Home

16 comments

Freak_NLabout 2 months ago
This was already happening, unfortunately. The user&#x27;s mail agent is deemed untrustworthy (and so is the user), so every service which needs to send confidential data just turns your email into a notification with a link. There are so many of these, but often they are limited in scope. For sectors like healthcare you have companies offering this type of service to companies which need to adhere to security theatre standards such as ISO 27001, and because nations often have their own added requirements for specific sectors (think HIPAA in the US or NEN 7510 in the Netherlands) these services tend to remain focussed on single countries.<p>Then there are the national governments and things like insurance companies. All happily sending message notifications where you need to sign in to their own portals.<p>Securing email is too complex, so everyone builds their own secured portal thingy, and your mailbox has become a receptacle for notifications. Figuring out a solution would require cooperation, pragmatic lawmaking, and giving up those nice cashcows of moated portals, so it won&#x27;t happen.
评论 #43605271 未加载
评论 #43605230 未加载
评论 #43605329 未加载
评论 #43605217 未加载
评论 #43605383 未加载
jurschreuderabout 2 months ago
People in China could not open a url sent in Gmail. I happened to be in China, I tried to open the webpage and it worked, no firewall.<p>I hovered on the link in Gmail and Chrome told me left bottom it was just that exact url.<p>But when I opened the url it got blocked by the great firewall.<p>Why? Any link in Gmail secretly gets replaced by a link to Google that tracks you and then redirects you to the original link.<p>The most obnoxious thing about this I think is that Chrome shows the original link.
评论 #43605193 未加载
评论 #43605223 未加载
评论 #43606358 未加载
评论 #43605272 未加载
kardianosabout 2 months ago
This is how all HIPAA &quot;secure email&quot; works. Outlook, Zoho, clinic comms, BECAUSE it lets you revoke email access.<p>If you want an opportunity in this space, it isn&#x27;t actually encrypted emails, but possibly standardizing and streamlining such &quot;message pointers&quot; and address endpoint verification.
评论 #43604931 未加载
stwrznabout 2 months ago
What happens if the sender&#x27;s Google account ceases to exist for whatever reason? What if Google ceases to exist?<p>I know that there are a lot of HIPAA &quot;secure email&quot; solutions that also do this, but I don&#x27;t want this to become more common practice then it already is...
评论 #43605054 未加载
评论 #43605022 未加载
评论 #43606010 未加载
评论 #43605339 未加载
p2detarabout 2 months ago
The E2E problem has already been solved long time ago. We used to have Thunderbird with an OpenPGP extension and GPG keys.<p>Then there were a whole plethora of products were build around Lotus Notes Domino that provided a central place for securing outgoing E-mail using either S&#x2F;MIME or GPG keys. All of this on premises. Then came the Cloud and obliterated these products. And for what?<p>edit: typos
评论 #43605101 未加载
评论 #43605700 未加载
评论 #43605220 未加载
solardevabout 2 months ago
Isn&#x27;t this how banks send secure messages too? You can&#x27;t send secure emails to arbitrary clients otherwise. PGP stands no chance of being adopted by regular users.
jonathantf2about 2 months ago
This is exactly how M365&#x27;s solution works. Decrypts if the recipient is using MSN or EXO, otherwise punt them to a webpage.
ranger_dangerabout 2 months ago
I think one of the growing threats lately in the community has been over malicious client-side javascript, especially when the client handles end-to-end encrypted content (used on sites like Proton, MEGA etc.), so requiring users to trust Google with the contents of these client pages, and by extension the emails themselves, seems (in my opinion) to defeat the entire point of this feature.<p>Some work in this area has been done in the form of browser extensions that are used to verify signed assets delivered to the client:<p><a href="https:&#x2F;&#x2F;github.com&#x2F;freedomofpress&#x2F;webcat">https:&#x2F;&#x2F;github.com&#x2F;freedomofpress&#x2F;webcat</a><p><a href="https:&#x2F;&#x2F;github.com&#x2F;tasn&#x2F;webext-signed-pages">https:&#x2F;&#x2F;github.com&#x2F;tasn&#x2F;webext-signed-pages</a><p><a href="https:&#x2F;&#x2F;github.com&#x2F;jahed&#x2F;webverify">https:&#x2F;&#x2F;github.com&#x2F;jahed&#x2F;webverify</a><p><a href="https:&#x2F;&#x2F;github.com&#x2F;facebookincubator&#x2F;meta-code-verify">https:&#x2F;&#x2F;github.com&#x2F;facebookincubator&#x2F;meta-code-verify</a><p>But unfortunately for now, none of these are seeing wide adoption and this remains an unsolved issue. It also does not require anyone to use known-good, audited and verified open-source components, meaning even if the client code is signed, it can still be malicious... there must be a greater reason to trust the code than just &quot;trust me bro&quot;.
zer0zzzabout 2 months ago
Doesn’t proton mail also do this for sending encrypted mail to folks with no encryption?<p>They ought to do pgp though
评论 #43604656 未加载
tkyabout 2 months ago
All the takes on this release miss one crucial point: if you want people to adopt E2E encryption, you must reduce friction. For users of Gmail, that means familiar elements and flow to their usual use of Gmail. If this lets even a handful of people use more secure messaging, it’s a win. For Google workspace-centric orgs it’s a good step in the right direction.<p>If you disagree, go set up GPG on a non-tech’s computer, tell them they need to use Thunderbird or some other helper app(s), and see if you can even go home before being asked to remove it all.
评论 #43605995 未加载
commandersakiabout 2 months ago
How does the E2EE happen if you&#x27;re clicking a gmail link? One thought is the secret bit is tacked onto the anchor part of the URL, but the secret is in plaintext both on the senders sent email and on the recipient side.
Woodiabout 2 months ago
email is dead, even gov&#x27;s use chat clients with emoticons ;)<p>That email is your internet id and majority countries digital id too ? Who cares, things usually need to be so broken that even elected officials families report problems :) Then we can have some &quot;plans&quot; announced. EU is especially good at this - announcing (and pushing for more centralization no matter what is happening) and not fixing anything, eg. sane CPU&#x27;s, when ? Rhetoric question because not in this decade...
tptacekabout 2 months ago
This is how most commercial secure email products work.
fnord77about 2 months ago
how else are they going to push ads?
n3stormabout 2 months ago
I guess minimal gmail for e2e is the tariff we have to pay for privacy and freedom. wink.
otterleyabout 2 months ago
&gt; I&#x27;m not going into how much this is not E2E, as this has already been proven<p>By whom? It looks like E2E to me. It’s just that both ends are controlled by the same entity.