3 ms·
I'm a paying would-be user of ProtonMail. "Would-be" because it is simply not reliable enough. It is frustrating that they are diversifying (contacts, vpn) when
by maggit 9y ago
I'm a paying would-be user of ProtonMail. "Would-be" because it is simply not reliable enough. It is frustrating that they are diversifying (contacts, vpn) when I find the core product too unreliable to depend on.
I mainly have two problems: 1. The mobile client logs out spontaneously (or crashes and logs out) every once in a while and I have to reenter both the password and the TOTP code. Cumbersome, and really inconvenient if I'm on the go and for example my plane ticket is in ProtonMail. (I don't know my password and keep it in a password manager, inaccessible from my mobile), 2. The web client logs out whenever the browser is restarted. The web browser at least remembers the password, but I need to interact with my phone to get the TOTP code in. This means that I end up in a state where I don't get notifications for new mails, and I have to go and deal with it proactively. They recently released the "bridge", which runs as a daemon and lets me access the mail via IMAP. This alleviates the problem, but it is unfortunately still unavailable for Linux.
Are there any other happy or unhappy ProtonMail users out there? Am I alone in these frustrations?
- stabbles 9y agoI'm happy to use a service that is not Gmail or Outlook. And I like the fact that I can use my custom domain easily. In the end I'm not really using it though, simply because none of my contacts uses it. In that case ProtonMail is simply begging the question when it comes to privacy and security: You can set an expiry for emails to non-Protonmail recipients, meaning they just receive a link to the contents of the email. Obviously you must also password protect it (otherwise gmail / outlook will just follow the link). Now the point is: how do you safely communicate the password? Either you know how to safely communicate a password; in that case why not send the message without ProtonMail? Or you do not know how to safely communicate a password; what security does ProtonMail offer then?
- nothrabannosir 9y agoDepends on your threat model. If you're protecting against dragnet surveillance and retroactive targeted surveillance, after your link expires, then just putting the password right there in the e-mail body, with an expiring link, should work fine. For now. Especially if it's not life-or-death, but you'd just "rather not appear in the data set, if avoidable." To each their own :)
- Fnoord 9y agobitwarden can handle both your password and a TOTP. I suppose other password managers could as well. Personally, I'm not fond of storing TOTP within a password manager. Then again, I also don't like webmail (because the JavaScript code can differ per session and we cannot audit notice any difference). Bridge is interesting.