psa-https-and-gmail/#comment-216</guid>
		<description>Why does Google redirect you to the unencrypted page?  OR, why don't they just make http://gmail.com redirect to https://gmail.com ?</description>
		<content:encoded><![CDATA[<p>Why does Google redirect you to the unencrypted page?  OR, why don&#8217;t they just make <a href="http://gmail.com" rel="nofollow">http://gmail.com</a> redirect to <a href="https://gmail.com" rel="nofollow">https://gmail.com</a> ?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
