Earlier quoted context omitted.
>Note: Although confidential mode helps prevent the recipients from accidentally sharing your email, it doesn't prevent recipients from taking screenshots or photos of your messages or attachments. Recipients who have malicious programs on their computer may still be able to copy or download your messages or attachments. If you click the "learn more" in gmail it says that ^. Gmail seems pretty upfront about what "con…
> Recipients who have malicious programs on their computer may still be able to copy or download your messages or attachments. I guess me exercising my right to do whatever I want with my bits on my computer is me having "malicious programs". What in the actual fsck.
Gmail confidential mode is not secure or private
101–110 of 226 posts
Re: Gmail confidential mode is not secure or private
#102Earlier quoted context omitted.
> If "accidental" is the true worry, display a confirmation/warning box before forwarding. Gmail supports other MUAs using IMAP and POP, so that doesn't work. The fact that there are valid reasons to forward sensitive emails is why there is an escape hatch. It's only the accidental forwards and copies that this is meant to stop.
We can invent a new e-mail header X-Confidential: true, and clients will start to adopt the warning behavior over time. If Gmail supports it off the bat it will already cover a huge fraction of the market.
When designing APIs I find that bools are often a smell or a missed opportunity. What if, for example, there was an X-Intended-Audience?
That could be integrated with Active Directory, Groups, IAM etc within an organization to make the warning only pop up when a potential violation is occurring which helps avoid seeing the warning so often that it gets ignored (or accidentally send to the wrong confidential party as in medicine or law). It could also inform IT after the fact.
Re: Gmail confidential mode is not secure or private
#103Earlier quoted context omitted.
It's worth mentioning that all these measures can be fairly trivially defeated by the analog loophole[1]. I suppose it's harder to prove authenticity in that case, however. https://en.wikipedia.org/wiki/Analog_loophole
Allow me to sell your organisation some VR goggles with iris-reading DRM protection. Your browser won't display on any other screen. And Google Services won't work in any other browser.
Re: Gmail confidential mode is not secure or private
#104"Options for recipients to forward, copy, print, or download this email's contents will be disabled." I simply don't understand how they think they can get away with this foolishness. I can forward, copy, print, or download ANYTHING that passes over my ethernet cables. Your silly UI will ultimately never stop me from wiresharking my own cables in my own home and doing whatever the hell I want with any bits of informa…
>Note: Although confidential mode helps prevent the recipients from accidentally sharing your email, it doesn't prevent recipients from taking screenshots or photos of your messages or attachments. Recipients who have malicious programs on their computer may still be able to copy or download your messages or attachments. If you click the "learn more" in gmail it says that ^. Gmail seems pretty upfront about what "con…
Also, I can think of a lot of ways to bypass the “confidentiality” settings that require no malware whatsoever. Not only is their giant asterisk hidden, it’s wildly inaccurate and misleading.
Re: Gmail confidential mode is not secure or private
#105Earlier quoted context omitted.
Consider for a moment: a company or school set up as an Enterprise Mobile Device Management provider, handing everyone out ChromeOS devices, setting up their GSuite domain so that nobody can connect to their GSuite GMail accounts except through the ChromeOS device (or an equivalent MDMed mobile device), and setting up an automatic, un-disable-able VPN on those devices for accessing Google domains. I think that’s the…
Even in a locked down ChromeOS device, won't hitting Ctrl-S in the browser still work?
The only way for this to work is to restrict the user freedom so much it will:
- cost a huge amount of money
- lower the productivity
- kill the mood of everybody
My take on this is that if your industry really needs this kind of feature, either you suck as a human being and I don't want to work for you, or you are doing something amazing and secretive and in this case you don't use gmail.
Re: Gmail confidential mode is not secure or private
#106Requires SMS verification or an impassable captcha loop if over TOR
And payment with a credit card
The cryptocurrency payment option with non-user identifiable info only being available to existing protonmail accounts where that info was already harvested
So it is ironic to see protonmail calling out those specific things about gmail confidential
Re: Gmail confidential mode is not secure or private
#107Earlier quoted context omitted.
So you reference Snowden then pretend dragnet surveillance doesn't exist? If you are on the internet the NSA is spying on you and everyone else. This is not an improvement because it makes guarantees that simply aren't true. These compromises are made to further Google's bottom line, not protect users. Don't pretend this is some kind of incremental improvement. It's a marketing gimmick.
> If you are on the internet the NSA is spying on you and everyone else. There's a difference between passively collecting and actively targeting.
They couldn't do this if they weren't drag-netting.
*FISA courts have 11 denied requests and over 34,000 approved.
Re: Gmail confidential mode is not secure or private
#108> It can still be accessed by Google and potentially exposed to governments or hackers. The article makes the classic mistake of assuming everyone has the full security apparatus of a country after them. This feature is obviously not built as an alternative to Signal or for the Snowdens of this world. These probably know better than using unencrypted email already. For the average user it's an improvement of the curr…
So you reference Snowden then pretend dragnet surveillance doesn't exist? If you are on the internet the NSA is spying on you and everyone else. This is not an improvement because it makes guarantees that simply aren't true. These compromises are made to further Google's bottom line, not protect users. Don't pretend this is some kind of incremental improvement. It's a marketing gimmick.
Re: Gmail confidential mode is not secure or private
#109Re: Gmail confidential mode is not secure or private
#110Earlier quoted context omitted.
So you reference Snowden then pretend dragnet surveillance doesn't exist? If you are on the internet the NSA is spying on you and everyone else. This is not an improvement because it makes guarantees that simply aren't true. These compromises are made to further Google's bottom line, not protect users. Don't pretend this is some kind of incremental improvement. It's a marketing gimmick.
> If you are on the internet the NSA is spying on you and everyone else. Citation needed. > This is not an improvement because it makes guarantees that simply aren't true. No, ProtonMail pretended it made guarantees that it doesn't make. Just like the exact same Exchange/Outlook feature that people have used for years, this is to prevent accidental copying of emails and their contents.