Google this month rolled out two new security features to its free Gmail service. The first should protect users against people who might be lurking on your network trying to snoop or hijack your inbox. The other makes it easy for users to tell if they are signed on in more than one location and then remotely sign that machine out of your account. When you log in to your Gmail account, by typing http://mail.google.com into a Web browser, Gmail automatically switches you over to an https:// login – or secure sockets layer (SSL) – page that encrypts the authentication process so that anyone sniffing the local network cannot simply snag your username and password. The trouble is that if you initially log in to Gmail using a plain http:// (unencrypted) session, Gmail will pop you back into an unencrypted session after that temporary switch to https:// for the login.