9 ms·
I switched to protonmail after losing my gmail password.It was literally impossible to get my account back thanks to gmail "security features". The 500mb free p
by SUr3na 8y ago
I switched to protonmail after losing my gmail password.It was literally impossible to get my account back thanks to gmail "security features". The 500mb free plan is enough for personal usage. I hope other 3rd world countries don't block it following Russia.interestingly this happened not long after EU €2 million award.Probably someone read the news and googled protonmail, saw "encrypted email" in Wikipedia page and decided to block the whole thing.
- pmlnr 8y agoOwn domain. That's the most important part of email. If you have that, you can move to wherever you want.
- aljarry 8y agoIt's also the weak point - do you trust your domain provider he won't allow a domain move / access based on parts of your personal information, like here [0]? Also is it only domain block and not ip block? [0] https://medium.com/@N/how-i-lost-my-50-000-twitter-username-24eb09e026dd https://medium.com/@N/how-i-lost-my-50-000-twitter-username-...
- Semaphor 8y agoYou shouldn't use the almost-scammers of GoDaddy as an example. Whenever I hear any Domain horror story it's about GoDaddy, it seems like a bad idea to extrapolate from them.
- seszett 8y agohttps://twitter.com/n https://twitter.com/n Apparently he's got his @N account back. I wonder how it happened, I don't see anything about it in the article.
- deadbunny 8y agoWell, that made me activate 2fa on my domain provider. Thanks!
- megous 8y agoYes, my main domain is locked by the registry and transfer requires some form of state ID validation with the registry to unlock the domain, before a registrar can transfer the domain. Should be good enough protection against social engineering targeting registrars.
- deleted 8y ago[deleted]
- LinuxBender 8y agoYou can take this a step further. You can set up multiple VM's in multiple regions to be your MX relays for your domains and route the traffic to whichever mail provider you want to use. You can then enforce TLS or set up TLS transport rules to require/optionally validate or enforce name+cert validation for specific domains (banks, etc). This also means that you can queue up mail even if that provider goes offline and you can see if the content is being tampered with (message sizes, headers excluded). If your mail provider runs into problems or you choose to change, then instead of waiting for DNS to propagate, you simply update your relay configuration. I should add that not all paid mail providers support this. Some lower-end providers require that you point your MX directly to them. Check before setting this up.
- johnisgood 8y ago> I switched to protonmail after losing my gmail password.It was literally impossible to get my account back thanks to gmail "security features" Same here. I gave them everything there is to identify me yet they refused to help on the same grounds. The only difference was the phone number, because the one associated with the account died. Funny thing is, if it were not for an accidental removal of cookies, I would still be using that account, and I would have been able to login as it only seems to ask for the code sent via SMS is when you lose your cookies and/or change your user agent. I switched to protonmail for non-serious e-mails.
- 0xfaded 8y agoI've been surprised to learn that several of my non-technical friends forget their passwords and rely on cookies, and then reset the password using their phone number whenever the cookies are lost.
- pampa 8y agoProbably it is better to forget a strong password and reset it, than use a weak password that is easy to remember. Last year I was working on a service that skipped passwords altogether. We used the phone number and a one time pin code by sms for registration, login and order confirmation all in one step.
- SUr3na 8y agoIf you lose your phone number gmail asks you these: -Last password you remember -Last time when you logged in -Your security questions -Devices connected with your Google account Just to tell you gmail is unable to recover your account. I am not sure but I think the more you try to recover it the worse it gets (which is understanble). So either you have the phone number and you magically get everything else in those questions right(what counts as right is the real question), or you enter a rabbit hole and get further from getting your account back the more you try.I'm not blaming this system entirely but apparently nothing matters except your phone number when it comes to recovering your account.
- 8y ago
- westpfelia 8y agoPeople didnt jump on blocking Telegram after Russia blocked it also. So I dont see people jumping on the bandwagon now. Well except for maybe other countries ran by authoritarians.
