5 ms·
Edit: removed some statements for legal reasons. Bottom line is that too many weird unexpected things are still happening to peoples emails and attachments. Pro
by runnerup 3y ago
Edit: removed some statements for legal reasons. Bottom line is that too many weird unexpected things are still happening to peoples emails and attachments. ProtonMail isn’t helping themselves when their communication is “just upload your private key to our servers and then everything will work great again because we can sign your emails with your key for you! But don’t worry, we don’t have access to keys. We just use them to sign emails after it’s uploaded to our servers. The key we don’t have access to after it’s uploaded to our servers. That we then use to sign emails with forevermore.”
ProtonMail’s communication needs to be a lot more clear on these issues, they need a dumb docs page or slideshow or YouTube video that address all the concerns in a super concise way that can be linked when these concerns come up.
And especially they need a warrant canary that says “we’ve never handed a government the contents of a private accounts emails or the metadata for when/whom they sent/received emails from”.
—————————-
Definitely not[0].
Black market sellers are often kicked off protonmail for “illegal activity”.
LavaBit was probably the last “secure” email provider, they got an NSL for Edward Snowden and chose to fold up the entire company rather than carry out the orders in the NSL.
CounterMail may deserve an honorable mention, but you’d likely want all parties that you need to communicate securely with to also have a countermail account and it’s invite-only. P.S. I would love an invite if anyone has one: HNrunnerup@protonmail.com
0: https://news.ycombinator.com/item?id=36639530 https://news.ycombinator.com/item?id=36639530
- psychphysic 3y agoIt's a shame because it would seem to be easy to make protonmail but low hanging fruit fixed. Similarly it seems relatively easy for signal to move away from needing a phone number. I don't know how good Session and Simplex are.
- booi 3y agoThat isn't really fair. If you read the article, protonmail essentially supplied the FBI the recovery email of the account. This is metadata that protonmail must have that isn't encrypted by the user for obvious reasons. Regarding the "MITM" for every email sent, this is related to their "bridge" software which allows regular IMAP/SMTP software to use Proton Mail. This software must edit the emails to encrypt them in their scheme. This software is open source and can be inspected and/or built locally. https://github.com/ProtonMail/proton-bridge https://github.com/ProtonMail/proton-bridge
- m00dy 3y agono one can ever know Protonmail is really encrypting mails. Opensourcing a piece of software doesn't really mean that Protonmail deployed that and also doesn't really mean that you are using their promised encryption.
- aydyn 3y agoSurely they could have an audit/attestation by 3rd party?
- bayindirh 3y agoYes, but did they?
- tephra 3y agoYes https://proton.me/blog/security-audit https://proton.me/blog/security-audit
- oneTbrain23 3y agoWorldcom passed audit I recalled. Enron too. FTC gave Bernie approval. How about FTX? Remember once uoon a time there was big 5 with one of them as Aurther Andersen? Did anyone auditted Securitum? And oh yeah did anyone actually verified what is being auditted and what is not? When so many info about a compromised Protonmail to law enforcers that Proton didnt even actively deny, I give Securitum as much confidence as AA 2 decade ago.
- illiac786 3y agoIn your logic it seems impossible to be considered secure, since audits do not matter. Which email service do you consider secure and why?
- booi 3y agoyou can also build it yourself
- WithinReason 3y agoDo you have any proof that they store all the keys to emails? Because in none of the cited cases did they provide email contents to law enforcement, only data that you know is not encrypted, like recovery email.
- protonmail 3y agoYour encryption key is stored encrypted so that we have no access to it. It is decrypted when you enter your password, which we have no access to. The article above confirms that, in fact, and all of these cases are proof that our encryption cannot be bypassed by legal means. All the data stored encrypted on our servers (email content, calendars, attachments, etc.) is inaccessible to us: https://proton.me/blog/zero-access-encryption https://proton.me/blog/zero-access-encryption. All we can provide is the unencrypted metadata which we need to have access to in order for the services to work properly.
- doublerabbit 3y ago> However, after receiving the email, we encrypt it immediately using the Proton Mail account owner’s public encryption key. Email contents could still be siphoned, copied and shipped before the encryption process starts. How can you clarify that does not occur between then and that?
- INGSOCIALITE 3y agoWell they double pinky promise, of course
- protonmail 3y agoFor emails between Proton Mail users, it's end-to-end encrypted, meaning the encryption happens client side before the message even reaches the Proton server. If a message is coming from Gmail, then of course that cannot be encrypted until it reaches the server, unless of course the Gmail user is using PGP, which Proton Mail is interoperable with.
- illiac786 3y ago
- KarlTheCool 3y agoAh, I tried to boot up my old account but it looks like it's been deleted from being in the free tier too long. I cancelled my subscription after they had a nearly week long downtime.
- pepa65 3y agoMine has been in the free tier forever, never use it, and it is still fine.
- arghwhat 3y agoHmm? Trusting their client aside (a huge issue with any secure service), I do seem to remember the key being used client-side with password-protection, i.e. not accessible to their server. Am I misremembering something? The part that is easier to misunderstand is encryption-at-rest, where normal emails are still readable at ingress before they are encrypted with an appropriate public key. Also, secure and private != willing and capable of hosting illegal activity. They can kick suspicious behavior without having to read your emails.
- protonmail 3y agoYes your encryption key is stored encrypted so that we have no access to it. It is decrypted when you enter your password, which we have no access to. The article above confirms that, in fact, and all of these cases are proof that our encryption cannot be bypassed by legal means. All the data stored encrypted on our servers (email content, calendars, attachments, etc.) is inaccessible to us: https://proton.me/blog/zero-access-encryption https://proton.me/blog/zero-access-encryption. All we can provide is the unencrypted metadata which we need to have access to in order for the services to work properly.
- svacko 3y agoI think Tutanota [0] is also worth mentioning with their transparent reports and warrant canary in place 0: https://tutanota.com/blog/transparency-report/ https://tutanota.com/blog/transparency-report/
- safety1st 3y agoI mean, what are people's expectations here? If you're sensible, you don't sign up for Proton Mail believing that the FBI will never be able to read your email. You sign up with the expectation that Proton Mail will follow the laws of Switzerland and only disclose information when they must do so under Swiss law. What more do you want from them?
- CodeTheInternet 3y agoI use it expecting they will not sell my data to third parties or use it for things like AI training. I'd expect Google, Microsoft, etc to do this.
- protonmail 3y agoDo you know how Proton Mail actually works? Encryption keys are encrypted client side so Proton never has access to your private key, just an encrypted copy that cannot be decrypted server side.
- ImJamal 3y agoI might be missing something, but how are the keys decrypted? Isn't it using the password? I assume the passwords are hashed on the server, but how would we know if you are storing the nonhashed password when we log in?
- protonmail 3y agoProton Mail is open source, anybody can review the code to see that that clearly is not the case.
- ImJamal 3y agoI haven't reviewed all the code, but my question would be related to the back end which I can't find the source for. Even if the back end is open source we wouldn't know if that is the same code on the servers.
- illiac786 3y agoYou're asking for a negative proof. How do you want an email provider to demonstrate they are not storing your nonhashed password? I don't see how that's feasible. Audits are a step in that direction, but it's not like mathematical proof.