Live data from Hacker News

Hosted S/MIME by Google provides enhanced security for Gmail in the enterprise

security.googleblog.com

11–19 of 19 posts

Re: Hosted S/MIME by Google provides enhanced security for Gmail in the enterprise

#11

Now that Google is shooting to be their own CA, couldn't they mass-generate S/MIME certificates for all their users? Even if the sender and receiver is Google-hosted, they could still encrypt mail, so it's encrypted at rest if it's copied from a user's gmail account to their local mail via pop/imap? And, since Google would be generating the private key, they could also decrypt it server-side in their secure environme…

Not only should they mass create keys for all accounts, but they should make (other/more) keys available for any purpose. An open system where most email addresses come with a set of keys would enable many types of encryption systems (file sharing, login, messaging, etc...) Users would still have keys managed by Google (or IT, or their webmail host) so they don't have to understand key management, and they'd have someone to call when things break.

Re: Hosted S/MIME by Google provides enhanced security for Gmail in the enterprise

#12

Now that Google is shooting to be their own CA, couldn't they mass-generate S/MIME certificates for all their users? Even if the sender and receiver is Google-hosted, they could still encrypt mail, so it's encrypted at rest if it's copied from a user's gmail account to their local mail via pop/imap? And, since Google would be generating the private key, they could also decrypt it server-side in their secure environme…

AFAIK the recent key transparency initiative is also the missing link in bringing the end-to-end to Gmail for real.

Re: Hosted S/MIME by Google provides enhanced security for Gmail in the enterprise

#13
post #3

> To use hosted S/MIME, companies need to upload their own certificates (with private keys) to Gmail, which can be done by end users via Gmail settings or by admins in bulk via the Gmail API. So this is just to give the illusion of privacy and security then?

It gives protection against eavesdropping of messages in transit, so it's better than nothing (Even SSL+SMTP allows email relays to see the email in the clear). However it does not protect against an attacker who gets into your GMail, does not protect against warrents/NSLs/subpoenas against Google, does not protect against your domain admin accessing your message.

I can't tell if you're agreeing or disagreeing with the parent comment.

Re: Hosted S/MIME by Google provides enhanced security for Gmail in the enterprise

#15

Earlier quoted context omitted.

It gives protection against eavesdropping of messages in transit, so it's better than nothing (Even SSL+SMTP allows email relays to see the email in the clear). However it does not protect against an attacker who gets into your GMail, does not protect against warrents/NSLs/subpoenas against Google, does not protect against your domain admin accessing your message.

I can't tell if you're agreeing or disagreeing with the parent comment.

It's detailing that it does provide real privacy and security protections against some scenarios, even if not against all scenarios.

Re: Hosted S/MIME by Google provides enhanced security for Gmail in the enterprise

#17
post #3

> To use hosted S/MIME, companies need to upload their own certificates (with private keys) to Gmail, which can be done by end users via Gmail settings or by admins in bulk via the Gmail API. So this is just to give the illusion of privacy and security then?

If you want to protect against an adversarial Google, you shouldn't be using Gmail at all. If you want to protect against an adversarial nation-state, well, power to you, but it's an uphill battle. Use PGP, not S/MIME, and pray that everyone else knows how to use it perfectly, making no mistakes at any point ever.

TBH, if you want to protect against an adversarial nation-state, don't use email. Full stop.

Re: Hosted S/MIME by Google provides enhanced security for Gmail in the enterprise

#18
post #8

> end users have to manually install certificates to their email applications This really is a problem that could be reduced. For instance there is no easy way to copy the S/Mime certificate from my macbook to my iPhone

It's been several years since I experimented with this, but I recall that S/MIME on an iPhone was much easier to setup than GPG anywhere else, including the desktop. I think I used a USB transfer, but googling now shows guides that allow emailing a password encrypted p12 file.

CA and Web of Trust both require verifying the key fingerprints of yo want to be serious about it, but smime was much more easy to use overall.

Re: Hosted S/MIME by Google provides enhanced security for Gmail in the enterprise

#19

Earlier quoted context omitted.

It gives protection against eavesdropping of messages in transit, so it's better than nothing (Even SSL+SMTP allows email relays to see the email in the clear). However it does not protect against an attacker who gets into your GMail, does not protect against warrents/NSLs/subpoenas against Google, does not protect against your domain admin accessing your message.

I can't tell if you're agreeing or disagreeing with the parent comment.

I've given up on trying to push a viewpoint on the internet. I just want to add to discussions by providing information, analysis and experience.
Post reply on HN