Live data from Hacker News

Gmail confidential mode is not secure or private

protonmail.com

181–190 of 226 posts

Re: Gmail confidential mode is not secure or private

#181

Earlier quoted context omitted.

These sort of features are really just security theater. If someone really wants to share your "confidential" docs they'll screenshot every page to do it.

BOTH parties want to avoid it sticking around in their email forever. Do folks not work with partners who are sloppy with security? You send over you stuff. No one wants to leak it but someone's email is hacked. Do you want your stuff in their email still 5 years later? Do folks not work in business? Bob sends sue draft of updated raises, sue edits and adds some notes and sends them back. A final decision is reached.…

I agree there is some benefit. But it also may lull people into a false sense of security thinking that information cannot possibly be copied outside the organization.

Re: Gmail confidential mode is not secure or private

#182

Earlier quoted context omitted.

> If you are on the internet the NSA is spying on you and everyone else. Citation needed. > This is not an improvement because it makes guarantees that simply aren't true. No, ProtonMail pretended it made guarantees that it doesn't make. Just like the exact same Exchange/Outlook feature that people have used for years, this is to prevent accidental copying of emails and their contents.

Is a citation really needed about the NSA collecting basically all the data on the Internet? This is "common knowledge" in information security circles. Go look up the battles the EFF has fought with the NSA about their data collection practices. The NSA is continually building giant data warehouses everywhere... they probably have more data centers than any other organization in existence. They collect all the data.

> Is a citation really needed about the NSA collecting basically all the data on the Internet?

Honestly, yes. According to some random infographic I came across, americans use ~2 million GB (2PB) of data per minute. We'll round down and call that one EB per day. So round down again and call it 300 EB per year (a high estimate would be 1K EB, or 1 YB). That's more than the entire global output of disk storage annually, and the NSA aren't the only ones who want hard drives.

Keep in mind that much (most?) of that data is encrypted in transit, so targeting exactly which data they want is not always possible.

Re: Gmail confidential mode is not secure or private

#183
post #3

"Options for recipients to forward, copy, print, or download this email's contents will be disabled." I simply don't understand how they think they can get away with this foolishness. I can forward, copy, print, or download ANYTHING that passes over my ethernet cables. Your silly UI will ultimately never stop me from wiresharking my own cables in my own home and doing whatever the hell I want with any bits of informa…

Well you can't claim anything as "secure" either because someone somewhere has a 0-day. It just depends on where you draw the line, and for what application you're using it.

Re: Gmail confidential mode is not secure or private

#184
post #19

Earlier quoted context omitted.

Consider for a moment: a company or school set up as an Enterprise Mobile Device Management provider, handing everyone out ChromeOS devices, setting up their GSuite domain so that nobody can connect to their GSuite GMail accounts except through the ChromeOS device (or an equivalent MDMed mobile device), and setting up an automatic, un-disable-able VPN on those devices for accessing Google domains. I think that’s the…

It's worth mentioning that all these measures can be fairly trivially defeated by the analog loophole[1]. I suppose it's harder to prove authenticity in that case, however. https://en.wikipedia.org/wiki/Analog_loophole

There are undoubtedly a variety of ways to bypass things for a motivated attacker. Analog is likely only one of those.

The thing that a lot of these measures protect against is not so much a targeted attack, it's stupid user tricks. It's not protection against Jane the Spy extracting as much information as she can, it's a measure against Danny the drunk who leaves his laptop at a bar or sitting in the back seat of the car where it's visible and stolen.

There are also likely a lot of places where it would be illegal to use something like this with auto expiring messages, though hopefully most such places won't be using Gmail.

Re: Gmail confidential mode is not secure or private

#185

The point of confidential mode is for corporate users. When the CEO sends out that confidential mail to the company, it adds a speed bump to users who are about to copy out data that they have been told they should not, so they get a chance to realize they should not do this, and then removes all plausible deniability when they choose to bypass that speed bump.

It is almost as if calling it "confidential" may be misleading.

Sounds exactly like confidential content works now, except with more than red text saying "confidential" on slides or similar.

