10 ms·
This post would be improved by discussing that their [threat model](https://en.wikipedia.org/wiki/Threat_model https://en.wikipedia.org/wiki/Threat_model) is so
by pushcx 9y ago
This post would be improved by discussing that their [threat model](https://en.wikipedia.org/wiki/Threat_model https://en.wikipedia.org/wiki/Threat_model) is so different than Google's that it regards some of Google's business practices as threats. And that, in turn, there are threats that Google treats as much bigger threats, bringing their own world-class security team to.
Calling this fundamental difference in approach "more secure" manipulates the less-informed instead of educating and almost eliminates the chance of a worthwhile conversation about tradeoffs and values that could be very flattering to ProtonMail.
- someguydave 9y agoThat's a fair criticism. I don't think the Gmail glossy brochure mentions its threat model either.
- blfr 9y agoThey do for their new Advanced Protection Program[1]. The regular Gmail service is not really marketed to the security concious users. It's like comparing Android to Qubes OS. Not really fair. For what they are, Google products are surprisingly secure. [1] https://landing.google.com/advancedprotection/ https://landing.google.com/advancedprotection/
- feld 9y agoQubes has a nice fat attack surface known as the hypervisor. I'm skeptical when people point to this as the panacea of computing security.
- blfr 9y agoIn practice it's a rather thin attack surface and serious cloud providers rely on it so it's both well-tested and any exploit can be used on much more valuable targets than your OS. It's not a panacea. There are physical threats, there are threats from the very hardware you're using. But, like it says on the box, it is a reasonably secure operating system.
- _e 9y agoYes, Qubes is only as secure as Xen which, itself, has had some pretty big security flaws pop up [1]. At the end of the day one has to decide what kind of trade offs they are willing to make in order to balance simple UX and security. [1] https://blog.quarkslab.com/xen-exploitation-part-2-xsa-148-from-guest-to-host.html https://blog.quarkslab.com/xen-exploitation-part-2-xsa-148-f...
- arghwhat 9y agoAnd, in turn, as secure as the hardware, with ROWHAMMER giving means to flipping bits in arbitrary memory locations, including recent work showing that one VM can flip bits in another.
- kakarot 9y agoFor Qubes 4, they are planning to deprecate the Xen paravirtual drivers in favor of the HVM drivers. These drivers are much more battle-tested and less complicated than PV drivers. Also, with their recent foray into enterprise support, they will hopefully be able to expand their auditing efforts in the next couple of years.
- mcny 9y agoI think the parent was talking about sandboxing and permissions
- userpass 9y agoThat sounds to me like a very small attack surface. Updating a hypervisor is far easier than e.g. updating hundreds of statically compiled executables.
- mzzter 9y agoDoes anyone have experience using Google’s advanced protection service? I’m wondering if it’s worth managing the dongles.
- tonyztan 9y agoI signed up last week and it isn't inconvenient at all. Security keys are only used when you first sign in to a device, after which devices are "remembered."
- DavideNL 9y ago> "Google products are surprisingly secure" For one their products are not "secured" from Google seeing your private data...
- bascule 9y agoNeither is ProtonMail. They see all email plaintexts unless you're using end-to-encryption like GPG/PGP. They only encrypt data at rest, and we can only take them at their word that they're even doing that.
- bigiain 9y agoThey claim (tho I haven't confirmed myself) to do encryption at the device - automatically between Protonmail accounts (right now though, they do not support sending pgp encrypted email to a protonmail account with a keypair not generated by them... Which seems a _very_ odd design decision): In simple terms, end-to-end encryption means that messages are encrypted on the sender’s device (before it even leaves their computer or mobile phone), and can only be decrypted by the recipient on their device. This means that no third party which transmits or intercepts the email between the sender and recipient (i.e. internet service providers, the NSA, or even ProtonMail as the mail server operator) can decrypt and view the message. This powerful protection is possible because ProtonMail has PGP email encryption built-in. End-to-end encryption is done automatically without user interaction whenever messages are exchanged between ProtonMail users. For an enterprise using ProtonMail for their email hosting, this means all communications between employees are automatically protected with end-to-end encryption. ProtonMail can also support sending/receiving end-to-end encrypted messages with recipients who are not using ProtonMail. The use of end-to-end encryption makes ProtonMail a better choice for security conscious individuals and organizations.
- adjkant 9y agoGmail isn't floating around any brochures on security though - it's pitch to the majority of its users is "It's Google and Mail and where most people have their emails. You don't want to be that one weirdo at @yahoo.com do you?" and that just about does it. ProtonMail is trying to recruit users with the brochure. That said, even though the argument is a bit flawed here, I think most attracted by it would still prefer ProtonMail for other sound arguments.
- matt_wulfeck 9y agoDo you really believe people use gmail because of its brand? I don't know about any security brochure, but I know I can setup 2FA to use push notifications (not an insecure SMS number), and can check where all of my logins are from, and have "suspicious" logins blocked automatically, etc, etc. I can also create single-use passwords for insecure devices (such as a youtube password just for my apple TV). Not to mention how amazing they are about spam detection. I think their security posture is actually excellent.
- efitz 9y agoThere are absolutely people (many of them) who use GMail because of its brand. They most commonly will say "GSuite" though.
- adjkant 9y agoYes, absolutely. I would guess at least 90% of the users are simply there by defaulting to it. The tech community is not the target market for Gmail. I never said they had bad security, simply that they were not advertising and trying to attract users from it.
