Gmail confidential mode is not secure or private
protonmail.com
protonmail.com
So this confidential mode let's this happen naturally. When the CFO's email is hacked (which it will be eventually at some company) then all is not lost.
I'm sure many other users will find it useful.
especially if sending across an ou boundary where you don’t know the retention treatment this will be great.
Sales teams can be very sloppy w email -> auto import into CRMs, sharing permissions, delegating permissions, running their own optimization apps etc. Because the want to claim credits for sales they don’t like tight retention limits etc
I’m curious if anyone has worked at a place that retains email longer than 30 days, I know I have
Both Google and MS provide a disclaimer that explains Information Rights Management can't prevent "malicious programs" from by bypassing the restrictions.
...they make it available to Google first, and then to the employees.
The article makes the classic mistake of assuming everyone has the full security apparatus of a country after them.
This feature is obviously not built as an alternative to Signal or for the Snowdens of this world. These probably know better than using unencrypted email already. For the average user it's an improvement of the current status.
If you are on the internet the NSA is spying on you and everyone else.
This is not an improvement because it makes guarantees that simply aren't true. These compromises are made to further Google's bottom line, not protect users. Don't pretend this is some kind of incremental improvement. It's a marketing gimmick.
There's a difference between passively collecting and actively targeting.
They couldn't do this if they weren't drag-netting.
*FISA courts have 11 denied requests and over 34,000 approved.
Citation needed.
> This is not an improvement because it makes guarantees that simply aren't true.
No, ProtonMail pretended it made guarantees that it doesn't make. Just like the exact same Exchange/Outlook feature that people have used for years, this is to prevent accidental copying of emails and their contents.
You are free to see harm in these statements but telling me they are always meant as harmful as you mentioned is your own negative reflection. Not mine or ours, we are free to have our own interpretation as well.
Honestly, yes. According to some random infographic I came across, americans use ~2 million GB (2PB) of data per minute. We'll round down and call that one EB per day. So round down again and call it 300 EB per year (a high estimate would be 1K EB, or 1 YB). That's more than the entire global output of disk storage annually, and the NSA aren't the only ones who want hard drives.
Keep in mind that much (most?) of that data is encrypted in transit, so targeting exactly which data they want is not always possible.
Keep in mind there are side channel attacks that let you guess passwords typed via SSH. I wouldn't be even a little surprised if the side channel leakage of most Internet traffic zooming around via TLS is good enough that the NSA can sort it pretty easily. This is all theorizing on my part, though.
What we do know is they can probably collect a huge amount of useful traffic and store it for a relatively short, but useful amount of time (weeks, probably). Kind of like a ring buffer. Systems are always sifting and flagging and saving some portion of what they are collecting, including raw traffic. Also consider that there are lots of ways of unmasking the basic metadata of the streams through any number of leaky things happening in the web browser.
This traffic is collected in an un-targeted fashion. They just promise (pinky swear) they don't look at it without a search warrant. Then a search program executes and they retrieve it from the data stores. Think about that legal theory, because that is exactly what Michael Hayden testified to. I don't know if it is just an age gap or something else, but I think people on HN are not aware of the extreme data collection the NSA performs and the ongoing threat this is, and continues to be, to privacy.
Anyhow, I think the generation after millennials should be called the surveillance generation, because it's all tracked. I just can't understand the skepticism at what the NSA is doing because of some lazy back of the envelope math. Anyway, this isn't really targeted at you as a reply, but this whole thread... there was a time when this sort of skepticism was basically the norm in technical circles with little doubt. Now I see it eroding in general tech circles.
https://en.m.wikipedia.org/wiki/PRISM_(surveillance_program)
https://www.eff.org/nsa-spying
“””The undisputed documents show that AT&T installed a fiberoptic splitter at its facility at 611 Folsom Street in San Francisco that makes copies of all emails web browsing and other Internet traffic to and from AT&T customers and provides those copies to the NSA. This copying includes both domestic and international Internet activities of AT&T customers. As one expert observed, “this isn’t a wiretap, it’s a country-tap.”
