Earlier quoted context omitted.
There's a big difference between "self-destructing g mail" and "self-destructing e mail". Even with the first, Google supports forwarding all mail to an arbitrary email address, which means the "Gmail" becomes a text-file stored on a dovecot server (or other regular mail server) somewhere. So unless they break delivery (you can forward only some subset of emails) - there's no way for the sender to have any better gua…
> So unless they break delivery Why break delivery when you can break sending? just store the contents locally, and replace the body with some URL that the user has to click.. then, when non-gmail users have been desensitized to clicking links in emails 'because gmail', and get viruses constantly, sell them gmail as a way to have email without risk of viruses. win win!
Google is testing expiring emails in the new Gmail
121–130 of 250 posts
Re: Google is testing expiring emails in the new Gmail
#122And they do it even though, as you note, there are tons of ways to really do confidentiality much better. The Signal protocol has worked great for chat, to name another example. The problem with that for Google, I guess, is that end-to-end security is more in line with the Apple model of smarts living on the user's device, not the Google model that requires the server to read and understand all of every user's content. (I say that as someone on Android, Linux, and so on. I'm not super invested in Apple or their ecosystem.)
Also, this idea is salvageable. You could have "request expiration," etc. and maybe you honor by default but don't suggest you enforce it. And managed work environments can try any DRMish stuff they like (though it will still be unreliable!), because the boss is the customer and if they want to make it a pain for the user to do certain things they can. But as it stands now, false sense of security for the average user, and an entirely valid feeling for those parsing the details that companies like Google are more than happy to erode user control.
I would love to see this idea ridiculed for how broken it is. Maybe it will even inspire less broken privacy features from competitors.
Re: Google is testing expiring emails in the new Gmail
#123Earlier quoted context omitted.
You should checkout https://privnote.com/# Basically if I send you a message using it, I have deniability. Screen shot all you want, I can simply say I never sent it. If we do go to court over something sent -- you will end up showing a screen shot or a copy and pasted text file. Those will be tough to support in court. Have fun going after an Uruguay tech company for deleted data. This is different with standard ema…
You're really overestimating what happens in actual jury trials. When I served on a jury, a lawyer presented photographs of evidence as evidence. Like, I'm talking paper printouts of photos that were taken on a cell phone. Juries aren't full of engineers, as a general rule. If the average person on Reddit will see a screen shot of a text message and assume the conversation happened, why wouldn't an average juror? The…
I'm not a trial lawyer, but I suspect that it's not a great defence strategy to deny basic matters of fact.
Re: Google is testing expiring emails in the new Gmail
#124What a bunch of hype garbage this is. If you send something in plaintext to a server it's already game over. If Google was serious about privacy it would pgp-encrypt everything so only the client, client-side can decrypt it, just like what protonmail does. pfff, 'self destructing emails', what a heaping pile of razzle dazzle no-ops that is -- this is more likely subliminal advertisement for the new mission impossible…
When your garbage goes out on the curb it's perfectly legal for anyone - including law enforcement - to sort thought it. I have to wonder if the same concept would / could be applied to such emails? The email might be gone from my account and yours, but it's still in a digital landfill somewhere. Free to be reviewed, sans warrants, etc. Perhaps?
Hmm, there could be a business opportunity for the USPS. They could sell 'stamped' trash bags, good for transport to the town dump, which could only be collected by authorized carriers, namely the regular trash collectors.
Pawing through those bags would be tampering with mail, a federal crime IIRC ( ah, here we go: https://about.usps.com/securing-the-mail/mailtampering.htm )
Probably not a market hit, though, no one really cares. Not to mention the bags would highlight "the good stuff".
