5 ms·
Founders with US affiliation/physicist creating crypto products [1], faulty claims how the relevant Swiss law (BÜPF) applies to them [2], doing crypto in JavaSc
by rettichschnidi 2y ago
Founders with US affiliation/physicist creating crypto products [1], faulty claims how the relevant Swiss law (BÜPF) applies to them [2], doing crypto in JavaScript on the client side, etc. To me, this smells like Crypto AG [3][4].
[1] https://proton.me/about/team https://proton.me/about/team
[2] https://steigerlegal.ch/2019/07/27/protonmail-transparenzbericht-buepf/#buepf-anwendbarkeit https://steigerlegal.ch/2019/07/27/protonmail-transparenzber...
[3] https://en.wikipedia.org/wiki/Crypto_AG https://en.wikipedia.org/wiki/Crypto_AG
[4] https://en.wikipedia.org/wiki/Operation_Rubicon https://en.wikipedia.org/wiki/Operation_Rubicon
- andrewinardeer 2y agoIs the suggestion that founders who have US affiliation are automatically in bed with three letter agencies?
- justinclift 2y agoIf they're physically located in the US, they have no way to stop (legal) coercion by the TLAs yeah?
- willis936 2y agoHow is this different than 90% of other VPN providers out there? The claim shouldn't be "Proton is a honeypot" but that "US VPNs are a honeypot".
- bartbutler 2y agoWe aren't physically located in the US.
- justinclift 2y agoWho's the "we" in this context? :)
- devman0 2y agoHow else would you do client side crypto for a website if not with JavaScript, isn't that kind of the point of how Proton does E2EE?
- stavros 2y agoCrypto for websites is completely broken (because the server can serve you whatever it wants), so doing crypto for websites at all is suspicious.
- iknowstuff 2y agoI guess they have this for local email decryption: https://proton.me/mail/bridge https://proton.me/mail/bridge idk if they have anything like that for their other products like calendar or file storage Presumably if you stick to mobile apps you won't be using JavaScript served by their server? Unless they're just html wrappers
- ranger_danger 2y agoIt's not "broken", please don't spread FUD. It's a whole lot more transparent than doing it on the server side. Client code can be inspected and publicly audited, and many times you can save/cache it so that it doesn't change. Also opens up the possibility for third party standalone apps that don't change often.
- akimbostrawman 2y ago
- nl 2y agoDoing crypto on the client side in JS is absolutely the correct way to do this if you want E2EE with a web client. You need to be careful about supply chain attacks etc. > To me, this smells like Crypto AG It's easy to throw around unsubstantiated, impossible to disprove theories.
- protonprivacy 2y agoWe are not affiliated with Crypto AG. Our encryption occurs client-side, our cryptographic code is open source, and our tech can and has been independently verified.