- turc1656 9y agoDo you really believe people use gmail because of its brand? Yes. Most definitely. I don't use Gmail and I recently had a discussion with my coworkers about Gmail. When I asked why they use it one person said, "because it's Google" and another said, "What else would I use? Yahoo or Hotmail? Hahahah". A third person responded by saying , "it's just easy because it's Google so it connects to everything else from them."
- pvg 9y agoA missing threat model gives this more credit than it merits. You can replace 'zero knowledge' with 'military grade' and it will be just as meaningful (if somewhat more obviously poor). Plus, you could say they are describing a threat model. If ProtonMail were compromised in this one particular way the confidentiality of your mail would be 'stronger' or 'improved'. This should be as reassuring as 'Switzerland', which is, of course, also trotted out.
- arghwhat 9y agoProtonMail has a publicly available threat model: https://protonmail.com/blog/protonmail-threat-model/ https://protonmail.com/blog/protonmail-threat-model/ Without a threat model (that is, the set of threats that one is trying to secure a system against), you have no idea what someone means by "secure". It could mean unpickable doorlocks, it could mean unbreakable windows, it could mean angry-Hippopotamus-proofing. It could mean that you smelly farts can't escape your pants. Any claim of security without a threat-model is in the most literal sense meaningless. And don't get me started on "Military Grade Encryption", which is a term that at this point should give you a sense of concern, rather than safety.
- pvg 9y agoAny claim of security without a thread-model I'm not sure I understand what your counterpoint here is since we seem to be saying the same thing but I had to go back and fix 'thread model' twice myself. An underestimated threat model to commenting about threat models!
- arghwhat 9y agoI am sorry, I misread your comment slightly, which resulted in the polar opposite meaning. English is a fun language. :)
- fauigerzigerk 9y agoThat sounds a bit formalistic and abstract to me. Perhaps you could educate us on which specific threats you think we should pay attention to when choosing between Gmail and Protonmail. What are some specific threats that Gmail defends us against more effectively than Protonmail?
- metalliqaz 9y agoOff the top of my head I think the number 1 "threat" that Google doesn't protect you from is privacy. They are actively watching your email with algorithms to use for advertising purposes. On the other hand, they have more resources than anyone else to protect against things like DDOS, nation-state hacking/phishing, and physical disasters. They also have a legion of lawyers to protect against improper legal requests, however they will roll right over for a government if it's legal. Protonmail is on point with the privacy, but their security engineering team is probably less than 1/10th that of Google's.
- fauigerzigerk 9y agoI think the right size of any security engineering team is largely determined by the diversity of threats it has to defend against. Same for the legal team. So team size alone doesn't convince me one way or the other, even if I were to completely disregard all privacy issues. I am a Gmail user as is my company, so I do trust them quite a bit. But I feel that Google has a much bigger problem on its hands than Protonmail. Both because of its business model and because Gmail does things like search and spam filtering, which Protonmail cannot do. [Edit] Protonmail actually does spam filtering.
- kbyatnal 9y agoExcept this is no longer true. Google does not read your gmail anymore. https://blog.google/products/gmail/g-suite-gains-traction-in-the-enterprise-g-suites-gmail-and-consumer-gmail-to-more-closely-align/ https://blog.google/products/gmail/g-suite-gains-traction-in...
- njarboe 9y ago
- HenryBemis 9y agoIt can be simplified to: Gmail + 0$ per month = zero privacy for you and anyone who emails you, plus Uncle Sam has full access to your life. Protonmail + 4$ per month = you will never see ads for a <insert_item_name> like the one you just bought, plus you will be driving Uncle Sam crazy!
- 3pt14159 9y agoUncle Sam can root your machine. If Uncle Sam is the threat vector you're better off using pen and paper.
- dredmorbius 9y agoThat costs Uncle Sam resources at scale.
- tonyztan 9y agoUncle Sam can't root everyone's machines at once. If Uncle Sam wants mass surveillance it's going be through the provider.
- ChuckMcM 9y agoIntel Management Engine.
- kuschku 9y agoThat is only remotely exploitable if you use Intel network cards. There’s a reason all my systems use other cards, and are behind a hardware firewall specifically configured for my use cases.
- squarefoot 9y agoThere is still a possibility, a scenario only a crazy conspiracy theorist could imagine a few years back, but I believe the current development of closed chipsets could soon allow remote penetration into any machine using any network card by any vendor, and in a way that nobody can even sniff the suspicious traffic over the network. It seems really complicated, if not impossible, but I'm starting to think it can be done if one has full access to the chipsets and their firmware (users, admins and developers don't, vendors and their "partners" do). Let's assume a system where every piece of hardware has a closed device driver, or part of it, CPU included. We're there, or very close. It's not that hard to imagine a system within the system that can access data (hard drives have closed blobs), read passwords before they are encrypted through keylogging (USB sniffing), make screenshots of the desktop (video card closed blobs) and send them wherever they're instructed to (network card blobs), not to mention downloading and executing arbitrary code. Now one could object that the traffic could be easily intercepted, but what if all network chipsets of all vendors, including those inside routers, had a small set of instructions to intercept any magic packet satisfying some rules and treat it differently. Let's say send it to some hardcoded addresses without counting them or reporting them to user applications; even leds on front panels would not report those packets passing through. The only way to realize something fishy is going on would be by tapping physically into the network cable using non-network dedicated chipsets, say very fast digital analyzers, decode all traffic and match it with what a normal sniffer would report. I admit this is a crazy scenario, but if an entity with nearly infinite resources had the power to force any hardware vendor to put spying hardware/firmware into every machine, wouldn't it attempt to do something like that?