{"id":8527,"date":"2025-04-10T16:56:09","date_gmt":"2025-04-10T16:56:09","guid":{"rendered":"https:\/\/www.europesays.com\/uk\/8527\/"},"modified":"2025-04-10T16:56:09","modified_gmt":"2025-04-10T16:56:09","slug":"google-confirms-gmail-update-choice-3-billion-users-must-now-decide","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/uk\/8527\/","title":{"rendered":"Google Confirms Gmail Update Choice\u20143 Billion Users Must Now Decide"},"content":{"rendered":"<p class=\"color-body light-text\" role=\"button\">Gmail users have a surprising choice to make.<\/p>\n<p>NurPhoto via Getty Images<\/p>\n<p>Update: Republished on April 10 with a report into a new attack designed to defeat existing security techniques and to deliver high-value outcomes.<\/p>\n<p>Gmail needs a rethink, as do Outlook, Apple Mail, and other email platforms. The driver for this is AI \u2014 and not in a good way. <a class=\"color-link\" href=\"https:\/\/www.security.com\/threat-intelligence\/ai-agent-attacks\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.security.com\/threat-intelligence\/ai-agent-attacks\" aria-label=\"Symantec\">Symantec<\/a>, <a class=\"color-link\" href=\"https:\/\/cofense.com\/blog\/microsoft-copilot-spoofing-a-new-phishing-vector\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/cofense.com\/blog\/microsoft-copilot-spoofing-a-new-phishing-vector\" aria-label=\"Cofense\">Cofense<\/a> and most recently <a class=\"color-link\" href=\"https:\/\/hoxhunt.com\/blog\/ai-powered-phishing-vs-humans\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/hoxhunt.com\/blog\/ai-powered-phishing-vs-humans\" aria-label=\"Hoxhunt\">Hoxhunt<\/a> warn that <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/04\/05\/new-gmail-outlook-warning-unbeatable-ai-attacks-are-suddenly-here\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/04\/05\/new-gmail-outlook-warning-unbeatable-ai-attacks-are-suddenly-here\/\" target=\"_self\" aria-label=\"unbeatable AI attacks\" rel=\"noopener\">unbeatable AI attacks<\/a> are now inevitable, as the best known large language models (LLMs) design, develop and even execute attacks. But Gmail users also face a more immediate decision, given a critical problem with its most recent updates.<\/p>\n<p>Hoxhunt says \u201cAI agents can now out-phish elite human red teams, at scale,\u201d which means mass customization as spear phishing attacks tailored to a particular victim become the norm. <a class=\"color-link\" href=\"https:\/\/blog.google\/products\/gmail\/gmail-holidays-2024-spam-scam\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/blog.google\/products\/gmail\/gmail-holidays-2024-spam-scam\/\" aria-label=\"Google,\">Google, <\/a><a class=\"color-link\" href=\"https:\/\/techcommunity.microsoft.com\/blog\/microsoft-security-blog\/staying-ahead-of-modern-day-attacks-part-2-defense-at-scale-approach-with-office\/256881\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/techcommunity.microsoft.com\/blog\/microsoft-security-blog\/staying-ahead-of-modern-day-attacks-part-2-defense-at-scale-approach-with-office\/256881\" aria-label=\"Microsoft\">Microsoft<\/a> and others say they catch \u201cmore than 99%\u201d of the spam, phishing and malware targeting inboxes. And yet millions of messages still get through before today\u2019s trickle of AI attacks becomes an unstoppable tidal wave.<\/p>\n<p>And it isn\u2019t just AI making email threats more potent and hard to detect, such is the non-stop procession of security and captcha-style verifications, that attackers are now turning these against us, finding ways to exploit this for their own purposes.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-8\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/04\/09\/do-not-ignore-nsa-warning-check-your-iphone-settings-now\/\" target=\"_blank\" aria-label=\"NSA Warning\u2014Check These Settings On Your iPhone Now\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/04\/09\/do-not-ignore-nsa-warning-check-your-iphone-settings-now\/\">ForbesNSA Warning\u2014Check These Settings On Your iPhone NowBy Zak Doffman<\/a><\/p>\n<p>That\u2019s the latest warning from <a class=\"color-link\" href=\"https:\/\/cofense.com\/blog\/the-rise-of-precision-validated-credential-theft-a-new-challenge-for-defenders\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/cofense.com\/blog\/the-rise-of-precision-validated-credential-theft-a-new-challenge-for-defenders\" aria-label=\"Cofense\">Cofense<\/a>, which has just reported on a novel and crafty new technique that \u201clevels up their credential phishing tactics using Precision-Validated Phishing, a technique that leverages real-time email validation to ensure only high-value targets receive the phishing attempt.\u201d<\/p>\n<p>This is why I\u2019ve argued email needs a fundamental change, not evolutionary add-ons. A change to better replicate the immediacy and brevity of the messaging platforms pulling users away from email, both in and out of the workplace. A change to leverage private and secure on-device filtering and threat defense. And a change with security built in, not added on. Again, as we now expect from other comms platforms.<\/p>\n<p>Email can\u2019t be adjusted to fit, it needs that rethink. And while many of Gmail\u2019s recent innovations are welcomed \u2014 enhanced sender authentication, cloud-based AI filtering, and (in development) shielded addresses, its two most recent updates show the challenge in building on what we have today.