Secret government documents, published by the media in 2013, confirm the NSA obtains full copies of everything that is carried along major domestic fiber optic cable networks.”””
This is utter nonsense posted by somebody who has the reading level of a Snowden or a Greenwald. There is no such document. Can you point me to one?
That you pointed to PRISM as an example, a system that processes communications from specifically targeted foreign individuals already obtained by the FBI, shows you haven't read any of the documents.
Yes because this claim is preposterous. You don't even need a napkin to show this is impossible.
> This is "common knowledge" in information security circles.
The "common knowledge" in Internet industry circles is that Snowden misinterpreted several documents and made wild claims about what they said.
> Go look up the battles the EFF has fought with the NSA about their data collection practices.
Snowden's documents showed that the EFF arguments against about what was happening at AT&T were unfounded. The documents showed that instead of copying everything, they filtered to traffic to or from certain foreign targets outside the US.
Then either you have the same reading errors as Snowden, or you haven't looked at the actual documents instead of Greenwald's incompetent reporting of them.
> A variety of laws allow government agencies to investigate regulatory violations or criminal activity. Google receives requests for user data from government agencies investigating criminal activity, administrative agencies, courts and others.
...
A federal statute called the Electronic Communications Privacy Act, known as ECPA, regulates how a government agency can use these types of legal process to compel companies like Google to disclose information about users. This law was passed in 1986, before the web as we know it today even existed. It has failed to keep pace with how people use the Internet today. That's why we've been working with many advocacy groups, companies and others, through the Digital Due Process Coalition, to seek updates to this important law so it guarantees the level of privacy that you should reasonably expect when using our services
For instance, India, a nation run by English-speaking elites has conducted all the affairs of the nation on Google''s servers - such bumbling idiots, normal as they are, are the targets of such a PR campaign. "Oh, you're don't have to worry about it. You're not a terrorist.."
Why build something half ass when you can do it right? I'll tell you why... it's because of those secret letters from the NSA... (the NSA = the real leader in our Government)
Keywords like djihad, Siemens, Krupp, Deutsche Bank, Airbus, Santander, Dassault, ...
The BND was in essence helping the NSA do industrial espionage on both their own and fellow EU companies, as they were too idiotic to actually check the keyword lists or for whatever reason felt they couldn't refuse.
So if the NSA is actively and purposefully doing industrial espionage there is little doubt that Gmail traffic is vulnerable to US spying and should simply not be used in sensitive settings.
I simply don't understand how they think they can get away with this foolishness. I can forward, copy, print, or download ANYTHING that passes over my ethernet cables. Your silly UI will ultimately never stop me from wiresharking my own cables in my own home and doing whatever the hell I want with any bits of information that enter my space.
All it does is fool a bunch of less-tech-savvy people into a false sense of security.
Or for the less technically inclined, opening the email on your phone/tablet and put it in a photocopier.
Google is making an entirely different claim about controlling the actions of a third party. It's fundamentally impossible to do what Google is claiming.
When I was in college (early 2000s) a local company sold notes/study guides for different courses. But they were printed in black text on dark green paper to prevent photocopying and sharing.
Good idea on their part but I used my digital camera to take photos of the pages and cranked up the details to make them look like blackish text on whiteish paper. Ended up selling them to all my friends.
I do remember some app not "letting" me screenshot something with stock Android, which I felt to be a violation of my freedom. Obviously in my case just use a modified Android ROM without the silly anti-screenshotting logic, or screenshot it with adb over USB, but for the less-technically inclined, take a picture of the phone.
Bank apps tend to do that. When I first hit this issue, it also felt like a violation of my freedom, and it was also very annoying because I badly needed to make that screenshot.
On top of that self deleting email will make it also a bit harder to prove that the screenshot is real - unless you get a court order to get the senders outbox folder from google and the data still exists there.
Except it isn't deleted from your send folder.
It's not unusual for whole sales organizations in particular industries have all emails archived under legal hold requirements (whether sent or received.) Another set of organizations will purge all of the same email older than than a certain date.
