Skip to main content

Homeland Security is worried about Gmail’s confidentiality mode

One of the most intriguing features in the 2018 update of Google’s Gmail service was confidentiality mode. While it might improve the security of email contents for some users though, the Department of Homeland Security (DHS) is concerned that it could lead to more users than ever before being caught out by phishing scams.

Confidentiality mode works by not sending the actual contents of an email, but sending an email with a link to said content and requiring a password to access. The idea is that users can protect the data they’re trying to communicate with someone on the other end. While that sounds fine in theory, in practice it means clicking on links within emails, which any security expert will tell you is fraught with danger and it’s where phishing hackers make the bulk of their attacks.

A couple of months on from Google’s early rollout of confidentiality mode and other new features, the DHS has been in contact with the tech giant to try and work on a solution to the problem. Google’s response, according to ABCNews, has been to say that it believes no additional security risks have been created with the implementation of the new feature.

That may well be the case for Gmail users, who experience a typical email scenario when receiving confidential emails. However, should that email be sent to someone outside of the Google sphere of influence, a placeholder message and link to the original content is provided instead. According to the DHS, that “presents an opportunity for malicious cyber actors to mimic the email message and phish unwary users.”

Google claims that it has a stellar track record in blocking phishing attempts, suggesting that as many as 99.9 percent of all attempts are caught out by its machine learning and image scanning technologies. However, the potential threat with confidentiality mode isn’t in phishing attacks targeting Gmail users, but in going after those outside of Google’s services. By sending links in emails, Google could be setting a precedent that makes people less wary of unsolicited emails containing links that they need to click.

Keeping away from email links is just one of the many top tips for staying safe online.

Editors' Recommendations

Jon Martindale
Jon Martindale is the Evergreen Coordinator for Computing, overseeing a team of writers addressing all the latest how to…
7 things you didn’t know you could do in Gmail
Google Press Photo of Google products

Gmail is up there as one of the world's most well-known email services, so you're likely already familiar with the basic functionality of it, whether that's sending important reports for work or sharing silly cat photos with friends. However, there are some features hidden in Gmail that you may not know exist.

Did you know that you could send disappearing emails or make Gmail feel a bit more like Outlook, directly through Gmail on the web? We got you covered with the secrets. Here are seven things you didn't know you could do in Gmail.
Send self-destructing emails

Read more
How to add a signature in Gmail
how to file for stimulus

While it might not be necessary for personal emails or when you’re sharing funny cat videos with family members, a lot of Gmail users like to have an email signature for business reasons. Rather than typing out your phone number or contact information every time, Gmail will do all the legwork for you. 

Since this isn’t a default option, you’ll need to head into your Gmail settings to add or change an existing Gmail signature. 
How to add a signature on your desktop
Step 1: Launch your favorite browser and log into your Gmail account as you normally would.

Read more
Gmail experiencing disruption globally, Google confirms
Gmail app icon.

Gmail not working properly? You're not the only one.

Google's web-based email service is experiencing issues, with users around the world affected. The problems appear to have started at around 2 p.m. PT on Tuesday, December 15.

Read more