Live data from Hacker News

Client-side encryption for Gmail in Google Workspace is now generally available

workspaceupdates.googleblog.com

21–30 of 101 posts

Re: Client-side encryption for Gmail in Google Workspace is now generally available

#21
post #18
post #4

Title is misleading. > Not available to users with personal Google Accounts

This blog is not for personal accounts: "about new features and improvements for Google Workspace customers." RTFM.

I was referring to the HN title. The domain that shows up is 'googleblog.com' which doesn't indicate it's not for regular Gmail.

> RTFM

What manual?

Re: Client-side encryption for Gmail in Google Workspace is now generally available

#22
post #20

Good for gmail. These days, people really should get their own domain and host there email there. If you do not know how to do this, there are plenty of cheap hosting companies you can use. And if you want to encrypt, use gnupg or that thing Thunderbird now uses. I am a mutt user and gnupg with mutt is rather easy.

What if you want email you send to make it to the inbox of gmail, 365 users?

Re: Client-side encryption for Gmail in Google Workspace is now generally available

#23

>Availability > >Available to Google Workspace Enterprise Plus, Education Plus, and Education Standard customers >Not available to Google Workspace Essentials, Business Starter, Business Standard, Business Plus, Enterprise Essentials, Education Fundamentals, Frontline, and Nonprofits, as well as legacy G Suite Basic and Business customers >Not available to users with personal Google Accounts Also to be available it m…

Yeah, It's understandable that they would use this as a differentiator, but in reality, we all gain when encryption is rolled out more broadly.

Re: Client-side encryption for Gmail in Google Workspace is now generally available

#24
post #3

This is purely marketing AFAIT. I don't see how it provides any protection against the 5 eyes or having one's google account breached. The encryption/decription is done with javascript code served to your browser by google (= can be hijacked/changed/…) The only way to do client side encryption is PGP on a native client distributed by a third party.

>I don't see how it provides any protection against the 5 eyes or having one's google account breached.

It isn't supposed to protect you from government agencies. Really what this feature is, is 1) e2e of email, and 2) integration with an external enterprise key management service.

#2 means that at very least, your org will have access to your keys and therefore all encrypted mail, and if they have access to that, then they are open to things like subpoenas from law enforcement.

Re: Client-side encryption for Gmail in Google Workspace is now generally available

#25
post #20

Good for gmail. These days, people really should get their own domain and host there email there. If you do not know how to do this, there are plenty of cheap hosting companies you can use. And if you want to encrypt, use gnupg or that thing Thunderbird now uses. I am a mutt user and gnupg with mutt is rather easy.

The email allow-lists will be a problem.

Re: Client-side encryption for Gmail in Google Workspace is now generally available

#26
i think i read all the blog posts and announcements, yet i can't for the life of me find a technical explanation of what exactly this does.

it looks like it could be like s/mime, or possibly a scheme for encrypting the contents of messages stored in gmail accounts. where are the keys stored? what is the threat model?

can anyone enlighten?

Re: Client-side encryption for Gmail in Google Workspace is now generally available

#27
post #20

Good for gmail. These days, people really should get their own domain and host there email there. If you do not know how to do this, there are plenty of cheap hosting companies you can use. And if you want to encrypt, use gnupg or that thing Thunderbird now uses. I am a mutt user and gnupg with mutt is rather easy.

What if you want email you send to make it to the inbox of gmail, 365 users?

Then get a legit-looking domain name and hope you don't get algorithmically deranked. It's literally a gamble.

Re: Client-side encryption for Gmail in Google Workspace is now generally available

#28
post #20

Good for gmail. These days, people really should get their own domain and host there email there. If you do not know how to do this, there are plenty of cheap hosting companies you can use. And if you want to encrypt, use gnupg or that thing Thunderbird now uses. I am a mutt user and gnupg with mutt is rather easy.

What if you want email you send to make it to the inbox of gmail, 365 users?

Most hosted mail services have no issues getting to mailbox. I've used Gandi, Mailbox, FastMail, and never have any mails flagged as spam.

Deliverability is only an issue when self hosting (particularly for home IPs)

Re: Client-side encryption for Gmail in Google Workspace is now generally available

#29
post #20

Good for gmail. These days, people really should get their own domain and host there email there. If you do not know how to do this, there are plenty of cheap hosting companies you can use. And if you want to encrypt, use gnupg or that thing Thunderbird now uses. I am a mutt user and gnupg with mutt is rather easy.

> These days, people really should get their own domain and host there email there

It seems to be a giant pain in the ass, and might be impossible in some circumstances

https://cfenollosa.com/blog/after-self-hosting-my-email-for-...

Re: Client-side encryption for Gmail in Google Workspace is now generally available

#30
post #19

That is not Generally available: Availability * Available to Google Workspace Enterprise Plus, Education Plus, and Education Standard customers * Not available to Google Workspace Essentials, Business Starter, Business Standard, Business Plus, Enterprise Essentials, Education Fundamentals, Frontline, and Nonprofits, as well as legacy G Suite Basic and Business customers * Not available to users with personal Google A…

At Google, generally available means it's no longer in testing. It's a development lifecycle term.

Not just at Google, MS also uses GA when something is sold, no need for it to be free.
Post reply on HN