Live data from Hacker News

Gmail confidential mode is not secure or private

protonmail.com

11–20 of 226 posts

Re: Gmail confidential mode is not secure or private

#11
post #8

I like posts being out there like this. I expect many non-technical users will get the wrong impression about confidential mode. Impression is different from the stated words and can be filled in by our subconscious thoughts about the space between what is said. When words are explicitly said it can cause people to think things through.

heh... my subconscious was sure there was a "from this article" at the end of your second sentence and had to reread it a couple of times to figure out what you were saying...

Re: Gmail confidential mode is not secure or private

#13

I'm always curious how the Project Managers working on these projects think about posts like these. It's a very public call-out, effectively saying "this product is not what they say it is and is dangerous." Especially when it's obviously true, I'd be curious if anyone here can speak to the mental state of someone on the receiving end. For example I was publicly put on blast for something that was false about me. So…

They probably eye-roll the deliberate misinterpretation of the feature by a competitor. Particular ironic given that that company's marketing schtick is that the first listed security feature is "We are incorporated in Switzerland"

Outlook has had the same feature for 20 years.

Re: Gmail confidential mode is not secure or private

#14
post #9
post #4

Gmail has no incentive to create anything secure or private because that would prevent them from going through your email to show ads. [This is wrong] Update! Gmail changed this behavior a while ago. Went under my radar: https://variety.com/2017/digital/news/google-gmail-ads-email... Thanks!

“We will not scan or read your Gmail messages to show you ads.” https://support.google.com/mail/answer/6603?hl=en

You're absolutely right. Turns out they changed this behavior in 2017. Thanks for making me look into it.

Re: Gmail confidential mode is not secure or private

#15
post #3

"Options for recipients to forward, copy, print, or download this email's contents will be disabled." I simply don't understand how they think they can get away with this foolishness. I can forward, copy, print, or download ANYTHING that passes over my ethernet cables. Your silly UI will ultimately never stop me from wiresharking my own cables in my own home and doing whatever the hell I want with any bits of informa…

Why is it hard to understand? Because your average user will not "wireshark their own cables", and those who do will use different methods of secure communication. You'd be surprised how many users are unable to bypass various extremely simple restrictions - and this is the target market for these features.

On top of that self deleting email will make it also a bit harder to prove that the screenshot is real - unless you get a court order to get the senders outbox folder from google and the data still exists there.

Re: Gmail confidential mode is not secure or private

#16

This is a feature that Outlook already has and corporate users expect. It's for making forwarding sensitive emails or any of their content require intent instead of being accidental.

If "accidental" is the true worry, display a confirmation/warning box before forwarding.

There are valid reasons to need to forward even e-mails marked confidential, including lawsuits, harassment cases, or even just asking your own lawyer before signing an agreement, among others.

Deciding when a piece of information should not have been forwarded is the job of the workplace or law, not the e-mail client.

Re: Gmail confidential mode is not secure or private

#17
All of this is clearly explained in the setting to enable the mode for a domain. It's for making forwarding sensitive emails or any of their content require intent instead of being accidental, and people who are used to Exchange/Outlook already understand this feature. Domain administrators still need to keep copies for legal compliance.

Re: Gmail confidential mode is not secure or private

#18
> This is not an expiring email. It can still be accessed by Google and potentially exposed to governments or hackers.

This "expiration" could protect the receiver from subpoena/discovery ("Sorry I don't have it anymore") but it sounds like the sender is still liable to produce the original message on demand.

Re: Gmail confidential mode is not secure or private

#19
post #3

"Options for recipients to forward, copy, print, or download this email's contents will be disabled." I simply don't understand how they think they can get away with this foolishness. I can forward, copy, print, or download ANYTHING that passes over my ethernet cables. Your silly UI will ultimately never stop me from wiresharking my own cables in my own home and doing whatever the hell I want with any bits of informa…

Consider for a moment: a company or school set up as an Enterprise Mobile Device Management provider, handing everyone out ChromeOS devices, setting up their GSuite domain so that nobody can connect to their GSuite GMail accounts except through the ChromeOS device (or an equivalent MDMed mobile device), and setting up an automatic, un-disable-able VPN on those devices for accessing Google domains.

I think that’s the scenario Google had in mind when designing this feature. For enterprise users, where the enterprise controls the hardware, the policy-level controls actually have teeth, because people don’t have root over the devices in their possession. For everyone else, it’s not “real security”, but rather just a gateway drug to get you used to the workflow that “real security” would provide in an enterprise context.

(Context: I used to work at IBM, and they had a very similar setup—company issued laptop, app that enforces MDM profile installation, VPN that checks with the app to ensure MDM is active before connecting, email servers only accessibly through said VPN, and, on top of all that, a policy-enforcing email app [IBM Notes] where you can delete already-sent things out of other enterprise-users’ inboxes, send expiring emails, etc.)

Re: Gmail confidential mode is not secure or private

#20
post #16

This is a feature that Outlook already has and corporate users expect. It's for making forwarding sensitive emails or any of their content require intent instead of being accidental.

If "accidental" is the true worry, display a confirmation/warning box before forwarding. There are valid reasons to need to forward even e-mails marked confidential, including lawsuits, harassment cases, or even just asking your own lawyer before signing an agreement, among others. Deciding when a piece of information should not have been forwarded is the job of the workplace or law, not the e-mail client.

> If "accidental" is the true worry, display a confirmation/warning box before forwarding.

Gmail supports other MUAs using IMAP and POP, so that doesn't work.

The fact that there are valid reasons to forward sensitive emails is why there is an escape hatch. It's only the accidental forwards and copies that this is meant to stop.

Post reply on HN