Google says it’s making it easier than ever for businesses to send fully encrypted emails. But there are fears that Gmail’s encrypted email system could be exploited by phishing attacks.
The new system will allow enterprise users of Gmail to send end-to-end encrypted (E2EE) messages to any recipient, whether they’re inside your own organisation or external.
Google Workspace currently uses the Secure/Multipurpose Internet Mail Extensions (S/MIME) protocol to encrypt messages. That requires IT teams at both ends of the chain to manage certificates and deploy them to users, but most organisations simply don’t implement it. Which means the vast bulk of messages are sent unencrypted.
The company has developed a neat workaround that makes the process much easier to deploy, using client-side encryption. Under the new system, if the recipient is a Gmail user (either enterprise or personal), the email is automatically decrypted, and they can reply with encryption switched on.
However, if the recipient isn’t a Gmail user, they will receive an invitation to view the email in a “restricted version of Gmail”. According to Google, the “recipient can then use a guest Google Workspace account to securely view and reply to the email”, as shown below.
Here’s what non-Gmail users will see when sent an encrypted email (image: Google)
Encrypted Gmail: business advantage
Google claims this approach has several benefits for businesses.
For example, IT teams will “have the option to require all external recipients (even if they are Gmail users) to use the restricted version of Gmail,” the company stated in a blog post announcing the new feature. “This helps ensure that their organisation’s data does not end up stored on third-party servers and devices.”
Google added: “It also makes it easier for organisations to protect their data by having the ability to apply security policies and revoke access to emails, no matter how long ago they were sent.
“Essentially, the E2EE email becomes like a document in Google Drive, allowing the IT team to control its access.”
Phishing fears
The concern with Google’s new system is that it will become a target for phishing attacks, with fraudsters generating similar-looking emails that encourage victims to click through and enter their credentials.
Google is alive to this threat, with a warning message appearing when users click on the View Message link reading: “Be careful when signing in to view this encrypted message” and warning recipients to “make sure you trust the sender and their identity provider before entering your username and password”.
Google says it has also developed a new threat protection model using (yep, you guessed it) AI, which “evaluates thousands of combined signals from billions of endpoints based on the actor, behaviour, and content to catch more spam and phishing before they reach users”.
Although that won’t offer any protection to users who aren’t using Gmail.
The new system is now available in beta, but currently only supports sending encrypted email within your own organisation. The ability to send encrypted emails to any Gmail inbox will arrive in the “coming weeks”, with the option to send to any email inbox arriving “later this year”.
Barry has 25 years of experience working on national newspapers, websites and magazines. He was editor of PC Pro and is co-editor and co-owner of BigTechQuestion.com. He has published a number of articles on TechFinitive covering data, innovation and cybersecurity.
To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behavior or unique IDs on this site and show (non-) personalized ads. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Click below to consent to the above or make granular choices. Your choices will be applied to this site only. You can change your settings at any time, including withdrawing your consent, by using the toggles on the Cookie Policy, or by clicking on the manage consent button at the bottom of the screen.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.