8 ms·
What is end-to-end encryption and how does it work?
- s_dev 4y agohttps://techcrunch.com/2021/09/06/protonmail-logged-ip-address-of-french-activist-after-order-by-swiss-authorities/ https://techcrunch.com/2021/09/06/protonmail-logged-ip-addre... The controversy here is is that Prontonmail announced they didn't do something, log IPs for example and then when compelled by law enforcement-- somehow had a log of IPs. I use Protonmail but there is no way for me to ensure they are E2E just like there is no way to ensure they don't log IPs. This why faith and trust are so important. "Real security" people don't need faith just Math but for the rest of us we need an off the shelf solution that's good enough.
- sedeki 4y agoFeel free to correct me on this, but in terms of ProtonMail's E2E, it's done entirely client-side (= in JavaScript), at least in the web UI. This was claimed on PM's website a while back iirc. So I believe this makes the claim "true E2E" more believable. Or at least verifiable - because it's just JS.
- mgerdts 4y agoI think the key criticism here is that since they deliver the code (javascript) that handles the keys, they could easily replace the code with a version that leaks/harvests your private key. Once your private key is known by someone that also has your ciphertext, that party can get the plaintext.
- sedeki 4y agoYeah, I saw this type of argument after I made my original comment that you responded to. While this argument undeniably makes sense, I guess it boils down to what assumptions are made about the user. Like, if we assume that the user is this paranoid, then why couldn't they just check the JS file/bundle with a local copy that is verified? Think of a Chrome extension or whatever. We still run the JS locally on our own computers.
- tentacleuno 4y ago> Like, if we assume that the user is this paranoid, then why couldn't they just check the JS file/bundle with a local copy that is verified? Well for one, the code is minified. That makes it a lot harder to inspect, so therefore it's substantially harder to make sure that the code isn't doing something malicious. Plus then of course, should the JS file served from Proton's servers be updated, you'd need to diff the changes (which, in the context of minified code, is not easy) to ensure nothing dodgy is added.
- sedeki 4y agoI assume that, realistically, the JS is verified by outside experts (and not by the user), and that a check on the user's part would simply be comparing a calculated hash to a given one. I understand that this might not be how things are really done at PM (i.e. do they provide a hash? probably not) so my arguments may be hypothetical, but it doesn't render them invalid in the larger context imo.
- mgerdts 4y agoIf the trusted web service is under law enforcement order to decrypt mail of a particular user, a version of the JavaScript code that breaks the encryption could be delivered to only that user. No third party experts will be aware of this special version so no red flags can be raised by these third parties. In contrast if an app does not download code, the eavesdropping will require a new version of the app to hit the app store. Third party experts may review this and raise red flags. This is the first time I felt that an app had a privacy advantage over a browser interface.
- charcircuit 4y agoIt's more believable, but in theory there could be a secret store of unencrypted emails that have been sent to ProtonMail's email servers.
- tragictrash 4y agoThey actually claim no IP logging by default, not that they don't log IPs at all. If you're worried about that, use tor. If you're looking for a service that ignores law enforcement requests, I don't think proton is for you.
- blitzar 4y agoIf you're looking for a service that ignores law enforcement requests, I don't think services anywhere are for you.
- yabones 4y agoExactly. I don't know why people think that they can pay somebody to break the law on their behalf. There's no jurisdiction on the planet where privacy law is stronger than search warrants. Even selfhosting everything won't get you very far, as law enforcement can still just come into your house. Proton is simply a compromise that most users find acceptable.
