4 ms·
I use proton mail just for the privacy guarantees enforced by social pressure on their brand. They hold your PGP keys (you can't give them a subkey of your own
by bitdizzy 6y ago
I use proton mail just for the privacy guarantees enforced by social pressure on their brand. They hold your PGP keys (you can't give them a subkey of your own private master key) so there's no reasonable security there. In general, I don't think PGP encrypted emails provide much security anyway. If I need to send a message securely, something like Signal provides better cryptographic properties like forward secrecy.
All I know is, I would hear about it very quickly as soon as Proton Mail is discovered to violate my privacy, and that's all I can expect of email. To be honest, the fact that their API is not open sourced and I have to use their web client or mediocre IMAP bridge would make me seek alternatives if I were to reconsider email providers. It would have to be one that has as strong of a privacy-conscious brand, or self-hosting.
- upofadown 6y ago>... something like Signal provides better cryptographic properties like forward secrecy. Forward secrecy only works up to the point your end point gets compromised and only for messages you have not kept. So for the vast majority of people it provides very little value. It provides no protection against someone who breaks your encryption and something like the Signal Protocol's much greater complexity provides more opportunities to do that.
- bitdizzy 6y agoPGP isn't any better on the first point and on the second point, I would bet the money in my pocket that GPG (being the most dominant implementation of PGP) is far more complex and bug-ridden than Signal's cryptography or implementation are unsound.
- upofadown 6y agoGPG is an implementation of the OpenPGP standard. Signal Messenger is an implementation of the Signal Protocol quasi-standard. Comparing like to like, OpenPGP is much less complex than the Signal Protocol. GPG is much less complex than the Signal Messenger.
- inglor_cz 6y agoDepends on where you live and who is your potential adversary. For someone from Belarus and opposing Lukashenko, ProtonMail is fairly secure service. For Edward Snowden, probably less so.
- kijin 6y agoI avoid ProtonMail, and encourage others to do the same, because of the reasons you stated. They have all the keys. It's security theater, just like pre-2013 Lavabit used to be. Unlike pre-2013 Lavabit, the fact that they have the keys doesn't even result in usability benefits like, you know, being able to use plain old IMAP with my favorite email client. ProtonMail has been dragging their feet for so long in the interoperability department, it almost feels like they're aiming for vendor lock-in. If they truly were serious about interoperability, they've had plenty of time to create an open standard around their protocol (like FastMail and post-2017 Lavabit has done), or release patches to make their protocol available in widely used open-source email clients like Thunderbird. Instead they've got that mediocre IMAP bridge you mentioned. No thanks. When I choose an email service I want to retain the ability to export all my data and leave on short notice, without having to depend on non-standard tools.
- pmoriarty 6y ago"I use proton mail just for the privacy guarantees enforced by social pressure on their brand." There are no such guarantees. Social pressure on their brand did not stop Enron or Madoff from committing fraud. Nor did it stop millions of others from committing various crimes, atrocities, and other unethical acts throughout history. In the realm of email providers, the case of Hushmail[1] serves as an instructive example. Hushmail is an email provider that provides a service similar to ProtonMail, but: "Developments in November 2007 led to doubts, amongst security-conscious users, about Hushmail's security, specifically, concern over a backdoor. The issue originated with the non-Java version of the Hush system. It performed the encrypt/decrypt steps on Hush's servers, and then used SSL to transmit the data to the user. The data is available as cleartext during this small window of time; the passphrase can be captured at this point, facilitating the decryption of all stored messages and future messages using this passphrase. Hushmail stated that the Java version is also vulnerable, in that they may be compelled to deliver a compromised java applet to a user." and "Hushmail supplied cleartext copies of private email messages associated with several addresses at the request of law enforcement agencies under a Mutual Legal Assistance Treaty with the United States.; e.g. in the case of United States v. Stumbo. In addition, the contents of emails between Hushmail addresses were analyzed, and 12 CDs were supplied to U.S. authorities." Incidentally, despite all this, and what you'd expect to be "damage to their brand", Hushmail is still around, and I'd expect many of their users have never even heard of any of this. [1] - https://en.wikipedia.org/wiki/Hushmail#Compromises_to_email_privacy https://en.wikipedia.org/wiki/Hushmail#Compromises_to_email_...
- bitdizzy 6y agoTo be clear, I am connected enough to security-conscious social media that I think I would hear about it if someone found it out. I agree with you that someone who isn't at least a little bit diligent would miss news like this. Let me also reemphasize that I don't consider email to be a secure or confidential medium of communication at all, even with PGP. I only want that my inbox is not sold to advertisers and the security practices of my provider aren't utter garbage. Maybe the fact that they're in Switzerland helps me in some ways, but if I had a state adversary I wouldn't bet on it.
- dgellow 6y agoI'm a happy Protonmail user, but The lack of quality of their bridge and import/export tools will cost them quite a lot on the long term. It's a bit sad to see. The UX work is really lacking there. On the other hand their current web interface is quite fast and straightforward.