2 ms·
> If you access ProtonMail via their web app, all that's needed to steal your password and decrypt email at will is a few quick changes to the index.html they s
by desktop-app 7y ago
> If you access ProtonMail via their web app, all that's needed to steal your password and decrypt email at will is a few quick changes to the index.html they serve you. This could be targeted to specific users, and once the password is exfiltrated, the page can be reloaded, leaving no trace of the attack. Anyone with access to ProtonMail's back end code or infrastructure could do this. So at least in the case of their web app, they could absolutely provide LE with whatever they wanted in a way that would be quite difficult for the average user to detect.
There is no such issue if you use https://github.com/vladimiry/ElectronMail https://github.com/vladimiry/ElectronMail desktop app as it comes with static resources built on the CI server from the official source code repositories and embedded in then installation packages, see https://github.com/vladimiry/ElectronMail/issues/79 https://github.com/vladimiry/ElectronMail/issues/79 for details. See here https://github.com/vladimiry/ElectronMail/blob/d974b43908e10fef2d67b7e7daafe75d6f772798/src/shared/constants.ts#L70-L111 https://github.com/vladimiry/ElectronMail/blob/d974b43908e10... the "ProtonMail Version 4.0-beta Web UI" versions embedded in the most recent v4.2.1 release.
The way of verifying that the installation packages attached to the releases have been assembled from the source code is being provided, see https://github.com/vladimiry/ElectronMail/issues/183 https://github.com/vladimiry/ElectronMail/issues/183.
And finally, the app is fully open-source creature, so anyone could assembly own package.