- blitzar 4y agoThere is a large portion of the privacy community for whom services should take a bullet in the face before handing over the data they hold. Its hard to take anyone who raises the "IP logging" seriously anyway - the situation is perfectly clear and rational and they are either shilling for some cause or just plain stupid. Proton is transparent, and people are free to read for themselves just how they operate. https://proton.me/news/transparency-report https://proton.me/news/transparency-report Sometimes they dont even wait for the court order: In July 2017, we received a request for assistance from British police in the case of the kidnapping of Chloe Ayling. In light of the fact that we were able to verify that the kidnappers were, in fact, using a Proton Mail account, and the fact that the first 48 hours are the most critical in kidnapping cases, we rendered assistance to law enforcement before the signed order was delivered to us, but with the understanding that the court order was in the process of being sent. Yet the commenters never complain about this or cases where a minor was at risk. They just claim there is a controversy because they turned on ip logging for one account at the behest of a court order. To be honest Proton as a product I am not particularly drawn to - encrypting email takes two, and there are not many people who are equiped to recieve my secure emails!
- WallyFunk 4y agoYou can turn of IP logs in the Protonmail webapp. I do that as a small precaution, but if the authorities want your IP, they will get it, and in the worst case compel Proton to deploy a compromised webapp frontend where emails can be seen in the clear. But you'd have to be a really juicy target for that to happen, and most people aren't juicy targets.
- Xeoncross 4y agoSadly, at this point just not scanning my inbound purchase and travel emails is a big enough win. Encryption in proton mail was never the selling point since everyone I talk to is on google anyway.
- otachack 4y agoI see where you're coming from. But other email providers also don't scan your mail. I guess it's a question on how well they do the other things that Gmail is on top of (spam?) I've been using Fastmail for a few years and it's great though I still haven't offloaded all my Gmail to it.
- chrismorgan 4y ago> E2EE eliminates this possibility because the service provider does not actually possess the decryption key. When you’re talking about first-party end-to-end encryption (that is, where the pipe and software are provided by the same entity), this is snake oil, pure and simple, especially in the presence of automatic updates, which is uncontrollably the state of affairs on the web. The service provider only doesn’t possess the decryption key as long as they don’t want to possess it. They can maliciously insert a backdoor into the software in order to obtain the decryption key (whether by a rogue employee, or the company as a whole deciding to do the wrong thing, or legal compulsion). And that’s even ignoring the possibility of interception by software distributors, which I think both Apple and Google can do for their mobile platforms (but I’m not certain; it used not to be possible on Android, but they shifted to resigning stuff a couple of years ago). In the context of this article, it’s severely misleading, and although I can’t quite justify calling it a lie (though it was a close call), I am content to declare it a dishonest argument made either in bad faith or incompetently, both of which are very bad things. First-party end-to-end encryption is broken by design. Yes, it protects you against some threats, though generally at a significant cost to functionality, but it offers almost no protection against one of the most important sorts of attacks. To not even mention that rather massive weakness when you must certainly know of it is malfeasance. If this were a one-off, I could bear it. But ProtonMail keeps on spouting this sort of misinformation despite it being pointed out, and indeed trades on it. I am displeased with ProtonMail. (Disclosure: I worked for Fastmail for a few years. I don’t believe that has influenced my position on this matter at all, save that it may have better informed me about all the factors involved in the email space. But my remarks here are true of anything that trades in end-to-end encryption, not just the email space.)
- mike_hock 4y agoI mean, it's a blog by a company whose business model is built on selling privacy snakeoil. > but I’m not certain; it used not to be possible on Android, but they shifted to resigning stuff a couple of years ago Yeah, and where was the outrage about that? With the stroke of a brush, all apps on the Play Store were backdoored in one go. Whether or not the apps currently have any backdoors in them is completely irrelevant because it is effectively exactly the same thing! The apps could be patched any moment and no one would be the wiser. With the signing key known only to the developer, you have near 100% confidence (as long as the developer keeps the key secure) that Google hasn't manipulated the app. With the signing key in Google's hands, you have ZERO confidence. Or more precisely, you can have exactly as much confidence as if no signing had taken place, making signing a complete farce. Yes, it still protects you from manipulation by a 3rd party between you and Google, but it's still a major loss of trustworthiness.
- 0daystock 4y agoE2E encryption only matters when the cryptosystem is reputable, open and withstood the test of time and scrutiny. E2E encryption only matters when the identity provider is trustworthy, unlike most services which manage the PKI on users' behalf. And most importantly, E2E encryption only matters when both sides apprehend the strengths and limitations of it, and practice appropriate opsec. After reading this article, I'm not sure how Proton delivers on any of these requirements. It seems to infantilize a complicated infosec topic to comfort laypersons using their service instead, not unlike most of their marketing material I've seen.