None of these measures are particularly hard to defeat for a bright user, but many of the risks at the company-level are mitigated. This is mostly to solve challenges with regulation or company certification, but it can make a real difference when someone is handling a privacy incident.
I think that’s the scenario Google had in mind when designing this feature. For enterprise users, where the enterprise controls the hardware, the policy-level controls actually have teeth, because people don’t have root over the devices in their possession. For everyone else, it’s not “real security”, but rather just a gateway drug to get you used to the workflow that “real security” would provide in an enterprise context.
(Context: I used to work at IBM, and they had a very similar setup—company issued laptop, app that enforces MDM profile installation, VPN that checks with the app to ensure MDM is active before connecting, email servers only accessibly through said VPN, and, on top of all that, a policy-enforcing email app [IBM Notes] where you can delete already-sent things out of other enterprise-users’ inboxes, send expiring emails, etc.)
It's not possible to do what Gmail wants to do without a SCIF.
https://en.wikipedia.org/wiki/Sensitive_Compartmented_Inform...
If not, consider that you might be making your own broadly wrong assumptions.
This could be a useful feature when dealing with PHI, legal, HR, etc.
This seems like it should be true, but having worked with end users in the past I would not take this for granted
Disc: Googler
The thing that a lot of these measures protect against is not so much a targeted attack, it's stupid user tricks. It's not protection against Jane the Spy extracting as much information as she can, it's a measure against Danny the drunk who leaves his laptop at a bar or sitting in the back seat of the car where it's visible and stolen.
There are also likely a lot of places where it would be illegal to use something like this with auto expiring messages, though hopefully most such places won't be using Gmail.
The only way for this to work is to restrict the user freedom so much it will:
- cost a huge amount of money
- lower the productivity
- kill the mood of everybody
My take on this is that if your industry really needs this kind of feature, either you suck as a human being and I don't want to work for you, or you are doing something amazing and secretive and in this case you don't use gmail.
On the other hand, that means there's no reason to resort to something as complicated as JS injection or dev tools. Screenshots will usually work fine, because messages aren't threaded, so you'll likely get the entire message showing up on one page. They do block Ctrl-S, they use a click handler that prevents it from reaching the browser. Very fiendish, very clever. Except that the save button still works in the menu.
On the plus side, I'm now wondering if that, "go to the top of your menu and hit the file->save button" exploit would make me eligible for a bug bounty, since according to their documentation I should need malicious software to download the message. I guess Chrome falls into that category though?
Wow, so it kills your offline productivity as well, and of course make back ups and archiving harder. I know it's kinda of the point, but I haven't realized the implications of it until you said so.
Unless you were on a Fedora workstation.
That was a fun discovery. Never figured out who at IT I should inform before I quit.
I've come to the conclusion that these products are just to cover the low-hanging fruit situations of someone accidentally doing something that they shouldn't have. In other words, it's a UI integrated "DO NOT FORWARD" message from an e-mail.
However, I've found you can print confidential emails if you comment-out/disable all the @media print rules using Firefox developer tools: https://grokprivacy.org/2018/06/24/archiving-self-destructin...
And if even this is still too "technical" for a user, I have seen people take literal shots of their screens, with their phone camera or whatever.
If you click the "learn more" in gmail it says that ^. Gmail seems pretty upfront about what "confidentiality mode" does.
I guess me exercising my right to do whatever I want with my bits on my computer is me having "malicious programs". What in the actual fsck.
Recipients who do not have malicious programs on their computer also may still be able to copy or download your messages or attachments.
Although on further consideration, my previous comment may actually be wrong: "malicious programs" includes ones that attempt to violate the user's right to copy, and recipients who do not have the malicious program Gmail on their computer might not be able to copy or download your messages or attachments.
Even this is really poorly worded. You don't need a "malicious" program on your computer, you just need to go to your browser menu and hit the print button.
