12 ms·
OpenPGPjs has passed an independent security audit
- EGreg 8y agoThanks to the great folks at PARAGONIE our open source platform (ie you can actually tell the code is always the same and you can host it yourself) also just passed an independent security audit: https://paragonie.com/audit/L7TtZbFoJBxR91Xg https://paragonie.com/audit/L7TtZbFoJBxR91Xg I didn’t think it was worth it to post to HN as news, though. Perhaps I should start posting our achievements a bit more. Like for example our Group Rides feature: https://youtu.be/PHuYV7q7NeM https://youtu.be/PHuYV7q7NeM
- yacn 8y ago> Perhaps I should start posting our achievements a bit more. Maybe, but don't do it in someone else's thread trying to steal the spotlight from them... Really bad taste.
- EGreg 8y agoHow am I stealing the spotlight from them? They are on the front page, whereas mine is just a comment that's relevant to it. They still have the spotlight, the link is still there and my comment only adds to the number of comments on the story. If anything, the comments saying that they shouldn't be trusted, etc. harm them more than my comment. Actually my comment should be: I don't think being audited by a third party firm is newsworthy, this is us being audited and we didn't post it.
- DoreenMichele 8y agoPR is hard. Replies like the one you got are a hint that you need to learn a lot more than just "This right here that I thought was not really newsworthy is totally newsworthy." ;) (Chin up and all that. This is not intended to be in any way hostile.)
- sshb 8y agoIt seems that easier approach would be to compile Go's openpgp library or something higher level like https://github.com/lastochkanetwork/easypgp https://github.com/lastochkanetwork/easypgp into wasm.
- bankspot 8y agoHave any current protonmail users experienced denial of service from online providers solely because of their email address?
- prolikewh0a 8y agoNot yet at around a year worth of usage. I use a custom .space address which I thought would bring its own issues, but hasn't. I have spf, dkim, and dmarc setup with it as well.
- amaccuish 8y agoYupp. My account at a particular website was terminated. They pointed to their TOS, where "anonymous" address are not allowed. Wasn't even given the chance to keep the account and change the email to an "acceptable" one.
- Sir_Cmpwn 8y agoNot that it matters. They could silently replace it with a backdoored script and your browser would never tell you it happened. And to preempt the ProtonMail rep who is probably going to respond to this comment, I know that you can run the web app on localhost. But that doesn't mean that users who don't are any more secure.
- bastawhiz 8y agoThe readme indicates that it can be installed via npm, so I'm not sure what your concern is. https://github.com/openpgpjs/openpgpjs/blob/master/README.md https://github.com/openpgpjs/openpgpjs/blob/master/README.md
- Sir_Cmpwn 8y agoThat doesn't have anything to do with what I said.
- cdubzzz 8y agoTo be fair, what you said is only tangentially related to the posted article anyway. It is about a security audit of the OpenPGPjs library (what bastawhiz commented about), not how ProtonMail implements it (what you commented about).
- LeoPanthera 8y agoI don't know if Protonmail do this or not, but presumably you could supply the javascript part of your web application as a browser plugin, which would render it immune to attacks on the server.
- taf2 8y agoisn't this why https://developer.mozilla.org/en-US/docs/Web/Security/Subresource_Integrity https://developer.mozilla.org/en-US/docs/Web/Security/Subres... was invented?
- diggan 8y ago
- makmanalp 8y ago> The only limitations come from the platform itself (JavaScript/web), which do not allow for side channel resistance or reliable constant time operations. Overall however this is an exceptional library for JavaScript cryptography. How would this compare to something like WebCrypto, which assume would be implemented in a way that would allow for side channel resistance etc? It does seem surprising that we don't have something like a browser API version of libsodium in widespread use already.
- bartbutler 8y agoYou are confusing crypto primitives with a high-level spec like OpenPGP. OpenPGPjs used WebCrypto and node crypto libraries when available for primitives. You still need a library for the OpenPGP stuff.
