Live data from Hacker News

Client-side encryption for Gmail in Google Workspace is now generally available

workspaceupdates.googleblog.com

11–20 of 101 posts

Re: Client-side encryption for Gmail in Google Workspace is now generally available

#14

There is no info on how it works! It looks more like a marketing stunt! How the key is generated, where it is stored, and which encryption is used.

It’s in the references below the blog post

https://support.google.com/a/answer/13069736?hl=en

Re: Client-side encryption for Gmail in Google Workspace is now generally available

#15
post #3

This is purely marketing AFAIT. I don't see how it provides any protection against the 5 eyes or having one's google account breached. The encryption/decription is done with javascript code served to your browser by google (= can be hijacked/changed/…) The only way to do client side encryption is PGP on a native client distributed by a third party.

Not saying much. Same is true about any e2e encrypted messaging (Telegram, Signal, etc.)

There's no way to tell if they are intercepting your messages clientside, and you'd have to monitor all the network traffic (which would be encrypted with their keys) to detect exfiltration.

Re: Client-side encryption for Gmail in Google Workspace is now generally available

#17
post #5
post #3

This is purely marketing AFAIT. I don't see how it provides any protection against the 5 eyes or having one's google account breached. The encryption/decription is done with javascript code served to your browser by google (= can be hijacked/changed/…) The only way to do client side encryption is PGP on a native client distributed by a third party.

If the key is encrypted with your password, I don't see how that compromises security by a lot. If they adapt the javascript to break encryption on a large scale, that would sooner or later come out. Yes, they could target specific people, deliver different javascript and break their encryption, but in general it's still a huge security gain. It makes it impossible for Google to handover E-Mails retrospectively to po…

[deleted]

Re: Client-side encryption for Gmail in Google Workspace is now generally available

#19

That is not Generally available: Availability * Available to Google Workspace Enterprise Plus, Education Plus, and Education Standard customers * Not available to Google Workspace Essentials, Business Starter, Business Standard, Business Plus, Enterprise Essentials, Education Fundamentals, Frontline, and Nonprofits, as well as legacy G Suite Basic and Business customers * Not available to users with personal Google A…

At Google, generally available means it's no longer in testing. It's a development lifecycle term.

Re: Client-side encryption for Gmail in Google Workspace is now generally available

#20
Good for gmail.

These days, people really should get their own domain and host there email there. If you do not know how to do this, there are plenty of cheap hosting companies you can use.

And if you want to encrypt, use gnupg or that thing Thunderbird now uses. I am a mutt user and gnupg with mutt is rather easy.

Post reply on HN