Technology

Gmail can now send end-to-end encrypted email from your phone — here is what that really protects

Gmail’s Android and iOS apps can now send end-to-end encrypted messages with a tap on the lock icon, no extra app required. What end-to-end means in email, what Google can and cannot see, and when it is worth the extra step.

Gmail can now send end-to-end encrypted email from your phone — here is what that really protects

Email is the oldest thing most of us still use online and the least private: messages sit on servers in readable form, and anyone with access to the server — the provider, an attacker, a government with a warrant — can read them. Google has now brought end-to-end encryption to the Gmail apps on Android and iOS, so that a message can be locked on your phone and opened only on the recipient’s. The rollout is gradual and will reach all Gmail users over time; BleepingComputer first reported it.

How to send one

  1. Compose a message in the Gmail app as usual.
  2. Tap the lock icon in the compose screen.
  3. Switch on Additional encryption, then send.

Encryption is not automatic — ordinary messages stay ordinary — and neither you nor the recipient has to install anything. The encrypted message lands in the recipient’s inbox like any other and opens in Gmail.

What “end-to-end” means here

Standard Gmail is already encrypted in transit, so nobody on the Wi-Fi can read it. End-to-end goes further: the content is encrypted on the sender’s device with a key the recipient holds, and it stays encrypted on Google’s servers. Google itself cannot read the body of the message, which also means it cannot scan it for spam, index it for search or feed it to features like Smart Reply. That trade-off is the reason the setting is opt-in rather than default.

What it does not hide

  • Who you emailed and when. Addresses, timestamps and, usually, the subject line remain visible to the provider.
  • The recipient’s side. Once decrypted on their phone, the message is as safe as their device and their habits.
  • Attachments you forward on. Encryption applies to the message as sent, not to copies made afterwards.

When to bother

For most day-to-day email, the extra tap is unnecessary. It earns its place when the content would hurt if leaked: identity documents sent to an agent, salary or medical details, contracts, anything a journalist or lawyer would rather not have sitting readable on a server. Bangladeshis routinely email passport scans and NID copies for visa, banking and job applications — those are exactly the messages that should now carry the lock.

Source: Prothom Alo

Written by

Tech BD

Editorial team of Tech BD.