Skip to main content

Homeland Security is worried about Gmail’s confidentiality mode

Image used with permission by copyright holder

One of the most intriguing features in the 2018 update of Google’s Gmail service was confidentiality mode. While it might improve the security of email contents for some users though, the Department of Homeland Security (DHS) is concerned that it could lead to more users than ever before being caught out by phishing scams.

Recommended Videos

Confidentiality mode works by not sending the actual contents of an email, but sending an email with a link to said content and requiring a password to access. The idea is that users can protect the data they’re trying to communicate with someone on the other end. While that sounds fine in theory, in practice it means clicking on links within emails, which any security expert will tell you is fraught with danger and it’s where phishing hackers make the bulk of their attacks.

A couple of months on from Google’s early rollout of confidentiality mode and other new features, the DHS has been in contact with the tech giant to try and work on a solution to the problem. Google’s response, according to ABCNews, has been to say that it believes no additional security risks have been created with the implementation of the new feature.

That may well be the case for Gmail users, who experience a typical email scenario when receiving confidential emails. However, should that email be sent to someone outside of the Google sphere of influence, a placeholder message and link to the original content is provided instead. According to the DHS, that “presents an opportunity for malicious cyber actors to mimic the email message and phish unwary users.”

Google claims that it has a stellar track record in blocking phishing attempts, suggesting that as many as 99.9 percent of all attempts are caught out by its machine learning and image scanning technologies. However, the potential threat with confidentiality mode isn’t in phishing attacks targeting Gmail users, but in going after those outside of Google’s services. By sending links in emails, Google could be setting a precedent that makes people less wary of unsolicited emails containing links that they need to click.

Keeping away from email links is just one of the many top tips for staying safe online.

Please enable Javascript to view this content

Jon Martindale
Jon Martindale is a freelance evergreen writer and occasional section coordinator, covering how to guides, best-of lists, and…
10 helpful Gmail tips and tricks everyone should know
Google Pixel Fold in Obsidian showing Gmail app on inner display.

Part of what makes Gmail the go-to email client is its broad range of customization. There's a plethora of ways to use Gmail, and plenty of underused tips that can make it a far more enjoyable experience.

Below, you'll find some of our favorite methods for managing your emails and giving Gmail an extra boost when it comes to organization.
Send and archive in one step

Read more
Google could kill Gmail spam with an upcoming major update
Gmail icon on an Android phone.

Google Workspace has plans to beef up the security within Gmail in the coming year, with a focus on making bulk emails less easy to flood users with.  

While the brand has begun sharing details of its plans for Gmail, it won't begin rolling out updates to the email service until February 1, 2024. The advance notice is to prepare users, especially those who navigate the Gmail platform in bulk, meaning over 5,000 messages at once, of the upcoming changes.

Read more
Google just made this vital Gmail security tool completely free
The top corner of Gmail on a laptop screen.

Hackers are constantly trying to break into large websites to steal user databases, and it’s not entirely unlikely that your own login details have been leaked at some point in the past. In cases like that, upgrading your password is vital, but how can you do that if you don’t even know your data has been hacked?

Well, Google thinks it has the answer because it has just announced that it will roll out dark web monitoring reports to every Gmail user in the U.S. This handy feature was previously limited to paid Google One subscribers, but the company revealed at its Google I/O event that it will now be available to everyone, free of charge.

Read more