Live data from Hacker News

Gmail confidential mode

gsuiteupdates.googleblog.com

161–170 of 206 posts

Re: Gmail confidential mode

#161

If anyone is curious how it works with external accounts, I just tested it: 1) Mail arrives (subject intact) with text like "John Doe has sent you an email via Gmail confidential mode" and a "View Email" link 2) The link takes you to a "To view this email, you must first confirm your identity. A one-time passcode will be sent to (your email)" page. 3) Entering the separately-emailed passcode lets you see the email bo…

Ugh... there are companies that did this sort of stuff for Outlook users, and it's a royal pain in the ass.

It's not searchable, it can't be archived for legal purposes this way, this is a nightmare for anyone that does business with you.

Re: Gmail confidential mode

#162
Work is the one place this seems OK: if the company provides the email service, it can hide the forward button or whatever if it thinks that advances its interests.

Still think disclaimers about the limits (in the UI, not just the blog post) have to be be stronger. It could help avoid accidental leakage and communicate your intent to keep the contents confidential, but it's absolutely no use against someone hostile. I feel like the name should be more like "mark as confidential" or something, to clearly get across it's a strong suggestion but has no hard enforcement behind it.

Re: Gmail confidential mode

#163
post #55

I love the concept as a sender, I hate the concept as a receiver. It means a ton more mental overhead: "do I need to jot down the info from this email somewhere (manually?) now because at some point it's going to expire or my access is going to be revoked?". Frustrating. It's the opposite of all the benefits of gMail search.

This will result in one of two things from me: 1) auto forward everything to a non-gmail archive account 2) if blocked, finally leave gmail

Someone posted further up that when you send a "secure" email to an outside the company email address, they get a link to ope the email and have to enter a one-time code that is emailed to them.

So even forwarding is broken, as is search for those of us that search our emails a lot.

Re: Gmail confidential mode

#164
post #6

Earlier quoted context omitted.

Won't it simply fallback to regular email view on external clients, like outlook's "recall email" function?

The reasonable implementation would be to not send anything more than a link to a site where the receiver can view the content.

Which is exactly what this does... and now I can't search my email for relevant information anymore.

This is a step back.

Re: Gmail confidential mode

#165

Earlier quoted context omitted.

But anyone can screenshot the message or take a photo of it. The point is that it's not actually enforced.

Anyone can screenshot or take a photo of any decrypted message. The question is when the email leaves Google's servers and whether you can trust Google with that same document. Personally, if I had a message where I would consider a tool like this, I would just encrypt it on the client with PGP or something.

> Anyone can screenshot or take a photo of any decrypted message.

Yes, but ordinary decrypted messages don't claim to have superpowers like self-destructing.

Re: Gmail confidential mode

#167
This is so incredibly stupid and irresponsible on so many levels.

Beyond obvious lock-in "Gmail Confidential Mode" tells users SMS is secure (it isn't), teaches users they can prevent message printing (they can't), and teaches users to open links in emails from strangers to then put in their Google credentials to view the message!

Was anyone on the Google Security team given a chance to look at this before it got shoved out there? I know there are people at Google smarter than this.

This is a massive setback in educating users about actually useful security measures.

Re: Gmail confidential mode

#168
post #130

Earlier quoted context omitted.

That only works for internal communications. Once it leaves Google's servers, you lose all control. I don't know the specifics here, but the only ways to guarantee that an email server somewhere isn't caching your emails (and I don't trust Google to not cache them either) is to either encrypt them (GPG) or require hitting your server to read the email (potentially what Google is doing), and that doesn't prevent the u…

I think this is only for internal communications. They were talking about this feature being “enabled by your GSuite domain administrator.” Presumably it only works for email sent between members of the affected domain (though I’m not sure why they’d fail to mention that.)

Does that mean I then can't use a native mail client?

Re: Gmail confidential mode

#169

Earlier quoted context omitted.

But anyone can screenshot the message or take a photo of it. The point is that it's not actually enforced.

Anyone can screenshot or take a photo of any decrypted message. The question is when the email leaves Google's servers and whether you can trust Google with that same document. Personally, if I had a message where I would consider a tool like this, I would just encrypt it on the client with PGP or something.

The person I replied to wrote that this was "algorithmically enforced". I'm just pointing out that this is incorrect.

Re: Gmail confidential mode

#170

I feel that many of these pseudo-secure, proprietary enhancements to email create a false sense of security for non-tech-savvy users. Given the smoke-and-mirrors presentation of this as a way to "secure your email^tm" and the plethora of recent info leaks, i am sure some poor c-level exec will get caught inadvertently sharing something with an external recipient thinking that it will disappear in a few days, but then…

Huh? Can't print this email? Let me forward to my non-secure other address. Huh, message is going to expire? Better make a screenshot that syncs who knows where. If they were serious, they'd create a mode that mirrors Protonmail, where they can't even read your stuff. And make it easy to use PGP. As suggested below/above, the fact that our company Office365 Android env stops me from copy pasting text to other apps do…

In real life, most of the corporate leaks are accidental. Disappearing messages, and sharing/printing restrictions can perfectly augment employee training, reminding them that some things require more careful touch, and reduce the chance of making thoughtless mistake. Sure, making email e2e-encrypted is a good thing, but completely different one.
Post reply on HN