3 ms·
To be clear, I am connected enough to security-conscious social media that I think I would hear about it if someone found it out. I agree with you that someone
by bitdizzy 6y ago
To be clear, I am connected enough to security-conscious social media that I think I would hear about it if someone found it out. I agree with you that someone who isn't at least a little bit diligent would miss news like this.
Let me also reemphasize that I don't consider email to be a secure or confidential medium of communication at all, even with PGP. I only want that my inbox is not sold to advertisers and the security practices of my provider aren't utter garbage. Maybe the fact that they're in Switzerland helps me in some ways, but if I had a state adversary I wouldn't bet on it.
- pmoriarty 6y agoThe problem is that ProtonMail could violate your privacy by sending you Javascript that gave them your keys and you'd never know about it. Relying on hearing about compromises in the news only sort-of works when: 1 - such compromises are revealed 2 - they're big enough to make news in the first place 3 - your own data hasn't yet been stolen, so you have time to change services after you hear about the compromise None of these is guaranteed to happen ever. And even if you did hear about some compromise in the news, it could be far too late for you, as your data (the data ProtonMail is supposed to protect) could already be in somebody else's hands.
- bitdizzy 6y ago> The problem is that ProtonMail could violate your privacy by sending you Javascript that gave them your keys and you'd never know about it. I think we don't agree on how proton mail works. As I understand it, they already have my keys. You can't even give them just a subkey, it only works if you upload a set of PGP keys including the master secret key. What is your understanding of how it works? As for your other concerns, unless I am conversing only with myself, the attack vector for my data is the entire e-mail ecosystem. Even if I only talk to people who use encrypted email, they are also part of my threat model, even if I don't trust a provider with my keypair. e-mail is simply not secure. It wasn't meant to be secure; security cannot be bolted on top. What is your threat model and how do other providers or self hosting achieve your desired level of security?
- pmoriarty 6y ago"As I understand it, they already have my keys." From: https://protonmail.com/security-details https://protonmail.com/security-details "ProtonMail's zero access architecture means that your data is encrypted in a way that makes it inaccessible to us. Data is encrypted on the client side using an encryption key that we do not have access to."
- bitdizzy 6y agoThat is a very interesting claim on their part considering that they hold the private PGP keys used by their service. I'll have to figure out what they mean by this. Edit: Ok I see. They store the PGP keys encrypted with your password. Like you said, they could just as well inject javascript to phish your password from your session. But this does seem to mean that if one uses their API directly it would be possible to securely use their service. Thanks for the heads up. There is a third party open source bridge that reverse engineers their API. I think I will look into it to see how authentication is done. https://github.com/emersion/hydroxide https://github.com/emersion/hydroxide