Lucian Constantin
CSO Senior Writer

Comcast to start encrypting email traffic with Gmail in the coming weeks

News
Jun 4, 20142 mins

encryption email
Credit: Shutterstock

Responding to reports that it fails to encrypt the majority of its email traffic, Comcast said that it will ramp up domain-to-domain encryption efforts over the next few weeks.

Google released data Tuesday showing how much of the email traffic to and from Gmail is encrypted in an attempt to raise awareness about the benefits of securing email in transit, which requires both sending and receiving servers to support encryption.

Users can secure their webmail connections from snooping by using HTTPS when available, but have no control over how their emails are sent out to the intended recipients by their email providers. According to Google’s data, between 40 and 50 percent of email messages sent by other servers to Gmail addresses in May traveled in plain text because those servers didn’t support encryption.

The need to secure email in transit became a hot topic after documents leaked by former U.S. National Security Agency contractor Edward Snowden showed that intelligence agencies intercept and collect electronic communications, including email messages, as they travel through the global Internet infrastructure.

Google’s data showed that less than 1 percent of emails exchanged between Gmail and Comcast in May were encrypted.

Comcast is currently beta testing TLS (Transport Layer Security) encryption for domain-to-domain email messaging and has enabled it for its email traffic with certain websites and some smaller ISPs, said Charlie Douglas, a spokesman for Comcast, via email. “Since Gmail is a large domain, we plan to gradually ramp up encryption with Gmail in the coming weeks. We’ll also implement it with others.”

According to Douglas, a Comcast engineer will be on a panel at the Messaging Anti Abuse Working Group (MAAWG) next week to discuss how to drive adoption of domain-to-domain email encryption.

Facebook also ran a test in May and found that almost 60 percent of billions of notification emails it sends every day are encrypted in transit and encouraged more email providers to deploy an encryption technology called STARTTLS.

Lucian Constantin

Lucian Constantin writes about information security, privacy, and data protection for CSO. Before joining CSO in 2019, Lucian was a freelance writer for VICE Motherboard, Security Boulevard, Forbes, and The New Stack. Earlier in his career, he was an information security correspondent for the IDG News Service and Information security news editor for Softpedia.

Before he became a journalist, Lucian worked as a system and network administrator. He enjoys attending security conferences and delving into interesting research papers. He lives and works in Romania.

You can reach him at lucian_constantin@foundryco.com or @lconstantin on X. For encrypted email, his PGP key's fingerprint is: 7A66 4901 5CDA 844E 8C6D 04D5 2BB4 6332 FC52 6D42

More from this author