- arisAlexis 8y agoif we keep using it (the "free world") then they will be the ones missing out on communication capabilities because we can send them email but they can't.
- akskos 8y agoI once lost my protonmail password and was able to get my account back by providing only my browser information, display name, rough timestamps of my requests to their servers and that "i preserved the last session for quite long time". Not sure how secure that was :d Of course I didn't get back any of the emails since they were encrypted with the previous password but still if that is their normal protocol, someone with my browser information and name could just mitm me recording the timestamps of requests to protonmail's server and request a password reset.
- gruez 8y ago>someone with my browser information and name could just mitm me recording the timestamps of requests to protonmail's server and request a password reset. If they can MITM you, why not steal the password directly, or serve malicious js to get your password?
- uponcoffee 8y agoBecause https mitigates their attack vectors as a mitm. They can't steal the password since it's not sent in plaintext, and for similar reasons can't deliver/inject malicious Javascript. They could collect timestamps though and scrape header information from http connections to other sites.
- StreamBright 8y agoNot really. It just requires HTTPS mitm. It is harder to have a CA that can create a cert that looks like it was issued by the original website you are trying to achieve but this is standard practice in gov agencies to mitm HTTPS communication. The mitigation of these sort of attacks is called certificate pinning. https://security.stackexchange.com/questions/29988/what-is-certificate-pinning https://security.stackexchange.com/questions/29988/what-is-c...
- uponcoffee 8y agoThat's a fair point. My reply was more in the context of the root comment - and with an average attacker in mind - where they were describing eavesdropping as opposed an attack carried out by a sophisticated actor. My point was that MITMing HTTPS and HSTS isn't really necessary to carry out an attack as described by the root comment. You only need to be in position to eavesdrop and/or MITM http connections to scrape together the necessary information; a much lower bar.
- BorRagnarok 8y ago1st, Russia is not a 3rd world country. Second, if you'd read the article, it wasn't a case of someone seeing "encrypted email" in a description of protonmail and blocking it, they were having problems with bomb threats.
- SUr3na 8y agoWhat Exactly protonmail offers you over any other disposable email if you are sending bomb threats? I think this was just a an excuse made just to have an excuse.
- duchenne 8y ago> I hope other 3rd world countries don't block it following Russia. Interestingly, the original meaning of "third world" country was: a country that is neither part of the Soviet block nor the US side ( the two first worlds)
- pessimizer 8y agoThat's also the current meaning of "third world." A lot of people use it to mean "country I think is backwards." Ah: https://news.ycombinator.com/item?id=19367437 https://news.ycombinator.com/item?id=19367437
- vectorEQ 8y agorussia isn't a third world country by any definition (second world by the original definition....) "Probably someone read the news and googled protonmail, saw "encrypted email" in Wikipedia page and decided to block the whole thing." <-- where do you get that? it's complete nonsense
- SUr3na 8y agoI didn't mean to say Russia is a third world country .but I live in a third world country which closely follows Russia's rules.Apology to all Russians misinterpreting my comment :) As for the complete nonsense you have something working for 5 years suddenly it gets news coverage with no significant usage increase and is blocked . I have no source but this is the exact case where I live. there's something ,like a publicity threshold.It sounds silly and irrational because it is silly and irrational. Or perhaps I am wrong and some experts were analyzing protonmail for 5 years and now came to the rational conclusion to block it.
- aivisol 8y agoIf only PM did not have such low limit on number of domains you can have. Messages per day are already good limitation, why limit domains?
- jsjsjsjsjsjs 8y agoAnd no SMTP/IMAP for free accounts. Free plan is unusable.
- towaway1138 8y agoAlso ran into this. Even had a Google manager I've known for years go to bat for me internally. No dice. Which is crazy, since web logs would have shown that the account was completely and always under my control. Like a distant god, Google gives and Google takes away...