Live data from Hacker News

Google is testing expiring emails in the new Gmail

techcrunch.com

151–160 of 250 posts

Re: Google is testing expiring emails in the new Gmail

#151
post #99

Earlier quoted context omitted.

> So unless they break delivery Why break delivery when you can break sending? just store the contents locally, and replace the body with some URL that the user has to click.. then, when non-gmail users have been desensitized to clicking links in emails 'because gmail', and get viruses constantly, sell them gmail as a way to have email without risk of viruses. win win!

Isn't that how protonmail works for non protonmail users ?

Only if the PM sender “encrypts” the message with a password.

Re: Google is testing expiring emails in the new Gmail

#152
post #99

Earlier quoted context omitted.

> So unless they break delivery Why break delivery when you can break sending? just store the contents locally, and replace the body with some URL that the user has to click.. then, when non-gmail users have been desensitized to clicking links in emails 'because gmail', and get viruses constantly, sell them gmail as a way to have email without risk of viruses. win win!

Isn't that how protonmail works for non protonmail users ?

Yeah, and it's not really email either. Facebook started doing something similar for its "email notifications" a good while back. At one point, they sent the comment body in the email notification alerting you to a new comment - so you didn't have to use the (Web) app just to read a couple of lines of text. So they used to have email integration. These days they've settled for email annoyance.

Re: Google is testing expiring emails in the new Gmail

#153

Earlier quoted context omitted.

wait. why wouldn't at least some corporate customers be interested in this sort of thing? they'd have a standard, non-selective, purely time-based expiration policy which would be defensible in the face of a government investigation. "Your honor, we made no attempt to hide specific details about this matter. Our policy has always been to destroy all messages that are greater than 90 days old."

Then a Judge says that policy is designed to hamper the police and security services based on "reasons" contempt of court and sends a CEO to jail for a month. A retention period in line with SEC requirements (7 years I believe) might fly but 90 days is to short -also how would you discipline some one for abuse of the email system if the evidence disappears

yes, right. that's fine. they could make the expiration time 7 years and a day.

also, when a company finds itself under investigation in court, the judge can order a temporary halt to the ongoing process of timely email deletion so that a fair discovery process can occur.

i believe there are existing penalties for abusing the email system if evidence disappears. that wouldn't change.

Re: Google is testing expiring emails in the new Gmail

#154
Someone possibly already building a service to undelete "expired" email.

Automatic local snapshots that you control!

Sort of like deleted tweets that suddenly everyone have elevated interest in and can read forever.

In fact the more "deleted" the tweet (or email) is - the more attention it will get.

Re: Google is testing expiring emails in the new Gmail

#155
Gmail intentionally deviates from the IMAP spec, forcing email clients to either become Gmail clients or work poorly with Gmail. They refuse to support IMAP push, instead saving push for the Gmail API. Recently they introduced AMP for Email, which happens to work via emails that only Gmail can read. Now they introduce another feature which happens to work via emails that only Gmail can read.

I think it's pretty clear what's going on here.

By the way, FastMail's work at the protocol level - http://jmap.io/ - is open source, and being standardized by the IETF.

Re: Google is testing expiring emails in the new Gmail

#156

What a bunch of hype garbage this is. If you send something in plaintext to a server it's already game over. If Google was serious about privacy it would pgp-encrypt everything so only the client, client-side can decrypt it, just like what protonmail does. pfff, 'self destructing emails', what a heaping pile of razzle dazzle no-ops that is -- this is more likely subliminal advertisement for the new mission impossible…

You should checkout https://privnote.com/# Basically if I send you a message using it, I have deniability. Screen shot all you want, I can simply say I never sent it. If we do go to court over something sent -- you will end up showing a screen shot or a copy and pasted text file. Those will be tough to support in court. Have fun going after an Uruguay tech company for deleted data. This is different with standard ema…

Not touching the legal bits, but the comparison between privnote and GMail's thing actually help me zero in what bugs me about GMail's.

From these screenshots, Google calls the note an email, integrates it with their email client, and removes some normal email controls for forwarding, etc. That violates people's expectations of email, in terms of recipients' control of their data and vendor neutrality. Those are things I don't want changed about email!