<\/p>\n<p class=\"color-body light-text\" role=\"button\">Gmail&#8217;s AI relevancy search<\/p>\n<p>Google<\/p>\n<p>This month, Google confirmed it is \u201cmaking <a class=\"color-link\" href=\"https:\/\/workspace.google.com\/blog\/identity-and-security\/gmail-easy-end-to-end-encryption-all-businesses\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/workspace.google.com\/blog\/identity-and-security\/gmail-easy-end-to-end-encryption-all-businesses\" aria-label=\"end-to-end encrypted emails\">end-to-end encrypted emails<\/a> easy to use for all organizations\u201d which use Gmail. This delivers the table stakes security we rely on with voice and video comms and with messaging. But it\u2019s harder with email\u2019s wide open architecture. That\u2019s why this change is coming first to enterprises.<\/p>\n<p><a class=\"color-link\" href=\"https:\/\/arstechnica.com\/security\/2025\/04\/are-new-google-e2ee-emails-really-end-to-end-encrypted-kinda-but-not-really\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/arstechnica.com\/security\/2025\/04\/are-new-google-e2ee-emails-really-end-to-end-encrypted-kinda-but-not-really\/\" aria-label=\"Ars Technica\">Ars Technica<\/a> and others have qualified the excitement that quickly followed Google\u2019s game-changiung announcement: \u201cGmail unveils end-to-end encrypted messages. Only thing is: It\u2019s not true E2EE.&#8221; The reason being that the keys protecting the secure email traffic sit within the client-side infrastructure, not within the actual \u201cend.\u201d<\/p>\n<p>As Ars Technica warns, \u201cthe new feature is of potential value to organizations that must comply with onerous regulations mandating end-to-end encryption. It most definitely isn\u2019t suitable for consumers or anyone who wants sole control over the messages they send. Privacy advocates, take note.\u201d<\/p>\n<p>True end-to-end encryption (E2EE) sits within the client itself, managing key exchange between sender and recipient. The only way to deliver E2EE email is a walled garden such as <a class=\"color-link\" href=\"https:\/\/proton.me\/support\/password-protected-emails\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/proton.me\/support\/password-protected-emails\" aria-label=\"Proton\">Proton<\/a>, which relies on manually password protecting emails sent outside.<\/p>\n<p>With <a class=\"color-link\" href=\"https:\/\/about.fb.com\/news\/2024\/09\/an-update-on-how-were-building-safe-and-secure-third-party-chats-for-users-in-europe\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/about.fb.com\/news\/2024\/09\/an-update-on-how-were-building-safe-and-secure-third-party-chats-for-users-in-europe\/\" aria-label=\"Meta\u2019s\">Meta\u2019s<\/a> third-party chats and <a class=\"color-link\" href=\"https:\/\/www.gsma.com\/newsroom\/article\/rcs-encryption-a-leap-towards-secure-and-interoperable-messaging\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.gsma.com\/newsroom\/article\/rcs-encryption-a-leap-towards-secure-and-interoperable-messaging\/\" aria-label=\"GSMA\u2019s\">GSMA\u2019s<\/a> RCS E2EE update, we will see (almost) full E2EE between different walled gardens. <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/03\/14\/fbi-warning-apple-confirms-iphone-update-for-all-users\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/03\/14\/fbi-warning-apple-confirms-iphone-update-for-all-users\/\" target=\"_self\" aria-label=\"RCS\" rel=\"noopener\">RCS<\/a> &#8220;will be the first large-scale messaging service to support interoperable E2EE between client implementations from different providers.\u201d There is no direct read across to email of course. But it moves the bar.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-6\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/04\/10\/samsungs-android-problem-you-have-missed-update-deadline\/\" target=\"_blank\" aria-label=\"Samsung\u2019s Android Update\u2014Millions Of Galaxy Owners Miss Deadline\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/04\/10\/samsungs-android-problem-you-have-missed-update-deadline\/\">ForbesSamsung\u2019s Android Update\u2014Millions Of Galaxy Owners Miss DeadlineBy Zak Doffman<\/a><\/p>\n<p>Gmail is secured with Workspace\u2019s <a class=\"color-link\" href=\"https:\/\/support.google.com\/a\/answer\/10741897\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/support.google.com\/a\/answer\/10741897\" aria-label=\"Client Side Encryption\">Client Side Encryption<\/a> (CSE), which keeps an &#8220;organization\u2019s data private with end-to-end encryption that Google servers and third parties can\u2019t decrypt, giving [an] organization greater control over access to its data. CSE is especially beneficial for organizations that store sensitive or regulated data, like IP, healthcare records, or financial data,&#8221; not person-to-person comms.<\/p>\n<p>And this brings us to the second innovation. <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/03\/24\/google-confirms-gmail-upgrade-3-billion-users-must-now-decide\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/03\/24\/google-confirms-gmail-upgrade-3-billion-users-must-now-decide\/\" target=\"_self\" aria-label=\"AI-based relevancy search\" rel=\"noopener\">AI-based relevancy search<\/a>. Ten days before Gmail\u2019s quasi E2EE, Google <a class=\"color-link\" href=\"https:\/\/blog.google\/products\/gmail\/gmail-search-update-relevant-emails\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/blog.google\/products\/gmail\/gmail-search-update-relevant-emails\/\" aria-label=\"announced\">announced<\/a> \u201cGmail is rolling out a smarter search feature powered by AI to show you the most relevant results, faster\u2026 Search results now factor in elements like recency, most-clicked emails and frequent contacts. With this update, emails you\u2019re looking for are far more likely to be at the top of your search results.