Live data from Hacker News

Gmail confidential mode is not secure or private

protonmail.com

81–90 of 226 posts

Re: Gmail confidential mode is not secure or private

#82

Article makes good points. But clearly they are promoting their own product, over Gmail, and compete directly with them. One thing I find troubling is that they seem to be making their own false claim. >Because we do not have access to the recipient’s private key, we are never able to read the message. We do have access to metadata, like the email addresses, timestamp, and subject line. I am not sure how proton could…

I don't see where they claim they don't know the recipient's address.

I'm an idiot. I miss read the sentence.

Re: Gmail confidential mode is not secure or private

#83
post #19
post #3

"Options for recipients to forward, copy, print, or download this email's contents will be disabled." I simply don't understand how they think they can get away with this foolishness. I can forward, copy, print, or download ANYTHING that passes over my ethernet cables. Your silly UI will ultimately never stop me from wiresharking my own cables in my own home and doing whatever the hell I want with any bits of informa…

Consider for a moment: a company or school set up as an Enterprise Mobile Device Management provider, handing everyone out ChromeOS devices, setting up their GSuite domain so that nobody can connect to their GSuite GMail accounts except through the ChromeOS device (or an equivalent MDMed mobile device), and setting up an automatic, un-disable-able VPN on those devices for accessing Google domains. I think that’s the…

Even in a locked down ChromeOS device, won't hitting Ctrl-S in the browser still work?

Re: Gmail confidential mode is not secure or private

#84

Earlier quoted context omitted.

Nobody said the emails aren't scanned; they're just not used as context for ads. Obviously they're scanned, otherwise spam filtering wouldn't be possible.

I think there’s a difference between scanning all incoming mail for spam and keeping a details list of my purchase history by scanning my inbox for receipts somehow... If they aren’t using this data for context ads it must be being used for something else otherwise why would they do it?

The critical words in the statement are not "We will not scan or read your Gmail messages"; they are "to show you ads."

In other words, they reserve the right to scan or read your Gmail for any purpose other than showing you ads. So they can still read your email for things like creating that purchases list, as well as a myriad of other tasks. As long as that task doesn't involve showing you an ad, your Gmail is wide open to them.

Re: Gmail confidential mode is not secure or private

#86
post #3

"Options for recipients to forward, copy, print, or download this email's contents will be disabled." I simply don't understand how they think they can get away with this foolishness. I can forward, copy, print, or download ANYTHING that passes over my ethernet cables. Your silly UI will ultimately never stop me from wiresharking my own cables in my own home and doing whatever the hell I want with any bits of informa…

No foolishness. Such features intended to enhance handling of sensitive data when users' laziness, or lack of understanding is the problem - and it works well in this way. Malicious recipient can do anything, of course, but usually you don't send your secrets to people you don't trust at all.

Re: Gmail confidential mode is not secure or private

#87
post #19
post #3

"Options for recipients to forward, copy, print, or download this email's contents will be disabled." I simply don't understand how they think they can get away with this foolishness. I can forward, copy, print, or download ANYTHING that passes over my ethernet cables. Your silly UI will ultimately never stop me from wiresharking my own cables in my own home and doing whatever the hell I want with any bits of informa…

Consider for a moment: a company or school set up as an Enterprise Mobile Device Management provider, handing everyone out ChromeOS devices, setting up their GSuite domain so that nobody can connect to their GSuite GMail accounts except through the ChromeOS device (or an equivalent MDMed mobile device), and setting up an automatic, un-disable-able VPN on those devices for accessing Google domains. I think that’s the…

And, in addition to all of those requirements, a ban on cameras to protect screen photos.

Re: Gmail confidential mode is not secure or private

#88

Article makes good points. But clearly they are promoting their own product, over Gmail, and compete directly with them. One thing I find troubling is that they seem to be making their own false claim. >Because we do not have access to the recipient’s private key, we are never able to read the message. We do have access to metadata, like the email addresses, timestamp, and subject line. I am not sure how proton could…

It literally says that they have access to the email address in what you quoted.

Re: Gmail confidential mode is not secure or private

#89
post #19

Earlier quoted context omitted.

Consider for a moment: a company or school set up as an Enterprise Mobile Device Management provider, handing everyone out ChromeOS devices, setting up their GSuite domain so that nobody can connect to their GSuite GMail accounts except through the ChromeOS device (or an equivalent MDMed mobile device), and setting up an automatic, un-disable-able VPN on those devices for accessing Google domains. I think that’s the…

It's worth mentioning that all these measures can be fairly trivially defeated by the analog loophole[1]. I suppose it's harder to prove authenticity in that case, however. https://en.wikipedia.org/wiki/Analog_loophole

The analog loophole can’t prevent leakage but steganography can trace it back to its source. Iirc Windows 8 prerelease copies used to put an imperceptible watermark on the screen of the user account. When a leak was published to the news a simple filter would tell Microsoft who to fire.

Re: Gmail confidential mode is not secure or private

#90
post #16

This is a feature that Outlook already has and corporate users expect. It's for making forwarding sensitive emails or any of their content require intent instead of being accidental.

If "accidental" is the true worry, display a confirmation/warning box before forwarding. There are valid reasons to need to forward even e-mails marked confidential, including lawsuits, harassment cases, or even just asking your own lawyer before signing an agreement, among others. Deciding when a piece of information should not have been forwarded is the job of the workplace or law, not the e-mail client.

> Deciding when a piece of information should not have been forwarded is the job of the workplace or law, not the e-mail client.

You seem to misunderstand who controls the workplace. Within limits, the employer has significant control which increases or decreases based on jurisdiction.

Yes, these measures could limit an individual, but there are generally options like just asking the sender to forward a copy of an agreement/contract so that an outside counsel can review it. Denying review of a contract is a good way to get it invalidated.

I guess harassers could use this feature of the system to try to protect themselves, but it won't stop someone taking a photo from their phone. Realistically most organizations don't want to be complicit in that - even if they tend to default to silence - and HR only exists to protect the company.

Post reply on HN