Live data from Hacker News

Gmail confidential mode

gsuiteupdates.googleblog.com

171–180 of 206 posts

Re: Gmail confidential mode

#171

I feel that many of these pseudo-secure, proprietary enhancements to email create a false sense of security for non-tech-savvy users. Given the smoke-and-mirrors presentation of this as a way to "secure your email^tm" and the plethora of recent info leaks, i am sure some poor c-level exec will get caught inadvertently sharing something with an external recipient thinking that it will disappear in a few days, but then…

Huh? Can't print this email? Let me forward to my non-secure other address. Huh, message is going to expire? Better make a screenshot that syncs who knows where. If they were serious, they'd create a mode that mirrors Protonmail, where they can't even read your stuff. And make it easy to use PGP. As suggested below/above, the fact that our company Office365 Android env stops me from copy pasting text to other apps do…

I'm curious how they prevent printing.. is it a custom chrome configuration, and they only allow viewing in chrome? Even then... Copy/Paste, F12, copy/paste, etc.

Agreed on the forward thing. Though, fortunately I'm not currently as locked down as your android config, it would seem.

It's a relatively nifty feature for users emailing from/to gmail only and then likely just to match a couple of feature people have come to expect when using Outlook/Exchange(or office 365). But definitely oversold on security.

Re: Gmail confidential mode

#172
post #130

Earlier quoted context omitted.

That only works for internal communications. Once it leaves Google's servers, you lose all control. I don't know the specifics here, but the only ways to guarantee that an email server somewhere isn't caching your emails (and I don't trust Google to not cache them either) is to either encrypt them (GPG) or require hitting your server to read the email (potentially what Google is doing), and that doesn't prevent the u…

I think this is only for internal communications. They were talking about this feature being “enabled by your GSuite domain administrator.” Presumably it only works for email sent between members of the affected domain (though I’m not sure why they’d fail to mention that.)

No. It does, definitely, work with external recipients.

Source: am googler, have used.

Re: Gmail confidential mode

#173
Interesting take from a friend overseas who is into a lot of Security and Data Surveillance.

Me: So, what do you think about Google's Confidential Mode settings? Are you going to use it in your company?

Friend: It is one of the topics heavily debated right now. Especially by our management.

Me: Is that so? Why?

Friend: Lots of legal implications that needs to be addressed.

Me: How about you? What's your take?

Friend: Well, for a start, given Google's history of surveillance, this type of enhancement only just gives them more power and capability to focus on information that are being deemed sensitive by an individual or an organization.

Me: You think so?

Friend: Absolutely. Imagine if this person sends out approximately 100 emails in a day, and marks 5 of them as sensitive or confidential or whatever terms you would like. Google can then sequence the emails to track based on the confidentiality that was set forth on it.

Me: Never thought of things in that perspective.

Friend: Yes. Further to that, they could then add more focus on confidential emails which would have a very specific expiry dates. This becomes more specific to their focus, where they can direct their resources specifically on this.

Me: (Intently listening)....

Friend: It's like this. Assume you have boxes in your house. Each box contains different stuff. Some box may contain your cash, or jewelry or any other important stuff. Now, you have a burglar going inside your house. With a 100 boxes, they would certainly only spend a couple of time to rummage through the boxes. If they can only open 5 boxes, with the possibility of those boxes containing nothing but garbage, then the burglars are not successful in getting your prized stuff. Now imagine having those boxes labeled with stuff like 'MONEY', 'JEWELRY', 'CONFIDENTIAL', 'IMPORTANT TO DISPOSE BY DATE YYYY-MM-DD', etc. Doesn't that give the burglar an easier way to run through the boxes? This eliminates for them wasting on boxes that may have no importance at all.

Me: That is certainly a possibility if you would think of it.

Even though such scenario may be far-fetched from a corporate (Google for Business) standpoint, it is still worthy of a discussion. IMHO.

Re: Gmail confidential mode

#174
post #130

Earlier quoted context omitted.

I think this is only for internal communications. They were talking about this feature being “enabled by your GSuite domain administrator.” Presumably it only works for email sent between members of the affected domain (though I’m not sure why they’d fail to mention that.)

No. It does, definitely, work with external recipients. Source: am googler, have used.

