Unfortunately - very true!
Main Topics
Browse All TopicsOne of my clients would like to use email (specifcally webmail) for interoffice communication in a dental office (also occasionally want to be able to view outside the office). The office has approx 30 associates who would use this method of communication. Email is of course slow and insecure so I am considering Google Talk (IM). I would like to know:
1) how secure/insecure is this?
2) Is there a way that I can control passwords for all of the users?
3) what port does G Talk use and is it always open (listening?) and is that a security risk?
Is there a better way to achieve the same result?
Bill
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
The packets are secure from the client to the server via them being encrypted via TLS (ssl's replacement) and from the server to the other client.
GTalk is based on the Jabber protocol http://www.google.com/talk
GoogleDesktop might have something that your looking for, but I'm not sure
http://desktop.google.com/
But I don't think there is centralized managment for Gtalk... you might use your own jabber server internally, there are tools for that.
IM typically is a 3rd party service. You sign in to Gtalk, AIM, MSN, and your on-line talking to that services servers, those servers then send your messages to other online buddies/contacts, and since each client initiated the contact to the IM's servers, your not listening for anything other than contact from those servers.
1.2.3.4 on port 45698 connects to (IM sever) 9.8.7.6 on port 443... no one can contact 1.2.3.4 on port 45698 unless their ip is 9.8.7.6... it's called an established session
or a stateful session: http://en.wikipedia.org/wi
-rich
Email is of course slow and insecure so I am considering Google Talk (IM).
=> You can use PGP encrypton that is a very strong security, but of couse not as fast as intime talk.
http://eu.pgpstore.com/ (Im sure there are also free PGP programs around)
1) how secure/insecure is this?
=> Atm Google talk is beta. Unless its stable I wouldnt recommend it if security is a issue. All over: no system is unbreakable.
Googles business is storing and analyizing data. So they store certain user data (how you configure Google talk, how long you very talking per session, timepoint of using GT, stored contatcs in GT, frequency and size of sent files, communication partner)
All over I didnt find anything they are storing/checking what is spoken over GT.
Sent data are encrypted like in most IM tools.
2) Is there a way that I can control passwords for all of the users?
=> No, Google talk is a single user program.
3) what port does G Talk use and is it always open (listening?) and is that a security risk?
=> As long as GT is open and set to "Online" its listening to GT server. Any programm with a open port to the Internet is vulnerable as soon as a exploit is known. IM programs are in general very secure against exploits (you dont hear a lot of IM exploits).
GT uses default port 5223. If its not working Google recommends port 443. Hacker programs will proably dock on those ports. So its recommandable to change the port to any other ID.
Is there a better way to achieve the same result?
=> Google talk is not better or worse than other IM tools. I have no security issue but Im happy with Skype. Of course they all have some unqiue features others wont have.
There are also providers you can find in Internet offering so called "meeting rooms" but they cost every time you use them and its only good for time based meetings.
As long as the dentist have http://www.experts-exchang
Oh, I just saw that PGP also offers IM encryption. You got more infos on the link above.
Hope I could help
Tayger
Are the employee's of this dental office going to use gTalk to relay protected health information over the network? If so then I you can't recommend that solution to your client. When you are dealing with HIPAA you have to be vigilant about the protection of the patient information. These are the issues I see with doing this.
1. Everyone has to create a google mail account. There is no mass password tool to facilitate this. You are at the mercy of your users using simple passwords.
2. Google by default turns on chat history. This means that patient information will be stored on google servers and is forever searchable by you.
3. Being that your data has now been stored by google you have lost control of the data. If an employee quits or is terminated they have permanent access to this information.
Just think of the ramifications of a disgruntled employee having access to this data once they've been terminated. They could then start an investigation into your clients HIPAA practices. With $10k per day fines per area of non-compliance that could really add up when they have blatant proof of your non-compliance.
If inner-office communication is a priority then I would recommend running a Wildfire server. This is based off of Jabber which is the same protocol that gTalk uses. You can use encryption which would be preferable. Best of all the data stays within your network!!
http://www.jivesoftware.or
FarFromHome, some points I have to correct:
Its not true that entered text is stored on Google's side. They store data like session time, set config, etc. but - so far - not typed text. You can YOURSELF activate chat history on the local PC if you want to. Information you entered/set on GMail/over email will be used for internal (Google) analysis but NO ONE except Google can search that personal stuff.
Here is Googles licence agreement: http://www.google.com/talk
Google commited to the termns of SafeHarbor: http://www.export.gov/safe
Just to make some things clear.
Do you even have a google talk account? It does in fact store your chat conversations on their servers. I just created another gmail account and by default they save chat history. You can also search your chat history from your gmail account. It is stored on googles servers and you can search it from any computer in the world. Try it out before you comment on it next time...
By default, chats are not logged, Tayger is correct, you have to enable the setting- further you can go off-record if you wish
Your chat history will appear here if you choose to save your chats. You can change this in Settings
http://www.google.com/talk
http://mail.google.com/sup
http://mail.google.com/sup
-rich
Business Accounts
Answer for Membership
by: chris_calabresePosted on 2006-10-30 at 11:30:12ID: 17836500
I'm thinking that the reql question is not how secure or well built it is, but how the jury will react when they find out that the dentists were sending their patient's private information to a free service they didn't have a contract with guaranteeing a specific level of security.