Live data from Hacker News

Gmail Will Warn If Message Is Not Authenticated/Encrypted

gmailblog.blogspot.com

11–20 of 216 posts

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#11
post #5

[deleted]

> Gmail has always supported encryption in transit using TLS, and will automatically encrypt your incoming and outgoing emails if it can. We support industry-standard authentication to help combat email impersonation.

> 1. If you receive a message from, or are about to send a message to, someone whose email service doesn’t support TLS encryption, you’ll see a broken lock icon in the message.

> 2. If you receive a message that can’t be authenticated, you’ll see a question mark in place of the sender’s profile photo, corporate logo, or avatar.

AKA, it operates like the lock in my URL bar right now except in reverse. By the way Google has explained this feature, it seems fairly good to me. At least it doesn't say "this is secure" because, among other vulnerabilities, the remote server admin can still read what is received (as has always been the case with email).

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#13
post #7

Earlier quoted context omitted.

Yep surprised they haven't rolled one out yet. Ideally placed.

And by ideally placed, you mean for the NSA, right? I'd never put any GPG keys of mine in an American cloud provider. That sort of voids the entire point of it.

More importantly, end-to-end encryption means that your desktop/laptop/tablet/phone/TI-83 is doing the crypto, especially signatures.

On a somewhat related note, I remember reading some documentation on a one-time password scheme, which I can't find anymore. It briefly mentioned something about using DES calculators to handle crypto signatures (for what reason i cannot remember). For our purposes, a PGP/GPG hand-held device would be neat, though perhaps cumbersome to actually user.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#14

meh. This doesn't seem very interesting. What would be really interesting is gmail support for public key encryption. They're perfectly positioned to roll out a user-friendly key management system.

Yep surprised they haven't rolled one out yet. Ideally placed.

They've been working on a browser extension for it:

https://googleonlinesecurity.blogspot.com/2014/06/making-end...

https://github.com/google/end-to-end

I don't know what they might do in the future to encourage people to use this, or if they feel that there's a point at which it would be sensible or useful to actively promote it.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#16
post #7

Earlier quoted context omitted.

Yep surprised they haven't rolled one out yet. Ideally placed.

And by ideally placed, you mean for the NSA, right? I'd never put any GPG keys of mine in an American cloud provider. That sort of voids the entire point of it.

Why do you believe non-American cloud providers aren't compromised?

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#18
post #9

>If you receive a message that can’t be authenticated, you’ll see a question mark in place of the sender’s profile photo, corporate logo, or avatar. This makes it sound like I (the sender) can set the image displayed if I am using DKIM. Is that the case? Or is it only if I have DKIM and have a Google account with that email?

Gmail uses an associated Google+ profile for authenticated emails, so you need both for it to work going forward, I presume. To get started, check https://www.google.com/business/

Outlook uses Facebook and Twitter, if you have these contacts integrated. Yahoo does this too: http://techcrunch.com/2015/03/04/smart-contact-cards-arrive-...

There really should be some kind of standard or mail header though. :) Come to think of it, services could support a vcard mime-type attachment, perhaps? Except that likely wouldn't support URLs to profile photos... Maybe we've identified a missing feature of DKIM? ;-)

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#19

In my opinion, you should just behave like your emails are public record. This is the best way of approaching that technology.

That's what I do as email is more akin to a postcard than a letter. If that makes someone uncomfortable, then they should choose another medium.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#20
post #9

>If you receive a message that can’t be authenticated, you’ll see a question mark in place of the sender’s profile photo, corporate logo, or avatar. This makes it sound like I (the sender) can set the image displayed if I am using DKIM. Is that the case? Or is it only if I have DKIM and have a Google account with that email?

Gmail uses an associated Google+ profile for authenticated emails, so you need both for it to work going forward, I presume. To get started, check https://www.google.com/business/ Outlook uses Facebook and Twitter, if you have these contacts integrated. Yahoo does this too: http://techcrunch.com/2015/03/04/smart-contact-cards-arrive-... There really should be some kind of standard or mail header though. :) Come to th…

  > There really should be some kind of standard or mail header though. :)
https://en.wikipedia.org/wiki/X-Face
Post reply on HN