5 ms·
Show HN: End-to-end encrypted email, based in Switzerland
- gesman 12y agoIs that similar to zerobin (http://sebsauvage.net/wiki/doku.php?id=php:zerobin http://sebsauvage.net/wiki/doku.php?id=php:zerobin) where server has no knowledge of the content of a message?
- Jgrubb 12y agoFunny, when I hear "Switzerland" I think about how just this morning I heard that the American IRS has finally broken the long standing tradition of Swiss banking privacy, and that CreditSuisse will be paying billions of dollars in fines.
- fareastcoast 12y agoWell, selling out American millionaires is one thing, I have a feeling the Swiss would be less willing to sell out private communications to the NSA.
- tptacek 12y agoBecause...
- rdl 12y agoBecause they've already sold them out to USG? (Crypto AG)? Or possibly, because someone else is a higher bidder?
- lesterbuck 12y agoBecause the "neutral" Swiss company Crypto AG was backdoored by the NSA long, long ago. https://en.wikipedia.org/wiki/Crypto_AG#Back-doored_machines https://en.wikipedia.org/wiki/Crypto_AG#Back-doored_machines
- MHordecki 12y agoOnly for US citizens, and this is on a per-bank basis - if you're a US citizen (or pay taxes in the US) you might be rejected in some of the banks.
- ddorian43 12y agoHow does searching work ?
- praeivis 12y agoFrom the page source: "We only use GA on our Home and Invite pages to view where traffic is coming from as we prepare for beta. We will be removing GA and all third party sourced scripts from the site afterwards. - Jason" So far we are still tracked by GA, so IDK...
- tptacek 12y agoThis appears to be a PHP wrapper around OpenPGP.js. If the encryption comes from Javascript loaded by browsers from the servers every time they visit the site, the encryption isn't "end to end". It's controlled by the server and can be broken by the server. Also: the RSA Security logo isn't the logo of the RSA algorithm; it's the logo of the company that sells RSA tokens.
- fareastcoast 12y agoThe JS doesn't appear to be compressed so it's possible to view source and see what exactly it's doing. So if it was actually backdoored, somebody will actually find out.
- rdl 12y agoYou can serve different JS to "special" users once. If you're smart, you run checks "for the security of the browser environment" first to make sure it's something unlikely to contain debugging capabilities, e.g. an unmodified iOS device. The site even helpfully asks you to identify yourself with ANOTHER username and passphrase first, making it even safer for the attacker.
- fareastcoast 12y agoAn attacker would have to (1) Gain access to the server in Switzerland (without the admins noticing) or (2) Break the SSL and execute a MITM attack. It seems ProtonMail actively scans the code on the backend for unauthorized changes. It's not 100% secure against a very determined attacker (NSA), but for the citizen that wants more privacy without the hassle of PGP, it's pretty good until we can replace SMTP.
- brute 12y agoThis is a browser addon, right? Is everything loaded locally? If no, what prevents you from putting up some javascript that transfers the decryption password (or the plain text) to you. Sorry, didn't bother to download and look for the source code, to find out how the inner mechanics work. The website doesn't give much information either.
- tptacek 12y agoNo, it doesn't appear to be. They're at pains to say "nothing is installed", and when I created an account, it loaded "openpgp.min.js" from the server.
- rdl 12y agoWow. How exactly does one do this given there have been 15 years of well documented problems with exactly this model of deploying "secure mail"?
- sneak 12y agoEncryption to keys that are not properly authenticated is more unsafe than no encryption at all. This holds up "No private / public key management." as a feature. Without key management (specifically, secure generation, storage, and authentication) encryption is worse than useless.
- kylec 12y agoAnyone that values their privacy should never trust a service like this. The idea of in-browser encryption and decryption is nothing new, and it always suffers from the fact that the server can replace the client side software at any time without warning. If you must use a browser, find a plugin that you trust that works with any webmail service. Better yet, use an actual mail client and encrypt/decrypt in that.
- fareastcoast 12y agoI think the idea of ProtonMail is to serve the part of the population that mostly uses the browser. Obviously if you wanted to be super secure, there are more sophisticated methods out there, but they aren't exactly accessible to the non-HN population. I don't think we should say, just because a perfect browser based solution isn't possible, this shouldn't exist at all. It's like saying, do something only if you can do it perfectly.
- tptacek 12y agoEven if I thought this was a sensible way to describe the value of the service (I don't): that's not remotely what this site says. It makes expansive claims about security, which it can't possibly back up. Why should ordinary people be expected to trust them with secrets?
- hglaser 12y agoIs "Based in Switzerland" relevant in this case? I know their government is historically neutral in major wars. Are they also a good place to base security-minded companies?
- bjoernw 12y agoAnd whose banks are currently releasing the names of tax evaders to every country that wants to know... Not saying that's in any way unjust but it does hurt Switzerland's reputation for being that anonymous safe haven.
- mrsaint 12y agoSwitzerland is currently in a state of flux. They are adopting to "international" laws at astonishing speeds. A safe heaven for data privacy? Think twice: http://arstechnica.com/tech-policy/2013/12/switzerland-wont-save-you-either-why-e-mail-might-still-be-safer-in-us/ http://arstechnica.com/tech-policy/2013/12/switzerland-wont-... That's the current status quo. And members of the Bundesrat (the executive gov body) have proposed more plans to ease the use of wiretaps.
- cmpb 12y agoCan I view the source of the actual program? If not, it doesn't serve much purpose to say that all the cryptographic libraries you use are open-source. Let me see the source and then I'll see about trying your product. As an aside, I see other people on this thread talking about the well-documented problems of in-browser encryption/decryption. Could someone point me to a list?
- brute 12y agohttp://www.wired.com/2012/08/wired_opinion_patrick_ball/all/ http://www.wired.com/2012/08/wired_opinion_patrick_ball/all/ It's about cryptocat (secure chat) but the same principles apply. Note that cryptocat has switched to a browser addon-based design afterwards.
- memming 12y agoYou can send encrypted emails to non-protonmail users, but they have to click a link and enter passphrases, and not to mention that the emails will expires?
- IgorPartola 12y agoDamn. I got excited for a second that someone had put together a decent mail client that supports PGP and a hosted email service to rival GMail where the unencrypted email they store would have some semblance of protection from the NSA. Too bad this is the same old crypto in JS stuff.
- ctz 12y ago> By using a CA owned by the Swiss government, we ensure the highest security for our users because it is extremely unlikely SwissSign can be coerced into validating another website impersonating us This is a dangerous and insane misunderstanding of the trust relationships work in the public CA system. Any CA can impersonate any site. Your choice of CA has no bearing on your exposure to this risk. (If this were an app or browser extension, you could plausibly pin the right certificate path to only trust SwissSign. But if you can do that, you can just pin your certificate and don't need a CA at all.)
- deleted 12y ago[deleted]
- eliteraspberrie 12y agoWith respect to their servers' location in Switzerland, if you don't live in Europe, that will not benefit you. Even the best of laws require you to actively defend yourself. I for one cannot travel to Switzerland and represent myself in a Swiss court, at least not at a tolerable cost.
- mrsaint 12y agoInteresting that they did not choose to support TLS 1.2 for SSL encryption, and that they added RC4-MD5 as one of their (few) supported ciphers. Certainly doesn't make me feel any warmer.