15 ms·
ProtonMail takes aim at Google with an encrypted calendar
- vabmit 7y agoHere is their write up of the security model: https://protonmail.com/blog/protoncalendar-security-model/ https://protonmail.com/blog/protoncalendar-security-model/
- asdf21 7y agoDid anyone else notice ProtonMail being used in the movie "Knives Out" to send the ransom note? Cracked me up..
- jpcapdevila 7y agoYes I did! I thought I was alone. I love when movies do their best to have some sense on the tech side, it could have been an annoying "sending ransom note.." loader instead.
- groovybits 7y agoI also saw it, and got a chuckle. I noticed how they were using the mobile web-app version instead of dedicated app. I think its a testament to ProtonMail's popularity, that they get some screentime in a film with such a high-profile cast. Perhaps a techie in the film crew suggested they use it.
- edoceo 7y agoThe writers likely have a tech-consultant that checks these things. Can't have another NCIS moment.
- groovybits 7y agoI'm sure the film's budget could have afforded a consultant. However, if you watch the movie, you may notice that there was no need to show ProtonMail at all. It was a close-up, over-the-shoulder shot of the culprit using a phone to send an email. The whole shot lasted ~2 seconds, with narration. They could have simply chosen a front-facing shot of the culprit using a computer or phone to achieve the same affect. In any case, there are still plently of TV series and movies that put less effort into a 5 minute 'hacker' scene than this movie did into a 2 second shot. They get my kudos.
- tomjakubowski 7y agoIt could also be a paid product placement.
- gruez 7y agoNot that surprising. It was also shown on mr. robot a few years ago.
- groovybits 7y agoI would say its more suprising that ProtonMail shows up in a movie like Knives Out (which has no technical content), than it is for it to appear in Mr. Robot (a purposefully technical series, and being underwritten by Michael Bazzel, who is an advocate of ProtonMail).
- leetcrew 7y agomr robot is uncommonly good about depicting technology and security practices. it also shows elliot booting into kali linux, despite most viewers having no idea what that is.
- techsupporter 7y agoI noticed it as well and just that little touch (along with the line "What is this, CSI:KFC?!") pushed me from "I will probably stream this a few times in the background because it's funny" to "I am preordering the 4K disc as soon as it is listed."
- bfrog 7y agoI switched to tutanota for the price and features already provided, protonmail is really quite nice though. I'd love to better understand the legal implications of the hosting countries laws better.
- jamwaffles 7y agoI moved over to Fastmail from ProtonMail a few weeks ago. I think if you value the encryption and privacy and don’t mind the lack of basic stuff like threading in the mobile app or IMAP integration, ProtonMail is fully worth it. That said, for me I just want a well featured email/calendar service that can replace gmail once Gewgle fucked us over with Inbox. Fastmail does that for me and provides a lot less friction whilst doing so. ProtonMail feels like a one-trick pony to me. They’re cruising on the allure of privacy features but they have a ways to go on other basics.
- mumblemumble 7y agoI'm not even sure it's all that great of a trick, considering that no amount of encryption and security on Proton's own servers or in their app can protect the contents of emails that are sent to (edit: or received from) someone who doesn't use Proton. I am a current customer and think they've got a really well-done service and app, but lately I've been wondering if it's the privacy equivalent of the Maginot Line.
- stevenicr 7y agoMakes me wonder if its possible or reasonable to consider an option with protonmails (and similar) - have a note in the footer of the email - explaining that encrypted is default in their system, but sending to your email provider has it converted to plain text where others can access it.. if you'd like to keep this mail message private click to login to protonReadPortal - where you can read, and if you'd like make a passphrase, to reply and keep messaging on secure servers.. get an optional app for replies to your contacts that have proton accounts.. then tap to checkbox so further emails to you from proton accounts send you a notice to check out the protonReadPortal instead of including the plain text.. I'd want my protonReaderApp to have default shred message after reading.. keep available on proton server for 48 hours after.. one click to save as pdf or zip or other safer password format, or save on protonServer longer.. with easy to change defaults.. would be nice option. I dunno maybe something like this exists? There are several use cases for this.. a system like this could make for encrypted form storage and messaging with the right API maybe hippa compliant? I'd expect my lawyers and accountants and such to use something like this.
