Live data from Hacker News

Gmail confidential mode is not secure or private

protonmail.com

201–210 of 226 posts

Re: Gmail confidential mode is not secure or private

#201

The point of confidential mode is for corporate users. When the CEO sends out that confidential mail to the company, it adds a speed bump to users who are about to copy out data that they have been told they should not, so they get a chance to realize they should not do this, and then removes all plausible deniability when they choose to bypass that speed bump.

It is almost as if calling it "confidential" may be misleading.

It matches the name of an existing Outlook/Exchange feature that people have used for many years. Naming it anything else would have been confusing.

Re: Gmail confidential mode is not secure or private

#202
post #54

Earlier quoted context omitted.

>Note: Although confidential mode helps prevent the recipients from accidentally sharing your email, it doesn't prevent recipients from taking screenshots or photos of your messages or attachments. Recipients who have malicious programs on their computer may still be able to copy or download your messages or attachments. If you click the "learn more" in gmail it says that ^. Gmail seems pretty upfront about what "con…

> Recipients who have malicious programs on their computer may still be able to copy or download your messages or attachments. Even this is really poorly worded. You don't need a "malicious" program on your computer, you just need to go to your browser menu and hit the print button. This still makes it sound like the average user won't be able to save your email unless they're doing some kind of tech mumbo-jumbo -- t…

To address your concerns, every major browser supports css media queries. Gmail could simply hide the elements when the user tries to use the browser's print button. Again, this is designed to remove plausible deniability, not to provide an actually secure service. It's still email after all.

Re: Gmail confidential mode is not secure or private

#203
post #195

Earlier quoted context omitted.

Though since the Snowden leak Google really upped their game. Everything internally is encrypted in transit and at rest. Even when you use Google Cloud you automatically get encryption at rest.

Should we be proud of them for that? What does it have to do with Snowden? They can still read my emails.

It would take a very concerted effort. There are multiple levels of encryption and the best practice is that only verified builds can run in production and only non-humans are ACLd to access security keys. Any attempt to do so would be limited to a very small group of people, trivially logged, caught by AI for inappropriate behavior, and cause a firing.

Re: Gmail confidential mode is not secure or private

#204
post #202

Earlier quoted context omitted.

> Recipients who have malicious programs on their computer may still be able to copy or download your messages or attachments. Even this is really poorly worded. You don't need a "malicious" program on your computer, you just need to go to your browser menu and hit the print button. This still makes it sound like the average user won't be able to save your email unless they're doing some kind of tech mumbo-jumbo -- t…

To address your concerns, every major browser supports css media queries. Gmail could simply hide the elements when the user tries to use the browser's print button. Again, this is designed to remove plausible deniability, not to provide an actually secure service. It's still email after all.

Very nice catch -- I checked and they do use media queries during print-to-pdf.

Saving the webpage itself works fine though -- which again, is a browser feature your secretary probably knows about and is comfortable using.

I guess my objection to the idea that this is just removing deniability is that it really doesn't feel to me like it's being marketed that way. I wouldn't call a service like this "confidential mode", I would call it something like "auto-delete mode". Maybe I'm just arguing over semantics though.

Re: Gmail confidential mode is not secure or private

#205
post #199

Earlier quoted context omitted.

> Recipients who have malicious programs on their computer may still be able to copy or download your messages or attachments. Even this is really poorly worded. You don't need a "malicious" program on your computer, you just need to go to your browser menu and hit the print button. This still makes it sound like the average user won't be able to save your email unless they're doing some kind of tech mumbo-jumbo -- t…

> Recipients of the confidential message will have options to forward, copy, print, and download disabled. Doesn't seem to be that easy. You're probably not going to get a copy without taking a screenshot, opening up developer tools or digging into your browser's cache.

I checked, you can go to the menu at the top of your browser, and hit File->Save Page As. It took me about 15 seconds. You can also save the page as HTML only, which both prevents any weird clientside tricks that Google might like to try in the future and makes the file more portable.

Assuming you don't want to save the HTML page, you still might not even need to download a separate program to screenshot it. New installs of Firefox just have a button on the toolbar labeled, "Take a Screenshot". It'll grab the entire page without forcing you to do any scrolling, and doesn't require you to know anything about HTML. I tested, and it bypasses all of the security features on confidential emails.

People are arguing that this is designed to prevent accidental sharing, which is a really good point that I think I agree with overall. However, HN is a tech site and I'm seeing comments that say the only way you could beat this is to dig into your developer tools.

