ioc.exchange is one of the many independent Mastodon servers you can use to participate in the fediverse.
INDICATORS OF COMPROMISE (IOC) InfoSec Community within the Fediverse. Newbies, experts, gurus - Everyone is Welcome! Instance is supposed to be fast and secure.

Administered by:

Server stats:

1.6K
active users

#gmail

91 posts74 participants0 posts today
Continued thread

Here is Google’s announcement, with a lot of additional detail: workspace.google.com/blog/iden

NB this functionality is good from a security perspective, but its competitive implications will need to be thought through carefully: “the option to require all external recipients (even if they are Gmail users) to use the restricted version of #Gmail.” #DMCCA #DMA

Google Workspace BlogGmail: Bringing easy end-to-end encryption to all businesses | Google Workspace BlogAnnouncing plans to bring easy to use end-to-end encryption in Gmail to all our business customers
Continued thread

Secondly, it’s not clear if #gmail is using this workaround just for message recipients who don’t have their own “digital #X509 certificates” to enable message encryption yet (which would be justifiable) or not (which would be an improvement over the status quo, but not genuine #E2EE.)

Why does neither Google nor Microsoft's cloud services understand the "Maximum size exceeded" error in an email rejection? If a competent mail service rejects an email that is too large, Microsoft will tell users the email was rejected as spam and Google will tell users the email was rejected because the destination mailbox is full. Both are wrong and dumb. #email #gmail #outlook

#Google acaba de llamar #E2EE a un recién estrenado método de cifrado en #GMail que de hecho es la muestra más evidente de lo que podrían querer quienes apoyan #ChatControl.
Las claves de cifrado quedan en mano de los administradores, y quien tenga acceso a ellas puede husmear en las comunicaciones de cualquiera bajo su paraguas. Venden su gestor de contraseñas igual.

Si las llaves de tu coche las custodia otro, no es tu coche.
Con las claves de cifrado sucede lo mismo.

arstechnica.com/security/2025/

Ars Technica · Google unveils end-to-end messages for Gmail. Only thing is: It’s not true E2EE.By Dan Goodin

> The use of Gmail, a far less secure method of communication than the encrypted messaging app Signal, is the latest example of questionable data security practices by top national security officials already under fire for the mistaken inclusion of a journalist in a group chat about high-level planning for military operations in Yemen.

**Waltz and staff used Gmail for government communications, officials say**

washingtonpost.com/national-se

The Washington Post · Waltz and staff used Gmail for government communications, officials sayBy John Hudson