Slashdot Mirror


Google is Testing Self-Destructing Emails in New Gmail (techcrunch.com)

The upcoming update to Gmail might include a feature which would allow users to send emails that expire after a user-defined period of time. From a report: Working on an email service is hard as you have to be compatible with all sorts of email providers and email clients. But it doesn't seem to be stopping Google as the company is now evolving beyond the simple POP3/IMAP/SMTP protocols. Based on those screenshots, expiring emails work pretty much like expiring emails in ProtonMail. After some time, the email becomes unreadable. In the compose screen, there's a tiny lock icon called "confidential mode." It says that the recipient won't be able to forward email content, copy and paste, download or print the email.

20 of 172 comments (clear)

  1. O rly? by Anonymous Coward · · Score: 4, Insightful

    I receive data on my computer. It is then uncrypted and displayed on my screen. Ergo, stored in clear in RAM. What prevents me from finding a way to copy-paste this data?

    1. Re:O rly? by MightyYar · · Score: 3, Insightful

      Nothing - it's not for you or any other thinking person. It's meant for the same people who use the other insanely popular "self-destructing" message apps. They undoubtedly know it is stupid, but ultimately they need to compete with stupid.

      --
      W..w..W - Willy Waterloo washes Warren Wiggins who is washing Waldo Woo.
    2. Re:O rly? by taustin · · Score: 3, Insightful

      If I can read it, I can copy it. The only way to keep me from copying an email is to keep me from reading it.

    3. Re:O rly? by aaarrrgggh · · Score: 3, Insightful

      But there is no way to plug the analog hole. You can still take a screenshot... it might need to be from another device, but it is there.

      But, one thing works in its favor-- verification. If I have a screenshot of a document there is no way for me to prove its authenticity. Without some kind of verification means, much information loses its value.

    4. Re:O rly? by cstacy · · Score: 4, Interesting

      And they could enforce whatever nonsense in a browser visiting that link.

      This means that mail reading apps need a new feature: auto-archive linked web content. When a message includes an (e.g. unlikely trivial IMG self-destruct implementation) link, and you have enabled (for this message, or for the domain) Show Web Content, then in addition to showing the content, you save it. If the pixels appear in your browser (or email app that includes a browser, like most do), then you can save them for yourself. Depending on how they write the Javascript, it might be less straightforward to analyze to get the desired content. (In the worse case, if it's in my video frame buffer...) But at the end of whatever nonsense Google (or whoever) comes up with, there is visible content such as an image. And there is no way to stop that from being automatically copied and conveniently saved as part of the message.

      If I was making this feature in the app, I would automatically save the content the first time, along with retrieval metadata. That metadata could include the entire page contents (that is, the Javascipt and everything, not just all the downloaded pixels). This would then be hashed. On subsequent viewings of the message, I would compare the hash to see if I need to download another version. Message presentation would then include an indication that this was saved content, and indicate whether it had changed. Options on the message include: Always Show Original vs. Show Latest Content. Either way, the message presentation shows what's going on and let's you click to see other versions that you've captured.

      Some people would like to see the latest content, presumably a little picture of a charred envelop and the words "Message self-destructed after reading on 4/1/2018 01:02:03 EDT". There could even be a setting in the app to disable offering by default the historical versions. Or even settings to disable capturing the initial version (or later versions, or more than x number of versions, etc.) For those who like to go along with the self-destruct fantasy.

      There are security issues associated with this, most of which should already be addressed by existing apps, since people send HTML mail all the time. Basically what's going on is that every time you retrieve the message, you are downloading a new virus. And every time you display it you are executing potential malware (even if it's just showing you a captured JPEG, it could be a crafted one). General security principles should take care of stateful tactics based on having downloaded previous versions, but that's something to think about since you've now introduced thises new data store features into the app.

    5. Re:O rly? by o_ferguson · · Score: 4, Insightful

      Conversely, once this "feature" is poplar, you can just produce a "screenshot" of whatever shit you want, and then claim it was sent as an "expiring email." No need to prove it was actually sent anymore. Anyone who uses "expiring email" willingly opens themselves up to whatever fakes other people desire to produce.

      --
      - In Soviet Korea, only old people loose all their bases to Natalie Portman's petrified hot grits overlords.
    6. Re:O rly? by 93+Escort+Wagon · · Score: 3, Interesting

      If you're using Gmail you'll see it.
      Otherwise you'll get an email with a link. The link takes you to Google Docs to view the shit.

      We've spent the last decade or so training users never to click on links in emails. This seems like a good reason to double down on that practice.

      --
      #DeleteChrome
  2. Screenshot... by b0s0z0ku · · Score: 4, Insightful

    So easy to take a screenshot. Also, it's ultimately up to the browser whether to enable copy/paste or not.

    1. Re:Screenshot... by Joce640k · · Score: 3, Insightful

      Screenshots would never be admissible as evidence.

      --
      No sig today...
    2. Re:Screenshot... by MobyDisk · · Score: 5, Insightful

      FYI: Just because something can be doctored does not mean it is not permitted as evidence. The most common form of evidence is witness testimony, which is inaccurate, easily altered, and degrades over time.

