4 ms·
Sounds good... in theory. Truth is we don't know this, their mail client is proprietary and even if it was open source we still wouldn't know what their servers
by thiccly 7y ago
Sounds good... in theory. Truth is we don't know this, their mail client is proprietary and even if it was open source we still wouldn't know what their servers are logging. I am in a similar situation and I trust Google more than ProtonMail with all that Tesonet data weirdness pointing back to one guy. These shell companies can go and disappear overnight, something to consider.
- wildduck 7y agoProtonmail's email encrypted in the browser! Their client is open source: https://github.com/ProtonMail/WebClient https://github.com/ProtonMail/WebClient It is main reason to use ProtonMail over Gmail.
- lugubris 7y agoActually their web mail client is open source and you can see if it is encrypting all your data before sending, yes in theory they can send you malicious js (again you can verify it). They don't get your password so no issue of them logging anything, they just verify that it is userA and send userA's required information (encrypted mailbox + encrypted private RSA key) which your browser decrypts using your password (never send to protonmail) [0]. Again in protonmails case you don't have to trust them, you can just verify the js they send you everytime and be sure that e2ee emails to other protonmail users are always e2e, about email to other non PM servers - you have to trust them to just send it and not store anywhere. Also for emails coming in from other servers - you have to trust them to encrypt it with your public key and not store elsewhere. Note that I don't use protonmail. [0] -> https://en.wikipedia.org/wiki/Secure_Remote_Password_protocol https://en.wikipedia.org/wiki/Secure_Remote_Password_protoco...