3 ms·
"And the flaw is that it is relatively simple for ProtonMail to serve you a modified version of their web application or the underlying PGP implementation. Ther
by mLuby 5y ago
"And the flaw is that it is relatively simple for ProtonMail to serve you a modified version of their web application or the underlying PGP implementation. There is no way to cryptographically verify that you are getting the official version of the web client as stored in their repository.
If PM decides to act maliciously, they can do so undetected. Unlike the mobile application who’s binaries get cryptographically signed to match the official codebase, there is no method to verify a web application."
If the web client is open-source (as at seems), can't anyone build it locally and compare the built files to what they were served?
- pmoriarty 5y ago"If the web client is open-source (as at seems), can't anyone build it locally and compare the built files to what they were served?" Yes, but the results of such an inspection would only apply to that particular web request at that particular time. At another time, or to some other person, a different app could be served up by ProtonMail if they so chose. That's not to mention that the vast majority of ProtonMail users probably don't (and wouldn't have the skills to) evaluate the code they receive from ProtonMail, so even if they were being served up something suspicious, they'd never know.
- mLuby 5y agoSomething like a browser extension could make that kind of check repeatable, automatic, and unobtrusive unless there's a discrepancy. Assuming builds don't happen too too often. Yes, either you'd have to verify the build yourself or trust someone else to do it and independently publish something for the extension to compare to the client it's served.
- dane-pgp 5y agoSomething like a browser extension for this does already exist, fortunately: https://github.com/tasn/webext-signed-pages https://github.com/tasn/webext-signed-pages