Live data from Hacker News

Gmail confidential mode

gsuiteupdates.googleblog.com

131–140 of 206 posts

Re: Gmail confidential mode

#131

I would like to see Gmail offer end-to-end encryption for "confidential" emails.

How are they supposed to do that on the protocol level?

Protonmail allows you to add PGP key. Not sure if the user just sees 'garbage' data inside the email but it's entirely possible to send E2EE email already, just encrypt the contents of the message and send that across.

If the person has the key, they can decrypt it.

Re: Gmail confidential mode

#132

Earlier quoted context omitted.

I assumed it was in the context of advertising. You literally can't have an email service that doesn't process your emails somehow. Spam filtering and phishing protection has to work on the content of the email, the act of sending email needs to read parts of it to send it. At the absolute least they need to "read" your email to store it's contents and send/display them. If that is something you want to prevent, then…

The OP mentioned Google reading their email and does not mention the context of advertising you assumed. Another poster pointed out that Google no longer scans Gmail for advertising purposes anyways: https://variety.com/2017/digital/news/google-gmail-ads-email... . I understand what you are saying about all email getting "processed" however, Google is doing way more to process email than spam protection or else they…

The subprocessesors page lists Google subsidiaries, datacenter subcontractors, and customer support contractors.

None of those things are "external people we automatically share your email with". They're "Google" and the people who you'd ask for help when you call a customer service line.

Re: Gmail confidential mode

#133

I feel that many of these pseudo-secure, proprietary enhancements to email create a false sense of security for non-tech-savvy users. Given the smoke-and-mirrors presentation of this as a way to "secure your email^tm" and the plethora of recent info leaks, i am sure some poor c-level exec will get caught inadvertently sharing something with an external recipient thinking that it will disappear in a few days, but then…

> In my utopia world, i'd love to see basics of information privacy and personal security be taught in schools akin to Driver's Ed or Sex Ed classes.

Except that the last two don't change much while keeping pace with first is like riding a tiger. You can never get off.

Re: Gmail confidential mode

#135
post #100

Earlier quoted context omitted.

How long before someone makes a chrome browser plugin that will automatically screenshot and download any message flagged in this manner? Completely agree with your last sentiment. We all assume that "kids these days" grow up well aware of these things, but my experience to date has been that new hires are disturbingly unaware of these things.

The "kids are tech savvy these days" narrative seems pretty ridiculous once you consider the fact that most of them have never so much as manually installed a piece of software that didn't involve an "app store" on a touchscreen device.

This 1000x

They don't know computers any more then they know toasters. They push a button and get a result. If not reboot it and push button again.

Re: Gmail confidential mode

#136

I feel that many of these pseudo-secure, proprietary enhancements to email create a false sense of security for non-tech-savvy users. Given the smoke-and-mirrors presentation of this as a way to "secure your email^tm" and the plethora of recent info leaks, i am sure some poor c-level exec will get caught inadvertently sharing something with an external recipient thinking that it will disappear in a few days, but then…

There are two schools of thought: 1) Security has to be enforced by code 2) Your employees are reasonable, and won't try to maliciously bypass security controls I'm firmly in camp #2. In a normal corporate setting, a locked door or a locked cabinet is security, even with a cheap, easily pickable lock. That's all this is. And for 95% of corporate applications, that's good enough. If you have high-level executive crime…

I agree with your stance -- in a vast majority of corporate setting trying to enforce security with code tends to cause more problems than it solves. It alienates users and makes them skip sanity checks and use loopholes (whatever is allowed by the security must be OK to use). Informing users of the policy and providing tools for them to voluntarily check compliance when needed works much better.

> This also helps with email retention policies. Sometimes you want ephemeral communications you don't want a record of.

This IMO is a lost battle. Once "Sent" gets pressed you should assume the message is out in the wild (any retention policies only complicate experience and can be ignored/countered by clients). If you want ephemeral communication, pick up the phone or talk face to face. My 2c.

Re: Gmail confidential mode

#137

Earlier quoted context omitted.

this is nothing more than a "me-too" feature to stack up one more checkbox in the gmail vs exchange sales pitch https://support.office.com/en-us/article/mark-your-email-as-...

I imagine they will show confidential emails to other gmail users inline, but make a link for non gmail users. It is in Google's interest to make GMail less and less the same as "plain mail", until you are forced (for practical reasons) to create a Gmail account to interact with other Gmail users. Together with Amp and Chrome, eventually we will be at a point where the decentralized internet is replaced by Google's s…

Embrace, Extend, Extinguish.

Re: Gmail confidential mode

#138

I feel that many of these pseudo-secure, proprietary enhancements to email create a false sense of security for non-tech-savvy users. Given the smoke-and-mirrors presentation of this as a way to "secure your email^tm" and the plethora of recent info leaks, i am sure some poor c-level exec will get caught inadvertently sharing something with an external recipient thinking that it will disappear in a few days, but then…

There are two schools of thought: 1) Security has to be enforced by code 2) Your employees are reasonable, and won't try to maliciously bypass security controls I'm firmly in camp #2. In a normal corporate setting, a locked door or a locked cabinet is security, even with a cheap, easily pickable lock. That's all this is. And for 95% of corporate applications, that's good enough. If you have high-level executive crime…

Exactly. You might just forward an e-mail to someone with an action without thinking of the e-mail chain below.

But if you're taking screenshots or photos of a secure e-mail because it doesn't allow you to copy the text, you know you're doing wrong.

Re: Gmail confidential mode

#139
post #19

Earlier quoted context omitted.

The Airbnb app prevents screenshots on certain pages on the OS level on Android, I'm sure the Gmail app will do the same.

Worthless from a security standpoint, because the screenshots can still be taken from a desktop or laptop device.

You can always steal something if it can be seen. I think it's more of to clearly express that they don't want you to screenshot whatever it is. You can subvert it but you know you're doing something you shouldn't.

I don't use AirBnB so I can't actually think why you'd want to disable screenshots in certain places. I'm curious now though, can someone tell me?

Re: Gmail confidential mode

#140

I feel that many of these pseudo-secure, proprietary enhancements to email create a false sense of security for non-tech-savvy users. Given the smoke-and-mirrors presentation of this as a way to "secure your email^tm" and the plethora of recent info leaks, i am sure some poor c-level exec will get caught inadvertently sharing something with an external recipient thinking that it will disappear in a few days, but then…

"A lock only keeps honest people out" is ancient wisdom and this is not a new debate.
Post reply on HN