    3. Re: Screenshot... by Anonymous Coward · · Score: 5, Interesting

      Itâ(TM)s called the Investigatory Powers Act in the UK and itâ(TM)s actually 1 years retention of data for all national level or international level companies. Small, local companies donâ(TM)t have to comply. GPs claim of 7 years is based on the older Regulatory Investigative Powers from 2000-2016.

      It applies to data and service providers so for the ISP itâ(TM)s web history, email, phone calls. For data and service providers its all data and meta data.

      Itâ(TM)s a horrible piece of legislation and currently being fought in the UK courts by many parties. In the Mainland EU they are trying to pretend that they disagree with the UK at EU parliament level but have the same data collection program only itâ(TM)s classified in the EU so nobody talks about it. In the UK people in the know are raging but the general public have no idea.

      The US is no better, infact the UK collects extra data in conjunction with the US as part of the US Prism Program

      I work with these systems every day, I work digital forensics with a large police county. You donâ(TM)t even have to be law enforcement to get access, your kids school can request access, your doctor can request access, pretty much anyone in a public service job can request your web and email history.

      First google link in search: https://www.theguardian.com/law/2015/oct/30/telecoms-companies-to-retain-browsing-data-under-new-law

      Some of the Agencies that can access collected data:
      https://www.independent.co.uk/life-style/gadgets-and-tech/news/investigatory-powers-bill-act-snoopers-charter-browsing-history-what-does-it-mean-a7436251.html

    4. Re:Screenshot... by Anonymous Coward · · Score: 4, Informative

      As a real lawyer, I use screenshots all the time. Usually, I use them with text messages and Facebook posts, but I could see it working here too. The courts I am in front of allow screenshots because a lot of time, they are the only evidence available in a way accessible to the Court. The thinking of the courts is that you want the best evidence available to be what is admitted. If you don't have the better evidence but have a good reason why, they will let you do so.

      You cannot haul your cell phone provider in front of the court for every little dispute, nor can you bring Apple, or Facebook, so they let in screenshots. In the case of emails, they prefer printouts with full headers but not everyone knows that so in small claims, they will allow lesser evidence in.

      In this case, because the email, by its nature, destroys itself, screenshots are all that would remain of said email. Therefore, the best evidence available to a party is the screenshot, so if the disagreement is about the content of the message, then screenshots will almost have to be admitted if the actual content is in dispute. No better evidence + Good reason why == admissible evidence. Of course, all this assumes there are no other objections to the evidence (relevance, hearsay, privilege, etc.).

  3. Extensions? by hcs_$reboot · · Score: 3, Insightful

    Not long before a bunch of extensions are released to automatically save a copy of all these "self destructive" emails...

    --
    Slashdot, fix the reply notifications... You won't get away with it...
  4. DRM for emails? by TimMD909 · · Score: 4, Insightful

    DRM for emails? Do not want.

  5. Re:Confused by Anonymous Coward · · Score: 3, Insightful

    It's perfectly consistent.

    The email are 'self-destructing' only from the user's perspective. Google can still read them.

  6. the further proprietization of email. by nimbius · · Score: 4, Insightful

    self-destructing, secured, or even recall-able messages have been the hallmark of feature sets demanded by users without so much as a cursory understanding of email. Since most of human civilization uses GMail im sure the hubris of google rides high in testing this new "feature" but for power users or those outside the domain of the big G, this is feature is as useless as 'do not track.'

    mash away at self destruct all you like. Once the message leaves your Google mailserver and enters my Postfix, its mine.

    --
    Good people go to bed earlier.
  7. Embrace, extend, and extinguish? by mi · · Score: 3, Insightful

    the company is now evolving beyond the simple POP3/IMAP/SMTP protocols

    I find this rather worrying for the future of e-mail...

    --
    In Soviet Washington the swamp drains you.
  8. Translation provided by Chris+Mattern · · Score: 3, Insightful

    "the company is now evolving beyond the simple POP3/IMAP/SMTP protocols."

    Translation: "Those leave complete control of the recipients mailboxes in the hands of the recipient. We can't have that."

  9. Too many idiots in this thread by Chameleon+Man · · Score: 3, Insightful

    You all think you're so smart saying "Lol, I can copy/paste or screenshot it!". That's not the point, dummies! Say you want to send someone some info you don't want hanging around in their inbox. They get it, use the info to access...whatever...and then you get assured that they don't just hoard that email. If a user's email is compromised, it's just a house of cards as they can easily skim through and see all the services you're signed up for and reset passwords to those, including banking, credit cards, etc. It's advised to keep your inbox clean to prevent stuff like this from happening, at least now companies that send out the emails will have some control over this.

  10. Exactly by fyngyrz · · Score: 3, Insightful

    If I can read it, I can copy it. The only way to keep me from copying an email is to keep me from reading it.

    Yep. No matter what they do, there's always screen-capture, and if not at some point in the future with the OS (Windows and OSX and Linux can all do this at present), then with a camera; your phone or a DSLR or an HD video camera, etc.

    If it's ever readable, it's readable forever if anyone who can read it wants it to be. End of story.

    --
    I've fallen off your lawn, and I can't get up.