Live data from Hacker News

Google is testing expiring emails in the new Gmail

techcrunch.com

111–120 of 250 posts

Re: Google is testing expiring emails in the new Gmail

#111

What I'm struck by is how many people don't see value in this. If you work with sensitive data, this is valuable. A business may already trust google, but they want to send emails (even internally) that expire. I'd like it if it just expired the attachments - that's normally where sensitive data lives. I don't even need to prevent printing etc. I'd also love a setting, email over 1 year old, you have to jump through…

There is no value in it because it is a false promise. If you give someone access to data, you have lost control over it, especially if it is by email - because not everyone uses Gmail. Many of those who do do not use the web client, and email clients are ultimately controlled by end users, even web based ones.

Only if you have complete end-to-end control over all the devices that everyone uses, including their brain, can you stop people from copying data.

If I have a file that I want to limit access to, I would never dream of sending it via e-mail. Some hosted document service which only shows parts of the file would be far preferable.

Re: Google is testing expiring emails in the new Gmail

#112

Earlier quoted context omitted.

I do that all the time without any problems. What issues have you seen with it?

marked as SPAM. I get that a lot

Not good at all. This should happen only if one of your servers has been compromised and spits out spam that gets logged by Google. Does unmarking your email as spam by the recipient work? If not that would be an indication it's intentional.

Re: Google is testing expiring emails in the new Gmail

#113

Earlier quoted context omitted.

Except in info-sec there's different degrees of information disclosure. You seem to be focused on mitigating disclosure to government, Google, or a rogue employee of either one but the scope is significantly larger and more diverse than that. The biggest benefit of this is removing the email from archives, so weeks, months, or years later if the account gets compromised the gains are lower. For example an email with…

As long as I can always override the feature on the receiving end then fine. I have an incredibly bad memory and I want my email account to listen to me, not someone else.

Outside of Gmail, they just won't be emailing you the content to begin with. It's another way to keep the data on Google's servers, you'll just get a link in the email to them.

Mind you, this is a better case than for Gmail users who will probably see the content inline with their mail, only for it to disappear later.

Re: Google is testing expiring emails in the new Gmail

#114
post #75

Earlier quoted context omitted.

I think the genie's out of the bottle on that one, I can already do the same with a million other services.

Well, this gives a plausible reason for having to log back into an account you're already logged into. And normalizes the behavior. So the next time you get an email from "google", you won't think twice about why you have to log back in.

Yeah, but I think the battle is lost. All users should always double-check why they need to enter credentials on any page from any website. I think that the simple act of logging into a site to use it has already "normalized" the need to re-enter credentials to a point beyond saving.

Re: Google is testing expiring emails in the new Gmail

#115

This is only possible if one believes in the capacity to control client security on the other side. There’s also the problem that something viewable by the recipient’s eyeballs is also photographable by the recipient’s camera. Moreover, I worry about the new Gmail feature that undermine the open platform of email. Email is just about the last unwalled comms platform we have, and I really worry for its safety if gmail…

Email is doomed either way. The standard is indefinitely stuck in "IE6" mode, where there's few if any improvements, updates, or fixes. Everyone time anyone suggests significant improvements one of the big players (Google, Microsoft, Yahoo!, etc) says no and it stalls. If email gets a "HTML5"-like major refresh at some point then I'd be proven wrong but that hasn't happened yet in my lifetime. Microsoft in particular…

It seems like it would be worth all the effort if there were a fork that solved every authentication and encryption problem, and also addressed some less important things like: hey, maybe don’t use the Microsoft Word rendering engine for html.

But that would require all the transfer agents, delivery agents, and user agents to agree on the new spec, implement it in some standard/predictable backwards compatible way, and then support a legacy mode for the next 5-10 years.

Re: Google is testing expiring emails in the new Gmail

#116

"On the recipient’s side, the person was using the existing version of Gmail and received a link to view the confidential email. The recipient had to log into their Google account once again to view the content." IMO this is an open invitation to phishers.

I think the genie's out of the bottle on that one, I can already do the same with a million other services.

It just encourages and exposes a wider range of people to an attack vector. No one should be actively _training_ people to open random links in an email.

Re: Google is testing expiring emails in the new Gmail

#119
Well, this is finally the nudge that broke the camel's back, to leave Gmail.

And it will play havoc in GSuite, where there are needs and requirements for various entities to maintain business records. (Maybe these deleted emails remain visible to administrators? Still leaves employees without control over the messages sent to them, including and especially abusive ones.)

Anyway, feels like more asymmetry in what was designed as a symmetric model -- like much of the Net.

Re: Google is testing expiring emails in the new Gmail

#120

What a bunch of hype garbage this is. If you send something in plaintext to a server it's already game over. If Google was serious about privacy it would pgp-encrypt everything so only the client, client-side can decrypt it, just like what protonmail does. pfff, 'self destructing emails', what a heaping pile of razzle dazzle no-ops that is -- this is more likely subliminal advertisement for the new mission impossible…

I feel like client-side email encryption is a missed opportunity for Apple. Easy encrypted email would fit nicely into their narrative of “we can offer privacy features that Google can’t, because we sell you stuff”

They already have, it's called iMessage ;)
Post reply on HN