Hacker News new | ask | show | jobs
by Alupis 4376 days ago
> Why in the world should that be assumed instead of checked?

Because email is not encrypted and not secure... so any server or anybody in between GS and the google server that data wound up on, could have a copy or seen a copy.

Not to mention all the possible ways this data could be exposed. The receiver took a picture. Printed it. Saved to a file. Forwarded it and it was forwarded again. Not every device marks emails as "read" on the server. The point is, Google can't tell GS if this data is secure or not. Deleting the email is irrelevant at this point.

You are forced to assume it has been exposed because the data left your premise and your control.

1 comments

Most email these days is sent via TLS. Google could check if it was.

Of course they wouldn't just check if the email was marked as read, but the server very likely knows if the email (or the attachment if it was one?) has been accessed at all.