14 ms·
Gmail confidential mode
- ktpsns 8y ago> removing options for recipients to forward, copy, print, and download Oh please... Everybody can do a screenshot nowadays, and even Google itself integrated OCR into its Screenshot tool at Android a few years ago. What a waste of time to make the life of people harder who must use this "security" feature!
- halayli 8y ago> Note: Although confidential mode helps prevent the recipients from accidentally sharing your email, it doesn't prevent recipients from taking screenshots or photos of your messages or attachments. Recipients who have malicious programs on their computer may still be able to copy or download your messages or attachments. it's not a security feature. it's to help prevent users shooting themselves in the foot.
- a012 8y agoCan you explain how "removing options for recipients to forward, copy, print, and download" could "help prevent users shooting themselves in the foot"?
- stingraycharles 8y agoNot sure why you’re being downvoted. To me it seems only to increase the chance for users to shoot themselves in the foot, as they now have a false sense of security.
- ShinTakuya 8y agoI agree, I can definitely see people thinking "oh, this has the option to forward, it must be safe to share".
- lozaning 8y agoI get a bunch of information through emails at work that Im not allowed to share outside the company, and tons of others that I need to send to people outside the company. If the people sending me the internal company emails mark them as such, I can be sure I never inadvertently forward the wrong emails to the wrong group. I think the threat model is about catching your own mistakes, not preventing bad actors from acting.
- buboard 8y agoit seems it would be more useful to implement things such as "delete message after X days" or "do not forward" instead of mock features like this. Adding an autodelete feature in gmail is overly complex, requires filters + google scripts.
- TrueDuality 8y agoThis feature only works for users of Gmail and specifically web mail. All the users I would want to have an extra layer around 'shoot themselves in the foot' usually also insist on using Outlook to access their email. This is simply a superficial UI that gives a false sense of doing anything for most of the cases.
- ymolodtsov 8y agoThe most important security feature is just the fact that email won’t be saved in that account. I had cases when I had to send or receive a small piece of sensitive data (SSN, bank account details) and we used Virtru for that. Now we can just send in Gmail.
- tdb7893 8y agoThe first thing that springs to mind is attorney client privileged emails. My understanding from how legal explained it to me is that if I have a privileged email conversation with them but then forward it to my boss that communication wouldn't be privileged (and I just shot myself in the foot legally)
- duchenne 8y agoYes, this system does not seem to prevent the information from spreading. I guess that the logic is that most people who know how to make a screenshot also know how to make a fake screenshot. So, let's say that Mr A is not a very honest guy. Moreover, Mr A has a sensitive document that could be a liability in court. He wants to share it with Mr B. But, he does not completely trust Mr B. With this system, he can share it. If Mr B sends a screenshot to the police or a judge, it will be easier for Mr A to claim that the screenshot is fake. That's just a guess... I hope that it was not the intent of the dev, though.
- chronogram 8y agoEven easier, right? Can’t B press F12 and change the content easily? One mail is not enough evidence. A would be better off using something like Snapchat for the confidentiality.
- reustle 8y agoThe Airbnb app prevents screenshots on certain pages on the OS level on Android, I'm sure the Gmail app will do the same.
- enriquto 8y ago> The Airbnb app prevents screenshots on certain pages on the OS level on Android it is creepily dystopian that this sort of behavior is even possible
- Cthulhu_ 8y agoI think you're overreacting there and misappropriating that term to express your outrage, without thinking of realistic use cases. It's a security feature. Bank apps and 2FA apps probably have it as well when displaying sensitive information. In Airbnb it's probably a protective measure to avoid sharing information via screenshots instead of links to the app / website though. That's not dystopian either though.
- realusername 8y agoIt's not a "security" feature, anything which can be displayed can be captured, you can even take a picture of your phone with another phone if you want, it just makes users annoyed without adding any security.
- Spivak 8y agoJust because you can get around a policy doesn't make it ineffective. I'm sure that slight barrier reduced the number of people taking screenshots of their bank app 99%. Perfect is the enemy of good.
- realusername 8y agoIt just gets user annoyed for no reason, why can't they take a screenshot of their bank account anyway? It just makes no sense. I understand banks like it because they are full of regulatory security which don't make sense in real life, that's probably one more to add to the list.
