This has the potential to create a huge legal headache. We can no longer rely on email to be there in our archive and presented as evidence in court, but now have to worry about expiry. In many countries an exchange of emails which represents a series of terms, restrictions, an offer, and finally acceptance can be considered a legally binding contract between parties and can be presented in court. With expiry and ema…
Is this situation not the same as verbally binding legal contracts? What you need is to record your expiring messages otherwise it'll just devolve into a they said, they said in the courtroom.
Gmail confidential mode
201–206 of 206 posts
Re: Gmail confidential mode
#202I feel that many of these pseudo-secure, proprietary enhancements to email create a false sense of security for non-tech-savvy users. Given the smoke-and-mirrors presentation of this as a way to "secure your email^tm" and the plethora of recent info leaks, i am sure some poor c-level exec will get caught inadvertently sharing something with an external recipient thinking that it will disappear in a few days, but then…
There are two schools of thought: 1) Security has to be enforced by code 2) Your employees are reasonable, and won't try to maliciously bypass security controls I'm firmly in camp #2. In a normal corporate setting, a locked door or a locked cabinet is security, even with a cheap, easily pickable lock. That's all this is. And for 95% of corporate applications, that's good enough. If you have high-level executive crime…
If the government comes knocking with a secret subpoena, what is "reasonable"? If someone malicious breaks in to your system, does it matter that this person isn't an employee?
For "95% of corporate applications", even plain email is good enough.
Re: Gmail confidential mode
#203Earlier quoted context omitted.
You aren't really sending email any more, just a link to a website.
This is unfortunately how lots of people and companies think "secure" email needs to work. Any message from my bank or doctor works this way even it is something as simple as an appointment reminder. It is massive waste of user's time and programing effort, but I'm afraid that is where the world is moving.
Dates of service for a patient are protected health information. Most covered entities and business associates won't risk sending any PHI using methods that are not covered under the safe harbor provisions of the HITECH act. So... endless proliferation of "secure email" systems instead of using email. (And I don't see S/MIME taking off anytime soon as an alternative, even though that would be sufficient to qualify for safe harbor.)
Re: Gmail confidential mode
#204Earlier quoted context omitted.
It explicitly said yes: > Additionally, if your users send or receive messages in Gmail confidential mode, Vault will retain, preserve, search and export confidential mode messages. The message body of received messages will be accessible in Vault only if the sender of the message is from within your organization. Learn more about how Vault works for confidential mode messages here.
I would not read that to imply that the message is not available for discovery. Legal pressure is legal pressure, and data is very hard to delete.
Re: Gmail confidential mode
#205Earlier quoted context omitted.
How? If you send an email with this on to me@protonmail.com and I download the message to my IMAP client how does google magically reach out and delete it from my hard drive? Is the email HTML only that only displays the text when the user is online and that text is fetched from the Google server? Let us say it is and I view the email, how does Google stop me from cutting and pasting that email using my thunderbird,…
You view the message on a Google server through a browser. The message body is never actually sent to the recipient's address. "When someone sends a confidential mode message, Gmail removes the message body and any attachments from the recipient's copy of the message. These are replaced with a link to the content. Gmail clients make the linked content appear as if it's part of the message. Third-party mail clients di…
Re: Gmail confidential mode
#206Earlier quoted context omitted.
There are two schools of thought: 1) Security has to be enforced by code 2) Your employees are reasonable, and won't try to maliciously bypass security controls I'm firmly in camp #2. In a normal corporate setting, a locked door or a locked cabinet is security, even with a cheap, easily pickable lock. That's all this is. And for 95% of corporate applications, that's good enough. If you have high-level executive crime…
Camp #2 is naive and dangerous thinking if your company protects anything of value. Even if every employee is honest today, one of them can be extorted tomorrow. If you allow your employees easy access to substantial value without hard technical controls to enforce accountability then you are creating a situation where someone has reason to threaten or harm your employees. Gas stations have "Never more than $200 in t…
95% isn't nearly secure enough. You're actually looking for the one malicious agent among thousands. If you conduct contracting bids, you have to realize that at any moment your employees can be offered incentive to leak, and their leaks will cost millions of dollars.
So when we apply our strict need to know policies and data transfer tracking, it's not about trusting individual employees. It's about finding a needle in a haystack.