mauld and others,
If a corporate user accesses a web mail service like Gmail over an encrypted https URL, besides using a key logger on the client pc, what technical methods could be used for the employer to monitor the content of inbound or outbound encrypted web mail messages?
Even if there is a proxy server, log analyzer, packet sniffing, and/or other monitoring tools in place; could the actual content be monitored if the employee is using an encrypted webmail connection?
E.g. they could tell Jane Doe spends 5 hours a day in
https://gmail.com but how could they read what she writes and gets in Gmail without a key logger on her client?