4 ms·
Of course they can, why would anyone assume otherwise?
by mslate 7y ago
Of course they can, why would anyone assume otherwise?
- reaperducer 7y agoBecause every time I log in to Google with a web browser, no matter what device I'm using, it pesters me to install the GMail app on my phone because it's "better" and "safer" and "more secure." Funny how "I don't want the GMail app" is the only piece of my existence that Google seems unable to keep track of.
- agentdrtran 7y agoThe GMail app is absolutely more secure that using POP/IMAP which is what almost all other mail apps use.
- reaperducer 7y agoI trust mail over TLS way more than I trust anything from Google. Especially an app with who knows what telemetry. https://www.fastmail.com/help/technical/ssltlsstarttls.html https://www.fastmail.com/help/technical/ssltlsstarttls.html
- lmkg 7y ago"More secure" is different than "more private." I absolute trust that Google can prevent unauthorized parties from reading my email. The issue is what parties are authorized.
- michaelt 7y agoI am aware it's common, and perhaps unavoidable so long as administrators can reset users' passwords, but it's always struck me as strange. In many organisations the guy who operates the mail server does not have the same seniority as the CEO, and neither would they be read into every commercially sensitive project, every HR, disciplinary, or employee medical discussion. So it seems odd to me that IT administrators, who are often such sticklers for security and opponents of the idea of trustingly granting overly-broad permissions, would even want the ability to do an end-run around information isolation.
- kryogen1c 7y agowe trusted few who hold the line. on a more serious note, this is only the case for small businesses. in anything larger, security practices like separation of duties and minimum required permissions strongly mitigate this problem. you cannot eliminate it by definiton; there is always a ring 0.
- tmpz22 7y agoIt's a power trip, especially given most employees cross-pollinate their email accounts with personal email either accidentally or because they don't understand the repercussions of doing so. Searching LastPass I (an engineering manager who knew from day 1 this very problem set) signed up to HBO Now and Task Rabbit with my work email - entirely by accident. It's worse in email-obsessive non-technical roles like sales. They can spend 3+ hours per day in Gmail alone and anecdotally sign up for all manner of personal deliveries and dating profiles through that same work email! Ultimately email providers like Gmail should do a better job separating professional and personal accounts and informing their users how little privacy they actually have. I heavily blame GMail's multi-account selection interface and how non-technical users can struggle to change the default account they are logged in under. I think the odds of Google warning users to worry more about their own privacy is slim to none. /rant
- jmchuster 7y agoOh, the IT admins are definitely not reading the emails or flagging them unless the CEO tells them to. Example use case I've seen is, who leaked this sensitive internal memo and let's just check if someone was dumb enough to forward it directly from their work email.
- LatteLazy 7y ago>So it seems odd to me that IT administrators, who are often such sticklers for security and opponents of the idea of trustingly granting overly-broad permissions, would even want the ability to do an end-run around information isolation. You're not wrong but: * It's necessary for someone (or some group) to have these powers in order for anything to work. * Usually everything you do as an Admin is logged just like for the users and you cannot purge those logs or not without drawing a lot of attention or making it obvious you did so. So you too will eventually be caught and punished if you abuse these powers. You have more power but not infinite power as there will be other admins watching you and if a log file suddenly disappears at the same time you make some strange stock purchases you may be asked difficult questions... It's also worth noting that humans are surprisingly honest. Millions of workers have access to your medical records, your bank accounts, information useful for insider trading or state\company secrets. And it's pretty rare that anyone steals any of it. If anything, humans are too willing to keep company\state secrets and we'd be better off if people leaked MORE (e.g. Sherron Watkins or Edward Snowden)...