- nukeop 8y agoThe day this comes out I hope there will be a browser extension that automatically strips the retarded DRM by copying the html from the "viewer" website and replies to the original sender with the contents, so that a "cracked" copy of the email is saved in both the sender's and recipient's history as it should have been in the first place.
- heavenlyblue 8y agoNetflix moved their high-definition DRM to end devices by now. The only way to rip their shows is by getting the output from HDMI.
- teilo 8y agoYou also need to defeat HDCP for HD content, which is possible but not as easy as a simple HDMI capture.
- garaetjjte 8y agoYou just need HDMI splitter that doesn't use HDCP on output.
- teilo 8y agoRight. And that means getting a cheap Chinese splitter that may or may not strip HDCP, buying one on the grey market, or making one yourself.
- nova22033 8y agohttps://gawker.com/the-best-times-reporters-were-accidentally-emailed-insi-1778700227 https://gawker.com/the-best-times-reporters-were-accidentall...
- lern_too_spel 8y agoThis is a feature Outlook has had for years. Users understand it. It's only pedantic geeks who don't seem to understand the use cases.
- saberience 8y agoOr just take a photo of the screen with their iPhone!
- miki123211 8y agoWill this be a lock in feature that makes it harder for people using external mail clients?
- brajesh 8y agoWon't it simply fallback to regular email view on external clients, like outlook's "recall email" function?
- saagarjha 8y ago> Recipients who have malicious programs on their computer may still be able to copy or download your messages or attachments. “Malicious programs” such as any standards-complaint email software?
- Zarel 8y agoIf I were implementing something like this, it would just be a link to an auto-expiring viewer page, if you opened the email in a third-party email client. And according to Google, that's exactly how it's implemented: https://support.google.com/mail/answer/7674059 https://support.google.com/mail/answer/7674059 "Malicious programs" here most likely refers to things like keyloggers.
- deleted 8y ago[deleted]
- incompatible 8y agoYou aren't really sending email any more, just a link to a website.
- tgragnato 8y agoDoes this mean that I only need a new reject rule in my spam filter?
- josteink 8y agoAlso requiring the recipient to log into Google to allow google to track them.
- acdha 8y agoI agree that this is something to be concerned about but according to the instructions it doesn't require a Google login so you could do the entire session in a private browsing window if you wanted as long as you can get the verification code by SMS or the email address.
- samuelfekete 8y agoI would like to see Gmail offer end-to-end encryption for "confidential" emails.
- ymolodtsov 8y agoHow are they supposed to do that on the protocol level?
- tcd 8y agoProtonmail allows you to add PGP key. Not sure if the user just sees 'garbage' data inside the email but it's entirely possible to send E2EE email already, just encrypt the contents of the message and send that across. If the person has the key, they can decrypt it.
- codebook 8y agoDo you really want to hand over your private PGP key to 3rd-party company? I never ever won't do that. If I will use PGP key for web email service, it is only when the service provider gives a way to communicate with my local machine so that the email text is SIGNED IN MY MACHINE and send it back to the email provider, then send to the recipients. For encryption, it can be done with public key of the recipients.
- swalsh 8y agoEh, frankly while I Trust google a lot, I wouldn't trust any third party including Google for my end-to-end encryption needs.
- cryptonector 8y agoEnd-to-end encrypted e-mail is an exceedingly difficult problem. First, none of the envelope can be encrypted, sorry -- that's routing information, and it must be visible to all involved MTAs. The communications between MTAs can be encrypted with TLS, but the MTAs get to see the envelope. Second, end-to-end key management is an O(N^2) problem unless you have introducers. Who shall be your introducers? If the introduction problem was trivial to solve, we'd all be using PGP/whatever now. But it's not trivial at all. Besides that, it's nice to have IMAP/whatever be able to search your e-mail. Which means your e-mail servers need to be able to see your e-mail. You can give up on this if you have your devices decrypt and index your e-mail. This is the only part of the problem that is "easy" -- and you can even encrypt e-mail as it comes in when it's not already encrypted.
- Simon_says 8y agoThey're about two weeks early for April Fools.
