Live data from Hacker News

Gmail confidential mode is not secure or private

protonmail.com

161–170 of 226 posts

Re: Gmail confidential mode is not secure or private

#161

Earlier quoted context omitted.

But as a worker in a corporation, the chances that you would want an email so badly that you start breaking more corporate rules trying to get a copy of an email is very unlikely at least for common everyday work. This could be a useful feature when dealing with PHI, legal, HR, etc.

I disagree, there have been politicians that go through the trouble of setting up their own email server in their basement because the official way is too arcane or not comfortable.

They said corporation, not government. Do you have an example of a low level employee or C level executive using private email server for their official communication.

Disc: Googler

Re: Gmail confidential mode is not secure or private

#162

All of this applies to making a new protonmail account too Requires SMS verification or an impassable captcha loop if over TOR And payment with a credit card The cryptocurrency payment option with non-user identifiable info only being available to existing protonmail accounts where that info was already harvested So it is ironic to see protonmail calling out those specific things about gmail confidential

solving a ReCAPTCHA ( a google product that fingerprints users) is required to create an account even when not using TOR.

Re: Gmail confidential mode is not secure or private

#163

Wow, marketing spam from a competitor. We send confidential docs regularly to users, who need access to those docs for perhaps 1 week at most. No one wants / needs to keep these around, but no one goes through their email carefully to delete these items. If that users email was hacked -> they have a big problem. If we can mark the items for a 3 week retention and then expire those items for them, that great - and thi…

wow. you couldn’t be more wrong! protonmail knows very well that their point is false. it’s just free marketing for them. they are just hijacking the popularity of google to gain some benefit for their tiny company.

they aren’t idiots, they’re just failing and desperate.

Re: Gmail confidential mode is not secure or private

#164
post #162

All of this applies to making a new protonmail account too Requires SMS verification or an impassable captcha loop if over TOR And payment with a credit card The cryptocurrency payment option with non-user identifiable info only being available to existing protonmail accounts where that info was already harvested So it is ironic to see protonmail calling out those specific things about gmail confidential

solving a ReCAPTCHA ( a google product that fingerprints users) is required to create an account even when not using TOR.

right, it is just impossible to get past over most TOR exit nodes.

Re: Gmail confidential mode is not secure or private

#165
post #30

> It can still be accessed by Google and potentially exposed to governments or hackers. The article makes the classic mistake of assuming everyone has the full security apparatus of a country after them. This feature is obviously not built as an alternative to Signal or for the Snowdens of this world. These probably know better than using unencrypted email already. For the average user it's an improvement of the curr…

Part of the Snowden revelations was that the German intelligence agency was using one of the US-developed tools in return for feeding back keyword-based searches of that very same German traffic they were processing.

Keywords like djihad, Siemens, Krupp, Deutsche Bank, Airbus, Santander, Dassault, ...

The BND was in essence helping the NSA do industrial espionage on both their own and fellow EU companies, as they were too idiotic to actually check the keyword lists or for whatever reason felt they couldn't refuse.

So if the NSA is actively and purposefully doing industrial espionage there is little doubt that Gmail traffic is vulnerable to US spying and should simply not be used in sensitive settings.

Re: Gmail confidential mode is not secure or private

#166
post #51

Earlier quoted context omitted.

So you reference Snowden then pretend dragnet surveillance doesn't exist? If you are on the internet the NSA is spying on you and everyone else. This is not an improvement because it makes guarantees that simply aren't true. These compromises are made to further Google's bottom line, not protect users. Don't pretend this is some kind of incremental improvement. It's a marketing gimmick.

> If you are on the internet the NSA is spying on you and everyone else. Citation needed. > This is not an improvement because it makes guarantees that simply aren't true. No, ProtonMail pretended it made guarantees that it doesn't make. Just like the exact same Exchange/Outlook feature that people have used for years, this is to prevent accidental copying of emails and their contents.

Citation: https://support.google.com/transparencyreport/answer/7381738...

> A variety of laws allow government agencies to investigate regulatory violations or criminal activity. Google receives requests for user data from government agencies investigating criminal activity, administrative agencies, courts and others.

...

A federal statute called the Electronic Communications Privacy Act, known as ECPA, regulates how a government agency can use these types of legal process to compel companies like Google to disclose information about users. This law was passed in 1986, before the web as we know it today even existed. It has failed to keep pace with how people use the Internet today. That's why we've been working with many advocacy groups, companies and others, through the Digital Due Process Coalition, to seek updates to this important law so it guarantees the level of privacy that you should reasonably expect when using our services

Re: Gmail confidential mode is not secure or private

#167

The point of confidential mode is for corporate users. When the CEO sends out that confidential mail to the company, it adds a speed bump to users who are about to copy out data that they have been told they should not, so they get a chance to realize they should not do this, and then removes all plausible deniability when they choose to bypass that speed bump.

Actually, in many corporate cases BOTH parties want to keep the info confidential - the CEO sends over salary details to CFO to load into payroll system. After it's all loaded and printed for the files (or saved in the HR system), they BOTH want it to auto-expire out of their emails, but both are too busy to scrape back through old emails after a month to delete things.

So this confidential mode let's this happen naturally. When the CFO's email is hacked (which it will be eventually at some company) then all is not lost.

I'm sure many other users will find it useful.

Re: Gmail confidential mode is not secure or private

#168

Earlier quoted context omitted.

It's not saying exercising your rights is having malicious programs, they are not mutually exclusive and they didn't make that claim.

Recipients who have malicious programs on their computer may still be able to copy or download your messages or attachments. Recipients who do not have malicious programs on their computer also may still be able to copy or download your messages or attachments.

It is using "malicious" to mean "intending to circumvent your intention to keep this email confidential." Is there a different word that could be substituted to maintain that meaning?

Re: Gmail confidential mode is not secure or private

#169

Wow, marketing spam from a competitor. We send confidential docs regularly to users, who need access to those docs for perhaps 1 week at most. No one wants / needs to keep these around, but no one goes through their email carefully to delete these items. If that users email was hacked -> they have a big problem. If we can mark the items for a 3 week retention and then expire those items for them, that great - and thi…

These sort of features are really just security theater. If someone really wants to share your "confidential" docs they'll screenshot every page to do it.

BOTH parties want to avoid it sticking around in their email forever.

Do folks not work with partners who are sloppy with security? You send over you stuff. No one wants to leak it but someone's email is hacked. Do you want your stuff in their email still 5 years later?

Do folks not work in business? Bob sends sue draft of updated raises, sue edits and adds some notes and sends them back. A final decision is reached. After some time the big list of salary info by position -> folks want that out of their emails. This would keep it out.

This is a REAL security benefit. It goes to show that folks like protonmail and other security experts don't have a good real world understanding of risks to info people face. It's not all state level hacking, it's folks being lazy, not cleaning out their email, then getting hacked.

Re: Gmail confidential mode is not secure or private

#170

Earlier quoted context omitted.

> I do remember some app not "letting" me screenshot something with stock Android, which I felt to be a violation of my freedom. Bank apps tend to do that. When I first hit this issue, it also felt like a violation of my freedom, and it was also very annoying because I badly needed to make that screenshot.

I think bank apps do this less to stop you from making screenshots, and more to stop that new Candy Clash app you just installed from making that screenshot.

That's what sandboxing is for.
Post reply on HN