diff --git a/content/blog/trying-gmail-confidential-mode-for-g-suite-users/feature-gmail-confidential.jpeg b/content/blog/trying-gmail-confidential-mode-for-g-suite-users/feature-gmail-confidential.jpeg new file mode 100644 index 0000000..381e2fa Binary files /dev/null and b/content/blog/trying-gmail-confidential-mode-for-g-suite-users/feature-gmail-confidential.jpeg differ diff --git a/content/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-01.png b/content/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-01.png new file mode 100644 index 0000000..3da0323 Binary files /dev/null and b/content/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-01.png differ diff --git a/content/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-02.png b/content/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-02.png new file mode 100644 index 0000000..2042200 Binary files /dev/null and b/content/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-02.png differ diff --git a/content/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-03.png b/content/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-03.png new file mode 100644 index 0000000..974cb25 Binary files /dev/null and b/content/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-03.png differ diff --git a/content/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-04.png b/content/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-04.png new file mode 100644 index 0000000..5b96aa0 Binary files /dev/null and b/content/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-04.png differ diff --git a/content/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-05.png b/content/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-05.png new file mode 100644 index 0000000..4a18d3e Binary files /dev/null and b/content/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-05.png differ diff --git a/content/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-06.png b/content/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-06.png new file mode 100644 index 0000000..6a5a2e7 Binary files /dev/null and b/content/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-06.png differ diff --git a/content/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-07.png b/content/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-07.png new file mode 100644 index 0000000..a5c6618 Binary files /dev/null and b/content/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-07.png differ diff --git a/content/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-08.png b/content/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-08.png new file mode 100644 index 0000000..87e6ee1 Binary files /dev/null and b/content/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-08.png differ diff --git a/content/blog/trying-gmail-confidential-mode-for-g-suite-users/index.md b/content/blog/trying-gmail-confidential-mode-for-g-suite-users/index.md new file mode 100644 index 0000000..cb91f1b --- /dev/null +++ b/content/blog/trying-gmail-confidential-mode-for-g-suite-users/index.md @@ -0,0 +1,92 @@ +--- +title: "Trying Gmail Confidential Mode for G Suite Users" +description: "Gmail Confidential mode allow G Suite users sending emails with expiration date, restrict to forward, copy, print, or download email content or attachments." +date: 2019-05-29T02:40:06+07:00 +lastmod: +draft: false +noindex: false +featured: false +pinned: false +# comments: false +series: +# - +categories: + - Security + - Privacy +tags: + - Gmail +images: +# - +# menu: +# main: +# weight: 100 +# params: +# icon: +# vendor: bs +# name: book +# color: '#e24d0e' +authors: + - ditatompel +--- + +On March 7, 2019, Google announced that they launch their new feature: [Gmail confidential mode](https://www.google.com/appserve/mkt/p/AFnwnKXVaLLz4xNwmc5rWL3tVvNvAeKWlMyQlIOqGxA59ESDm6x2hiqez7CPqHv4WcsTIxKrMbr16TX1OgtZum8Vy6CMwLmZErvwhqp8_CA7) in beta. This feature allow G Suite users with Gmail enabled **sending emails with expiration date**, in additional, the **recipients won't be able to forward, copy, print, or download email content or attachments and sender can be revoke email message any time**. + + + +I am super exited about the this features. how come an email couldn't be forwarded? How does Google delete / revoke e-mails that already sent to another e-mail servers? Therefore, let's find out! + +## Getting Started +This feature will become generally available (GA) on June 25, 2019 and will be set to default ON for all domains with Gmail enabled. So **before the date, you need to be G Suite admin to enable this feature**. + +To enable confidential mode for G Suite organisation, go to the Admin console and navigating to **Apps** > **G Suite** > **Settings for Gmail** > **User settings**. There will be select option to **Enable confidential mode**. + +![Google Admin Console](gsuite-confidential-01.png#center) + +## End Users - Sender +Once Gmail confidential mode is activated by admin, users can use Gmail confidential mode. When they compose an email, there is a button to enable confidential mode for the email. + +![Google