8 ms·
It hurts the trust mostly. If they cannot handle basic things like PGP correctly, how should I trust other part of their software. Especially they are a "Priva
by twleo 3y ago
It hurts the trust mostly.
If they cannot handle basic things like PGP correctly, how should I trust other part of their software. Especially they are a "Privacy-first" company.
"Privacy" becomes a marketing term nowadays.
- brookst 3y agoPrivacy was always a marketing term, just like performance, affordable, future-proof, etc. It’s a user benefit. By definition that means it’s a marketing term. That is not mutually exclusive with being a general concept.
- pavs 3y agoAlso. "Unlimited" doesnt actually mean unlimited.
- bboygravity 3y agoI learned that when I was like 10: download free full mp3 album now (no download just spam, not free, not mp3, not the album you wanted and not now)
- mszcz 3y agoThat always astounds me - someone expecting me to pay them for something right after I was lied to by them (the ad). Who do those ads target?
- willis936 3y agoSucker middle managers with more money than brains.
- Psychoshy_bc1q 3y agothey target idiots.
- ravenstine 3y agoYes, like how "all you can eat" doesn't literally mean staying at the restaurant all day and exhausting their supply.
- nvy 3y agoPGP is for security LARPers and doesn't matter at all.
- thesf 3y agoIt was good enough for Snowden. Apparently not good enough for the people here who want a centralized server that requires phone numbers run by a hip guy with a cute name.
- nvy 3y agoI'm not a Signal user nor a Moxie fanboy but I believe Snowden used PGP because that's what Laura Poitras used, not because of its technical merits.
- hardenedproof 3y agoSo what are some recommendations then? Seems like a lot of talk but not many sources nor suggestions.
- deleted 3y ago[deleted]
- hardenedproof 3y agoYa, either the parent post is troll, or he read the Vice article from 5 years ago and thinks it nullifies PGP? Not sure, but is it perfect? No. But I don’t think Snowden is a security LARPer.
- localplume 3y ago[dead]
- littlestymaar 3y agoSnowden also praised Signal several times though…
- 3y ago
- nabla9 3y ago"It's not perfect so it's now shit and completely useless." You can genuinely support privacy and still have features or user cases that don't work. This feature does nothing to weaken privacy.
- twleo 3y agoFor other functionality, I will say nothing because it takes time to implement features and Proton is not as big as Google. But for PGP? You should treat it seriously, considering your target customers.
- danw1979 3y agoAgreed. Buried in twiss’ reply above is the actual response to the article: > though we could of course add that in the future.
- twiss 3y agoNot exactly. The article says: > It’s absurd that there’s no way to disable this, no option to tell Proton “if you see a multipart/signed or multipart/encrypted message, just leave it the hell alone.” which, as I said in my response, I disagree with the first half of that. Our goal is to (automatically) encrypt messages whenever possible, and leaving multipart/signed messages alone doesn't reach that goal. So I proposed two different solutions to what OP wants, one of which is already built into Proton Bridge, and one which we could add in the future (but which would be more effort than the one OP proposes).
- twiss 3y agoHi - crypto team lead here. I'll hijack this comment to try to explain what Proton Bridge is intended to do, and why it doesn't work the way OP wants. Bridge is a proxy which hosts a local IMAP and SMTP server, and takes "normal" unencrypted and unsigned messages from desktop MUAs like Thunderbird, signs and encrypts them, and then sends them out. Note that this requires changing the MIME message somehow. OP writes: > Everything was great until I decided the other day that I’d also like to do PGP signing on my outgoing messages. The "intended" way to do this is enable the setting in Proton Mail that says "Sign external messages" :) That way, Bridge will sign them for you. (Internal messages are always signed.) > Tough luck, bucko, we’re the SECURE email company, you’ll upload your private key to our servers and you’ll like it! FWIW, private keys are stored encrypted on the server, we don't have access to them. But yes, the entire goal of Proton is to handle PGP for you, without having to set up PGP encryption and signing manually on all of your devices. I know that the HN audience is fully capable of doing so, but our goal is to make it easier for everyone else :) > It’s absurd that there’s no way to disable this, no option to tell Proton “if you see a multipart/signed or multipart/encrypted message, just leave it the hell alone.” IMO, if we see a multipart/signed message, we should still encrypt it whenever possible, not leave it alone. But note that normally in OpenPGP, signing and encrypting is a single operation. It's possible in PGP/MIME to sign a message first and then encrypt it, but we don't support sending that way at the moment, though we could of course add that in the future. But in any case, that's the reason we currently recommend signing using Bridge rather than manually using gpg or similar.
- unconed 3y agoWhy can't you just detect that it was already signed with a valid signature, especially if you have the user's public key? PS: the lack of threading support in your mobile apps is embarrassing, it's been like this for years. No I will never use your web client. Stop trying.
- twiss 3y agoSee my last paragraph :) PS: yes, this is being worked on
- 3y ago