- EduardoBautista 7y agoI recently left ProtonMail and went back to Fastmail. My reason was that they will never be able to fully support IMAP and now CalDAV because of the encryption they use. I grew to accept that email is not for secure messaging and my paranoia of "I'm being watched" just went away. If you need secure messaging, use something other than email.
- ravenstine 7y agoDid you try this? https://protonmail.com/bridge/ https://protonmail.com/bridge/ Or did it not work for you?
- prophesi 7y agoWell, snap! Does Tutanota have something akin to this? I also have stopped using Tuta/Proton due to the IMAP incompatibility.
- prophesi 7y agoDid some digging, and it seems like it's at least on the roadmap, but I'm not sure how high of a priority it is. https://github.com/tutao/tutanota/issues/544 https://github.com/tutao/tutanota/issues/544
- EduardoBautista 7y agoI did. It’s slow. Also, it’s not available on iOS.
- martinbm 7y agoWhen did you last use the bridge? They released an update a month or so ago which has made it significantly faster to sync changes. I do agree that it would be great to be able to use your own mail client on iOS. Not sure that will ever happen though.
- steveeq1 7y ago> I grew to accept that email is not for secure messaging and my paranoia of "I'm being watched" just went away. Agreed. Even if you use protonmail, google still has most of your email because they have the most of everyone else's.
- lvh 7y agoArticle is light on the details, but ProtonMail has published some here: https://protonmail.com/blog/protoncalendar-security-model/ https://protonmail.com/blog/protoncalendar-security-model/ > This calendar key will then be symmetrically encrypted (PGP standard) using a 32-byte passphrase that is randomly generated on your device. Once it is encrypted, your calendar key will be stored on the ProtonCalendar backend server. 32-byte passphrase: might be fine, depending on what those bytes are; the interesting question is how much entropy it got generated from. > Each member of a calendar will have a copy of the same passphrase that is encrypted and signed using their primary address key. The signature ensures that no one, not our server or any third-party adversary, changed the passphrase. This is where it gets weird. Why do both? The obvious way to encrypt with an ECC key comes with authentication for free. Signing mostly has negative privacy implications. (I think the answer is "we incorrectly decided PGP was a good idea a long time ago and now we are stuck with its problems, which include being wrong about authenticators".) > The invited member, if they decide to join the calendar, can decrypt the passphrase using their address key. They can also verify that the signature on the passphrase belongs to your email address key. This lets the invited member cryptographically verify that you invited them. To accept the invitation, ProtonCalendar will then pin the passphrase for the invited member by replacing your signature with one created using their own email address key. This signature will later be used by the invited member to verify the passphrase at each application start. Again, with designs less than twenty years old you can do that without a signature. > To accept the invitation, ProtonCalendar will then pin the passphrase for the invited member by replacing your signature with one created using their own email address key. This signature will later be used by the invited member to verify the passphrase at each application start. what I'm reviewing the attendee scheme next, but I need more coffee first.
- anaphor 7y agoWhat are your thoughts on Protonmail's security in general? Specifically this part from their whitepaper https://pbs.twimg.com/media/EKpHwB-WwAE4YN0?format=png&name=small https://pbs.twimg.com/media/EKpHwB-WwAE4YN0?format=png&name=... This is a bad idea right? We aren't supposed to decrypt then verify usually, correct? I'm told this is standard for implementations of OpenPGP, but it just seems like a horrible design (of course OpenPGP itself is probably bad). https://protonmail.com/docs/business-whitepaper.pdf https://protonmail.com/docs/business-whitepaper.pdf
- sverige 7y agoThis is a welcome development. ProtonMail has worked well for me. Now if I could only find a way to make a Pixel phone accept that email address instead of one of my several one-off fake name gmail addresses that I use for such things.