- itronitron 8y ago'con' was auto-corrected to 'confidential'
- newsbinator 8y agoI love the concept as a sender, I hate the concept as a receiver. It means a ton more mental overhead: "do I need to jot down the info from this email somewhere (manually?) now because at some point it's going to expire or my access is going to be revoked?". Frustrating. It's the opposite of all the benefits of gMail search.
- stubish 8y agoIts kind of the point to frustrate the receiver. If I don't want you archiving or resending what I sent to you, I can use this feature to do that. Sure, you can jot down the information, make a screenshot or similar if you wish to override my wishes, in much the same way as you could record a phone call, but the onus is on you. Hopefully you stored my confidential data somewhere secure and GDPR compliant, and not left a copy in your mailbox as a lawsuit waiting to happen. And if I protect emails this way that I would be happy for you to archive, then I'm an idiot.
- prepend 8y agoThis will result in one of two things from me: 1) auto forward everything to a non-gmail archive account 2) if blocked, finally leave gmail
- glennpratt 8y agoThis is a Gsuite admin feature, leaving personal Gmail does nothing and if you happen to control your Gsuite account... just don't turn it on.
- X-Istence 8y agoSomeone posted further up that when you send a "secure" email to an outside the company email address, they get a link to ope the email and have to enter a one-time code that is emailed to them. So even forwarding is broken, as is search for those of us that search our emails a lot.
- bambax 8y agoThis is very bad and makes me angry. If you send me an email I need to not worry about being able to save the information forever. Once somebody sends out something it is no longer theirs. But now the cancer of DRM leaks into our personal lives???!? At the very least receivers should be able to automatically reject any such email.
- Kamshak 8y agoThis isn't for your personal E-Mail, it's for professional E-Mail via GSuite
- sverige 8y agoThe title made me think Google was announcing that they won't read my email any more. Alas.
- chronogram 8y agoThis is for gsuite, so I suppose at least they don’t read your mails there.
- aw4y 8y agowhy do you suppose that?
- Klathmon 8y agoBecause they very explicitly say they don't: https://gsuite.google.com/learn-more/security/security-whitepaper/page-6.html https://gsuite.google.com/learn-more/security/security-white...
- somebehemoth 8y agoI'm probably misunderstanding "read your emails" but the link you provided suggests that GSuite users are very much subject to their "emails being read" but with greater restrictions on who can read it and why (https://gsuite.google.com/terms/dpa_terms.html https://gsuite.google.com/terms/dpa_terms.html). Lots of text about following EU or other legislation, but definitely this text does not say, "Google does not process your email." There is an entire page dedicated to "subprocessors" who consume your email to provide services (https://gsuite.google.com/intl/en/terms/subprocessors.html https://gsuite.google.com/intl/en/terms/subprocessors.html). I get that this agreement presents restrictions on how Google can process GSuite user data, but it does not prevent it from doing so.
- Klathmon 8y agoI assumed it was in the context of advertising. You literally can't have an email service that doesn't process your emails somehow. Spam filtering and phishing protection has to work on the content of the email, the act of sending email needs to read parts of it to send it. At the absolute least they need to "read" your email to store it's contents and send/display them. If that is something you want to prevent, then i think using any hosted email provider is completely out of the question. Email in general might be unusable if that is the level of privacy you are looking for. I normally hate parroting back the "if you don't like it then don't use it" line of thinking, but in this case it's the only real option. Sure they could offer a special service with no scanning, spam protection, etc... But they'd still need to store and "read" your email to work, and they'd still need to be able to do some analytics to protect their system from you (you could be a bad actor that would act in bad faith, and they need to protect against that to keep the entire service running). For someone that doesn't trust that they aren't going to just "read" your email anyway even if they say they only use it for some very limited things like spam protection, an additional layer of "we promise we also won't do this" won't change anything. If you want absolute control over exactly what bytes are sent and where they go, host your own email service. Just like how if you want to be completely 100% absolutely sure that nobody is going to spit in your food, and you don't trust anyone else to not spit in your food, you need to cook it yourself.