This still makes it sound like the average user won't be able to save your email unless they're doing some kind of tech mumbo-jumbo -- that your real risk is if an IT person gets a hold of it. But printing or saving a web page are basically the first thing I would teach anyone to do if I were mentoring them on how to use a computer.
Probably every secretary in your office already knows how to get around this restriction.
Doesn't seem to be that easy. You're probably not going to get a copy without taking a screenshot, opening up developer tools or digging into your browser's cache.
Assuming you don't want to save the HTML page, you still might not even need to download a separate program to screenshot it. New installs of Firefox just have a button on the toolbar labeled, "Take a Screenshot". It'll grab the entire page without forcing you to do any scrolling, and doesn't require you to know anything about HTML. I tested, and it bypasses all of the security features on confidential emails.
People are arguing that this is designed to prevent accidental sharing, which is a really good point that I think I agree with overall. However, HN is a tech site and I'm seeing comments that say the only way you could beat this is to dig into your developer tools.
If a nontrivial portion of HN users think this service is more secure than it actually is, how much more uninformed are ordinary users? Saving a web page is not going to be a difficult problem for most people in your office to solve. So my objection here would be, Google isn't doing a good enough job of informing even tech-literate people of just how easy this is to circumvent.
A CEO is going to look at this and think, "well, I guess they're doing voodoo magic so most people in my office won't be able to share." The reality is, pretty much anyone in your office who wants to be able to beat this will be able to figure out how to do so.
Saving the webpage itself works fine though -- which again, is a browser feature your secretary probably knows about and is comfortable using.
I guess my objection to the idea that this is just removing deniability is that it really doesn't feel to me like it's being marketed that way. I wouldn't call a service like this "confidential mode", I would call it something like "auto-delete mode". Maybe I'm just arguing over semantics though.
Also, I can think of a lot of ways to bypass the “confidentiality” settings that require no malware whatsoever. Not only is their giant asterisk hidden, it’s wildly inaccurate and misleading.
Nonsense, it does a great job of discouraging people from forwarding, copying, printing or downloading the emails contents.
Sure, it'll do nothing with a malicious recipient but incompetent recipients are vastly more common than malicious recipients.
Nobody believes fences stop criminals, and nobody believes Gmail has ended the DRM arms race.
I agree with the thrust of your comment, but this isnt true. Measures like this do prevent some crime. When i didnt lock my car and someone stole the gift cards out of it, locking the doors would have prevented it. Just because the car is still stealable doesnt mean door locks are security theater. Putting an unlocked package cabinet for deliveries on your porch lowers incidences of theft without making it impossible.
Then why is every military base surrounded by a fence?
Their silly UI won't, but what about HTTPS? Won't wiresharking your own cables only get you the ciphertext from the HTTPS session which would be useless to you without the ephemeral key?
Source - same discussion years ago at Microsoft when Windows introduced this at an OS level to prevent screenshots of confidential mail.
I actually tried the "wiresharking my own cables" approach, but because it's encrypted, you also need to dump the ephemeral encryption keys. There's a simple guide on how to do this here: https://jimshaver.net/2015/02/11/decrypting-tls-browser-traf...
Requires SMS verification or an impassable captcha loop if over TOR
And payment with a credit card
The cryptocurrency payment option with non-user identifiable info only being available to existing protonmail accounts where that info was already harvested
So it is ironic to see protonmail calling out those specific things about gmail confidential
> Secure Your Communications with ProtonMail
> Anonymous Email
> No personal information is required to create your secure email account.
requires personal information to create the secure email account
"Protonmail does those thongs to try and prevent bad actors or bots from making encrypted accounts to hide their shady tracks."
oh okay, pack it up everyone, don't listen to glib ole me coming to a rational conclusion
its IRONIC that I have to trust them as much as I have to trust Gmail confidential's claims about what they may actually do with the data collection. or what they may be coerced to do with the data collection. "Swiss law" doesn't prevent that.
We send confidential docs regularly to users, who need access to those docs for perhaps 1 week at most. No one wants / needs to keep these around, but no one goes through their email carefully to delete these items.