confidential mode button](gsuite-confidential-02.png#center) + +If users click on the button, it opens the Gmail confidential mode user settings dialog box where they can modify the settings: + +![Google confidential mode dialog box](gsuite-confidential-03.png#center) + +Users can set an expiration date for messages and messages can revoked by sender at any time. When choosing *"No SMS passcode"* option, Google will send passcode to recipients by email. + +## End Users - Recipient's +I tried sending an email with confidential mode enabled from G Suite to non Google-related e-mail service (in this case is cPanel), the results is like this: + +![Google confidential mode message](gsuite-confidential-04.png#center) + +When user sends a confidential message, **Gmail replaces the message body and attachments with a unique link**. Only the subject and body containing the unique link are sent via SMTP. There's no other special email headers set by Gmail confidential message. So, that's the reason why sender can revoke the mail message: the **mail body and attachment are kept at Google servers**. The recipient's are forced to read confidential email message from the generated link. + +When recipient's click at message link, a new tab in recipient's browser will open and recipient's need to click on **"SEND PASSCODE"** button. The one-time passcode will be sent to the recipient's e-mail (or phone number if sender choose "SMS passcode" option). + +![Google confidential mode passcode](gsuite-confidential-05.png#center) + +After verifying passcode, recipient's will be able to see the original email message. + +![Google confidential mode opened](gsuite-confidential-06.png#center) + +## Google Really Keeps Their Words +On the ~~"simple"~~ message page, Google really keeps his word: there are no **"forward message"** button. Recipient's won't be able to print or copy the message contents because shortcut features CTRL + P for printing pages, and mouse click on message body is disabled. Trying to print using browser menu options won't help because message body **CSS** likely set to `@media print { display: none !important; }`. + +![Google confidential mode disable copy](gsuite-confidential-07.png#center) + +The most interesting thing is when opening the **developer console**/**inspect element** (look at the picture below). + +![Browser developer console](gsuite-confidential-08.png#center) +When I open the attached link, my browser is currently being logged in to my gmail.com personal account and google maybe ~~tracking~~, or at least they know that I've access (maybe as the owner, or an unauthorized user) of recipient's email. Yes, Google know that recipient's email (in this case `administrator@devilzc0de.id`) having relations or linked to my personal gmail account. :) + +## Conclusions +- Removes the option to forward, copy, download or print messages **reduce the risk** of confidential information being accidentally shared with the wrong people. +- Protecting sensitive content in your emails by creating expiration dates and additional authentication via text message to view an email makes it **possible to protect data even if a recipient’s email account has been hijacked** while the message is active. +- Although confidential mode helps prevent the recipients from accidentally sharing your email, **it doesn't prevent recipients from taking screenshots or photos of messages or attachments**. +- Recipients who have **malicious programs** on their computer **may still be able to copy or download your messages or attachments**. +- When sending emails, **subject header should not contain any confidential content**. + +## Resources +- [https://gsuiteupdates.googleblog.com/2019/03/keep-data-secure-with-gmail-confidential-mode-beta.html](https://gsuiteupdates.googleblog.com/2019/03/keep-data-secure-with-gmail-confidential-mode-beta.html) +- [https://support.google.com/a/answer/7684332](https://support.google.com/a/answer/7684332) +- [https://support.google.com/vault/answer/9000913](https://support.google.com/vault/answer/9000913) + diff --git a/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/feature-gmail-confidential_hucd23d725102fc91c948972a3ddf9aed7_77058_0x360_resize_q75_box.jpeg b/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/feature-gmail-confidential_hucd23d725102fc91c948972a3ddf9aed7_77058_0x360_resize_q75_box.jpeg new file mode 100644 index 0000000..35bbe08 Binary files /dev/null and b/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/feature-gmail-confidential_hucd23d725102fc91c948972a3ddf9aed7_77058_0x360_resize_q75_box.jpeg differ diff --git a/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/feature-gmail-confidential_hucd23d725102fc91c948972a3ddf9aed7_77058_0x640_resize_q75_box.jpeg b/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/feature-gmail-confidential_hucd23d725102fc91c948972a3ddf9aed7_77058_0x640_resize_q75_box.jpeg new file mode 100644 index 0000000..13f7b2e Binary files /dev/null and b/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/feature-gmail-confidential_hucd23d725102fc91c948972a3ddf9aed7_77058_0x640_resize_q75_box.jpeg