Hacker News new | ask | show | jobs
by parliament32 2654 days ago
If anyone is curious how it works with external accounts, I just tested it:

1) Mail arrives (subject intact) with text like "John Doe has sent you an email via Gmail confidential mode" and a "View Email" link

2) The link takes you to a "To view this email, you must first confirm your identity. A one-time passcode will be sent to (your email)" page.

3) Entering the separately-emailed passcode lets you see the email body in-browser. Selecting text is disabled in the body (so no copy-paste), trying to print the page blanks out the body area -- I'm sure you could bypass either with a bit of JS wizardry. Printscreen/screenshot work as expected.

2 comments

Ugh... there are companies that did this sort of stuff for Outlook users, and it's a royal pain in the ass.

It's not searchable, it can't be archived for legal purposes this way, this is a nightmare for anyone that does business with you.

That seems like a perfect way to spear-fish people for their google password.