5 ms·
Protonmail customer here. Sigh. This is why I keep my own domain and can point it wherever I need. Dear Protonmail, email is fucking cheap and easy, I pay you $
by istingray 5y ago
Protonmail customer here. Sigh. This is why I keep my own domain and can point it wherever I need. Dear Protonmail, email is fucking cheap and easy, I pay you $58 a year to solve stupid shit like this.
Vendors really need to figure out how to thread the needle of "No don't trust us" but still encourage customers to buy. Protonmail failed here. Apple's still very much in the "trust no one but us!" vibe, and it's just not sustainable.
I'll be switching my Protonmail use to default to Tor now. Open to Tor-first vendors...are there any?
I like how Brave has "open in Tor" displayed on Tor-mirrored sites. There's even an option for "Automatically redirect .onion" sites too. Makes it easy to switch over.
What if Protonmail pushed their Tor services more? "Guide to using Protonmail as privately as possible", have a switch for "Private Mode" that kicks you over to Tor/download Tor.
- pphysch 5y agoTor is a State Dept/DARPA project, so at best a sidegrade from Proton if your concern is being surveilled by Western governments.
- sneak 5y agoTor is open source. Point to the vulnerability you are claiming, or stop spreading FUD.
- arglebarglegar 5y agoit’s been known for a while that the NSA runs tor nodes, right?
- cortesoft 5y agohttps://nusenu.medium.com/tracking-one-year-of-malicious-tor-exit-relay-activities-part-ii-85c80875c5df https://nusenu.medium.com/tracking-one-year-of-malicious-tor...
- pessimizer 5y agoTor has known limitations. Pretending like all communication channels with limitations are equal is like saying X minus Y always equals five.
- sweetbitter 5y agoThis wouldn't even have resulted in the catching of the person in question, due to the use of an Onion Service, your link referring to the guy downgrading HTTPS on bitcoin exchanges. Hacker News users have surprisingly little comprehension of just what Tor is, so much so that I made an account here just now. Lurkers, please read: Tor is a powerful tool for increasing the privacy of its users, though it is worth noting that it prioritizes performance over privacy. Tor's threat model does not include global adversaries, particularly those who can access traffic metadata for large numbers of ISPs- though, hidden services do fare significantly better than your usual clearnet services, usually requiring DoS attacks to deanonymize their hosts, and protecting their users especially. But note that Tor is not a mix network- it does not provide mathematically provable anonymity against a global passive adversary, unlike systems such as Loopix. See from this paper describing Tor in 2004, and consider reading the whole thing for a better understanding of Tor: https://www.usenix.org/legacy/publications/library/proceedings/sec04/tech/full_papers/dingledine/dingledine.pdf https://www.usenix.org/legacy/publications/library/proceedin... Tor's Threat Model "A global passive adversary is the most commonly assumed threat when analyzing theoretical anonymity designs. But like all practical low-latency systems, Tor does not protect against such a strong adversary. Instead, we assume an adversary who can observe some fraction of network traffic; who can generate, modify, delete, or delay traffic; who can operate onion routers of his own; and who can compromise some fraction of the onion routers. In low-latency anonymity systems that use layered encryption, the adversary’s typical goal is to observe both the initiator and the responder. By observing both ends, passive attackers can confirm a suspicion that Alice is talking to Bob if the timing and volume patterns of the traffic on the connection are distinct enough; active attackers can induce timing signatures on the traffic to force distinct patterns. Rather than focusing on these traffic confirmation attacks, we aim to prevent traffic analysis attacks, where the adversary uses traffic patterns to learn which points in the network he should attack. Our adversary might try to link an initiator Alice with her communication partners, or try to build a profile of Alice’s behavior. He might mount passive attacks by observing the network edges and correlating traffic entering and leaving the network by relationships in packet timing, volume, or externally visible user-selected options. The adversary can also mount active attacks by compromising routers or keys; by replaying traffic; by selectively denying service to trustworthy routers to move users to compromised routers, or denying service to users to see if traffic elsewhere in the network stops; or by introducing patterns into traffic that can later be detected. The adversary might subvert the directory servers to give users differing views of network state. Additionally, he can try to decrease the network’s reliability by attacking nodes or by performing antisocial activities from reliable nodes and trying to get them taken down—making the network unreliable flushes users to other less anonymous systems, where they may be easier to attack." Tor increases the costs to uncover your identity, especially so in the context of a hidden service, which the entity in question (Protonmail) actually does offer to users. Perfection is the enemy of the good- Tor is not built to deal with global adversaries unlike a mix network, but surely any increase in privacy is a good thing, no? You do not complain that your wrench does not serve the purpose of a hammer quite as well as a hammer might- you either put some more energy into it, or you buy a hammer.
- pphysch 5y ago"Open source" means literally nothing for the majority of Tor users that are downloading prebuilt binaries from US Government-funded www.torproject.org/download/
- sneak 5y agoSo now you're asserting that the binaries are backdoored, or built from something other than the published source. Again, provide evidence or stop spreading FUD.
- pphysch 5y agoThat's sadly not how (cyber)security works. The USG persecutes and imprisons journalists for exposing its war crimes, anyways I'm going to download this Tor binary from them because it says 'totally legit' on the packaging and there's no "hard evidence" to the contrary...
- rank0 5y agoDon’t those binaries come with signatures you can verify? People in the community would notice if building from source produced different signatures than the binaries provided directly by torproject
- pphysch 5y agoIn practice the USG would not distribute malevolent binaries everywhere, but could target them to particular IP- and time-ranges. Downloading Tor from a particular IP in Iran? We'll add a little something extra... Or maybe you're a US citizen with a set of known IPs on a "watchlist".
- sneak 5y agoThe USG does not operate or control the Tor Project’s servers.
- 5y ago
- acheron 5y agoWhere “this” in “solve stupid shit like this” is “hide you from police with a legally authorized warrant”? If you were relying on Protonmail to conceal evidence of criminal activity for you, you may not have thought that all the way through.
- istingray 5y agoWhere "this" is using soft language like "by default" to hide shortcomings. I expect Protonmail to do more to educate users to be aware of how surveillance happens, whether a rogue employee enables the function on their end, warrant, etc.
- acmdas 5y ago"hide shortcomings" like what? Doesn't language like "by default" infer/suggest/imply that there would be circumstances in which they would save logs? And wouldn't an obvious circumstance like that be a warrant?
- Daneel_ 5y agoI think for most people the interpretation of "by default" means "we will not log your IP unless you enable it", i.e. the power is in the hands of the user. The complaint people are making here is that this statement should really have a clarifying clause saying "or unless requested to do so by law enforcement".