I feel that many of these pseudo-secure, proprietary enhancements to email create a false sense of security for non-tech-savvy users. Given the smoke-and-mirrors presentation of this as a way to "secure your email^tm" and the plethora of recent info leaks, i am sure some poor c-level exec will get caught inadvertently sharing something with an external recipient thinking that it will disappear in a few days, but then…
This feature isn't about security. Email is already pretty secure with TLS and DKIM. This is basically the equivalent of the "DO NO FORWARD" header people use for internal-only information but with a little more UX polish.
Gmail confidential mode
141–150 of 206 posts
Re: Gmail confidential mode
#142Earlier quoted context omitted.
Worthless from a security standpoint, because the screenshots can still be taken from a desktop or laptop device.
You can always steal something if it can be seen. I think it's more of to clearly express that they don't want you to screenshot whatever it is. You can subvert it but you know you're doing something you shouldn't. I don't use AirBnB so I can't actually think why you'd want to disable screenshots in certain places. I'm curious now though, can someone tell me?
Re: Gmail confidential mode
#143Earlier quoted context omitted.
it seems it would be more useful to implement things such as "delete message after X days" or "do not forward" instead of mock features like this. Adding an autodelete feature in gmail is overly complex, requires filters + google scripts.
Did you read the actual article? They added that as well.
Re: Gmail confidential mode
#144The target audience for this feature are CIOs of organizations Google sells G-Suite to. Companies do need IRM on emails, to prevent leaks that could happen by accident or intentionally; to limit email audience; to avoid endless replies-to-all on announcements; to put an expiration date on the "perishable" bits of information; etc. I'm pretty positive that they have to have this to compete with Office 365, which had IRM [1] for a very long time.
Yes, it's not perfect, however, if it's there, it mitigates a lot of the issues I mentioned above. Note the wording: "mitigates", not "fixes".
It's interesting that they still list screenshots as a possibility: email clients (e.g. Outlook) are able to utilize OS mechanisms to prevent those as well. I thought that browser protected media APIs would allow Gmail opt-in to this kind of protection too.
[1]: https://docs.microsoft.com/en-us/office365/SecurityComplianc...
Re: Gmail confidential mode
#145I feel that many of these pseudo-secure, proprietary enhancements to email create a false sense of security for non-tech-savvy users. Given the smoke-and-mirrors presentation of this as a way to "secure your email^tm" and the plethora of recent info leaks, i am sure some poor c-level exec will get caught inadvertently sharing something with an external recipient thinking that it will disappear in a few days, but then…
There are two schools of thought: 1) Security has to be enforced by code 2) Your employees are reasonable, and won't try to maliciously bypass security controls I'm firmly in camp #2. In a normal corporate setting, a locked door or a locked cabinet is security, even with a cheap, easily pickable lock. That's all this is. And for 95% of corporate applications, that's good enough. If you have high-level executive crime…
Gas stations have "Never more than $200 in the drawer" for a reason. Criminals knowing that is the case deters most of them and if it doesn't you are out $200 at most.
Re: Gmail confidential mode
#146Earlier quoted context omitted.
There are two schools of thought: 1) Security has to be enforced by code 2) Your employees are reasonable, and won't try to maliciously bypass security controls I'm firmly in camp #2. In a normal corporate setting, a locked door or a locked cabinet is security, even with a cheap, easily pickable lock. That's all this is. And for 95% of corporate applications, that's good enough. If you have high-level executive crime…
Exactly. You might just forward an e-mail to someone with an action without thinking of the e-mail chain below. But if you're taking screenshots or photos of a secure e-mail because it doesn't allow you to copy the text, you know you're doing wrong.
I can easily imagine this system “training” users to take screenshots, especially if their correspondents are a little to eager to use this feature. It would only take a few rounds of “I sent you this”/“No you didn’t” with the boss, or the computer “eating” important documents.
Now you’ve normalized this deviance and emails are now spread all over creation (including personal devices) and in a much less searchable format....
Re: Gmail confidential mode
#147I feel that many of these pseudo-secure, proprietary enhancements to email create a false sense of security for non-tech-savvy users. Given the smoke-and-mirrors presentation of this as a way to "secure your email^tm" and the plethora of recent info leaks, i am sure some poor c-level exec will get caught inadvertently sharing something with an external recipient thinking that it will disappear in a few days, but then…
There are two schools of thought: 1) Security has to be enforced by code 2) Your employees are reasonable, and won't try to maliciously bypass security controls I'm firmly in camp #2. In a normal corporate setting, a locked door or a locked cabinet is security, even with a cheap, easily pickable lock. That's all this is. And for 95% of corporate applications, that's good enough. If you have high-level executive crime…
In fact, these records will be even more discoverable than the standard inbox dumps because they're pre-curated with messages that the senders thought were sensitive.
It appears the only point where there's an extra hoop to jump through is with an external sender. In cases where that sender is in another jurisdiction or the investigation is purely internal, the added cost will likely stop further inquiry.
I can see legal departments requesting filters to block acceptance of external messages as a result. Just takes the metadata from one confidential email a competitor sends you to make it look like you're a bad colluding boy.
Re: Gmail confidential mode
#148Earlier quoted context omitted.
There are two schools of thought: 1) Security has to be enforced by code 2) Your employees are reasonable, and won't try to maliciously bypass security controls I'm firmly in camp #2. In a normal corporate setting, a locked door or a locked cabinet is security, even with a cheap, easily pickable lock. That's all this is. And for 95% of corporate applications, that's good enough. If you have high-level executive crime…
No, these records will remain discoverable through Vault, unless I'm reading things wrong. In fact, these records will be even more discoverable than the standard inbox dumps because they're pre-curated with messages that the senders thought were sensitive. It appears the only point where there's an extra hoop to jump through is with an external sender. In cases where that sender is in another jurisdiction or the inv…
Re: Gmail confidential mode
#149I feel that many of these pseudo-secure, proprietary enhancements to email create a false sense of security for non-tech-savvy users. Given the smoke-and-mirrors presentation of this as a way to "secure your email^tm" and the plethora of recent info leaks, i am sure some poor c-level exec will get caught inadvertently sharing something with an external recipient thinking that it will disappear in a few days, but then…
Re: Gmail confidential mode
#150> removing options for recipients to forward, copy, print, and download Oh please... Everybody can do a screenshot nowadays, and even Google itself integrated OCR into its Screenshot tool at Android a few years ago. What a waste of time to make the life of people harder who must use this "security" feature!