How? If you send an email with this on to me@protonmail.com and I download the message to my IMAP client how does google magically reach out and delete it from my hard drive? Is the email HTML only that only displays the text when the user is online and that text is fetched from the Google server? Let us say it is and I view the email, how does Google stop me from cutting and pasting that email using my thunderbird, et.al. IMAP client?

Re: Gmail confidential mode

#175
post #154

I feel that many of these pseudo-secure, proprietary enhancements to email create a false sense of security for non-tech-savvy users. Given the smoke-and-mirrors presentation of this as a way to "secure your email^tm" and the plethora of recent info leaks, i am sure some poor c-level exec will get caught inadvertently sharing something with an external recipient thinking that it will disappear in a few days, but then…

> In my utopia world, i'd love to see basics of information privacy and personal security be taught in schools Yes! This should be required, beginning in primary school and extended into high school. Concepts like authentication, encryption, man-in-the-middle attack, why authentication without encryption isn't very useful for communication, etc — this is not "technical" (I hate this word; it is used as an excuse not…

In a world where basic civics, economics, and other life skills are not pervasively and effectively taught (at least in the US), I doubt our ability to teach this more complex and somewhat less obviously relevant content.

Re: Gmail confidential mode

#177
post #130

Earlier quoted context omitted.

I think this is only for internal communications. They were talking about this feature being “enabled by your GSuite domain administrator.” Presumably it only works for email sent between members of the affected domain (though I’m not sure why they’d fail to mention that.)

No. It does, definitely, work with external recipients. Source: am googler, have used.

What happens if domains have conflicting policies set?

Re: Gmail confidential mode

#178

I feel that many of these pseudo-secure, proprietary enhancements to email create a false sense of security for non-tech-savvy users. Given the smoke-and-mirrors presentation of this as a way to "secure your email^tm" and the plethora of recent info leaks, i am sure some poor c-level exec will get caught inadvertently sharing something with an external recipient thinking that it will disappear in a few days, but then…

>I feel that many of these pseudo-secure, proprietary enhancements to email create a false sense of security for non-tech-savvy users.

OTOH, circumventing a security measure means deliberately violating someone's boundaries.

For example, I communicate with my friends and partnets with Signal often. We usually keep the disappearing messages setting on so that over time, our ephermeral conversations drift away. (Especially useful since even if someone is not malicious, a stolen or compromised device could leak sensitive conversations).

I suppose someone could capture and save an embarasing conversation. But if they did that, I would turn around and shame them - for violating my boundaries, for breaking my trust, and using that trust to bully me.

I suspect that given how the conversation on privacy has shifted, it would be viewed worse to steal someone's nudees, gripes about friends/coworkers, or jokes made in poor taste than it was to do the original communication.

Total security is impossible, but I can ensure that it will be abundantly evident you are an untrustworthy, phony, and malicious person if you circumvent access controls to leak my communications.

Re: Gmail confidential mode

#179

There's a phrase that large companies often use to explain "puzzling" features like this to detractors: you are not the target audience. Often this phrase is mis-used to cover up straight up bad ideas, but in this case it's right on the money. The target audience for this feature are CIOs of organizations Google sells G-Suite to. Companies do need IRM on emails, to prevent leaks that could happen by accident or inten…

>The target audience for this feature are CIOs of organizations Google sells G-Suite to. Companies do need IRM on emails, to prevent leaks that could happen by accident or intentionally

I encourage anyone with a Gmail to take a lot back 1, 5, 10 years. There's a lot of data there. Setting up an automated deletion policy can be a great risk mitigation feature.

It won't stop malicious insiders, but it will help make sure run of the mill compromises won't be total disasters.

Re: Gmail confidential mode

#180

There's a phrase that large companies often use to explain "puzzling" features like this to detractors: you are not the target audience. Often this phrase is mis-used to cover up straight up bad ideas, but in this case it's right on the money. The target audience for this feature are CIOs of organizations Google sells G-Suite to. Companies do need IRM on emails, to prevent leaks that could happen by accident or inten…

Would like to note more IRM for DLP (data loss prevention) is an upcoming feature:

https://support.google.com/a/table/7539891

> Information Rights Management (IRM) for DLP

> Enable IRM enforcement as a DLP remediation action.

> In development

Post reply on HN