Live data from Hacker News

Google is testing expiring emails in the new Gmail

techcrunch.com

181–190 of 250 posts

Re: Google is testing expiring emails in the new Gmail

#181

Seems annoying. No one would rely on this to keep actual sensitive info private, since you can just screen shot it. On the other hand, part of the point of Gmail is that it makes your emails easily searchable, so you can quickly dig up info from old mail rather than have to make a note of said info in some sepearate program/notebook/whatever. But if emails are going to randomly be disappearing, it could really crippl…

>since you can just screen shot it. The benefit with automated rention policies embeded in content is that it's less easy for the information to be weaponized ex post. I.e. Now that a couple has broken up, a vindictive partner doesn't have a full log of their communications that they can use to blackmail their partner. Basically it tips the balance back towards conversation and less dystopian log by making people who…

How does this stop google from indexing the emails?

I think we have different distopias in mind. :-)

Re: Google is testing expiring emails in the new Gmail

#182

"On the recipient’s side, the person was using the existing version of Gmail and received a link to view the confidential email. The recipient had to log into their Google account once again to view the content." IMO this is an open invitation to phishers.

Possibly.

The current ad-hoc approach of "type this URL in" that's used in various places could be extended in this case to "click this link, or alternatively go to this short address and type this short code in".

This would actually work because the short URLs would be per-recipient-account - they wouldn't need to be "globally" unique!

Alas, we live in a denialist dystopia, not a self-acknowledging one, so the above will probably never happen - per-recipient short URLs rely firmly on a global social graph that can predict with a high degree of accuracy who is highly unlikely to click on who else's link.

Google has one of these, but nobody's supposed to realize how much of an oracle it is.

So, we've just upgraded to "for security, please click this 10000-character-long URL" emails being sent from Google itself.

The phishers are laughing.

Re: Google is testing expiring emails in the new Gmail

#183
post #23

Seems annoying. No one would rely on this to keep actual sensitive info private, since you can just screen shot it. On the other hand, part of the point of Gmail is that it makes your emails easily searchable, so you can quickly dig up info from old mail rather than have to make a note of said info in some sepearate program/notebook/whatever. But if emails are going to randomly be disappearing, it could really crippl…

Many companies keep copies of emails received. If the email has sensitive info, it's going to be kept around even if you "delete" it from your inbox. That's what this works around. Now the archived copy will be worthless because it only contains a link to the real content.

I seriously doubt this is true if either party is using an enterprise gmail account (you know, the ones that render the bcc list on the recipient side without prompting the sender?)

Re: Google is testing expiring emails in the new Gmail

#184
post #64

Earlier quoted context omitted.

Would be interesting if they built something like SMS/iMessage, where within the ecosystem emails were encrypted but when sent outside they weren't. Of course, hopefully PGP, and not some custom, private API like iMessage.

If you're looking for an "open ecosystem" option, Mail on both iOS and Mac (as well as a bunch of clients elsewhere, including Outlook and Thunderbird) supports S/MIME encryption and signing out of the box. Of course, no one uses it or even realizes it's there because S/MIME is terrible.

Actually, with let’s encrypt and friends, maybe it is finally time for s/mime (with cert pinning, web of trust for the paranoid)

Re: Google is testing expiring emails in the new Gmail

#185

Earlier quoted context omitted.

Email is doomed either way. The standard is indefinitely stuck in "IE6" mode, where there's few if any improvements, updates, or fixes. Everyone time anyone suggests significant improvements one of the big players (Google, Microsoft, Yahoo!, etc) says no and it stalls. If email gets a "HTML5"-like major refresh at some point then I'd be proven wrong but that hasn't happened yet in my lifetime. Microsoft in particular…

Not having improvements is a feature. Yes, please leave email the way it is, because it works fine. It’s one of the few things that does. The only feature I want is end to end encryption. Google will never make encryption easy on their own because they’ve got perverse incentives not to.

Email does work fine. We have a similar solution for encryption: PGP. If you do the encryption yourself instead of relying on your email client to handle it, it works fine. Type your text, encrypt it, then put it in an email; get a response, decrypt it, and read it — it's easy, and it works. People who say PGP is too hard to use are usually relying on a plugin for their email client, or some other unreliable, "encryption magic" tool that tries to hide how PGP works behind an incompatible abstraction.

Simple tools that do one thing well are almost always best.

Re: Google is testing expiring emails in the new Gmail

#186

Honest headline: Google is allowing you to hide emails from its public interface after a specific amount of time.

Did you read the article? That's not what they're doing. They're replacing the contents with a link that eventually stops working. Nothing is being changed in the recipient's e-mail interface.

Did you read the OP's post? They're replacing the contents with a link that eventually stops working for you. Nothing is being changed in Google's backend, so the original message can be preserved for as long as they desire.

Re: Google is testing expiring emails in the new Gmail

#187

Earlier quoted context omitted.

You should checkout https://privnote.com/# Basically if I send you a message using it, I have deniability. Screen shot all you want, I can simply say I never sent it. If we do go to court over something sent -- you will end up showing a screen shot or a copy and pasted text file. Those will be tough to support in court. Have fun going after an Uruguay tech company for deleted data. This is different with standard ema…

"If we do go to court over something sent -- you will end up showing a screen shot or a copy and pasted text file. Those will be tough to support in court." I'm not so sure about that. If you leave enough incriminating evidence in the note itself, it wouldn't take too much to convince the jury or judge. For example, if you write something that only you had knowledge of in the note, then it can be used as evidence to…

Los pollos.

Re: Google is testing expiring emails in the new Gmail

#188
post #148

Earlier quoted context omitted.

Not only that but Google scans your mail to serve ads, would it now say it doesn't scan your "burn after reading" emails? I wouldn't trust them to.

They stopped doing that in 2017. https://blog.google/products/gmail/g-suite-gains-traction-in...

They no longer do this for ads. They still scan your gmail for reasons that are probably more profitable to them (e.g. any of the comments in this thread about inbox’s AI stuff).

Re: Google is testing expiring emails in the new Gmail

#189

What a bunch of hype garbage this is. If you send something in plaintext to a server it's already game over. If Google was serious about privacy it would pgp-encrypt everything so only the client, client-side can decrypt it, just like what protonmail does. pfff, 'self destructing emails', what a heaping pile of razzle dazzle no-ops that is -- this is more likely subliminal advertisement for the new mission impossible…

Or double encryption with one key held by Google on an HSM enforced time-out so the email does self destruct.

[deleted]
Post reply on HN