4 ms·
This is purely marketing AFAIT. I don't see how it provides any protection against the 5 eyes or having one's google account breached. The encryption/decription
by acatton 4y ago
This is purely marketing AFAIT. I don't see how it provides any protection against the 5 eyes or having one's google account breached. The encryption/decription is done with javascript code served to your browser by google (= can be hijacked/changed/…)
The only way to do client side encryption is PGP on a native client distributed by a third party.
- Gasp0de 4y agoIf the key is encrypted with your password, I don't see how that compromises security by a lot. If they adapt the javascript to break encryption on a large scale, that would sooner or later come out. Yes, they could target specific people, deliver different javascript and break their encryption, but in general it's still a huge security gain. It makes it impossible for Google to handover E-Mails retrospectively to police or spy agencies.
- deleted 4y ago[deleted]
- kenniskrag 4y agoIt is encrypted by the key service and not by google: https://support.google.com/a/answer/10801691 https://support.google.com/a/answer/10801691 can be self hosted.
- tantalor 4y agoNot saying much. Same is true about any e2e encrypted messaging (Telegram, Signal, etc.) There's no way to tell if they are intercepting your messages clientside, and you'd have to monitor all the network traffic (which would be encrypted with their keys) to detect exfiltration.
- sneak 4y agoNo. Signal is not redownloaded from Signal each time you launch the app, unlike javascript web apps.
- tantalor 4y agoYou're 100% sure they didn't already ship the code and have the ability to flip a flag to enable message interception per user? Or the ability to execute arbitrary external code?
- sneak 4y agoSignal's feature flags are public as the client is open source and anyone can retrieve the feature flags from the server. You can also run your own self-built client (alternative implementations are available) and forward the messages securely any way you wish. Such subterfuge would not remain undetected. Signal is e2ee in ways that iMessage and WhatsApp are not.
- macspoofing 4y ago>I don't see how it provides any protection against the 5 eyes or having one's google account breached. It isn't supposed to protect you from government agencies. Really what this feature is, is 1) e2e of email, and 2) integration with an external enterprise key management service. #2 means that at very least, your org will have access to your keys and therefore all encrypted mail, and if they have access to that, then they are open to things like subpoenas from law enforcement.
- kevincox 4y agoI think the primary benefit is that in theory you can cut Google off at any time. If you disable the key service they can no longer decrypt your data. So if you decided that Google is no longer trustworthy you can leave and they can't access your data. Of course this is sort of an odd game where you need to cut their access off before they backdoor it, so you have to somehow predict that Google is going to become malicious and beat them to the punch. If you a reacting to something that they are doing it likely isn't helping much. Another possible advantage is that you could potentially have logging on key access which could give some idea of data usage. So if Google starts requesting keys for all of your stored data then you can be suspicious that they are siphoning up your data. (Or doing some background maintenance? Who knows?) In practice this is probably mostly checkbox theater where it is a feature that Google and their users can list.
- pmontra 4y agoI wonder which tool we can use to decrypt the exported messages before importing them into a local (mbox, maildir) or remote message store (IMAP.) At worst we can use the JS code Google sends us, but extracting it from the gmail JS bundle is probably non trivial.
- Idiot_in_Vain 4y agoWonder if there's a browser plugin that can calculate SHA 256 checksum for a page and all linked JS - to help verify that the encryption/decription code has not been compromised.
- 3ul3r 4y agoWhatsApp build something like that: https://engineering.fb.com/2022/03/10/security/code-verify/ https://engineering.fb.com/2022/03/10/security/code-verify/
- UncleMeat 4y agoExcept that we've got two decades of evidence of people regularly fucking up PGP leaking the contents of entire email threads. If the only thing that works is PGP then nothing works.