Earlier quoted context omitted.
e2e encryption solves a totally different problem. If you don't trust the intended recipient of a message don't send it. e2e helps make sure nobody else receives the message. Google is making an entirely different claim about controlling the actions of a third party. It's fundamentally impossible to do what Google is claiming.
What is Google claiming that you think is impossible?
Gmail confidential mode is not secure or private
91–100 of 226 posts
Re: Gmail confidential mode is not secure or private
#92Earlier quoted context omitted.
>All it does is fool a bunch of less-tech-savvy people into a false sense of security. Nonsense, it does a great job of discouraging people from forwarding, copying, printing or downloading the emails contents. Sure, it'll do nothing with a malicious recipient but incompetent recipients are vastly more common than malicious recipients.
You have to be a special kind of stupid to not be able to get around this "security".
Re: Gmail confidential mode is not secure or private
#93"Options for recipients to forward, copy, print, or download this email's contents will be disabled." I simply don't understand how they think they can get away with this foolishness. I can forward, copy, print, or download ANYTHING that passes over my ethernet cables. Your silly UI will ultimately never stop me from wiresharking my own cables in my own home and doing whatever the hell I want with any bits of informa…
I'm surprised no one has come up with a browser extension yet that circumvents this. I'm guessing it would be fairly trivial to do so.
Re: Gmail confidential mode is not secure or private
#94Earlier quoted context omitted.
> If "accidental" is the true worry, display a confirmation/warning box before forwarding. Gmail supports other MUAs using IMAP and POP, so that doesn't work. The fact that there are valid reasons to forward sensitive emails is why there is an escape hatch. It's only the accidental forwards and copies that this is meant to stop.
We can invent a new e-mail header X-Confidential: true, and clients will start to adopt the warning behavior over time. If Gmail supports it off the bat it will already cover a huge fraction of the market.
Re: Gmail confidential mode is not secure or private
#95I like posts being out there like this. I expect many non-technical users will get the wrong impression about confidential mode. Impression is different from the stated words and can be filled in by our subconscious thoughts about the space between what is said. When words are explicitly said it can cause people to think things through.
Re: Gmail confidential mode is not secure or private
#96Earlier quoted context omitted.
You have to be a special kind of stupid to not be able to get around this "security".
Who cares? This isn't supposed to stop anyone from intentionally doing bad things, this is supposed to make people stop and think "Huh, maybe I'm just not supposed to forward this email" It's really bizarre that so many people on HN can't seem to understand this. Do you guys ever interact with other human beings?
If they were saying, "this feature makes it clear to your employees that they shouldn't forward this email" then this entire HN thread would not exist.
Re: Gmail confidential mode is not secure or private
#97Earlier quoted context omitted.
> If "accidental" is the true worry, display a confirmation/warning box before forwarding. Gmail supports other MUAs using IMAP and POP, so that doesn't work. The fact that there are valid reasons to forward sensitive emails is why there is an escape hatch. It's only the accidental forwards and copies that this is meant to stop.
We can invent a new e-mail header X-Confidential: true, and clients will start to adopt the warning behavior over time. If Gmail supports it off the bat it will already cover a huge fraction of the market.
Re: Gmail confidential mode is not secure or private
#98> It can still be accessed by Google and potentially exposed to governments or hackers. The article makes the classic mistake of assuming everyone has the full security apparatus of a country after them. This feature is obviously not built as an alternative to Signal or for the Snowdens of this world. These probably know better than using unencrypted email already. For the average user it's an improvement of the curr…
So you reference Snowden then pretend dragnet surveillance doesn't exist? If you are on the internet the NSA is spying on you and everyone else. This is not an improvement because it makes guarantees that simply aren't true. These compromises are made to further Google's bottom line, not protect users. Don't pretend this is some kind of incremental improvement. It's a marketing gimmick.
There's a difference between passively collecting and actively targeting.
Re: Gmail confidential mode is not secure or private
#99Re: Gmail confidential mode is not secure or private
#100> It can still be accessed by Google and potentially exposed to governments or hackers. The article makes the classic mistake of assuming everyone has the full security apparatus of a country after them. This feature is obviously not built as an alternative to Signal or for the Snowdens of this world. These probably know better than using unencrypted email already. For the average user it's an improvement of the curr…
So you reference Snowden then pretend dragnet surveillance doesn't exist? If you are on the internet the NSA is spying on you and everyone else. This is not an improvement because it makes guarantees that simply aren't true. These compromises are made to further Google's bottom line, not protect users. Don't pretend this is some kind of incremental improvement. It's a marketing gimmick.
Citation needed.
> This is not an improvement because it makes guarantees that simply aren't true.
No, ProtonMail pretended it made guarantees that it doesn't make. Just like the exact same Exchange/Outlook feature that people have used for years, this is to prevent accidental copying of emails and their contents.