If that users email was hacked -> they have a big problem. If we can mark the items for a 3 week retention and then expire those items for them, that great - and this lets us do that.
The whole I can wireshark my network -> 99.9% of the confidential info we send goes to other folks who ALSO want to keep it confidential. Getting rid of stuff you no longer need to maintain is a key way of helping avoid big document dumps.
The proof is in the pudding. Either this will help google sell to business (it will in our case in a big way). Or folks will say it is a stupid feature and decide idiots like Protonmail who can't seem to understand the point of these features now deserve our business. My confidence in a place like protonmail goes down based on this, and I'd love to get a feel for their security history and overpromises (ie, webmail client has got to easily be able to log and hack encryption etc).
"Gmail confidential mode is little more than a marketing strategy."
FALSE - This type of approach has real and direct security benefits. The fact that proton can't see understand that makes them idiots.
"Gmail’s confidential mode is little more than a marketing trick designed to pacify users concerned about privacy."
FALSE - Many business users using google are less concerned about privacy than they are about SECURITY. In the business context, most privacy is already given up, your employer can go through your emails. They can vault them up, do e-discovery on them etc etc. These aren't folks fighting off nation states. These are folks who someone in the office WILL click the bogus link and have their account taken over - and the business wants to reduce the blast radius.
Saying this is a marketing "trick" is silly and the fact that proton can't see that makes them idiots.
Do folks not work with partners who are sloppy with security? You send over you stuff. No one wants to leak it but someone's email is hacked. Do you want your stuff in their email still 5 years later?
Do folks not work in business? Bob sends sue draft of updated raises, sue edits and adds some notes and sends them back. A final decision is reached. After some time the big list of salary info by position -> folks want that out of their emails. This would keep it out.
This is a REAL security benefit. It goes to show that folks like protonmail and other security experts don't have a good real world understanding of risks to info people face. It's not all state level hacking, it's folks being lazy, not cleaning out their email, then getting hacked.
they aren’t idiots, they’re just failing and desperate.
@dang: does this merit a flag or ban?
I think toxic fanatism make hn a worse place for discussion.
Talk about over the top language - “toxic fanaticism”? Really? The name calling of other posters you disagree with makes hn worse (my comments focused on a company not this community)
Also, why are you so eagerly defending the big guy/monopolist in the room. Is this the attitude of an entrepreneur or hacker? One that is part of the "hacker news" community?
If you think this feature (which you don’t need to use) is a “trick” that has no value that is fine - explain why no one should use it - give some examples etc
Stop with the whole focus on other posters motivations, calling them “toxic fanatics” etc.
Google has lots of competitors - the big one is exchange / outlook - which has a confidential email mode. For a list of competitors look here:
https://www.datanyze.com/market-share/email-hosting
It’s not unreasonable for them to add a feature to better compete with MS. I didn’t even see Protonmail on that pie chart
For example
"I guess it can't be proved that this guy is a shill for AWS. But this kind of toxic fanatism(yet trying to sound logical) is just harmful for the HN community.
dang: Can this kind of behavior be punished?"
as an earlier comment around something to do with AWS. Why does someone "trying to sound logical" mean they are a "shill" or a "toxic fanatic"?
In this thread I'm called a "toxic fanatic" and there is a claim about my support for monopolies and my lack of desire for competition (all of which is totally untrue in actual fact) with no substance regarding the value (or not) of the privacy / confidentiality feature google introduced. I'm also threatened with a ban.
This is a very unfortunate typo.
There are valid reasons to need to forward even e-mails marked confidential, including lawsuits, harassment cases, or even just asking your own lawyer before signing an agreement, among others.
Deciding when a piece of information should not have been forwarded is the job of the workplace or law, not the e-mail client.
Gmail supports other MUAs using IMAP and POP, so that doesn't work.
The fact that there are valid reasons to forward sensitive emails is why there is an escape hatch. It's only the accidental forwards and copies that this is meant to stop.
When designing APIs I find that bools are often a smell or a missed opportunity. What if, for example, there was an X-Intended-Audience?