- NetBeck 8y agoAOL 4.0 had a similar function [1]. [1] https://web.archive.org/web/20130115034301/http://americanshelflife.wordpress.com/2008/05/26/ode-to-aols-unsend-function/ https://web.archive.org/web/20130115034301/http://americansh...
- targ2002 8y agoWhen I was using lotus notes there was a similar feature, but it didn't work very well. As the message was sent to you inbox, you could modify the properties on the message, I created a button to unprotect the message because there were several people in my group who always had their message confidential and the information needed to sent to others quite frequently.
- maltalex 8y agoProprietary "extensions" to email make me nervous.
- glitchc 8y agoThis, thousand times this. Google is trying to remake the internet so that only Google's browser works with Google's version of the internet that operates entirely on Google servers.
- agentdrtran 8y agooutlook had this for years.
- dbbk 8y agoYou won’t want to look into AMP for Email then...
- aw4y 8y ago"gmail" and "confidential" in the same sentence. sure.
- arsenico 8y agoI do not understand your sarcasm here - the feature is for GSuite, which is at some level of confidentiality, isn't it?
- ukthrowaway123 8y agoA lot of people are posting that this is for gsuite. I've had this in my regular gmail for a couple of weeks now.
- wooptoo 8y agoThis has the potential to create a huge legal headache. We can no longer rely on email to be there in our archive and presented as evidence in court, but now have to worry about expiry. In many countries an exchange of emails which represents a series of terms, restrictions, an offer, and finally acceptance can be considered a legally binding contract between parties and can be presented in court. With expiry and email DRM we now have entered the alternative reality of such contracts written with disappearing ink.
- krageon 8y agoIs this situation not the same as verbally binding legal contracts? What you need is to record your expiring messages otherwise it'll just devolve into a they said, they said in the courtroom.
- mc32 8y agoIf it’s from your org, vault keeps the records, if it’s from personal or outside gmail accounts those vaults should retain records. A court order could compel the other party to provide records. Of course this adds a complication but it’s not completely deleting the records everywhere.
- nukeop 8y agoThey're cocky enough now to think that they can take on the e-mail as a de facto standard and do the Embrace, Extend, Extinguish dance with it. This is akin to DRM and just like DRM it will be ineffective - if I can see it, I can forward it, copy it, and print it, and do whatever I want with it. Users are being led to believe that they can enforce these sorts of controls over email but they can't.
- bachmeier 8y agoIt's not clear what the use case is for something like this. Why wouldn't you use an alternative communications channel like Slack in this situation? I mean, if you don't want to use email, don't use email. Why go through all the complications this introduces.
- dingo_bat 8y agoDRM for email.
- rospaya 8y agoWill this work only for Gmail/Gsuite clients?
- Spivak 8y agoNo, they're just sending a link in the email with some UI fluff to make it a little more transparent in GMail. An enterprise feature that doesn't work with Outlook might as well not exist.
- kerng 8y agoOutlook has had this for very long time. Even consumer versions have some of the rights management features. At my new job I am using Gmail via GSuites for first time and I didnt know how antiquated Gmail is. Lots of missing features and rather confusing UI. But adding more security options and giving users control is good.
- Spivak 8y agoComing from O365 the thing I miss most is sweeping rules.
- teddyh 8y agoEmbrace, extend, …
- Spivak 8y agoIf you think sending an expiring link is EEE then a lot of companies have been extinguishing email for a while now.
- drglitch 8y agoI feel that many of these pseudo-secure, proprietary enhancements to email create a false sense of security for non-tech-savvy users. Given the smoke-and-mirrors presentation of this as a way to "secure your email^tm" and the plethora of recent info leaks, i am sure some poor c-level exec will get caught inadvertently sharing something with an external recipient thinking that it will disappear in a few days, but then find themselves in a middle of a publicity nightmare. In my utopia world, i'd love to see basics of information privacy and personal security be taught in schools akin to Driver's Ed or Sex Ed classes.
- Spivak 8y agoThis feature isn't about security. Email is already pretty secure with TLS and DKIM. This is basically the equivalent of the "DO NO FORWARD" header people use for internal-only information but with a little more UX polish.
- kzzzznot 8y agoI think what the parent is saying is that they feel this DO NOT FORWARD header feature is being presented as a security feature. I probably agree
- anticensor 8y agoThis is an algorithmically enforced one, though.
