4 ms·
Previous discussions about PM 2018 - Ask HN: How secure is Protonmail really? https://news.ycombinator.com/item?id=18101090 https://news.ycombinator.com/item?i
by complexworld 6y ago
Previous discussions about PM
2018 - Ask HN: How secure is Protonmail really?
https://news.ycombinator.com/item?id=18101090 https://news.ycombinator.com/item?id=18101090
2019 - Ask HN: FastMail vs. ProtonMail?
https://news.ycombinator.com/item?id=19372882 https://news.ycombinator.com/item?id=19372882
How secure would it be to use PM if the following conditions were met?
- you only used one of the open-source native PM apps
- you only emailed other PM users
- someone you trust audited the PM source code for the native apps
- you installed from F-Droid
- app4soft 6y ago- your messages always processed by proprietary/closed source server So, it just like Telegram (or any other proprietary cloud/VPN/proxy service) - you really don't know what has happen on server side.
- kelnos 6y agoTrue, but if you do audit the client software, you can verify: * Your e2e encryption key never gets sent to the server. * Data is actually strongly encrypted using that key before leaving the client. Then isn't that sufficient to prove that the server can't do anything nefarious, even if it wanted to?
- app4soft 6y ago> Data is actually strongly encrypted using that key before leaving the client. Except "strongly encrypted message" you should send some extra info for server. And I'm not sure how those two types of info separated in Proton's communication protocol, so binary diff between those "parts" could be a key to select decrypt method.
- zaarn 6y agoTheir key encryption is fairly safe, if you use one-password mode, they could intercept your password from the webinterface if they wanted, but the password exchange is solid and doesn't reveal the password while still allowing to decrypt the key. Two password mode is technically more secure since even if the authentication exchange is cracked, the decryption key doesn't touch anything the server can see, it's locally decrypted. There isn't any meaningful diff you could make.