Re: Google is testing expiring emails in the new Gmail
#125What a bunch of hype garbage this is. If you send something in plaintext to a server it's already game over. If Google was serious about privacy it would pgp-encrypt everything so only the client, client-side can decrypt it, just like what protonmail does. pfff, 'self destructing emails', what a heaping pile of razzle dazzle no-ops that is -- this is more likely subliminal advertisement for the new mission impossible…
Except in info-sec there's different degrees of information disclosure. You seem to be focused on mitigating disclosure to government, Google, or a rogue employee of either one but the scope is significantly larger and more diverse than that. The biggest benefit of this is removing the email from archives, so weeks, months, or years later if the account gets compromised the gains are lower. For example an email with…
So why would I believe Google now?
Re: Google is testing expiring emails in the new Gmail
#126What a bunch of hype garbage this is. If you send something in plaintext to a server it's already game over. If Google was serious about privacy it would pgp-encrypt everything so only the client, client-side can decrypt it, just like what protonmail does. pfff, 'self destructing emails', what a heaping pile of razzle dazzle no-ops that is -- this is more likely subliminal advertisement for the new mission impossible…
Re: Google is testing expiring emails in the new Gmail
#127The really bad-news thing for me here is Google decided it's good for business to try DRM for email, doing their best to take away (recipient) user control and talking about it as a feature. (They've _gone along_ with crummy ideas, of course, but _promoting_ DRM for email's a whole 'nother thing.) And they do it even though, as you note, there are tons of ways to really do confidentiality much better. The Signal prot…
It's trying to turn email into a proprietary thing that only works between Gmail addresses. All the Inbox "AI-enhanced" nonsense was also part of this plan, and I'm glad it hasn't caught on because of that.
The only thing that would make me accept Gmail turning email into a less open format is if they enabled end-to-end encryption similar to ProtonMail that wasn't a pain to use like PGP is. At least then there would be a good reason for killing the old format and breaking compatibility with other providers.
Ideally, it would still be a format that other email providers could at least adopt later on, and then the email services could remain compatible with each other. But providing end-to-end encryption at all would be a big deal on its own.
But this or the AI stuff are a joke in comparison. And we know Google doesn't care anymore about end-to-end encryption (now that it has become Pentagon's bestie), as it has already killed its own End-to-End project.
Re: Google is testing expiring emails in the new Gmail
#128The really bad-news thing for me here is Google decided it's good for business to try DRM for email, doing their best to take away (recipient) user control and talking about it as a feature. (They've _gone along_ with crummy ideas, of course, but _promoting_ DRM for email's a whole 'nother thing.) And they do it even though, as you note, there are tons of ways to really do confidentiality much better. The Signal prot…
Not many people are paying attention, but this is just another move from Google to make email = Gmail. It's trying to turn email into a proprietary thing that only works between Gmail addresses. All the Inbox "AI-enhanced" nonsense was also part of this plan, and I'm glad it hasn't caught on because of that. The only thing that would make me accept Gmail turning email into a less open format is if they enabled end-to…
Agree with that.
And sad and weird. There are plenty of ways to do well in business without eroding the open nature of email!
Re: Google is testing expiring emails in the new Gmail
#129Earlier quoted context omitted.
When your garbage goes out on the curb it's perfectly legal for anyone - including law enforcement - to sort thought it. I have to wonder if the same concept would / could be applied to such emails? The email might be gone from my account and yours, but it's still in a digital landfill somewhere. Free to be reviewed, sans warrants, etc. Perhaps?
> When your garbage goes out on the curb Hmm, there could be a business opportunity for the USPS. They could sell 'stamped' trash bags, good for transport to the town dump, which could only be collected by authorized carriers, namely the regular trash collectors. Pawing through those bags would be tampering with mail, a federal crime IIRC ( ah, here we go: https://about.usps.com/securing-the-mail/mailtampering.htm )…
Re: Google is testing expiring emails in the new Gmail
#130Earlier quoted context omitted.
As long as I can always override the feature on the receiving end then fine. I have an incredibly bad memory and I want my email account to listen to me, not someone else.
Outside of Gmail, they just won't be emailing you the content to begin with. It's another way to keep the data on Google's servers, you'll just get a link in the email to them. Mind you, this is a better case than for Gmail users who will probably see the content inline with their mail, only for it to disappear later.