\u201d<\/p>\n<p>Using this is in itself a decision for users, given it lets AI loose on your data. On which, Google told me &#8220;our priority is respecting our users\u2019 privacy while giving them choice and control over their data. To that end, this particular tool is one of the &#8216;smart features\u2019 that users can control in their personalization settings.\u201d<\/p>\n<p>E2EE and AI search don\u2019t work together, because they\u2019re both wraps around a legacy comms architecture rather than one built for the world we live in today. Google confirmed to me that E2EE messages \u201care completely excluded&#8221; from AI search. &#8220;We do not have the key to decrypt, so we literally cannot read the message.\u201d<\/p>\n<p class=\"color-body light-text\" role=\"button\">Gmail&#8217;s end-to-end encryption<\/p>\n<p>Google<\/p>\n<p>That\u2019s as it should be, but you can see the problem from a user perspective. Two new headline features don\u2019t work together. Email is a fundamentally insecure platform to which we\u2019re adding AI, and that AI comes with new privacy expectations that email can\u2019t deliver. This is why so much enterprise and personal comms has moved from email to messaging. Cue that rethink and the decision you need to make.<\/p>\n<p>And as you make that decision, whether to opt for privacy and security or AI, you now need to keep in mind the changing threat landscape. Per Cofense\u2019s warning, new \u201cprecision-validated phishing\u201d is one such new tactic to watch for. This is designed to frustrate those charged with keeping our inboxes safe from attacks, which is done by studying new techniques, probing at the attack ecosystems themselves, watching how they work and looking for better ways to stop them.<\/p>\n<p>\u201cThe real-time validation process introduces multiple challenges for defenders,\u201d Cofense says. \u201cCybersecurity teams traditionally rely on controlled phishing analysis by submitting fake credentials to observe attacker behavior and infrastructure. With precision-validated phishing, these tactics become ineffective since any unrecognized email is rejected before phishing content is delivered.&#8221;<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-7\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/04\/10\/microsofts-free-upgrade-offer-for-500-million-windows-users\/\" target=\"_blank\" aria-label=\"Microsoft\u2019s Free Upgrade Offer For 500 Million Windows Users\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/04\/10\/microsofts-free-upgrade-offer-for-500-million-windows-users\/\">ForbesMicrosoft\u2019s Free Upgrade Offer For 500 Million Windows UsersBy Zak Doffman<\/a><\/p>\n<p>Put simply, when a phishing webpage is clicked on \u2014 which would normally come via an email in your Gmail or other inbox, the attack asks for the person\u2019s email address. They can then check this against their database to rule out fake credentials that might imply a security analyst, and then the malicious phishing login is displayed. If the email doesn\u2019t match one that\u2019s expected, the page redirects to something more benign.<\/p>\n<p>\u201cTraditional credential phishing often involves mass email distribution,\u201d Cofense says, \u201ccasting a wide net to capture as many victims as possible. In contrast, precision-validated phishing operates selectively, only engaging with email addresses that attackers have verified as active, legitimate, and often high-value.\u201d<\/p>\n<p>When added to the large-scale AI attacks now on the rise, the need for a redesign of the core platforms we use has never been greater.<\/p>\n","protected":false},"excerpt":{"rendered":"Gmail users have a surprising choice to make. NurPhoto via Getty Images Update: Republished on April 10 with&hellip;\n","protected":false},"author":2,"featured_media":8528,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[634,5593,5595,5592,636,5590,5591,5594,632,633,53,16,15],"class_list":{"0":"post-8527","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-technology","8":"tag-gmail-ai","9":"tag-gmail-android","10":"tag-gmail-data-deletion","11":"tag-gmail-encryption","12":"tag-gmail-gemini","13":"tag-gmail-new-address","14":"tag-gmail-new-app","15":"tag-gmail-upgrade","16":"tag-gmail-warning","17":"tag-google-warning","18":"tag-technology","19":"tag-uk","20":"tag-united-kingdom"},"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@uk\/114314725468556646","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/8527","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/comments?post=8527"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/8527\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media\/8528"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media?parent=8527"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/categories?post=8527"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/tags?post=8527"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}