Now that Google is shooting to be their own CA, couldn't they mass-generate S/MIME certificates for all their users? Even if the sender and receiver is Google-hosted, they could still encrypt mail, so it's encrypted at rest if it's copied from a user's gmail account to their local mail via pop/imap? And, since Google would be generating the private key, they could also decrypt it server-side in their secure environme…
Hosted S/MIME by Google provides enhanced security for Gmail in the enterprise
11–19 of 19 posts
Re: Hosted S/MIME by Google provides enhanced security for Gmail in the enterprise
#12Now that Google is shooting to be their own CA, couldn't they mass-generate S/MIME certificates for all their users? Even if the sender and receiver is Google-hosted, they could still encrypt mail, so it's encrypted at rest if it's copied from a user's gmail account to their local mail via pop/imap? And, since Google would be generating the private key, they could also decrypt it server-side in their secure environme…
Re: Hosted S/MIME by Google provides enhanced security for Gmail in the enterprise
#13> To use hosted S/MIME, companies need to upload their own certificates (with private keys) to Gmail, which can be done by end users via Gmail settings or by admins in bulk via the Gmail API. So this is just to give the illusion of privacy and security then?
It gives protection against eavesdropping of messages in transit, so it's better than nothing (Even SSL+SMTP allows email relays to see the email in the clear). However it does not protect against an attacker who gets into your GMail, does not protect against warrents/NSLs/subpoenas against Google, does not protect against your domain admin accessing your message.
Re: Hosted S/MIME by Google provides enhanced security for Gmail in the enterprise
#14Re: Hosted S/MIME by Google provides enhanced security for Gmail in the enterprise
#15Earlier quoted context omitted.
It gives protection against eavesdropping of messages in transit, so it's better than nothing (Even SSL+SMTP allows email relays to see the email in the clear). However it does not protect against an attacker who gets into your GMail, does not protect against warrents/NSLs/subpoenas against Google, does not protect against your domain admin accessing your message.
I can't tell if you're agreeing or disagreeing with the parent comment.
Re: Hosted S/MIME by Google provides enhanced security for Gmail in the enterprise
#16I wonder if Google is starting to get worried about services such as ProtonMail.
Re: Hosted S/MIME by Google provides enhanced security for Gmail in the enterprise
#17> To use hosted S/MIME, companies need to upload their own certificates (with private keys) to Gmail, which can be done by end users via Gmail settings or by admins in bulk via the Gmail API. So this is just to give the illusion of privacy and security then?
If you want to protect against an adversarial Google, you shouldn't be using Gmail at all. If you want to protect against an adversarial nation-state, well, power to you, but it's an uphill battle. Use PGP, not S/MIME, and pray that everyone else knows how to use it perfectly, making no mistakes at any point ever.
Re: Hosted S/MIME by Google provides enhanced security for Gmail in the enterprise
#18> end users have to manually install certificates to their email applications This really is a problem that could be reduced. For instance there is no easy way to copy the S/Mime certificate from my macbook to my iPhone
CA and Web of Trust both require verifying the key fingerprints of yo want to be serious about it, but smime was much more easy to use overall.
Re: Hosted S/MIME by Google provides enhanced security for Gmail in the enterprise
#19Earlier quoted context omitted.
It gives protection against eavesdropping of messages in transit, so it's better than nothing (Even SSL+SMTP allows email relays to see the email in the clear). However it does not protect against an attacker who gets into your GMail, does not protect against warrents/NSLs/subpoenas against Google, does not protect against your domain admin accessing your message.
I can't tell if you're agreeing or disagreeing with the parent comment.