Arthur Posted March 8, 2019 Author Posted March 8, 2019 (edited) Has anyone heard any more on this? Yes. https://gsuiteupdates.googleblog.com/2019/03/keep-data-secure-with-gmail-confidential-mode-beta.html We’re opening a beta program for Gmail confidential mode. With confidential mode, it’s easier to protect sensitive content in your emails by creating expiration dates or revoking previously sent messages, and removing options for recipients to forward, copy, print, and download. Who’s impacted Admins and end users Why you’d use it Built-in Information Rights Management (IRM) removes the option to forward, copy, download or print messages. This helps reduce the risk of confidential information being accidentally shared with the wrong people. In addition to protecting sensitive content in your emails by creating expiration dates, you can also require additional authentication via text message to view an email. This makes it possible to protect data even if a recipient’s email account has been hijacked while the message is active. How to get started Admins: Gmail confidential mode Beta is available as an opt-in to all G Suite customers. Admins can opt-in to the beta by going to the Admin console and navigating to Apps > G Suite > Settings for Gmail > User settings. Here they will be able to select the option to Enable confidential mode. End users: Once Gmail confidential mode is activated in the Admin console, users can send Gmail confidential mode emails. When they compose an email, there is a button to enable confidential mode for the email. Additional details At the beta launch, Gmail confidential mode will: Allow users to set an expiration date for messages or revoke access at any time Disable options to forward, copy, print, and download the email body and attachments Allow users to set SMS passcodes wherein recipients will get a passcode by text message to be able to access the email sent using confidential mode Let users choose to remove access early before the expiration date. Note: Although confidential mode helps prevent the recipients from accidentally sharing your email, it doesn't prevent recipients from taking screenshots or photos of your messages or attachments. Recipients who have malicious programs on their computer may still be able to copy or download your messages or attachments. Additionally, if your users send or receive messages in Gmail confidential mode, Vault will retain, preserve, search and export confidential mode messages. The message body of received messages will be accessible in Vault only if the sender of the message is from within your organization. Edited March 8, 2019 by Arthur 4
jthompson Posted March 8, 2019 Posted March 8, 2019 (edited) Just been testing this. The expiration options range from 1 day to 5 years, although the sender can pull access at any point using the button added to their copy in sent items. The SMS option requires the sender to enter the phone number: the recipient doesn't get to specify the phone number to use. I've taken some more screenshots so people can see how the various stages will appear to end users. Confidential mode stands out a little when used because it changes the compose window accent colour to a darker blue. [ATTACH=CONFIG]52518[/ATTACH] Edited March 8, 2019 by jthompson
markwilfan Posted March 8, 2019 Posted March 8, 2019 If anybody is doing ssl inspection on google domains you'll need to add an entry to not inspect locker-pa.*.google.com otherwise the send an sms code thing breaks at the user end 2
jthompson Posted March 8, 2019 Posted March 8, 2019 Not really sure of the value of this at the moment. I guess it ensures the message body and attachments aren't sent over an unencrypted channel. It seems like security theatre more than anything, though, and another thing for phishers to try and emulate.
fiza Posted March 8, 2019 Posted March 8, 2019 When looking at the sms code option it says if you choose no sms code and the recipient does not have a gmail account then the recipient will receive a code via email. How does that make sense? It doesnt work as I sent a confidential email to my hotmail account and on receiving it and clicking on the link I was asked to sign in to a gmail account first before I could open the email. Phishers paradise!!
jthompson Posted March 8, 2019 Posted March 8, 2019 (edited) I sent one to a non-Gmail account (although not Hotmail) and after clicking the link in the email, the recipient is shown a Google-hosted page with a "Send passcode" button. That sends a passcode to the same email address. No Google account required. It's an equivalent sequence for the SMS method, too (i,e. they see a "Send me a code" button). Try it in a private browser tab. Perhaps if you're signed into a Google account already it upsets it a bit? Edited March 8, 2019 by jthompson
enjay Posted March 8, 2019 Posted March 8, 2019 The SMS option requires the sender to enter the phone number: the recipient doesn't get to specify the phone number to use. Of course it does. What security is it if the recipient gets to choose which phone number receives the text? The idea is the sender specifies the mobile number to ensure it can only be read by the right person. It does limit it though - fine for emailing parents, but less use when sending things to County/NHS/etc.
enjay Posted March 8, 2019 Posted March 8, 2019 It doesnt work as I sent a confidential email to my hotmail account and on receiving it and clicking on the link I was asked to sign in to a gmail account first before I could open the email. I found that when testing from my personal GMail a few months back. I suspect it is a deliberate MS-Google thing, it works fine in other email clients. Phishers paradise!! Agreed!
jthompson Posted March 8, 2019 Posted March 8, 2019 Of course it does. What security is it if the recipient gets to choose which phone number receives the text? The idea is the sender specifies the mobile number to ensure it can only be read by the right person. Indeed. I was just relaying how it works, in case anyone thought it might be a Google only affair where the recipient needs to be a Google account with a pre-verified mobile number or something.
