Live data from Hacker News

Gmail confidential mode

gsuiteupdates.googleblog.com

111–120 of 206 posts

Re: Gmail confidential mode

#111
post #88

Earlier quoted context omitted.

It's not a "security" feature, anything which can be displayed can be captured, you can even take a picture of your phone with another phone if you want, it just makes users annoyed without adding any security.

Just because you can get around a policy doesn't make it ineffective. I'm sure that slight barrier reduced the number of people taking screenshots of their bank app 99%. Perfect is the enemy of good.

It just gets user annoyed for no reason, why can't they take a screenshot of their bank account anyway? It just makes no sense. I understand banks like it because they are full of regulatory security which don't make sense in real life, that's probably one more to add to the list.

Re: Gmail confidential mode

#113
post #19
post #2

> removing options for recipients to forward, copy, print, and download Oh please... Everybody can do a screenshot nowadays, and even Google itself integrated OCR into its Screenshot tool at Android a few years ago. What a waste of time to make the life of people harder who must use this "security" feature!

The Airbnb app prevents screenshots on certain pages on the OS level on Android, I'm sure the Gmail app will do the same.

Worthless from a security standpoint, because the screenshots can still be taken from a desktop or laptop device.

Re: Gmail confidential mode

#114

Earlier quoted context omitted.

I think what the parent is saying is that they feel this DO NOT FORWARD header feature is being presented as a security feature. I probably agree

This is an algorithmically enforced one, though.

As long as it doesn't leave Gmail.

Re: Gmail confidential mode

#115

I feel that many of these pseudo-secure, proprietary enhancements to email create a false sense of security for non-tech-savvy users. Given the smoke-and-mirrors presentation of this as a way to "secure your email^tm" and the plethora of recent info leaks, i am sure some poor c-level exec will get caught inadvertently sharing something with an external recipient thinking that it will disappear in a few days, but then…

this is nothing more than a "me-too" feature to stack up one more checkbox in the gmail vs exchange sales pitch https://support.office.com/en-us/article/mark-your-email-as-...

I imagine they will show confidential emails to other gmail users inline, but make a link for non gmail users.

It is in Google's interest to make GMail less and less the same as "plain mail", until you are forced (for practical reasons) to create a Gmail account to interact with other Gmail users.

Together with Amp and Chrome, eventually we will be at a point where the decentralized internet is replaced by Google's servers and software.

Re: Gmail confidential mode

#116
post #10

Earlier quoted context omitted.

Can you explain how "removing options for recipients to forward, copy, print, and download" could "help prevent users shooting themselves in the foot"?

I get a bunch of information through emails at work that Im not allowed to share outside the company, and tons of others that I need to send to people outside the company. If the people sending me the internal company emails mark them as such, I can be sure I never inadvertently forward the wrong emails to the wrong group. I think the threat model is about catching your own mistakes, not preventing bad actors from ac…

This feature only works for users of Gmail and specifically web mail. All the users I would want to have an extra layer around 'shoot themselves in the foot' usually also insist on using Outlook to access their email.

This is simply a superficial UI that gives a false sense of doing anything for most of the cases.

Re: Gmail confidential mode

#117

I feel that many of these pseudo-secure, proprietary enhancements to email create a false sense of security for non-tech-savvy users. Given the smoke-and-mirrors presentation of this as a way to "secure your email^tm" and the plethora of recent info leaks, i am sure some poor c-level exec will get caught inadvertently sharing something with an external recipient thinking that it will disappear in a few days, but then…

There are two schools of thought: 1) Security has to be enforced by code 2) Your employees are reasonable, and won't try to maliciously bypass security controls I'm firmly in camp #2. In a normal corporate setting, a locked door or a locked cabinet is security, even with a cheap, easily pickable lock. That's all this is. And for 95% of corporate applications, that's good enough. If you have high-level executive crime…

That only works for internal communications. Once it leaves Google's servers, you lose all control. I don't know the specifics here, but the only ways to guarantee that an email server somewhere isn't caching your emails (and I don't trust Google to not cache them either) is to either encrypt them (GPG) or require hitting your server to read the email (potentially what Google is doing), and that doesn't prevent the user from copying it (but at least you can know _who _ copied it or let it be copied).

I don't know how external access works, so maybe they're doing more than they say they are, but I don't trust my coworkers, I shouldn't trust Google either. Client-side encryption is the only acceptable solution IMO.

Re: Gmail confidential mode

#118

Question: Does this only work GMail to GMail or also across email platforms?

This only works inside Gmail and specifically only within the web interface. It does not protect emails accessed / forwarded / stored from IMAP and POP clients (though if the messages are only stored server side the IMAP one will still get deleted).

Re: Gmail confidential mode

#119

I feel that many of these pseudo-secure, proprietary enhancements to email create a false sense of security for non-tech-savvy users. Given the smoke-and-mirrors presentation of this as a way to "secure your email^tm" and the plethora of recent info leaks, i am sure some poor c-level exec will get caught inadvertently sharing something with an external recipient thinking that it will disappear in a few days, but then…

How long before someone makes a chrome browser plugin that will automatically screenshot and download any message flagged in this manner? Completely agree with your last sentiment. We all assume that "kids these days" grow up well aware of these things, but my experience to date has been that new hires are disturbingly unaware of these things.

On that note, I wonder if Firefox's new screenshot utility has an API for extensions...

Re: Gmail confidential mode

#120

Proprietary "extensions" to email make me nervous.

This, thousand times this. Google is trying to remake the internet so that only Google's browser works with Google's version of the internet that operates entirely on Google servers.
Post reply on HN