Live data from Hacker News

Gmail confidential mode is not secure or private

protonmail.com

141–150 of 226 posts

Re: Gmail confidential mode is not secure or private

#141
post #51
post #30

> It can still be accessed by Google and potentially exposed to governments or hackers. The article makes the classic mistake of assuming everyone has the full security apparatus of a country after them. This feature is obviously not built as an alternative to Signal or for the Snowdens of this world. These probably know better than using unencrypted email already. For the average user it's an improvement of the curr…

So you reference Snowden then pretend dragnet surveillance doesn't exist? If you are on the internet the NSA is spying on you and everyone else. This is not an improvement because it makes guarantees that simply aren't true. These compromises are made to further Google's bottom line, not protect users. Don't pretend this is some kind of incremental improvement. It's a marketing gimmick.

+1 The comment underplays the surveillance by using the benign mask to protect its sinister causes. Surveillance has been used to gain economic advantages (as was widely reported), and more importantly geopolitical leverage.

For instance, India, a nation run by English-speaking elites has conducted all the affairs of the nation on Google''s servers - such bumbling idiots, normal as they are, are the targets of such a PR campaign. "Oh, you're don't have to worry about it. You're not a terrorist.."

Re: Gmail confidential mode is not secure or private

#142

Protonmail is a fantastic service, I switched to an account with them in the last few years and have not logged into my gmail since. Can't say enough good things about their offerings. I'm glad to see them making arguments like these in public to out their competitors practices.

You mean creating blog spam that misses the point?

Re: Gmail confidential mode is not secure or private

#143
post #133
post #3

"Options for recipients to forward, copy, print, or download this email's contents will be disabled." I simply don't understand how they think they can get away with this foolishness. I can forward, copy, print, or download ANYTHING that passes over my ethernet cables. Your silly UI will ultimately never stop me from wiresharking my own cables in my own home and doing whatever the hell I want with any bits of informa…

> Your silly UI will ultimately never stop me from wiresharking my own cables in my own home and doing whatever the hell I want with any bits of information that enter my space. Their silly UI won't, but what about HTTPS? Won't wiresharking your own cables only get you the ciphertext from the HTTPS session which would be useless to you without the ephemeral key?

TLS MITM proxies are still doable with your own CA

Re: Gmail confidential mode is not secure or private

#144

Earlier quoted context omitted.

It's worth mentioning that all these measures can be fairly trivially defeated by the analog loophole[1]. I suppose it's harder to prove authenticity in that case, however. https://en.wikipedia.org/wiki/Analog_loophole

But as a worker in a corporation, the chances that you would want an email so badly that you start breaking more corporate rules trying to get a copy of an email is very unlikely at least for common everyday work. This could be a useful feature when dealing with PHI, legal, HR, etc.

I disagree, there have been politicians that go through the trouble of setting up their own email server in their basement because the official way is too arcane or not comfortable.

Re: Gmail confidential mode is not secure or private

#145
post #42

Earlier quoted context omitted.

So open the e-mail on a Kindle, or put an antiglare screen in front of your phone, or just take a picture of one phone with another phone if the screenshot button doesn't work . I do remember some app not "letting" me screenshot something with stock Android, which I felt to be a violation of my freedom. Obviously in my case just use a modified Android ROM without the silly anti-screenshotting logic, or screenshot it…

> I do remember some app not "letting" me screenshot something with stock Android, which I felt to be a violation of my freedom. Bank apps tend to do that. When I first hit this issue, it also felt like a violation of my freedom, and it was also very annoying because I badly needed to make that screenshot.

I think bank apps do this less to stop you from making screenshots, and more to stop that new Candy Clash app you just installed from making that screenshot.

Re: Gmail confidential mode is not secure or private

#146
post #115
post #3

"Options for recipients to forward, copy, print, or download this email's contents will be disabled." I simply don't understand how they think they can get away with this foolishness. I can forward, copy, print, or download ANYTHING that passes over my ethernet cables. Your silly UI will ultimately never stop me from wiresharking my own cables in my own home and doing whatever the hell I want with any bits of informa…

Dude, come on. You do understand. The feature is like a fence in a yard. It separates the honest from the dishonest, forcing the clueless/negligent/reckless to pick a side. Nobody believes fences stop criminals, and nobody believes Gmail has ended the DRM arms race.

> Nobody believes fences stop criminals

I agree with the thrust of your comment, but this isnt true. Measures like this do prevent some crime. When i didnt lock my car and someone stole the gift cards out of it, locking the doors would have prevented it. Just because the car is still stealable doesnt mean door locks are security theater. Putting an unlocked package cabinet for deliveries on your porch lowers incidences of theft without making it impossible.

Re: Gmail confidential mode is not secure or private

#147

Wow, marketing spam from a competitor. We send confidential docs regularly to users, who need access to those docs for perhaps 1 week at most. No one wants / needs to keep these around, but no one goes through their email carefully to delete these items. If that users email was hacked -> they have a big problem. If we can mark the items for a 3 week retention and then expire those items for them, that great - and thi…

These sort of features are really just security theater. If someone really wants to share your "confidential" docs they'll screenshot every page to do it.

Re: Gmail confidential mode is not secure or private

#148

Earlier quoted context omitted.

> Recipients who have malicious programs on their computer may still be able to copy or download your messages or attachments. I guess me exercising my right to do whatever I want with my bits on my computer is me having "malicious programs". What in the actual fsck.

It's not saying exercising your rights is having malicious programs, they are not mutually exclusive and they didn't make that claim.

Recipients who have malicious programs on their computer may still be able to copy or download your messages or attachments.

Recipients who do not have malicious programs on their computer also may still be able to copy or download your messages or attachments.

Re: Gmail confidential mode is not secure or private

#149

Wow, marketing spam from a competitor. We send confidential docs regularly to users, who need access to those docs for perhaps 1 week at most. No one wants / needs to keep these around, but no one goes through their email carefully to delete these items. If that users email was hacked -> they have a big problem. If we can mark the items for a 3 week retention and then expire those items for them, that great - and thi…

These sort of features are really just security theater. If someone really wants to share your "confidential" docs they'll screenshot every page to do it.

They always say that security is built layer by layer. Ensuring that the attached docs expire helps limit an impact of a hack or an account takeover.

Re: Gmail confidential mode is not secure or private

#150

Earlier quoted context omitted.

It's worth mentioning that all these measures can be fairly trivially defeated by the analog loophole[1]. I suppose it's harder to prove authenticity in that case, however. https://en.wikipedia.org/wiki/Analog_loophole

Allow me to sell your organisation some VR goggles with iris-reading DRM protection. Your browser won't display on any other screen. And Google Services won't work in any other browser.

Don't bother. Someone will figure out how to either fit a small camera into the VR goggles, or separate the iris-reader from the display part.
Post reply on HN