Live data from Hacker News

Gmail confidential mode

gsuiteupdates.googleblog.com

121–130 of 206 posts

Re: Gmail confidential mode

#121

I feel that many of these pseudo-secure, proprietary enhancements to email create a false sense of security for non-tech-savvy users. Given the smoke-and-mirrors presentation of this as a way to "secure your email^tm" and the plethora of recent info leaks, i am sure some poor c-level exec will get caught inadvertently sharing something with an external recipient thinking that it will disappear in a few days, but then…

It's disappointing that the article doesn't lead with this limitation. We (and everybody who's used Snapchat) know that self-deleting messages aren't truly possible, but there's no reason everybody should.

This is definitely a useful feature to manage sensitive documents within organisations where good faith (but not necessarily diligent policy adherence) can be assumed, but it's pitched dangerously wrong as you say.

Re: Gmail confidential mode

#122

Earlier quoted context omitted.

This is an algorithmically enforced one, though.

But anyone can screenshot the message or take a photo of it. The point is that it's not actually enforced.

Anyone can screenshot or take a photo of any decrypted message. The question is when the email leaves Google's servers and whether you can trust Google with that same document.

Personally, if I had a message where I would consider a tool like this, I would just encrypt it on the client with PGP or something.

Re: Gmail confidential mode

#123

I feel that many of these pseudo-secure, proprietary enhancements to email create a false sense of security for non-tech-savvy users. Given the smoke-and-mirrors presentation of this as a way to "secure your email^tm" and the plethora of recent info leaks, i am sure some poor c-level exec will get caught inadvertently sharing something with an external recipient thinking that it will disappear in a few days, but then…

There are two schools of thought: 1) Security has to be enforced by code 2) Your employees are reasonable, and won't try to maliciously bypass security controls I'm firmly in camp #2. In a normal corporate setting, a locked door or a locked cabinet is security, even with a cheap, easily pickable lock. That's all this is. And for 95% of corporate applications, that's good enough. If you have high-level executive crime…

>Sending an email which communicates something and disappears in a week is helpful.

There's nothing on the page that says google will purge all copies after the deletion date. I'd imagine that because google keeps backups, it'd still be available by subpoenaing google.

Re: Gmail confidential mode

#124

I feel that many of these pseudo-secure, proprietary enhancements to email create a false sense of security for non-tech-savvy users. Given the smoke-and-mirrors presentation of this as a way to "secure your email^tm" and the plethora of recent info leaks, i am sure some poor c-level exec will get caught inadvertently sharing something with an external recipient thinking that it will disappear in a few days, but then…

There are two schools of thought: 1) Security has to be enforced by code 2) Your employees are reasonable, and won't try to maliciously bypass security controls I'm firmly in camp #2. In a normal corporate setting, a locked door or a locked cabinet is security, even with a cheap, easily pickable lock. That's all this is. And for 95% of corporate applications, that's good enough. If you have high-level executive crime…

Yep - It's a good and useful feature. But it's very poorly pitched. Calling it 'retention management' or something would have made it sound like the boring administrative management tool it is, rather than a magic self-destruct button.

Re: Gmail confidential mode

#125
post #69

Earlier quoted context omitted.

Netflix moved their high-definition DRM to end devices by now. The only way to rip their shows is by getting the output from HDMI.

You also need to defeat HDCP for HD content, which is possible but not as easy as a simple HDMI capture.

You just need HDMI splitter that doesn't use HDCP on output.

Re: Gmail confidential mode

#126
post #48
post #19

Earlier quoted context omitted.

The Airbnb app prevents screenshots on certain pages on the OS level on Android, I'm sure the Gmail app will do the same.

Netflix does the same. If I owned my device I suppose I'd be the one to make decision about when I can screenshot and can't.

It's stuff like this that's hyping me for projects like the Librem 5[1]. Sure, I might lose out on some functionality, but at least I can use my device as I please, and I and the community can make alternatives without those restrictions. I don't think it'll "catch on", but I sure hope that it becomes relevant enough to make some of these app developers consider supporting it.

[1] https://puri.sm/products/librem-5/

Re: Gmail confidential mode

#127

Earlier quoted context omitted.

There are two schools of thought: 1) Security has to be enforced by code 2) Your employees are reasonable, and won't try to maliciously bypass security controls I'm firmly in camp #2. In a normal corporate setting, a locked door or a locked cabinet is security, even with a cheap, easily pickable lock. That's all this is. And for 95% of corporate applications, that's good enough. If you have high-level executive crime…

That only works for internal communications. Once it leaves Google's servers, you lose all control. I don't know the specifics here, but the only ways to guarantee that an email server somewhere isn't caching your emails (and I don't trust Google to not cache them either) is to either encrypt them (GPG) or require hitting your server to read the email (potentially what Google is doing), and that doesn't prevent the u…

Pretty much anything that can be consumed (read, viewed, listened to) by a person can be recorded and retransmitted in some form. This has always been true to a certain degree of course. With everyone carrying around a recording device almost everywhere, it's even truer today.

Sneaking a photo of a screen used to at least require a certain premeditation that was spy movie stuff. Today, it's casually pulling a smartphone out of a pocket.

If anyone can see or hear somewhere, barring the seeing or hearing being confined to a secure environment it can be easily and casually recorded.

Re: Gmail confidential mode

#128
post #123

Earlier quoted context omitted.

There are two schools of thought: 1) Security has to be enforced by code 2) Your employees are reasonable, and won't try to maliciously bypass security controls I'm firmly in camp #2. In a normal corporate setting, a locked door or a locked cabinet is security, even with a cheap, easily pickable lock. That's all this is. And for 95% of corporate applications, that's good enough. If you have high-level executive crime…

>Sending an email which communicates something and disappears in a week is helpful. There's nothing on the page that says google will purge all copies after the deletion date. I'd imagine that because google keeps backups, it'd still be available by subpoenaing google.

It explicitly said yes:

> Additionally, if your users send or receive messages in Gmail confidential mode, Vault will retain, preserve, search and export confidential mode messages. The message body of received messages will be accessible in Vault only if the sender of the message is from within your organization. Learn more about how Vault works for confidential mode messages here.

Re: Gmail confidential mode

#129

I feel that many of these pseudo-secure, proprietary enhancements to email create a false sense of security for non-tech-savvy users. Given the smoke-and-mirrors presentation of this as a way to "secure your email^tm" and the plethora of recent info leaks, i am sure some poor c-level exec will get caught inadvertently sharing something with an external recipient thinking that it will disappear in a few days, but then…

Sex ed is not the best example as it is a political hot potato in many places where the right want to limit sex ed and the left want to expand it.

Re: Gmail confidential mode

#130

Earlier quoted context omitted.

There are two schools of thought: 1) Security has to be enforced by code 2) Your employees are reasonable, and won't try to maliciously bypass security controls I'm firmly in camp #2. In a normal corporate setting, a locked door or a locked cabinet is security, even with a cheap, easily pickable lock. That's all this is. And for 95% of corporate applications, that's good enough. If you have high-level executive crime…

That only works for internal communications. Once it leaves Google's servers, you lose all control. I don't know the specifics here, but the only ways to guarantee that an email server somewhere isn't caching your emails (and I don't trust Google to not cache them either) is to either encrypt them (GPG) or require hitting your server to read the email (potentially what Google is doing), and that doesn't prevent the u…

I think this is only for internal communications. They were talking about this feature being “enabled by your GSuite domain administrator.” Presumably it only works for email sent between members of the affected domain (though I’m not sure why they’d fail to mention that.)
Post reply on HN