Forum Moderators: phranque
A security researcher has been in discussions with Google on an exploit he plans to release that would allow a hacker to easily intercept someone's communications with supposedly secure Web sites over an unsecured Wi-Fi network, but other sites, like Facebook, Yahoo Mail, and Hotmail, remain vulnerable.
One of the posters in that thread was right in that 100% SSL from front to back is reasonably secure, the problem is, short of most banks, the 100% SSL scenario isn't usually the situation which is how these MITM attacks get mounted.
Truthfully, this is mild compared to all the big ISPs that still use standard POP or insecure webmail accounts like most of the control panels (plesk, cpanel, etc.) which expose your login in plain text over any wifi network.
However, if the site pretends to be secure using SSL at any point then I think people have a reasonable expectation that it's completely secure from start to finish and Google should be commended for fixing it ASAP and all the rest need an earful of jeers about now.