Live data from Hacker News

Google is testing expiring emails in the new Gmail

techcrunch.com

91–100 of 250 posts

Re: Google is testing expiring emails in the new Gmail

#92
post #48

No. No. No. Google, please don't mess with email standards.

Waaaay too late on that. Just try setting up your own server and sending to a Gmail address.

I do that all the time without any problems. What issues have you seen with it?

Re: Google is testing expiring emails in the new Gmail

#93

What a bunch of hype garbage this is. If you send something in plaintext to a server it's already game over. If Google was serious about privacy it would pgp-encrypt everything so only the client, client-side can decrypt it, just like what protonmail does. pfff, 'self destructing emails', what a heaping pile of razzle dazzle no-ops that is -- this is more likely subliminal advertisement for the new mission impossible…

Except in info-sec there's different degrees of information disclosure. You seem to be focused on mitigating disclosure to government, Google, or a rogue employee of either one but the scope is significantly larger and more diverse than that. The biggest benefit of this is removing the email from archives, so weeks, months, or years later if the account gets compromised the gains are lower. For example an email with…

There's a big difference between "self-destructing gmail" and "self-destructing email".

Even with the first, Google supports forwarding all mail to an arbitrary email address, which means the "Gmail" becomes a text-file stored on a dovecot server (or other regular mail server) somewhere.

So unless they break delivery (you can forward only some subset of emails) - there's no way for the sender to have any better guarantee than "please delete after reading".

At least the pgp spec has (had?) an "eyes only" flag that, while it didn't guarantee anything, at least meant compliant software would try hard to not leave a plain text copy on the filesystem.

Re: Google is testing expiring emails in the new Gmail

#94
post #84

Earlier quoted context omitted.

You'd have to go to some special measure to copy and paste the text because they disable the standard, easy copy/paste functionality. But taking a photo is always doable. This is a standard argument. If you can't trust the recipient to preserve privacy then there isn't a technological way to defeat this kind of information leak.

You should be able to copy by disabling JavaScript

The typical way to avoid this particular problem is only to load the content via JavaScript while copy/paste are presumed disabled.

Re: Google is testing expiring emails in the new Gmail

#95

"On the recipient’s side, the person was using the existing version of Gmail and received a link to view the confidential email. The recipient had to log into their Google account once again to view the content." IMO this is an open invitation to phishers.

Oh, so Gmail is finally moving away from email. Guess it was a question of time.

Re: Google is testing expiring emails in the new Gmail

#96

Earlier quoted context omitted.

Not everyone is worried that NSA is tracking them live: virtually all are more worried about wife or dirty laundry being made public. Or an email sent at 2am after 14 beers...6 years ago. This solves quite a few problems. Then, Google can start on other problems, like PGP.

I kind of agree. Although, it doesn't really solve anything. Look at Snapchat--your naughty photos can still be saved no matter what you do.

The point here is not to stop malicious recipients from saving the data. The point is to stop sensitive stuff from showing up in discovery in a lawsuit 3 years from now because a recipient didn't know to delete it.

Re: Google is testing expiring emails in the new Gmail

#97

"On the recipient’s side, the person was using the existing version of Gmail and received a link to view the confidential email. The recipient had to log into their Google account once again to view the content." IMO this is an open invitation to phishers.

I agree about phishers. My bank does this for their "secure email". The first time I got one of their "secure emails", I first assumed it was a phishing attempt for my bank credentials.

Re: Google is testing expiring emails in the new Gmail

#98
post #64
post #31

Earlier quoted context omitted.

Encryption doesn't work unless both sides use it. Apple supporting it won't help apple users one bit, because nobody else uses an actual application to check mails anymore. It's mostly web mail clients everywhere, and they obviously can't use encryption.

Would be interesting if they built something like SMS/iMessage, where within the ecosystem emails were encrypted but when sent outside they weren't. Of course, hopefully PGP, and not some custom, private API like iMessage.

If you're looking for an "open ecosystem" option, Mail on both iOS and Mac (as well as a bunch of clients elsewhere, including Outlook and Thunderbird) supports S/MIME encryption and signing out of the box.

Of course, no one uses it or even realizes it's there because S/MIME is terrible.

Re: Google is testing expiring emails in the new Gmail

#99
post #93

Earlier quoted context omitted.

Except in info-sec there's different degrees of information disclosure. You seem to be focused on mitigating disclosure to government, Google, or a rogue employee of either one but the scope is significantly larger and more diverse than that. The biggest benefit of this is removing the email from archives, so weeks, months, or years later if the account gets compromised the gains are lower. For example an email with…

There's a big difference between "self-destructing g mail" and "self-destructing e mail". Even with the first, Google supports forwarding all mail to an arbitrary email address, which means the "Gmail" becomes a text-file stored on a dovecot server (or other regular mail server) somewhere. So unless they break delivery (you can forward only some subset of emails) - there's no way for the sender to have any better gua…

> So unless they break delivery

Why break delivery when you can break sending?

just store the contents locally, and replace the body with some URL that the user has to click..

then, when non-gmail users have been desensitized to clicking links in emails 'because gmail', and get viruses constantly, sell them gmail as a way to have email without risk of viruses.

win win!

Re: Google is testing expiring emails in the new Gmail

#100
What I'm struck by is how many people don't see value in this. If you work with sensitive data, this is valuable. A business may already trust google, but they want to send emails (even internally) that expire. I'd like it if it just expired the attachments - that's normally where sensitive data lives.

I don't even need to prevent printing etc.

I'd also love a setting, email over 1 year old, you have to jump through some extra hoops to access it.

Post reply on HN