Re: Gmail confidential mode is not secure or private

#186

Earlier quoted context omitted.

> If you are on the internet the NSA is spying on you and everyone else. Citation needed. > This is not an improvement because it makes guarantees that simply aren't true. No, ProtonMail pretended it made guarantees that it doesn't make. Just like the exact same Exchange/Outlook feature that people have used for years, this is to prevent accidental copying of emails and their contents.

Is a citation really needed about the NSA collecting basically all the data on the Internet? This is "common knowledge" in information security circles. Go look up the battles the EFF has fought with the NSA about their data collection practices. The NSA is continually building giant data warehouses everywhere... they probably have more data centers than any other organization in existence. They collect all the data.

> Is a citation really needed about the NSA collecting basically all the data on the Internet?

Yes because this claim is preposterous. You don't even need a napkin to show this is impossible.

> This is "common knowledge" in information security circles.

The "common knowledge" in Internet industry circles is that Snowden misinterpreted several documents and made wild claims about what they said.

> Go look up the battles the EFF has fought with the NSA about their data collection practices.

Snowden's documents showed that the EFF arguments against about what was happening at AT&T were unfounded. The documents showed that instead of copying everything, they filtered to traffic to or from certain foreign targets outside the US.

Re: Gmail confidential mode is not secure or private

#187

Earlier quoted context omitted.

Is a citation really needed about the NSA collecting basically all the data on the Internet? This is "common knowledge" in information security circles. Go look up the battles the EFF has fought with the NSA about their data collection practices. The NSA is continually building giant data warehouses everywhere... they probably have more data centers than any other organization in existence. They collect all the data.

> Is a citation really needed about the NSA collecting basically all the data on the Internet? Honestly, yes. According to some random infographic I came across, americans use ~2 million GB (2PB) of data per minute. We'll round down and call that one EB per day. So round down again and call it 300 EB per year (a high estimate would be 1K EB, or 1 YB). That's more than the entire global output of disk storage annually…

If a billion people watch the same YouTube video, the NSA isn’t going to store a billion copies of it.

Re: Gmail confidential mode is not secure or private

#188

Earlier quoted context omitted.

> Is a citation really needed about the NSA collecting basically all the data on the Internet? Honestly, yes. According to some random infographic I came across, americans use ~2 million GB (2PB) of data per minute. We'll round down and call that one EB per day. So round down again and call it 300 EB per year (a high estimate would be 1K EB, or 1 YB). That's more than the entire global output of disk storage annually…

If a billion people watch the same YouTube video, the NSA isn’t going to store a billion copies of it.

...But they don't know it's the same youtube video. It's just an encrypted bytes from a connection to youtube.com. Now you might be able to infer from metadata what the video is sometimes, but given that youtube does things like dynamically change the resolution it sends over the wire based on network congestion during a single watch session, it's not clear that size and length metadata would be enough to dedupe.

Re: Gmail confidential mode is not secure or private

#189
post #180
post #115

Earlier quoted context omitted.

Dude, come on. You do understand. The feature is like a fence in a yard. It separates the honest from the dishonest, forcing the clueless/negligent/reckless to pick a side. Nobody believes fences stop criminals, and nobody believes Gmail has ended the DRM arms race.

Can you please edit out personal swipes from your HN comments? This post would be just fine without the first two bits. https://news.ycombinator.com/newsguidelines.html

Thanks for the reminder, dang. You're right.

Re: Gmail confidential mode is not secure or private

#190
post #168

Earlier quoted context omitted.

Recipients who have malicious programs on their computer may still be able to copy or download your messages or attachments. Recipients who do not have malicious programs on their computer also may still be able to copy or download your messages or attachments.

It is using "malicious" to mean "intending to circumvent your intention to keep this email confidential." Is there a different word that could be substituted to maintain that meaning?

IME the "artificially and ineffectively trying to enforce e-mail confidentiality" part is malicious in itself. You don't get to tell me what I can do with a physical letter I get from you, so you shouldn't be able to do that with an e-mail either.
Post reply on HN