One approach is to decouple ephemeral messages from email or GMail like privnote, which avoids confusion or lock-in. You still should make precise promises, though; I think "disappearing message" is a bad way to say "we delete our copy." Seems 100% feasible but then it's just Google Privnote.

Another option is to keep it integrated but tweak it to try not to mess up email, by making the feature "expiration request" or something, and maybe many clients comply by default but don't force it, except possibly when account owner != user (work networks). That helps cooperating parties without being either vendor-specific or DRM-y. I can even imagine vendors working together on that, especially with handling of user data in focus right now. Senders can try to figure out if your recipient contacts/domains claim support for the feature so you don't try to use it when it's clearly meaningless.

A fear is that Google considers it a feature to mess with the email ecosystem by adding vendor-specific stuff, or that Google'll talk about security a lot and just happen to propose lots more solutions involving more Google lock-in. I'd like to see what comes out of Google I/O to get more of a sense.

Re: Google is testing expiring emails in the new Gmail

#157

What I'm struck by is how many people don't see value in this. If you work with sensitive data, this is valuable. A business may already trust google, but they want to send emails (even internally) that expire. I'd like it if it just expired the attachments - that's normally where sensitive data lives. I don't even need to prevent printing etc. I'd also love a setting, email over 1 year old, you have to jump through…

There is no value in it because it is a false promise. If you give someone access to data, you have lost control over it, especially if it is by email - because not everyone uses Gmail. Many of those who do do not use the web client, and email clients are ultimately controlled by end users, even web based ones. Only if you have complete end-to-end control over all the devices that everyone uses, including their brain…

There's no way to stop someone from copying the message if they really want to. That doesn't mean a system that prevents the recipient from accidentally leaking the message has no use.

There are plenty of scenarios where the sender may be confident that the recipient will not intentionally betray their trust but may not want to leave long-term traces behind (say, forwarding confidential documents to a family member). Rather than reminding them not to forward the email and to delete it ASAP, you could just use this feature instead.

Just because something doesn't can't cover all scenarios doesn't mean it's useless. Firefox's Private Browsing can't hide your activity from a determined eavesdropper, for example, but there are still plenty of ways in which it's useful.

Re: Google is testing expiring emails in the new Gmail

#158

Seems annoying. No one would rely on this to keep actual sensitive info private, since you can just screen shot it. On the other hand, part of the point of Gmail is that it makes your emails easily searchable, so you can quickly dig up info from old mail rather than have to make a note of said info in some sepearate program/notebook/whatever. But if emails are going to randomly be disappearing, it could really crippl…

Why do people keep bringing up screenshots as some kind of evidence of something that was said? I can easily go into an email, bring up the source code, edit the email body to have some racist tirade, then screenshot the edited email and use that as “evidence” against a person.

email often has DKIM headers, which are fantastic for non-repudiation

Re: Google is testing expiring emails in the new Gmail

#159
post #29
post #16

Earlier quoted context omitted.

> it's so beautiful because it's so standard I think it's really the opposite, every provider tends to introduce new/unique/nonstandards but they (mostly) interact at a minimum with eachother. Re: gmail DOT and + notation, those have been in common use on that platform for over a decade. >I like innovation, but to innovate email wouldn't be better to innovate in a slow and consensual way using RFC after RFC, at least…

Paypal still sends me someone else's email because they signed up with myemail@gmail.com whereas I signed up with my.email@gmail.com. Apparently there's some way to make an account there where the email is considered secondary and they just never verify it.

That's a problem with PayPal, not Gmail. You can't register "myemail" if someone else has already registered "my.email", so PayPal must not have verified the address (unless you accidentally clicked the verification link yourself).

There was an article posted recently that complained about how Netflix lets people create multiple accounts using dot variations of the same Gmail address, and plenty of people pointed out how it made no sense to blame Gmail for Netflix failing to verify email addresses: https://news.ycombinator.com/item?id=16781959

Re: Google is testing expiring emails in the new Gmail

#160

Earlier quoted context omitted.

I do that all the time without any problems. What issues have you seen with it?

marked as SPAM. I get that a lot

Interesting. I can't say that I ever get that, and I email Gmail a ton. I'm curious if Google outlines how to prevent getting considered SPAM or not. It could be that I've had my domain for >5 years as well.
Post reply on HN