What a bunch of hype garbage this is. If you send something in plaintext to a server it's already game over. If Google was serious about privacy it would pgp-encrypt everything so only the client, client-side can decrypt it, just like what protonmail does. pfff, 'self destructing emails', what a heaping pile of razzle dazzle no-ops that is -- this is more likely subliminal advertisement for the new mission impossible…
Except in info-sec there's different degrees of information disclosure. You seem to be focused on mitigating disclosure to government, Google, or a rogue employee of either one but the scope is significantly larger and more diverse than that. The biggest benefit of this is removing the email from archives, so weeks, months, or years later if the account gets compromised the gains are lower. For example an email with…
Google is testing expiring emails in the new Gmail
71–80 of 250 posts
Re: Google is testing expiring emails in the new Gmail
#72What a bunch of hype garbage this is. If you send something in plaintext to a server it's already game over. If Google was serious about privacy it would pgp-encrypt everything so only the client, client-side can decrypt it, just like what protonmail does. pfff, 'self destructing emails', what a heaping pile of razzle dazzle no-ops that is -- this is more likely subliminal advertisement for the new mission impossible…
Not everyone is worried that NSA is tracking them live: virtually all are more worried about wife or dirty laundry being made public. Or an email sent at 2am after 14 beers...6 years ago. This solves quite a few problems. Then, Google can start on other problems, like PGP.
Re: Google is testing expiring emails in the new Gmail
#73This is only possible if one believes in the capacity to control client security on the other side. There’s also the problem that something viewable by the recipient’s eyeballs is also photographable by the recipient’s camera. Moreover, I worry about the new Gmail feature that undermine the open platform of email. Email is just about the last unwalled comms platform we have, and I really worry for its safety if gmail…
Email is doomed either way. The standard is indefinitely stuck in "IE6" mode, where there's few if any improvements, updates, or fixes. Everyone time anyone suggests significant improvements one of the big players (Google, Microsoft, Yahoo!, etc) says no and it stalls. If email gets a "HTML5"-like major refresh at some point then I'd be proven wrong but that hasn't happened yet in my lifetime. Microsoft in particular…
Yes, please leave email the way it is, because it works fine. It’s one of the few things that does.
The only feature I want is end to end encryption. Google will never make encryption easy on their own because they’ve got perverse incentives not to.
Re: Google is testing expiring emails in the new Gmail
#74What a bunch of hype garbage this is. If you send something in plaintext to a server it's already game over. If Google was serious about privacy it would pgp-encrypt everything so only the client, client-side can decrypt it, just like what protonmail does. pfff, 'self destructing emails', what a heaping pile of razzle dazzle no-ops that is -- this is more likely subliminal advertisement for the new mission impossible…
I feel like client-side email encryption is a missed opportunity for Apple. Easy encrypted email would fit nicely into their narrative of “we can offer privacy features that Google can’t, because we sell you stuff”
I was playing around with using my own CA to issue certificates for internal stuff. I created a personal certificate for myself and imported it to my keychain - without doing anything, Apple Mail was digitally signing my messages. On the other side, however, people saw digital signatures that couldn't be verified and got confused by that.
[0] https://support.apple.com/en-ca/guide/mail/sign-encrypt-mess...
Re: Google is testing expiring emails in the new Gmail
#75"On the recipient’s side, the person was using the existing version of Gmail and received a link to view the confidential email. The recipient had to log into their Google account once again to view the content." IMO this is an open invitation to phishers.
I think the genie's out of the bottle on that one, I can already do the same with a million other services.
So the next time you get an email from "google", you won't think twice about why you have to log back in.
Re: Google is testing expiring emails in the new Gmail
#76Honest headline: Google is allowing you to hide emails from its public interface after a specific amount of time.
Re: Google is testing expiring emails in the new Gmail
#77Assuming gmail and g-suite share technology, I doubt any enterprise customers would be comfortable with the content of the email actually being purged. I'd guess there is some backdoor for corporate compliance and auditing reasons. I also don't see any reason you couldn't build a bot that grabs these for you to keep via the gmail add on api.
wait. why wouldn't at least some corporate customers be interested in this sort of thing? they'd have a standard, non-selective, purely time-based expiration policy which would be defensible in the face of a government investigation. "Your honor, we made no attempt to hide specific details about this matter. Our policy has always been to destroy all messages that are greater than 90 days old."
A retention period in line with SEC requirements (7 years I believe) might fly but 90 days is to short -also how would you discipline some one for abuse of the email system if the evidence disappears
Re: Google is testing expiring emails in the new Gmail
#78What a bunch of hype garbage this is. If you send something in plaintext to a server it's already game over. If Google was serious about privacy it would pgp-encrypt everything so only the client, client-side can decrypt it, just like what protonmail does. pfff, 'self destructing emails', what a heaping pile of razzle dazzle no-ops that is -- this is more likely subliminal advertisement for the new mission impossible…
This is an augmentation to what postini had, and now in core G Suite, of defined retention periods for email. Now, users can make one-off decisions on a per-email basis.
It's like the secret discussion/chat system that uber uses, I can't find the name, that guarantees protection against legal discovery by encrypting the chat and making sure it is ephemeral.
There are valid (maybe not morally, but legally) reasons to have defined retention periods and this is a nice addition to that.
It does bring Google into the Apple privacy-is-our-business sphere in that cooperating parties that solely use gmail have much better assurance that they don't leave traces behind.
Re: Google is testing expiring emails in the new Gmail
#79Re: Google is testing expiring emails in the new Gmail
#80What a bunch of hype garbage this is. If you send something in plaintext to a server it's already game over. If Google was serious about privacy it would pgp-encrypt everything so only the client, client-side can decrypt it, just like what protonmail does. pfff, 'self destructing emails', what a heaping pile of razzle dazzle no-ops that is -- this is more likely subliminal advertisement for the new mission impossible…
Basically if I send you a message using it, I have deniability. Screen shot all you want, I can simply say I never sent it. If we do go to court over something sent -- you will end up showing a screen shot or a copy and pasted text file. Those will be tough to support in court. Have fun going after an Uruguay tech company for deleted data.
This is different with standard email. A subpoena sent to gmail will reveal ip addresses (sender and receiver), what time it was sent, the fact that you logged in with account 9328439, the fact I logged in with account 298238, someone from google testifying it was sent and read, on and on.
I don't know what google is trying to do -- but what privnote did is really useful and an obvious win.