Cyber Security News

Gmail Client-Side Encryption Is Now Publically Available For Everyone

Google announced that CSE (client-side encryption) is now generally available for Gmail and Calendar users. This will let more companies become the sole arbiters of their own data and determine who has access to it.

Google Drive, Docs, Slides, Sheets, and other Workspace previously offered this feature. By protecting user data in the event of a server breach at Google, CSE is predicted to offer added benefits.

For users of Google Workspace Enterprise Plus, Education Plus, and Education Standard, client-side encryption (CSE) is currently generally available.

Benefits of Gmail Client-Side Encryption

Data on a client’s device is encrypted before it is delivered to Google in order to accomplish Gmail CSE. The security is increased since only a machine using the same key as the sender may decrypt the encrypted data.

“Starting today, users can send and receive emails or create meeting events with internal colleagues and external parties, knowing that their sensitive data (including inline images and attachments) has been encrypted before it reaches Google servers”, Google.

Hence, it makes sure that any private information sent in an email’s body or attachments (including embedded photos) is encrypted and rendered unreadable before it reaches Google’s servers.

Notably, the email header, which contains the subject, timestamps, and recipient lists, will not be encrypted.

“Client-side encryption takes this encryption capability to the next level by ensuring that customers have sole control over their encryption keys — and thus complete control over all access to their data”, says Google.

Customers maintain control of the encryption keys, and they use an identity management service to gain access to them, rendering sensitive information unreadable by Google and other outside parties.

“As customers retain control over the encryption keys and the identity management service to access those keys, sensitive data is indecipherable to Google and other external entities”, Google.

By clicking the lock icon next to the Recipients section for any email after it has been toggled on, you can enable “additional encryption.” Users of Gmail can then create their email messages and include attachments as usual.

Sending and receiving encrypted Gmail emails

Any emails you send using end-to-end encryption (E2EE) is encrypted on your end and only decoded upon arrival at the recipient’s end. 

Only the sender and receiver will be able to see the complete contents of an email due to this sort of encryption.

With Gmail CSE, other applications and company administrators may have access to the private keys used to decrypt encrypted emails.

Admins can enable the feature at the domain, organization, and Group levels via the Admin console > Security > Access and data control > Client-side encryption. The option will be disabled by default.

The customers of Google Workspace Essentials, Business Starter, Business Standard, Business Plus, Enterprise Essentials, Education Fundamentals, Frontline, and Nonprofits, as well as legacy G Suite Basic and Business customers, according to the firm, are not currently able to access the feature.

Network Security Checklist – Download Free E-Book

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago