4 ms·
"On the recipient’s side, the person was using the existing version of Gmail and received a link to view the confidential email. The recipient had to log into t
by harshulpandav 8y ago
"On the recipient’s side, the person was using the existing version of Gmail and received a link to view the confidential email. The recipient had to log into their Google account once again to view the content."
IMO this is an open invitation to phishers.
- kbsletten 8y agoI think the genie's out of the bottle on that one, I can already do the same with a million other services.
- croshan 8y agoWell, this gives a plausible reason for having to log back into an account you're already logged into. And normalizes the behavior. So the next time you get an email from "google", you won't think twice about why you have to log back in.
- kbsletten 8y agoYeah, but I think the battle is lost. All users should always double-check why they need to enter credentials on any page from any website. I think that the simple act of logging into a site to use it has already "normalized" the need to re-enter credentials to a point beyond saving.
- Twirrim 8y agoIt just encourages and exposes a wider range of people to an attack vector. No one should be actively _training_ people to open random links in an email.
- e12e 8y agoOh, so Gmail is finally moving away from email. Guess it was a question of time.
- inopinatus 8y agoIf anything it sounds closer in outline to djb's proposed Internet Mail 2000 (https://en.wikipedia.org/wiki/Internet_Mail_2000 https://en.wikipedia.org/wiki/Internet_Mail_2000) in which initial storage is the responsibility of the sender, not the recipient, thereby making spam much more expensive. This implementation, however - especially centralized tracking & policy enforcement, and HTTP as the delivery substrate instead of some properly designed protocol - typify everything I dislike about Google's product design choices. And if the open invitation to phishing wasn't bad enough, expiring messages sound to me like a built-for-purpose gaslighting tool.
- e12e 8y agoThat's interesting - I hadn't thought about greylisting like that; but I suppose that's one way to look at it. The sender needs to queue the mail, which effectively means "take responsibility for initial storage".
- ajnin 8y ago> djb's proposed Internet Mail 2000 (https://en.wikipedia.org/wiki/Internet_Mail_2000 https://en.wikipedia.org/wiki/Internet_Mail_2000) in which initial storage is the responsibility of the sender Seems even better for spammers and advertisers of the world since they wouldn't even have to send mail nor store it, they could just write mail server software to trivially generate it on demand, and they would instantly know who's opening their mail.
- inopinatus 8y agoNo, that won't happen, because the consequences are severe: they're instantly, globally, permanently and publicly blacklisted as a spam server.
- drewg123 8y agoI agree about phishers. My bank does this for their "secure email". The first time I got one of their "secure emails", I first assumed it was a phishing attempt for my bank credentials.
- exikyut 8y agoPossibly. The current ad-hoc approach of "type this URL in" that's used in various places could be extended in this case to "click this link, or alternatively go to this short address and type this short code in". This would actually work because the short URLs would be per-recipient-account - they wouldn't need to be "globally" unique! Alas, we live in a denialist dystopia, not a self-acknowledging one, so the above will probably never happen - per-recipient short URLs rely firmly on a global social graph that can predict with a high degree of accuracy who is highly unlikely to click on who else's link. Google has one of these, but nobody's supposed to realize how much of an oracle it is. So, we've just upgraded to "for security, please click this 10000-character-long URL" emails being sent from Google itself. The phishers are laughing.
- exikyut 8y agoThis comment is a bit old now, but I want to clarify some things that I completely skittered over and just didn't explain adequately. It isn't a case of "not clicking on someone else's link", it's a case of never receiving someone else's link. As it is, clueless people will forward their links in attempts to let others read their messages. Of course this won't work (I don't expect so anyway). But, if person A and person B both receive the same short code, which would (obviously/presumably, in such a scheme) unlock different messages for both, that would be a very confusing user experience. Given the "enterprise security" standpoint this (somewhat) confusing feature seems to be marketed toward, I can see this being the exact kind of situation that enterprises would never want happening (the resulting executive paranoia would undermine the perceived security of the system). And so this folds into the global social graph thing I was talking about.