Live data from Hacker News

Gmail confidential mode is not secure or private

protonmail.com

121–130 of 226 posts

Re: Gmail confidential mode is not secure or private

#122
post #119

Google and privacy in the same sentence, no one would bet their house on it if they were to choose

Google is very good at protecting data from unauthorized access. Many of the people who work there see themselves, with justification, as the guardians of privacy in that narrow sense.

Re: Gmail confidential mode is not secure or private

#123
post #44
post #26

Yes, Google isn't untrustworthy and doesn't care about the users privacy, we knew that, but the general public that isn't as aware (at this point it's hard to be completely unaware) also doesn't read this private company blog, so it doesn't really help much (except advertise the company). We should be thinking of ways to improve the situation for everyone (not saying I have the solution), but personally (and unfortun…

I would trust Google and Gmail way more than protonmail and whatever company behind it for protecting my private data to be honest.

You'd trust a company thats primary business model is based on the mass collection, analysis, and monetization of user data to protect your private data? Not saying I trust proton mail, but as far as I'm concerned Google is a malicious actor when it comes to my data same as Facebook, and I believe it's in individuals's best interest to limit their exposure

Re: Gmail confidential mode is not secure or private

#124
Wow, marketing spam from a competitor.

We send confidential docs regularly to users, who need access to those docs for perhaps 1 week at most. No one wants / needs to keep these around, but no one goes through their email carefully to delete these items.

If that users email was hacked -> they have a big problem. If we can mark the items for a 3 week retention and then expire those items for them, that great - and this lets us do that.

The whole I can wireshark my network -> 99.9% of the confidential info we send goes to other folks who ALSO want to keep it confidential. Getting rid of stuff you no longer need to maintain is a key way of helping avoid big document dumps.

The proof is in the pudding. Either this will help google sell to business (it will in our case in a big way). Or folks will say it is a stupid feature and decide idiots like Protonmail who can't seem to understand the point of these features now deserve our business. My confidence in a place like protonmail goes down based on this, and I'd love to get a feel for their security history and overpromises (ie, webmail client has got to easily be able to log and hack encryption etc).

Re: Gmail confidential mode is not secure or private

#125

Earlier quoted context omitted.

Allow me to sell your organisation some VR goggles with iris-reading DRM protection. Your browser won't display on any other screen. And Google Services won't work in any other browser.

I can still remember the message (or at least important bits) and can write it down when at home or tell it to other people.

Yeah but it is still a helluva lot harder to leak it, and it isn't as good as showing an email exchange.

Re: Gmail confidential mode is not secure or private

#126

Earlier quoted context omitted.

Even in a locked down ChromeOS device, won't hitting Ctrl-S in the browser still work?

Or screen capture, or inspect element, or taking a picture with your phone, or JS injection, or using an extension, or IMAP... The only way for this to work is to restrict the user freedom so much it will: - cost a huge amount of money - lower the productivity - kill the mood of everybody My take on this is that if your industry really needs this kind of feature, either you suck as a human being and I don't want to w…

Well, I tried it out. At least the IMAP is partially mitigated since you basically get a link to a separate web page -- the contents aren't embedded in the email itself.

On the other hand, that means there's no reason to resort to something as complicated as JS injection or dev tools. Screenshots will usually work fine, because messages aren't threaded, so you'll likely get the entire message showing up on one page. They do block Ctrl-S, they use a click handler that prevents it from reaching the browser. Very fiendish, very clever. Except that the save button still works in the menu.

On the plus side, I'm now wondering if that, "go to the top of your menu and hit the file->save button" exploit would make me eligible for a bug bounty, since according to their documentation I should need malicious software to download the message. I guess Chrome falls into that category though?

Re: Gmail confidential mode is not secure or private

#127
post #117

Earlier quoted context omitted.

I can still remember the message (or at least important bits) and can write it down when at home or tell it to other people.

for now

Well, presumably most communication is two way or actionable. If not, then there is no reason for the communication in the first place.

Re: Gmail confidential mode is not secure or private

#128

Earlier quoted context omitted.

> If you are on the internet the NSA is spying on you and everyone else. Citation needed. > This is not an improvement because it makes guarantees that simply aren't true. No, ProtonMail pretended it made guarantees that it doesn't make. Just like the exact same Exchange/Outlook feature that people have used for years, this is to prevent accidental copying of emails and their contents.

Is a citation really needed about the NSA collecting basically all the data on the Internet? This is "common knowledge" in information security circles. Go look up the battles the EFF has fought with the NSA about their data collection practices. The NSA is continually building giant data warehouses everywhere... they probably have more data centers than any other organization in existence. They collect all the data.

It's pretty common for people to throw out "citation needed" when they don't want to believe or admit something, but can't plausibly deny it. Sort of the same way people use the term "fallacy" these days.

Re: Gmail confidential mode is not secure or private

#129

I'm always curious how the Project Managers working on these projects think about posts like these. It's a very public call-out, effectively saying "this product is not what they say it is and is dangerous." Especially when it's obviously true, I'd be curious if anyone here can speak to the mental state of someone on the receiving end. For example I was publicly put on blast for something that was false about me. So…

They don't handle it well. I worked on a service that had some severe technical constraints at a prior job. (Basically, we were hosting a vendor's network device to the cloud, and it really wasn't designed for it, and it also wasn't a really great device.) We had one customer that loved to blog about us. The customer wasn't being all that unreasonable (from their perspective) and the higher-ups knew about the constraints we were operating under, but they still panicked every time a blog came out about us.

More broadly, I think if you talk to any journo in the trade press, some companies can be incredibly thin-skinned about any percieved negative press, and threats and intimidation are very common for percieved slights. And the trade press typically rolls over because those companies are their advertisers. It's why you typically see so many puff pieces, how-tos and PR reprints rather than actual journalism.

Re: Gmail confidential mode is not secure or private

#130
post #3

"Options for recipients to forward, copy, print, or download this email's contents will be disabled." I simply don't understand how they think they can get away with this foolishness. I can forward, copy, print, or download ANYTHING that passes over my ethernet cables. Your silly UI will ultimately never stop me from wiresharking my own cables in my own home and doing whatever the hell I want with any bits of informa…

I'm surprised no one has come up with a browser extension yet that circumvents this. I'm guessing it would be fairly trivial to do so.

There is honestly no actual demand for something like that, I'd guess. Screenshots are easy, and your OS usually comes with a built-in tool. And how to use that tool (or find a tool) is a matter of typing "how do I screenshot on X" into google.

And if even this is still too "technical" for a user, I have seen people take literal shots of their screens, with their phone camera or whatever.

Post reply on HN