Live data from Hacker News

Gmail confidential mode

gsuiteupdates.googleblog.com

71–80 of 206 posts

Re: Gmail confidential mode

#71
post #9

> Recipients who have malicious programs on their computer may still be able to copy or download your messages or attachments. “Malicious programs” such as any standards-complaint email software?

If I were implementing something like this, it would just be a link to an auto-expiring viewer page, if you opened the email in a third-party email client. And according to Google, that's exactly how it's implemented: https://support.google.com/mail/answer/7674059 "Malicious programs" here most likely refers to things like keyloggers.

Oh god, this is going to be great for phishing.

Re: Gmail confidential mode

#72
I feel that many of these pseudo-secure, proprietary enhancements to email create a false sense of security for non-tech-savvy users. Given the smoke-and-mirrors presentation of this as a way to "secure your email^tm" and the plethora of recent info leaks, i am sure some poor c-level exec will get caught inadvertently sharing something with an external recipient thinking that it will disappear in a few days, but then find themselves in a middle of a publicity nightmare.

In my utopia world, i'd love to see basics of information privacy and personal security be taught in schools akin to Driver's Ed or Sex Ed classes.

Re: Gmail confidential mode

#73
post #57

Outlook has had this for very long time. Even consumer versions have some of the rights management features. At my new job I am using Gmail via GSuites for first time and I didnt know how antiquated Gmail is. Lots of missing features and rather confusing UI. But adding more security options and giving users control is good.

Coming from O365 the thing I miss most is sweeping rules.

Re: Gmail confidential mode

#74
post #10
post #5

Earlier quoted context omitted.

> Note: Although confidential mode helps prevent the recipients from accidentally sharing your email, it doesn't prevent recipients from taking screenshots or photos of your messages or attachments. Recipients who have malicious programs on their computer may still be able to copy or download your messages or attachments. it's not a security feature. it's to help prevent users shooting themselves in the foot.

Can you explain how "removing options for recipients to forward, copy, print, and download" could "help prevent users shooting themselves in the foot"?

The first thing that springs to mind is attorney client privileged emails. My understanding from how legal explained it to me is that if I have a privileged email conversation with them but then forward it to my boss that communication wouldn't be privileged (and I just shot myself in the foot legally)

Re: Gmail confidential mode

#75
post #40

They're cocky enough now to think that they can take on the e-mail as a de facto standard and do the Embrace, Extend, Extinguish dance with it. This is akin to DRM and just like DRM it will be ineffective - if I can see it, I can forward it, copy it, and print it, and do whatever I want with it. Users are being led to believe that they can enforce these sorts of controls over email but they can't.

Google loves DRM though.

They helped launch WebDRM. Now we have EmailDRM, with a Google-account being mandatory for all recipients.

What’s the next standard Google plan on ruining?

Re: Gmail confidential mode

#76

Earlier quoted context omitted.

Because they very explicitly say they don't: https://gsuite.google.com/learn-more/security/security-white...

I'm probably misunderstanding "read your emails" but the link you provided suggests that GSuite users are very much subject to their "emails being read" but with greater restrictions on who can read it and why ( https://gsuite.google.com/terms/dpa_terms.html ). Lots of text about following EU or other legislation, but definitely this text does not say, "Google does not process your email." There is an entire page ded…

I assumed it was in the context of advertising.

You literally can't have an email service that doesn't process your emails somehow. Spam filtering and phishing protection has to work on the content of the email, the act of sending email needs to read parts of it to send it. At the absolute least they need to "read" your email to store it's contents and send/display them.

If that is something you want to prevent, then i think using any hosted email provider is completely out of the question. Email in general might be unusable if that is the level of privacy you are looking for.

I normally hate parroting back the "if you don't like it then don't use it" line of thinking, but in this case it's the only real option. Sure they could offer a special service with no scanning, spam protection, etc... But they'd still need to store and "read" your email to work, and they'd still need to be able to do some analytics to protect their system from you (you could be a bad actor that would act in bad faith, and they need to protect against that to keep the entire service running). For someone that doesn't trust that they aren't going to just "read" your email anyway even if they say they only use it for some very limited things like spam protection, an additional layer of "we promise we also won't do this" won't change anything.

If you want absolute control over exactly what bytes are sent and where they go, host your own email service. Just like how if you want to be completely 100% absolutely sure that nobody is going to spit in your food, and you don't trust anyone else to not spit in your food, you need to cook it yourself.

Re: Gmail confidential mode

#77
post #9

> Recipients who have malicious programs on their computer may still be able to copy or download your messages or attachments. “Malicious programs” such as any standards-complaint email software?

If I were implementing something like this, it would just be a link to an auto-expiring viewer page, if you opened the email in a third-party email client. And according to Google, that's exactly how it's implemented: https://support.google.com/mail/answer/7674059 "Malicious programs" here most likely refers to things like keyloggers.

"Malicious programs" can also be taking a screenshot or printing the email.

Re: Gmail confidential mode

#80
post #49

Will this work only for Gmail/Gsuite clients?

No, they're just sending a link in the email with some UI fluff to make it a little more transparent in GMail.

An enterprise feature that doesn't work with Outlook might as well not exist.

Post reply on HN