3 ms·
It depends on what kind of software you need to assess. In the case of client side encryption, which is the market in which Proton positions itself, you can ver
by nokya 3y ago
It depends on what kind of software you need to assess. In the case of client side encryption, which is the market in which Proton positions itself, you can verify the security of the implementation by just looking at the client-side code.
If for some reason you end up needing to read the server-side code, then it would technically mean that client-side encryption has failed and does not deliver the necessary assurance.
If you think about it in terms of threat model, we are operating on the assumption that the provider may be malicious, or compromised. There is no context in which reviewing the source code of the server-side component would help us, because the provider would always be able to modify the source code, whether we read it or not.
On the other side if proton reveals the server-side part of the service, it would likely reveal nothing in terms of your security as a customer but it would reveal a lot of proprietary information that could help wannabe competitors.
- lazyeye 3y agoThere is not much you can do on the client-side either unless everybody is prepared to do a code-audit on every device after every update.