- Stuckinsofa 8y agoBut anyone can screenshot the message or take a photo of it. The point is that it's not actually enforced.
- beatgammit 8y agoAnyone can screenshot or take a photo of any decrypted message. The question is when the email leaves Google's servers and whether you can trust Google with that same document. Personally, if I had a message where I would consider a tool like this, I would just encrypt it on the client with PGP or something.
- nmstoker 8y agoLooks like they should clarify the bounds of this functionality. Obviously they know who they're talking about, but good communication wouldn't assume the reader does. Presumably it's only working within a G Suite organisation (equivalent to aspects of similar features in Exchange)
- xivzgrev 8y agoWhat happens if you send an email to a non gmail address? I assume this mode has no effect.
- rocqua 8y agoI believe your message is put behind a link which, after the message expires, no longer directs you to the contents of your email.
- howard941 8y agoPlausible deniability for those times when the sender would rather not have email evidence preserved.
- bo1024 8y agoNaming this technology "confidential mode for email" is extremely dishonest and misleading to users about what it actually does. Very frustrating decision.
- kernelPan1c 8y agoConfidential...as in only you, the recipients, Google, the NSA, and other intelligence agencies the NSA shares information with can read these emails.
- sidcool 8y agoQuestion: Does this only work GMail to GMail or also across email platforms?
- TrueDuality 8y agoThis only works inside Gmail and specifically only within the web interface. It does not protect emails accessed / forwarded / stored from IMAP and POP clients (though if the messages are only stored server side the IMAP one will still get deleted).
- jimbobimbo 8y agoThere's a phrase that large companies often use to explain "puzzling" features like this to detractors: you are not the target audience. Often this phrase is mis-used to cover up straight up bad ideas, but in this case it's right on the money. The target audience for this feature are CIOs of organizations Google sells G-Suite to. Companies do need IRM on emails, to prevent leaks that could happen by accident or intentionally; to limit email audience; to avoid endless replies-to-all on announcements; to put an expiration date on the "perishable" bits of information; etc. I'm pretty positive that they have to have this to compete with Office 365, which had IRM [1] for a very long time. Yes, it's not perfect, however, if it's there, it mitigates a lot of the issues I mentioned above. Note the wording: "mitigates", not "fixes". It's interesting that they still list screenshots as a possibility: email clients (e.g. Outlook) are able to utilize OS mechanisms to prevent those as well. I thought that browser protected media APIs would allow Gmail opt-in to this kind of protection too. [1]: https://docs.microsoft.com/en-us/office365/SecurityCompliance/information-rights-management-in-exchange-online https://docs.microsoft.com/en-us/office365/SecurityComplianc...
- dontbenebby 8y ago>The target audience for this feature are CIOs of organizations Google sells G-Suite to. Companies do need IRM on emails, to prevent leaks that could happen by accident or intentionally I encourage anyone with a Gmail to take a lot back 1, 5, 10 years. There's a lot of data there. Setting up an automated deletion policy can be a great risk mitigation feature. It won't stop malicious insiders, but it will help make sure run of the mill compromises won't be total disasters.
- judge2020 8y agoWould like to note more IRM for DLP (data loss prevention) is an upcoming feature: https://support.google.com/a/table/7539891 https://support.google.com/a/table/7539891 > Information Rights Management (IRM) for DLP > Enable IRM enforcement as a DLP remediation action. > In development
- NullPrefix 8y ago> It's interesting that they still list screenshots as a possibility: email clients (e.g. Outlook) are able to utilize OS mechanisms to prevent those as well. I thought that browser protected media APIs would allow Gmail opt-in to this kind of protection too. Next thing you know, youtube ends up on the same list too.
- lalos 8y agoGreat way to have your users label their own data to improve their ML models by tagging it as confidential or not.
- parliament32 8y agoIf anyone is curious how it works with external accounts, I just tested it: 1) Mail arrives (subject intact) with text like "John Doe has sent you an email via Gmail confidential mode" and a "View Email" link 2) The link takes you to a "To view this email, you must first confirm your identity. A one-time passcode will be sent to (your email)" page. 3) Entering the separately-emailed passcode lets you see the email body in-browser. Selecting text is disabled in the body (so no copy-paste), trying to print the page blanks out the body area -- I'm sure you could bypass either with a bit of JS wizardry. Printscreen/screenshot work as expected.
