Live data from Hacker News

Google is testing expiring emails in the new Gmail

techcrunch.com

61–70 of 250 posts

Re: Google is testing expiring emails in the new Gmail

#61

Assuming gmail and g-suite share technology, I doubt any enterprise customers would be comfortable with the content of the email actually being purged. I'd guess there is some backdoor for corporate compliance and auditing reasons. I also don't see any reason you couldn't build a bot that grabs these for you to keep via the gmail add on api.

wait. why wouldn't at least some corporate customers be interested in this sort of thing? they'd have a standard, non-selective, purely time-based expiration policy which would be defensible in the face of a government investigation. "Your honor, we made no attempt to hide specific details about this matter. Our policy has always been to destroy all messages that are greater than 90 days old."

Some companies may want this feature.

Others would not because the regulators (like the SEC) have said that companies can't delete communication data (email/chat) prior to regulated windows. most companies want to delete as soon as possible after that window has expired which is it's own challenge.

I suppose I wanted to point out that not being able to read a message and fully purging it are not the same thing and gsuite likely alienates the enterprise if they cannot comply with regulation.

Re: Google is testing expiring emails in the new Gmail

#63

What a bunch of hype garbage this is. If you send something in plaintext to a server it's already game over. If Google was serious about privacy it would pgp-encrypt everything so only the client, client-side can decrypt it, just like what protonmail does. pfff, 'self destructing emails', what a heaping pile of razzle dazzle no-ops that is -- this is more likely subliminal advertisement for the new mission impossible…

Except in info-sec there's different degrees of information disclosure. You seem to be focused on mitigating disclosure to government, Google, or a rogue employee of either one but the scope is significantly larger and more diverse than that. The biggest benefit of this is removing the email from archives, so weeks, months, or years later if the account gets compromised the gains are lower. For example an email with…

[deleted]

Re: Google is testing expiring emails in the new Gmail

#64
post #31

Earlier quoted context omitted.

I feel like client-side email encryption is a missed opportunity for Apple. Easy encrypted email would fit nicely into their narrative of “we can offer privacy features that Google can’t, because we sell you stuff”

Encryption doesn't work unless both sides use it. Apple supporting it won't help apple users one bit, because nobody else uses an actual application to check mails anymore. It's mostly web mail clients everywhere, and they obviously can't use encryption.

Would be interesting if they built something like SMS/iMessage, where within the ecosystem emails were encrypted but when sent outside they weren't.

Of course, hopefully PGP, and not some custom, private API like iMessage.

Re: Google is testing expiring emails in the new Gmail

#67
post #31

Earlier quoted context omitted.

I feel like client-side email encryption is a missed opportunity for Apple. Easy encrypted email would fit nicely into their narrative of “we can offer privacy features that Google can’t, because we sell you stuff”

Encryption doesn't work unless both sides use it. Apple supporting it won't help apple users one bit, because nobody else uses an actual application to check mails anymore. It's mostly web mail clients everywhere, and they obviously can't use encryption.

> nobody else uses an actual application to check mails anymore

Got any data to back that up? I do, and so do a lot of my friends and colleagues.

Re: Google is testing expiring emails in the new Gmail

#68

What a bunch of hype garbage this is. If you send something in plaintext to a server it's already game over. If Google was serious about privacy it would pgp-encrypt everything so only the client, client-side can decrypt it, just like what protonmail does. pfff, 'self destructing emails', what a heaping pile of razzle dazzle no-ops that is -- this is more likely subliminal advertisement for the new mission impossible…

Not everyone is worried that NSA is tracking them live: virtually all are more worried about wife or dirty laundry being made public. Or an email sent at 2am after 14 beers...6 years ago.

This solves quite a few problems. Then, Google can start on other problems, like PGP.

Re: Google is testing expiring emails in the new Gmail

#69
post #31

Earlier quoted context omitted.

Encryption doesn't work unless both sides use it. Apple supporting it won't help apple users one bit, because nobody else uses an actual application to check mails anymore. It's mostly web mail clients everywhere, and they obviously can't use encryption.

iOS? Plus, I know folks who use mail.app. I also bet they could figure out how to instrument Safari with browser-side encryption for their cloud users. A few more privacy scandals break, and if Apple had an end-to-end encryption story that sounds roughly like: “If you’re using Apple products and services, you probably don’t need to think too much about the techy parts.” I could easily see Apple cementing their positi…

Where do you keep the keys?

* On the device? Oops--device broke, guess my emails are gone forever

* In the "cloud"? -- Oops, can't guarantee encryption

Who generated the keys and how do you build trust?

For both of these, you can trust Apple do do the right thing, but that's putting all your eggs into that basket, similar to iMessage.

Re: Google is testing expiring emails in the new Gmail

#70
post #20

What a bunch of hype garbage this is. If you send something in plaintext to a server it's already game over. If Google was serious about privacy it would pgp-encrypt everything so only the client, client-side can decrypt it, just like what protonmail does. pfff, 'self destructing emails', what a heaping pile of razzle dazzle no-ops that is -- this is more likely subliminal advertisement for the new mission impossible…

This isn't for cases when you don't trust the recipient. This is for plausible deniability for both of you. If someone is monitoring your email, they will get the link to the content but they won't be able to read it.

[deleted]
Post reply on HN