Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Recipients who have malicious programs on their computer may still be able to copy or download your messages or attachments.

“Malicious programs” such as any standards-complaint email software?



If I were implementing something like this, it would just be a link to an auto-expiring viewer page, if you opened the email in a third-party email client.

And according to Google, that's exactly how it's implemented:

https://support.google.com/mail/answer/7674059

"Malicious programs" here most likely refers to things like keyloggers.


Oh god, this is going to be great for phishing.


You aren't really sending email any more, just a link to a website.


This is unfortunately how lots of people and companies think "secure" email needs to work. Any message from my bank or doctor works this way even it is something as simple as an appointment reminder. It is massive waste of user's time and programing effort, but I'm afraid that is where the world is moving.


Unfortunately doctors have to do this because the common legal interpretation of HIPAA and HITECH Act is that they have to.

Dates of service for a patient are protected health information. Most covered entities and business associates won't risk sending any PHI using methods that are not covered under the safe harbor provisions of the HITECH act. So... endless proliferation of "secure email" systems instead of using email. (And I don't see S/MIME taking off anytime soon as an alternative, even though that would be sufficient to qualify for safe harbor.)


Harder to spoof or phish (depending on the implementation). I know that a message shown on my bank's main website, with the correct URL, is legit.


Does this mean that I only need a new reject rule in my spam filter?


Also requiring the recipient to log into Google to allow google to track them.


And conditioning users to click on links they see in emails. Ugh.


I've already experienced this with employers and when buying a home using "HP SecureMail" and some Microsoft e-mail encryption. All they would have in the e-mail body is a link and I would need to validate my identity in some way to access the "protected" content through the website instead of it just being in my e-mail.


I agree that this is something to be concerned about but according to the instructions it doesn't require a Google login so you could do the entire session in a private browsing window if you wanted as long as you can get the verification code by SMS or the email address.


"Private"/"incognito" tabs and windows do little to nothing to protect you from the kind of tracking companies like Google engage in.


"Malicious programs" can also be taking a screenshot or printing the email.


Um, but what about attachments? A screenshot of an attachment wouldn't be much use.

Edit: I suppose it would be online PDF viewers etc., that allowed viewing but not downloading.


I assume the mail body is simply an URL pointing to somewhere the email can be read. Once there it would need to be rendered in the browser as an image.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: