Live data from Hacker News

Gmail confidential mode is not secure or private

protonmail.com

211–220 of 226 posts

Re: Gmail confidential mode is not secure or private

#211
post #3

"Options for recipients to forward, copy, print, or download this email's contents will be disabled." I simply don't understand how they think they can get away with this foolishness. I can forward, copy, print, or download ANYTHING that passes over my ethernet cables. Your silly UI will ultimately never stop me from wiresharking my own cables in my own home and doing whatever the hell I want with any bits of informa…

All that's needed is to disable a few browser options https://boingboing.net/2018/07/22/adversarial-interop.html

I actually tried the "wiresharking my own cables" approach, but because it's encrypted, you also need to dump the ephemeral encryption keys. There's a simple guide on how to do this here: https://jimshaver.net/2015/02/11/decrypting-tls-browser-traf...

Re: Gmail confidential mode is not secure or private

#212

Earlier quoted context omitted.

It is almost as if calling it "confidential" may be misleading.

It matches the name of an existing Outlook/Exchange feature that people have used for many years. Naming it anything else would have been confusing.

In Outlook's docs, they also refer to it as "IRM-protected mail", which seems clearer to me. https://support.office.com/en-ie/article/mark-your-email-as-...

Both Google and MS provide a disclaimer that explains Information Rights Management can't prevent "malicious programs" from by bypassing the restrictions.

Re: Gmail confidential mode is not secure or private

#213
post #195

Earlier quoted context omitted.

Should we be proud of them for that? What does it have to do with Snowden? They can still read my emails.

It would take a very concerted effort. There are multiple levels of encryption and the best practice is that only verified builds can run in production and only non-humans are ACLd to access security keys. Any attempt to do so would be limited to a very small group of people, trivially logged, caught by AI for inappropriate behavior, and cause a firing.

Right but Google owns the encryption, which means I have to assume they are reading the messages. They changed their policy once, they can change it again.

Re: Gmail confidential mode is not secure or private

#214

The point of confidential mode is for corporate users. When the CEO sends out that confidential mail to the company, it adds a speed bump to users who are about to copy out data that they have been told they should not, so they get a chance to realize they should not do this, and then removes all plausible deniability when they choose to bypass that speed bump.

> When the CEO sends out that confidential mail to the company

...they make it available to Google first, and then to the employees.

Re: Gmail confidential mode is not secure or private

#215
post #191

Earlier quoted context omitted.

IMO "Citation needed" is a quick way to say "do you have a source for me?", and "fallacy" (hardly used without also mentioning the specific fallacy) is a quicker way to say "I recognized logic flaw X in your argument". You are free to see harm in these statements but telling me they are always meant as harmful as you mentioned is your own negative reflection. Not mine or ours, we are free to have our own interpretati…

I think citation needed carries a connotation of “I don’t believe this is true.” It is just a lazy way to converse if you are engaged in a genial conversation in good faith. “This is new to me, can you share some references?” I appreciate we can be technical and to the point, but given the context, I felt my response was appropriate.

I do understand you interpret it as "I don't believe this is true" but my explanation "do you have a source for me?" is also a likely explanation. If I then apply the HN rules where the reader must assume good faith and interpret posts in the most positive way, I'm leaning towards assuming "do you have a source for me?"

Re: Gmail confidential mode is not secure or private

#216

Earlier quoted context omitted.

Is a citation really needed about the NSA collecting basically all the data on the Internet? This is "common knowledge" in information security circles. Go look up the battles the EFF has fought with the NSA about their data collection practices. The NSA is continually building giant data warehouses everywhere... they probably have more data centers than any other organization in existence. They collect all the data.

But where do they put it?

Utah. There is a very high chance this conversation is now sitting on a disk in Utah for a bit. Collectively the NSA has built or leases more data center space than almost any other entity on the planet. Maybe not even the big four (goog amzn fb) rival them. What are they doing with all that space and black budget?

Re: Gmail confidential mode is not secure or private

#217

Earlier quoted context omitted.

I'm surprised no one has come up with a browser extension yet that circumvents this. I'm guessing it would be fairly trivial to do so.

I'd be surprised if the built in print to pdf function doesn't already circumvent this.

Google (ab)uses the @media print CSS rule to hide the message content and replace it with "Printing is not allowed by the sender of this message."

However, I've found you can print confidential emails if you comment-out/disable all the @media print rules using Firefox developer tools: https://grokprivacy.org/2018/06/24/archiving-self-destructin...

Re: Gmail confidential mode is not secure or private

#218
post #197

Earlier quoted context omitted.

Actually, in many corporate cases BOTH parties want to keep the info confidential - the CEO sends over salary details to CFO to load into payroll system. After it's all loaded and printed for the files (or saved in the HR system), they BOTH want it to auto-expire out of their emails, but both are too busy to scrape back through old emails after a month to delete things. So this confidential mode let's this happen nat…

So confidential mode is a cumbersome retention mechanism? A simple email rule can do this for all messages.

Some messages are MUCH more sensitive than others. You might have a default 3-5 year rule (many corps do). That’s way too long for some messages.

especially if sending across an ou boundary where you don’t know the retention treatment this will be great.

Sales teams can be very sloppy w email -> auto import into CRMs, sharing permissions, delegating permissions, running their own optimization apps etc. Because the want to claim credits for sales they don’t like tight retention limits etc

Re: Gmail confidential mode is not secure or private

#219
post #210

Earlier quoted context omitted.

Stop posting articles with over the top language from obvious competitors calling a competitors feature a “trick”. Talk about over the top language - “toxic fanaticism”? Really? The name calling of other posters you disagree with makes hn worse (my comments focused on a company not this community)

What's the problem with Google having a competitor, why are you so hyped about?(This is why I think you're a fanatic) Also, why are you so eagerly defending the big guy/monopolist in the room. Is this the attitude of an entrepreneur or hacker? One that is part of the "hacker news" community?

Apaec - can I encourage you to focus on the post / article and make comments about that rather than attacking other posters?

If you think this feature (which you don’t need to use) is a “trick” that has no value that is fine - explain why no one should use it - give some examples etc

Stop with the whole focus on other posters motivations, calling them “toxic fanatics” etc.

Google has lots of competitors - the big one is exchange / outlook - which has a confidential email mode. For a list of competitors look here:

https://www.datanyze.com/market-share/email-hosting

It’s not unreasonable for them to add a feature to better compete with MS. I didn’t even see Protonmail on that pie chart

Re: Gmail confidential mode is not secure or private

#220
post #197

Earlier quoted context omitted.

So confidential mode is a cumbersome retention mechanism? A simple email rule can do this for all messages.

Some messages are MUCH more sensitive than others. You might have a default 3-5 year rule (many corps do). That’s way too long for some messages. especially if sending across an ou boundary where you don’t know the retention treatment this will be great. Sales teams can be very sloppy w email -> auto import into CRMs, sharing permissions, delegating permissions, running their own optimization apps etc. Because the wa…

Everywhere I have ever worked has a 30 day email retention policy. This would never change message to message. It’s a regulatory issue and you have no reason to retain messages longer than the minimum so you’re better off enforcing it at the server level.
Post reply on HN