- nothrabannosir 7y agoIf memory serves you can create a Google account with your existing email address. They won’t create a gmail account for you, but you can still use other Google services with it. I’m guessing it’s worth trying with your Android phone?
- scarmig 7y agohttp://accounts.google.com/SignUpWithoutGmail http://accounts.google.com/SignUpWithoutGmail for reference.
- tjoff 7y agoYou sure you want them linked? I feel that it is better to have them compartmentalized.
- sandworm101 7y agoDon't integrate privacy-focused email service (hushmail/proton etc) into a non-private phone. Access it via the webmail interface. I've been asked several times to decrypt my phone at international boarders. If you leave things to webmail, unlocking your phone doesn't give them access to your email account, or even tell them where it is. All the TSA/Cops get is my "gmail-for-phone-2018@gmail.com" address that I haven't checked since day one with the phone. My access to my real email is covered by a web browser that doesn't keep records.
- tubbs 7y agoMy ProtonMail installation on Android supports PIN/fingerprint locking
- lvh 7y agoDuplicate of https://news.ycombinator.com/item?id=21913989 https://news.ycombinator.com/item?id=21913989 -- I started reading the actual spec here: https://protonmail.com/blog/protoncalendar-security-model/ https://protonmail.com/blog/protoncalendar-security-model/
- stabbles 7y agoI'm a bit confused it took Protonmail more than a year yo develop ProtonCalendar. Is it really that difficult to develop?
- 7777fps 7y agoA calendar? Yes. I'm surprised they could develop it as quickly as a year in fact. Calendars are difficult, there is a lot of hidden complexity in the way that users use calendars. They are iceberg products, they look simple from the outset but if you try making one you'll run into the myriad of edge cases.
- Topgamer7 7y agoCalendars are software so directly related to time, I'm not surprised. There are so many edge cases. Timezones, daylight savings time. The fact that so many regions don't use the same standards. We alter year length with leap years and doing things like adding leap seconds. Time is a nightmare to program around.
- fbnlsr 7y agoI somewhat believe our society would be easier if we had a better, simpler standard for time.
- gerikson 7y agoMy only agenda as Ruler of the World is to move the prime meridian to the longitude closest to the population center of the globe, and define one global time off that.
- Drdrdrq 7y agoYou have my full support! There is no reason why we couldn't introduce a better standard. https://xkcd.com/927/ https://xkcd.com/927/
- K0SM0S 7y ago
- SlowRobotAhead 7y agoI lost a lot of faith in Proton when I learned how much funding they took from the EU. It just runs entirely counter to evidence we’ve seen of Snowden, 5eyes/14eyes, and other programs that the EU truly wants end to end encrypted comms for people. Am I wrong to be skeptical? Edit: oh apparently I’m wrong to even suggest something we have other examples of
- Youden 7y agoI disagree with much of your comment: > I lost a lot of faith in Proton when I learned how much funding they took from the EU. Unless the origins of the money are unethical (e.g. blood money), it's not where it comes from that matters, it's what's done with it. I haven't seen any misconduct from ProtonMail and the EU's motivations for giving the money seem to be economic, which makes a lot of sense. They want competitive EU tech companies. > It just runs entirely counter to evidence we’ve seen of Snowden, 5eyes/14eyes, and other programs that the EU truly wants end to end encrypted comms for people. The EU is not a member of the 5 eyes nor 14 eyes, some of its member states are. The EU is composed of 28 member states, so not even half are participants in those groups. Even if the EU were a member of the 5 eyes, the EU is not a monolithic entity. The SIGINT arm of the EU (if such a thing exists) may very well oppose end to end encryption while the economic arm promotes it. The same is true in the US, where the NSA attempts to break encryption while the Department of State funds Tor development.
