4 ms·
Protonmail uses PGP and not "home-brewn encryption" and encryption is on by default between Protonmail users.
by tedcrilly 5y ago
Protonmail uses PGP and not "home-brewn encryption" and encryption is on by default between Protonmail users.
- Andrew_nenakhov 5y agoFalse. Even when it does use PGP, it is meaningless, explanation: I just created a spare protonmail account. It asked me to pick a username and password, and my account is created. Next, I send there a message from my other account. Yes, on the receiving end it does write "End-to-end encrypted and signed message", but encrypted and signed by what exactly? I have never created a PGP keys and loaded the public key to Protonmail on either account (and never used my private key to decrypt anything. This can mean only one thing: even if there is some kind of encryption happening, Protonmail themselves generate keys, and uses it for encryption-decryption, never asking you for anything but your password. And if they can uses these keys to decrypt the messages for you, they can decrypt it for anybody. Protonmail also gives a user an option to export his private keys. Yeah, right. Your private keys.
- Telemakhos 5y agoSomeone once explained to me that any webmail service is inherently able to read your mail: otherwise it could not display your mail to you. True end-to-end encryption means keeping your private keys client-side and the client on a computer over which you have full physical control.
- Andrew_nenakhov 5y agoYou are absolutely correct, with some caveats. Browser client can generate keys on clientside and allow to offload them as a file to be used on other devices. Our own web XMPP client does that. But Protonmail does not work like this. Verification is very simple: if you log in on a new device and see all your content while using only login and password to authenticate yourself, then the content stored on a server is NOT encrypted and is readable by server owner.
- jayjader 5y ago> if you log in on a new device and see all your content while using only login and password to authenticate yourself What about if the encryption key is derived from your password? This is common enough for "encrypt file with a password" services, I've personally implemented it in-browser as part of a small project. Now, having your account password be the same as the email decryption password is also probably a bad idea, but we're far from the server owner being able to read your emails.
- hesk 5y agoAFIAK, Protonmail private keys are kept client-side. They are decrypted by the password inside the browser UI.
- Andrew_nenakhov 5y agoNo. I just logged in to that very same account using different browser on a different computer. The email was displayed just fine. Protonmail keeps generated public and private keys on their servers.
- topranks 5y agoIt keeps copies that your browser locally encrypted with a symmetric key derived from your password. When you log on your browser downloads them, and decrypts them with your password. Protonmail do not see your password and without it cannot decrypt the pub/private key pair.
- karmanyaahm 5y agoafaik isn't it encrypted using your password or something when before it goes out of the browser
- smarx 5y agoThat experiment shows that whatever is stored on ProtonMail's servers plus your password is sufficient to decrypt your emails. This could be explained by the private key being derived from or encrypted with your password. ProtonMail's documentation says it's the latter (https://protonmail.com/support/knowledge-base/how-is-the-private-key-stored/ https://protonmail.com/support/knowledge-base/how-is-the-pri...): > Your ProtonMail private key is generated in your browser. Before sending the private key to the server for storage, we encrypt it with your password (or mailbox password if you use two-password mode). This ensures that you and only you can use your private key. So the only remaining question is whether ProtonMail has access to your password. If they do, they can decrypt your private key and then decrypt your emails. Often, passwords are sent in plaintext to a server for authentication. But ProtonMail uses the Secure Remote Password (SRP) protocol so they never see your password: https://en.wikipedia.org/wiki/Secure_Remote_Password_protocol https://en.wikipedia.org/wiki/Secure_Remote_Password_protoco.... (source: https://protonmail.com/blog/encrypted_email_authentication/ https://protonmail.com/blog/encrypted_email_authentication/) Of course, there are other threats to worry about, such as ProtonMail changing their client-side JavaScript to exfiltrate your password. But the system as they've documented it does not appear to have any way to decrypt your email server-side short of guessing your password.
- Andrew_nenakhov 5y agoThe most likely attacker against proton mail are various law enforcement or intelligence agencies. Such agency can force PM to modify login process to derive password from submitted form, or to just switch private keys for non-encrypred ones, because the user won't even notice it. Truly secure entity just wouldn't have private keys on a server at all. Users would have to go through an an uncomfortable process of generating and uploading keys to clients, but they would be truly safe. To sum it up, you can't really have security and convenience at once. besides skipping a proper key management process, PM also mail skips such important steps as verification of email partner identify and key verification, so you have to trust PM that you are really talking to a person you think you are talking.
- smarx 5y ago