enjay Posted March 11, 2019 Posted March 11, 2019 Am I missing something here? I've enabled it on the IT Admin organisation, but I'm not getting the icon come up. Do I have to enable it for the whole domain? I was hoping to get a look at it first and write some documentation on it.
rogerdnixon Posted March 11, 2019 Posted March 11, 2019 You enable it on an OU or Group level. Took a while to show when I first enabled it and a few reloads of mail.
enjay Posted March 11, 2019 Posted March 11, 2019 You enable it on an OU or Group level. Took a while to show when I first enabled it and a few reloads of mail. I enabled it on Friday, should it have appeared for me by now?
rogerdnixon Posted March 11, 2019 Posted March 11, 2019 I enabled it on Friday, should it have appeared for me by now? I'd say so. I've had a few users email me saying it was not there - a reload of GMail made it appear in every case so far. Does not appear on the Android app for me yet - only web.
enjay Posted March 11, 2019 Posted March 11, 2019 I'd say so. I've had a few users email me saying it was not there - a reload of GMail made it appear in every case so far. Does not appear on the Android app for me yet - only web. I've just done a Ctrl+F5, and it is now there for me. 1
enjay Posted March 13, 2019 Posted March 13, 2019 So, when I send confidential emails to another Google address, they just appear as normal in their inbox. Is that how it is meant to be? I don't see how that's secure...
rogerdnixon Posted March 13, 2019 Posted March 13, 2019 So, when I send confidential emails to another Google address, they just appear as normal in their inbox. Is that how it is meant to be? I don't see how that's secure...The option to print, forward etc are all disabled and you set and expiry date. You can optionally add a passcode via a phone number you supply. You can also use SMIME encryption if you want a higher level of encryption than the standard TLS.
enjay Posted March 14, 2019 Posted March 14, 2019 The option to print, forward etc are all disabled and you set and expiry date. You can optionally add a passcode via a phone number you supply. You can also use SMIME encryption if you want a higher level of encryption than the standard TLS. But the email is still unencypted and readable by anyone on the recipient's computer. Stopping printing and forwarding is nice, though. I am aware of the phone number option, but it isn't always practical - we could do it when emailing parents (although the extra steps would quickly drive the pastoral admins crazy) but couldn't use it when emailing county, NHS, other schools, etc.
rogerdnixon Posted March 14, 2019 Posted March 14, 2019 Not exactly sure what you want then. I get these things from O365 users which send "encrypted" emails and I just click on the link and it opens - nothing more needed to authenciate. If you use SMIME - you need to have the certificate added to the device to be able to read the email - if thats what you want. Perhaps users should lock their device?
enjay Posted March 14, 2019 Posted March 14, 2019 Not exactly sure what you want then. What I want is a way to send personal information via email without committing a GDPR data breach.
rogerdnixon Posted March 14, 2019 Posted March 14, 2019 I suggest you do a feature request specifying exactly what you require - they tend to be very good at listening to their users. If you enable SMIME you can do an exchange of emails with the other person and see what level of encryption they are using by looking at the padlock symbol - goes green if they support SMIME.
enjay Posted March 14, 2019 Posted March 14, 2019 SMIME is just about encryption during transit though isn't it, not at rest in the Outlook PST file on the recipient's computer?
rogerdnixon Posted March 14, 2019 Posted March 14, 2019 Not sure about Outlook - been years since I used it. I do know that you need the certificate installed on the device - otherwise, you won't be able to read the message (so having their login details is not enough). Mind you - I've yet to find an external organisation (except for Google) that actually support it - so its probably not that useful and I don't enable it for staff unless they request it (one to date!). then you have the faff of renewing certificates etc. Many don't even do TLS..... What confidential mode does bring is the inability to open the message without the code (unlike on O365 where you just click on the link and it opens - never been quite sure what this is achiving...). I've not seen that on anything other than a separate third party product that both ends need to subscibe to. So you need the login details of the individual (maybe get past 2FA - in our case) and nick their mobile phone to read the message.
mavhc Posted March 14, 2019 Posted March 14, 2019 If you want encryption while sending then enforce TLS for SMTP, if you want a simple 2 factor sms auth then use confidential mode, if you want useless encryption use Office365 message encryption, if you want real encryption use S/MIME public key encryption. So, how do I set up S/MIME for free?
rogerdnixon Posted March 14, 2019 Posted March 14, 2019 I did a guide a while back - https://wpsit.blogspot.com/2018/06/smime-email-signature-and-encryption.html 1
jthompson Posted March 14, 2019 Posted March 14, 2019 SMIME is just about encryption during transit though isn't it, not at rest in the Outlook PST file on the recipient's computer? I believe S/MIME can encrypt the message body if you choose to for a particular message, so that it's encrypted at rest. Otherwise it's just signing your messages to prove they're from you. Google's implementation is hosted S/MIME, which I think is subtly different: the keys are stored by Google, not by the end users, allowing G Suite admins access to their users' encrypted messages. Haven't had much time to toy with it yet but it's on my list of things to look at implementing.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now