- moralsupply 7y ago> Unless the origins of the money are unethical (e.g. blood money), it's not where it comes from that matters... Well, if it's government money it's hard to justify that it's ethical. Government money is blood money: don't pay your taxes and you'll get your property taken away from you, go to prison or even get murdered by the state. I understand that the idea the government is "benevolent" is somehow indoctrinated into people's heads from a young age, but objectively that's very far from being the case. Now, in regards to this "investment" in Proton, if it's government money, it's necessarily a "malinvestment". If people didn't get their money taken away from them through taxation and would spend it according to their needs, Proton might or might not exist. If it does exist solely because of that specific "investment" though, most likely it's not sustainable, and that "investment" created economic signals that are distorted.
- otec 7y agoNot so far ago, ProtonMail deleted user account for violation of their ToS by sending email that was reported to PM via their abuse service. I'm not taking sides here, but the fact that they have done it, is a bit sketchy and doesn't win them more trust vs. competitors.
- dddw 7y agonice, but don't put all your eggs in one basket
- lwhalen 7y agoCorrect me if I'm wrong, but this doesn't appear to be CalDAV-compatible. If so, xkcd-927 strikes again :-(
- artursapek 7y agoIf you want to build something which can't be compatible with popular standards, what is the better choice? Build it anyway, or let those standards stop you? It's the same reason I can't read my PGP-encrypted email on my phone.
- lwhalen 7y agoDo what Fastmail did, and work with the community (generally via the IETF) to make your new standard open and compatible: https://fastmail.blog/2019/08/16/jmap-new-email-open-standard/ https://fastmail.blog/2019/08/16/jmap-new-email-open-standar...
- artursapek 7y agoGood point, perhaps Proton will do so.
- C14L 7y agoNot yet, anyways. For IMAP email, there is Proton Bridge, to get around the fact that all data on their servers is encrypted with a key that only you have.
- Guest42 7y agoIs there an API for this calendar? I looked, but didn't notice anything. That's one of the G features that I like.
- deleted 7y ago[deleted]
- ben509 7y agoThe iCalendar spec[1] already features "encryption by committee" by being thoroughly obfuscated through its innate unreadability and undocumented vendor extensions. On a more serious note, a sibling comment asked if there's an API. And, really, for an API to work, we'd need to agree on some kind of data structures. Reading that spec, and having mucked with LDAP, IMAP and related specs, it really feels like we're still banging rocks together in how we define the semantics of data exchange. [1]: https://tools.ietf.org/html/rfc5545 https://tools.ietf.org/html/rfc5545
- josephg 7y agoThe Fastmail devs have been working on getting JMAP for calendars standardised through the IETF. It’s intended as a mature, modern replacement for all the iCal / CalDAV junk. The biggest bottleneck at the moment is getting past the chicken and egg problem - we really need Apple and Google and others to adopt the new protocols for them to start to be useful. JMAP for email is currently struggling against the same adoption issue. https://jmap.io/spec-calendars.html https://jmap.io/spec-calendars.html
- jxramos 7y agoIf one doesn't care about web access to their calendar is there any recommended encrypted calendar apps to use on an android device as the default calendar app? Does setting a default calendar app to something other than the calendar on ROM actually prevent calendar data from leaking to third parties?
- tasn 7y agoEteSync[1] has been around for a few years now. It's fully open source and offers secure, end-to-end encrypted, and privacy respecting sync for your contacts, calendars and tasks. Sounds like what you're looking for... [1]: https://www.etesync.com/ https://www.etesync.com/ Disclaimer: I created it.
- terrycody 7y agoI am satisfied with the Protonmail, easy to use, secure, good.
- dddw 7y agoI'd like to see how this compares to fruux, which hosts a privacy concious calendar for years.
- infide1castr0 7y agoGlad to see any encrypted mail grow their services, this is a bit of a sidebar, but what are some of the updated thoughts about the return of Lavabit and the Dark Mail Alliance group?
- mmd 7y agoStill requires google play store to install and google services to run - not really "polar opposite to google" after all.