- makmanalp 8y agoWhoops, I see my mistake, thanks.
- dane-pgp 8y agoI think you're right to pick up on this "side channel resistance or reliable constant time operations" wording, actually. If the OpenPGPjs library is using WebCrypto for the primitives, then what are the non-constant time operations and JavaScript-specific side channels that have security implications? Such a claim should really be accompanied by a specific threat model. Is the supposed threat actor a MitM that can use the timing of the packets your browser sends to work out when you stopped typing your email and when the email was sent to the server, allowing them to calculate the time taken by the encryption operation and thus infer something about the plaintext of the email? Alternatively, is the threat actor someone running JavaScript code in another tab of the same browser, who can infer how much CPU the browser is using at any given time, with enough accuracy to reveal bits of the private key? Perhaps they are imagining an attacker who could do both, and it would be very interesting to see a practical attack along these lines, but I still think that a decent WebCrypto implementation should make it close to impossible for an attacker to extract any useful information unless the user is sending billions of emails through the ProtonMail web client.
- krn 8y agoI have zero trust in Proton<anything> after learning, that the free ProtonVPN service is provided by a data mining company from Eastern Europe[1]. [1] https://news.ycombinator.com/item?id=17258203 https://news.ycombinator.com/item?id=17258203 (please turn on "showdead" in settings, to see the entire thread)
- driverdan 8y agoThey explained it quite clearly: > We used Tesonet as a local partner before we had an official Lithuanian subsidiary, and rented office space from them. We don't share employees, infrastructure, etc. We have had a similar temporary arrangements with local companies when we opened offices in other jurisdictions where we didn't have an official presence yet. This type of arrangement is common in the startup world.
- krn 8y agoThe section from the "About" page of Tesonet (26 Apr 2018)[1], which got removed soon after that HN thread: "For the latest project, Tesonet is working together with an international brand from Switzerland to create a security product that helps users protect their network traffic. As part of this technical partnership, we are collaborating on datacenter and network infrastructure that can easily supply 10 Gbps worth of bandwidth to users around the world. The product is developed using the latest authentication encryption methods and the best practices in the security world." [1] https://web.archive.org/web/20180426161609/https://tesonet.com/about/ https://web.archive.org/web/20180426161609/https://tesonet.c...
- deleted 8y ago[deleted]
- nabla9 8y agoThere is nothing wrong with data mining itself. It's completely neutral technology. You are just thrwoing shade with link flooding (those who read the links find out that they don't credibly confirm what you say). Tesonet provides all kinds of services, like hosting, software development and cybersecurity for it's customers.
- woranl 8y agoWhy not use WebCrypto instead? No library needed.
- bartbutler 8y agoYou are confusing crypto primitives with a high-level spec like OpenPGP. OpenPGPjs used WebCrypto and node crypto libraries when available for primitives. You still need a library for the OpenPGP stuff.
- acdha 8y agoDoes OpenPGPjs use WebCrypto to create keys which are not extractable? That's the big win here if you can make it impossible for a compromised client to leak keys which were used before/after the compromise.
- Boulth 8y agoThis also means you can't use another computer or that your key is lost if you clear browser data. Unless you'd do backups but I doubt this is standard procedure of ProtonMail users.
- acdha 8y agoThat's true assuming that the browser doesn't offer any way to manage that using e.g. Chrome/Firefox Sync. What PGP really needs is a modern security model so you'd have many device keys registered to an identity rather than requiring the risk of spreading copies around. I think I have IIRC 8 GPG subkeys currently (6 of them being Yubikeys) and every aspect of that toolchain is unacceptable in the modern era.
- Boulth 8y agoI've got the same setup with subkeys per Yubikey (though I had to rotate due to Infineon). What do you mean by "device keys"? Something like forward secrecy keys for initial session setup as used by e.g. Signal? This could be done with some effort... actually Rust OpenPGP library Sequoia developers already work on making this use case easier. Another set of patches circulating on the ML adds support for TPM bound keys, that are non extractable.