- X-Istence 8y agoUgh... there are companies that did this sort of stuff for Outlook users, and it's a royal pain in the ass. It's not searchable, it can't be archived for legal purposes this way, this is a nightmare for anyone that does business with you.
- tomjen3 8y agoThat seems like a perfect way to spear-fish people for their google password.
- twotwotwo 8y agoWork is the one place this seems OK: if the company provides the email service, it can hide the forward button or whatever if it thinks that advances its interests. Still think disclaimers about the limits (in the UI, not just the blog post) have to be be stronger. It could help avoid accidental leakage and communicate your intent to keep the contents confidential, but it's absolutely no use against someone hostile. I feel like the name should be more like "mark as confidential" or something, to clearly get across it's a strong suggestion but has no hard enforcement behind it.
- visarga 8y agoWhat if I take a screenshot of the email? How can they prevent that? Or use a phone to take a shot of the screen displaying the email.
- DontSueMeBro 8y agohttps://en.wikipedia.org/wiki/Analog_hole https://en.wikipedia.org/wiki/Analog_hole
- lrvick 8y agoThis is so incredibly stupid and irresponsible on so many levels. Beyond obvious lock-in "Gmail Confidential Mode" tells users SMS is secure (it isn't), teaches users they can prevent message printing (they can't), and teaches users to open links in emails from strangers to then put in their Google credentials to view the message! Was anyone on the Google Security team given a chance to look at this before it got shoved out there? I know there are people at Google smarter than this. This is a massive setback in educating users about actually useful security measures.
- AngeloAnolin 8y agoInteresting take from a friend overseas who is into a lot of Security and Data Surveillance. Me: So, what do you think about Google's Confidential Mode settings? Are you going to use it in your company? Friend: It is one of the topics heavily debated right now. Especially by our management. Me: Is that so? Why? Friend: Lots of legal implications that needs to be addressed. Me: How about you? What's your take? Friend: Well, for a start, given Google's history of surveillance, this type of enhancement only just gives them more power and capability to focus on information that are being deemed sensitive by an individual or an organization. Me: You think so? Friend: Absolutely. Imagine if this person sends out approximately 100 emails in a day, and marks 5 of them as sensitive or confidential or whatever terms you would like. Google can then sequence the emails to track based on the confidentiality that was set forth on it. Me: Never thought of things in that perspective. Friend: Yes. Further to that, they could then add more focus on confidential emails which would have a very specific expiry dates. This becomes more specific to their focus, where they can direct their resources specifically on this. Me: (Intently listening).... Friend: It's like this. Assume you have boxes in your house. Each box contains different stuff. Some box may contain your cash, or jewelry or any other important stuff. Now, you have a burglar going inside your house. With a 100 boxes, they would certainly only spend a couple of time to rummage through the boxes. If they can only open 5 boxes, with the possibility of those boxes containing nothing but garbage, then the burglars are not successful in getting your prized stuff. Now imagine having those boxes labeled with stuff like 'MONEY', 'JEWELRY', 'CONFIDENTIAL', 'IMPORTANT TO DISPOSE BY DATE YYYY-MM-DD', etc. Doesn't that give the burglar an easier way to run through the boxes? This eliminates for them wasting on boxes that may have no importance at all. Me: That is certainly a possibility if you would think of it. Even though such scenario may be far-fetched from a corporate (Google for Business) standpoint, it is still worthy of a discussion. IMHO.
- dontbenebby 8y agoWill this work with non-gsuite users? Gmail has a big marketshare, and setting a message to expire to them could be useful
- emgee_1 8y agoI never use Gmail in a browser. This means that this functionality is not available for me? ( using iSync msmtp mu mu4e emacs setup)
- thefounder 8y agoWhat a stupid thing. You may think that Google doesn't know how email works in the first place. Expiring emails?? DRM(rebranded as IRM) ?? Thank god we have so many email providers and these "features" are worthless outside of gmail.