- throwaway0x7E6 4y agoagreed, but I'd venture even further - there are no trustworthy providers. anyone can be forced, coerced or compromised, especially commercial entities
- damon_c 4y agoCheck out NuCypher (I work there) It attempts an approach at dealing with this. https://www.nucypher.com/network https://www.nucypher.com/network It's open source, decentralized, there are hundreds of providers... and it doesn't rely on trust. As long as less than half of them are forced, coerced or compromised you should be ok.
- throwaway2016a 4y agoI'm surprised to see this on Hacker News as I kind of expect that the NH crowd is more knowledgable than the general audience and this article is a little shallow. I for instance know E2EE pretty well but I'm not too familiar with how it is done with main. Notably, the article kind of skips over how Bob got Alice's public key in the first place. How does Proton handle this part? I would like to see something a little deeper here.
- FollowingTheDao 4y agoI would say it is on Hacker News for this very reason! Pure ridicule!
- throwaway2016a 4y agoExcept for the ones complaining about IP logging and such I don't see them as particular "ridicule"... my post for example was not meant to say it's a bad article, just that I expect something more deep for this particular audience.
- JGailor 4y agoThe problem with these articles is that they never go into exactly what parts of the message and metadata is actually encrypted. It can't all be encrypted (or at least I'm not aware of how that would work in practice), so it would be useful to know that, for instance, while the message is encrypted, the sender and receiver metadata is not, which certainly wouldn't make information about who is communicating with who private.
- blitzar 4y ago> The problem with these articles is that they never go into exactly what parts of the message and metadata is actually encrypted. It is just plain olde pgp - no better, no worse. Emails sent, the body is encrypted, everything else not. Inbox stored at rest - all encrypted.
- eating555 4y agoBy seeing so many drawbacks on ProtonMail, is there any other good alternatives? Gmail definitely is not one.
- ywain 4y agoDepends on your threat model. If all you want is to get away from Google / ad-tech, ProtonMail is fine, as are many alternatives (FastMail, etc.). ProtonMail is also probably fine(-ish) if you want to escape mass surveillance from US and allies. If you're worried about a nation-state actor targeting you specifically, then no commercial provider will fit the bill. Whatever you choose, my recommendation is to buy a domain name and use it with your new provider. It will make it much easier to migrate providers in the future.
- eating555 4y agoGood point! Thanks.
- ceva 4y agoWell when you hear e2e encryption you assume that provider who offer the service is not acting as a man in the middle and collecting the data like proton. There were cases when they obeyed by law and court order to give info on their clients.. aka us.
- VikingCoder 4y agoIf I were a journalist in a dangerous place... I'd want to buy a AA-battery powered (or just solar powered?) touch screen device that has a USB port that you can physically BREAK OFF after you've uploaded either a pub/private key chain, or just a huge ass one-time-pad. In my mind, it has a touch screen and a camera with a physical cover you can slide over it. No other ports or antennas or connectivity at all. To send an encrypted message, it flashes a series of QR codes to your smartphone. To receive an encrypted message, you show it a series of QR codes from your smartphone. Your smartphone or computer sends encrypted messages, but it doesn't actually do the encryption or decryption.
- anonporridge 4y agoYou're basically describing a bitcoin hardware wallet, many of which can also be used to encrypt/decrypt and sign messages. These manufacturers are really making exactly what you're describing a reality that is increasingly accessible to the average person. Still not foolproof, but increasingly so. Some, like Blockstream's beta Jade wallet, even work with the QR code scanning like you describe, https://blockstream.com/jade/ https://blockstream.com/jade/ The development of this product definitely seems like one of the many positive externalities of bitcoin.
- nerdyadventurer 4y agoDoes anyone know any open source libraries to implement E2EE in chat apps (text, audio, video)?