Live data from Hacker News

Gmail Will Warn If Message Is Not Authenticated/Encrypted

gmailblog.blogspot.com

31–40 of 216 posts

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#31
post #25
post #8

Other mailers should warn about Gmail, with "Your message was scanned for advertising purposes".

I never understood this sentiment. I doubt that there is a way to build a webmailer without processing the emails content at some point. And as it is processed anyway; using it to adjust your ads doesn't appear to me as something significant.

>I doubt that there is a way to build a webmailer without processing the emails content at some point.

It is disingenuous and/or ignorant to suggest that temporarily loading an email into memory for the purpose of displaying it on the users screen is the same as parsing and catagorising the text and storing the results of the analysis in a database for the purpose of manipulating the user.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#32

question about this: if i send mail to my IMAP or POP server over TLS, it may still travel to various spots on the journey to its final destination unencrypted using SMTP, right?

It's what the email server that you are making the IMAP or POP connection to does next that matters. If you send mail to a Gmail account it should make a TLS connection to Google's servers directly.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#33
post #24
post #19

Earlier quoted context omitted.

That's what I do as email is more akin to a postcard than a letter. If that makes someone uncomfortable, then they should choose another medium.

This is what GMail is doing: making sure that sending an email is like sending a letter (instead of a postcard). TLS email is not 100% secure (private, authenticated, etc), but not 100% insecure either. Verifying TLS for email is an easy step in making email a bit less insecure, and it requires no intervention from users. If you need something secure, then yes, go for GnuPG or other forms of end-to-end encryption (if…

Yes, TLS protects the information in transit but it does not prevent a malicous intermediary from reading or altering your mail. Sort of like an envelope could be opened at the post office, read, and then resealed before you get it.

You need gpg or s/mime to guard against that.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#34
post #23
post #14

Earlier quoted context omitted.

They've been working on a browser extension for it: https://googleonlinesecurity.blogspot.com/2014/06/making-end... https://github.com/google/end-to-end I don't know what they might do in the future to encourage people to use this, or if they feel that there's a point at which it would be sensible or useful to actively promote it.

It's still not ready for production use. One problem with e2e is that it's JavaScript based and runs in he browser, so there is a certain attack vector present there. To defend against this, ideally e2e needs to work with a smartcard (such as the yubikey neo) so that the private key cannot be stolen. There was an issue I was tracking a while back to integrate this support, but it's still a work in progress.

It doesn't even need the hardware part in most cases. OS keyrings support pkcs11 interface with signing exposed. That means you can just send data to be encrypted for example by gnome-keyring and the browser never sees the actual key.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#35
post #26
post #8

Other mailers should warn about Gmail, with "Your message was scanned for advertising purposes".

What about "Your message was categorized fir Bayesian spam filtering and may have contributed to eventual upstream rules" for all those installations that historically ran SpamAssassin? If you're using Gmail or sending to a gmail address[1], you know what you are in for, and if you don't you should at least know that anything you send to someone else is no longer in your control and you have very little control over…

You said 'using' or 'sending to' which imply that by my action I somehow consented to be tracked by using email as it was designed to be used. But there is also received from, i.e. I receive a message from a gmail user and now Google associates my address with some advertising keywords.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#36
post #35
post #26

Earlier quoted context omitted.

What about "Your message was categorized fir Bayesian spam filtering and may have contributed to eventual upstream rules" for all those installations that historically ran SpamAssassin? If you're using Gmail or sending to a gmail address[1], you know what you are in for, and if you don't you should at least know that anything you send to someone else is no longer in your control and you have very little control over…

You said 'using' or 'sending to' which imply that by my action I somehow consented to be tracked by using email as it was designed to be used. But there is also received from, i.e. I receive a message from a gmail user and now Google associates my address with some advertising keywords.

Are you assuming that's the case, or is there evidence that this is so?

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#37

This sounds great but Google has been making it harder and harder to run your own mail server even for personal use. I think they would be happy of email servers were only run by a few large companies. They make it sound like they are doing the right thing but really they are bully the industry to do it their way. So many people have Gmail accounts that you can't run an email server that cannot send email to Google.…

> some new technology that Gmail demands

> everyone is going to switch, now

The article is pretty clear that gmail users can keep emailing others who don't support TLS or authentication; they will just now see an additional icon informing them of that condition. Nobody is being demanded to switch anything.

disclaimer: works for Google

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#38

This sounds great but Google has been making it harder and harder to run your own mail server even for personal use. I think they would be happy of email servers were only run by a few large companies. They make it sound like they are doing the right thing but really they are bully the industry to do it their way. So many people have Gmail accounts that you can't run an email server that cannot send email to Google.…

Just to play devil's advocate: the vast majority of (even technical) people have no interest in running a mail server. Who should Google optimize for?

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#39

This sounds great but Google has been making it harder and harder to run your own mail server even for personal use. I think they would be happy of email servers were only run by a few large companies. They make it sound like they are doing the right thing but really they are bully the industry to do it their way. So many people have Gmail accounts that you can't run an email server that cannot send email to Google.…

Their users are suffering because of phishing.

Measurably.

And as to "sufficient warning," sure, I can see that it would be nice to have given people like you more lead time. But then again, "GMail has always supported encryption in transit using TLS," and if you care about running your own email server, it feels to me like the writing has been on the wall for that one for a long time.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#40
post #38

This sounds great but Google has been making it harder and harder to run your own mail server even for personal use. I think they would be happy of email servers were only run by a few large companies. They make it sound like they are doing the right thing but really they are bully the industry to do it their way. So many people have Gmail accounts that you can't run an email server that cannot send email to Google.…

Just to play devil's advocate: the vast majority of (even technical) people have no interest in running a mail server. Who should Google optimize for?

Couldn't agree more. I run a number of my own services on my own servers but email is not one of them. I don't have the time or energy to keep up with it and it's imperative that I receive all emails sent to me and all my sent emails are received. Google apps does that perfectly for me and I don't have to worry about it.

As far as "I take issue with Google making the decision that everyone is going to switch, now and with out sufficient warning." it would be nice to get some notice on these changes no doubt but email is shit. It just is but we are stuck with it and at least google is attempting to drag it forward even if in doing so they leave some outdated servers/services behind. I'll take more secure of infinitely backwards compatible any day.

Post reply on HN