If a nontrivial portion of HN users think this service is more secure than it actually is, how much more uninformed are ordinary users? Saving a web page is not going to be a difficult problem for most people in your office to solve. So my objection here would be, Google isn't doing a good enough job of informing even tech-literate people of just how easy this is to circumvent.

A CEO is going to look at this and think, "well, I guess they're doing voodoo magic so most people in my office won't be able to share." The reality is, pretty much anyone in your office who wants to be able to beat this will be able to figure out how to do so.

Re: Gmail confidential mode is not secure or private

#206

Earlier quoted context omitted.

It is endearing to me that people still think the NSA can't break most of the TLS traffic on the the Internet. I have my doubts about the security provided by traffic that transits US soil and is protected by US CAs. High skepticism would be a better way to put it. Citation needed, and I don't have one, but it is safest to assume they have this capability, and before anyone gets up in arms about this statement, I do…

Nothing that you conjectured is supported by any documents. Snowden grabbed pretty much everything he could get his hands on as a SharePoint admin, so if any of that were true, it would have made its way into bigger news than the ho-hum stuff that was reported.

https://thinkprogress.org/former-nsa-director-hayden-lied-to...

https://en.m.wikipedia.org/wiki/PRISM_(surveillance_program)

https://www.eff.org/nsa-spying

“””The undisputed documents show that AT&T installed a fiberoptic splitter at its facility at 611 Folsom Street in San Francisco that makes copies of all emails web browsing and other Internet traffic to and from AT&T customers and provides those copies to the NSA. This copying includes both domestic and international Internet activities of AT&T customers. As one expert observed, “this isn’t a wiretap, it’s a country-tap.”

Secret government documents, published by the media in 2013, confirm the NSA obtains full copies of everything that is carried along major domestic fiber optic cable networks.”””

Re: Gmail confidential mode is not secure or private

#207

Earlier quoted context omitted.

> If you are on the internet the NSA is spying on you and everyone else. Citation needed. > This is not an improvement because it makes guarantees that simply aren't true. No, ProtonMail pretended it made guarantees that it doesn't make. Just like the exact same Exchange/Outlook feature that people have used for years, this is to prevent accidental copying of emails and their contents.

Is a citation really needed about the NSA collecting basically all the data on the Internet? This is "common knowledge" in information security circles. Go look up the battles the EFF has fought with the NSA about their data collection practices. The NSA is continually building giant data warehouses everywhere... they probably have more data centers than any other organization in existence. They collect all the data.

But where do they put it?

Re: Gmail confidential mode is not secure or private

#208

Wow, marketing spam from a competitor. We send confidential docs regularly to users, who need access to those docs for perhaps 1 week at most. No one wants / needs to keep these around, but no one goes through their email carefully to delete these items. If that users email was hacked -> they have a big problem. If we can mark the items for a 3 week retention and then expire those items for them, that great - and thi…

The hacker news guidelines explicitly mention avoiding calling names like idiotic/idiots.

@dang: does this merit a flag or ban?

I think toxic fanatism make hn a worse place for discussion.

Re: Gmail confidential mode is not secure or private

#209
post #208

Wow, marketing spam from a competitor. We send confidential docs regularly to users, who need access to those docs for perhaps 1 week at most. No one wants / needs to keep these around, but no one goes through their email carefully to delete these items. If that users email was hacked -> they have a big problem. If we can mark the items for a 3 week retention and then expire those items for them, that great - and thi…

The hacker news guidelines explicitly mention avoiding calling names like idiotic/idiots. @dang: does this merit a flag or ban? I think toxic fanatism make hn a worse place for discussion.

Stop posting articles with over the top language from obvious competitors calling a competitors feature a “trick”.

Talk about over the top language - “toxic fanaticism”? Really? The name calling of other posters you disagree with makes hn worse (my comments focused on a company not this community)

Re: Gmail confidential mode is not secure or private

#210
post #208

Earlier quoted context omitted.

The hacker news guidelines explicitly mention avoiding calling names like idiotic/idiots. @dang: does this merit a flag or ban? I think toxic fanatism make hn a worse place for discussion.

Stop posting articles with over the top language from obvious competitors calling a competitors feature a “trick”. Talk about over the top language - “toxic fanaticism”? Really? The name calling of other posters you disagree with makes hn worse (my comments focused on a company not this community)

What's the problem with Google having a competitor, why are you so hyped about?(This is why I think you're a fanatic)

Also, why are you so eagerly defending the big guy/monopolist in the room. Is this the attitude of an entrepreneur or hacker? One that is part of the "hacker news" community?

Post reply on HN