That could be integrated with Active Directory, Groups, IAM etc within an organization to make the warning only pop up when a potential violation is occurring which helps avoid seeing the warning so often that it gets ignored (or accidentally send to the wrong confidential party as in medicine or law). It could also inform IT after the fact.
Those are reasons for employees to forward an email, not the companies who Google is selling to.
You seem to misunderstand who controls the workplace. Within limits, the employer has significant control which increases or decreases based on jurisdiction.
Yes, these measures could limit an individual, but there are generally options like just asking the sender to forward a copy of an agreement/contract so that an outside counsel can review it. Denying review of a contract is a good way to get it invalidated.
I guess harassers could use this feature of the system to try to protect themselves, but it won't stop someone taking a photo from their phone. Realistically most organizations don't want to be complicit in that - even if they tend to default to silence - and HR only exists to protect the company.
There is no way to convey information to a malicious human s.t. that human cannot convey it onwards to unwanted recipients. The best you can do is provide strong disincentives. Some options for doing this: make sure that your recipients generally don't want to hurt you. Make them fear you (even that doesn't always work, see [1]).
When words are explicitly said it can cause people to think things through.
One thing I find troubling is that they seem to be making their own false claim.
>Because we do not have access to the recipient’s private key, we are never able to read the message. We do have access to metadata, like the email addresses, timestamp, and subject line.
I am not sure how proton could send messages to anyone if they didn't know the recipients address!
EDIT: I'm stupid, please disregard this. They clearly state that the DO have access to metadata (for some reason my head read it as DO NOT).
This "expiration" could protect the receiver from subpoena/discovery ("Sorry I don't have it anymore") but it sounds like the sender is still liable to produce the original message on demand.
Posting this just to embarrass them into fixing it.
Sorry and personally that’s too much for me!
User Bob would like to recall email titled, "that sex party last night"
Riiiight
For benign purposes, some sense is seen.
Otherwise, the whole idea is silly.
For example I was publicly put on blast for something that was false about me. So in that case I just blew it off because it was wrong, and no reaction was really necessary. It was still very stressful though personally and for my family. I wonder how these product teams across Google and FB primarily feel in these cases.
Outlook has had the same feature for 20 years.
More broadly, I think if you talk to any journo in the trade press, some companies can be incredibly thin-skinned about any percieved negative press, and threats and intimidation are very common for percieved slights. And the trade press typically rolls over because those companies are their advertisers. It's why you typically see so many puff pieces, how-tos and PR reprints rather than actual journalism.
Update! Gmail changed this behavior a while ago. Went under my radar: https://variety.com/2017/digital/news/google-gmail-ads-email...
Thanks!
In other words, they reserve the right to scan or read your Gmail for any purpose other than showing you ads. So they can still read your email for things like creating that purchases list, as well as a myriad of other tasks. As long as that task doesn't involve showing you an ad, your Gmail is wide open to them.
We will not scan your messages. (One possible reason we would have done this would be for advertising.)
vs.
We will not use the scans we perform on your messages to make advertising decisions.
I'm honestly not sure which it is (although I also don't care much personally since I don't use Gmail).
We should be thinking of ways to improve the situation for everyone (not saying I have the solution), but personally (and unfortunately) I don't think this would have any impact.
What's Google's incentive to protect your privacy, and what are the consequences if they fail to?
Compared to a firm that is marketing services on the proposition of privacy being at the core, the risks to Google's business, reputation and finances are likely minimal.
Whereas, if one of the firms that markets providing services focused on your privacy is found to be intentionally and wilfully violating that, it ceases to be a violation of trust and becomes a violation of contract, false advertising... essentially fraud, and the consequences of deliberately misleading and defrauding customers is more significant than an accidental (or wilful) privacy breach by a corporation that openly markets itself as not respecting its users privacy.
If Protonmail fucks up, there's not going to be a NYT article about it.
If google screws up, they might see a small blip in add revenue before recovering.
If Protonmail screws up, then they'll lose paying customers which is their only source (presumably) of revenue.