differ diff --git a/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/feature-gmail-confidential_hucd23d725102fc91c948972a3ddf9aed7_77058_2dec2b49ad4414d24174726dc2003211.webp b/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/feature-gmail-confidential_hucd23d725102fc91c948972a3ddf9aed7_77058_2dec2b49ad4414d24174726dc2003211.webp new file mode 100644 index 0000000..61e1dc0 Binary files /dev/null and b/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/feature-gmail-confidential_hucd23d725102fc91c948972a3ddf9aed7_77058_2dec2b49ad4414d24174726dc2003211.webp differ diff --git a/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/feature-gmail-confidential_hucd23d725102fc91c948972a3ddf9aed7_77058_8c480fe77a2b964f5b5d6156cd618910.webp b/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/feature-gmail-confidential_hucd23d725102fc91c948972a3ddf9aed7_77058_8c480fe77a2b964f5b5d6156cd618910.webp new file mode 100644 index 0000000..4da397c Binary files /dev/null and b/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/feature-gmail-confidential_hucd23d725102fc91c948972a3ddf9aed7_77058_8c480fe77a2b964f5b5d6156cd618910.webp differ diff --git a/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-01_hu28c1a0d40001d111d61da449c17f27ea_70323_805x699_resize_q75_h2_box_3.webp b/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-01_hu28c1a0d40001d111d61da449c17f27ea_70323_805x699_resize_q75_h2_box_3.webp new file mode 100644 index 0000000..bf5622f Binary files /dev/null and b/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-01_hu28c1a0d40001d111d61da449c17f27ea_70323_805x699_resize_q75_h2_box_3.webp differ diff --git a/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-02_hu0a8500f7ac37bf4993fda645332251c3_42790_532x581_resize_q75_h2_box_3.webp b/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-02_hu0a8500f7ac37bf4993fda645332251c3_42790_532x581_resize_q75_h2_box_3.webp new file mode 100644 index 0000000..5530dba Binary files /dev/null and b/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-02_hu0a8500f7ac37bf4993fda645332251c3_42790_532x581_resize_q75_h2_box_3.webp differ diff --git a/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-03_hu683ed7e154855e3677a1f8f2ce9ff5be_28545_503x406_resize_q75_h2_box_3.webp b/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-03_hu683ed7e154855e3677a1f8f2ce9ff5be_28545_503x406_resize_q75_h2_box_3.webp new file mode 100644 index 0000000..3f652e3 Binary files /dev/null and b/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-03_hu683ed7e154855e3677a1f8f2ce9ff5be_28545_503x406_resize_q75_h2_box_3.webp differ diff --git a/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-04_hucb865e268b2c75d1067487fcb45b2ab9_200989_1184x594_resize_q75_h2_box_3.webp b/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-04_hucb865e268b2c75d1067487fcb45b2ab9_200989_1184x594_resize_q75_h2_box_3.webp new file mode 100644 index 0000000..e00b7be Binary files /dev/null and b/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-04_hucb865e268b2c75d1067487fcb45b2ab9_200989_1184x594_resize_q75_h2_box_3.webp differ diff --git a/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-05_hu3c317ce3ab3a5b637843195967de957a_45702_1280x734_resize_q75_h2_box_3.webp b/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-05_hu3c317ce3ab3a5b637843195967de957a_45702_1280x734_resize_q75_h2_box_3.webp new file mode 100644 index 0000000..3622a62 Binary files /dev/null and b/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-05_hu3c317ce3ab3a5b637843195967de957a_45702_1280x734_resize_q75_h2_box_3.webp differ diff --git a/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-06_hud5ff38ae3d98d1a2a39f95977ae97b17_72318_1280x735_resize_q75_h2_box_3.webp b/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-06_hud5ff38ae3d98d1a2a39f95977ae97b17_72318_1280x735_resize_q75_h2_box_3.webp new file mode 100644 index 0000000..2b310ed Binary files /dev/null and b/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-06_hud5ff38ae3d98d1a2a39f95977ae97b17_72318_1280x735_resize_q75_h2_box_3.webp differ diff --git a/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-07_hu58f8af399e39aebec32cc9291f5b9ac1_96266_1278x735_resize_q75_h2_box_3.webp b/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-07_hu58f8af399e39aebec32cc9291f5b9ac1_96266_1278x735_resize_q75_h2_box_3.webp new file mode 100644 index 0000000..0dd51be Binary files /dev/null and b/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-07_hu58f8af399e39aebec32cc9291f5b9ac1_96266_1278x735_resize_q75_h2_box_3.webp differ diff --git a/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-08_huead2a7e0a8a4e2f9b6d01c3f0e3734c0_157556_1278x734_resize_q75_h2_box_3.webp b/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-08_huead2a7e0a8a4e2f9b6d01c3f0e3734c0_157556_1278x734_resize_q75_h2_box_3.webp new file mode 100644 index 0000000..bead875 Binary files /dev/null and b/resources/_gen/images/blog/trying-gmail-confidential-mode-for-g-suite-users/gsuite-confidential-08_huead2a7e0a8a4e2f9b6d01c3f0e3734c0_157556_1278x734_resize_q75_h2_box_3.webp differ