Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bartbutler
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
bartbutler
8y ago
Only if you completely discount the related costs of building and maintaining such an additional API as well as the customer service impact of basically allowing users to screw up their own key management.
32.
▲
by
bartbutler
8y ago
This.
33.
▲
by
bartbutler
8y ago
We'll probably do this soon, HKP is older and more broadly supported at the moment so it got built first.
34.
▲
by
bartbutler
8y ago
1. We do support IMAP and SMTP, via the bridge. 2. We don't believe such compulsion would be legal and would fight it in court. 3. Yes, this is a security promise not a verifiable guarantee. As I said though, our incentives for this ar
35.
▲
by
bartbutler
8y ago
2. As said in 1, we have export now via multiple avenues. Some are paid, but the import/export tool certainly won't be for the general release and the bridge status may change too. It's taken a little while but there's n
36.
▲
by
bartbutler
8y ago
This is completely ignoring key management as a barrier to using encryption, not to mention manually syncing local keystore with the server, not being able to provision keys across devices, etc. In other words, why PGP and email encryption
37.
▲
by
bartbutler
8y ago
Headers are not encrypted in OpenPGP and not in ProtonMail. Message and attachment content is.
38.
▲
by
bartbutler
8y ago
I agree that providing it encrypted is better, which is what all of our APIs require. That said, you are mistaken that saving the cleartext for unencrypted mail benefits us at all. It most certainly doesn't--the incentives between the
39.
▲
by
bartbutler
8y ago
We don't store copies of plaintext emails indefinitely (it's obviously exists in the mail pipeline before processing). This statement is based on trust, as it would be for literally any email provider. That said, if we did store m
40.
▲
by
bartbutler
8y ago
It doesn't work how you seem to think it does. Your password never goes to the server: https://protonmail.com/blog/encrypted_email_authentication/
41.
▲
by
bartbutler
8y ago
1. The web client export been live since May IIRC, the support page just hasn't been updated yet. The main issue with that is that very few people want to export their encrypted blobs, they naturally want the plaintext. So we need a de
42.
▲
by
bartbutler
8y ago
This is basically the plan. There are some other concerns, notably bandwidth/space and, given it's untrusted input, thinking through all the other ways it could be abused. There will certainly be a byte limit.
43.
▲
by
bartbutler
8y ago
Doing some sort of image proxy download in a safe and efficient way (which is not entirely trivial) is certainly part of the plan.
44.
▲
by
bartbutler
8y ago
1. You can export your mail directly from the web app in EML form, using the bridge, and soon, from the import/export tool which is currently in beta for Visionary users. 2. We support IMAP/SMTP via the bridge (protonmail.com/
45.
▲
by
bartbutler
8y ago
That they have.
46.
▲
by
bartbutler
9y ago
Or you can just put all your stuff in a single Sieve filter.
47.
▲
by
bartbutler
9y ago
ProtonMail Plus (the lowest paid tier) is $48/yr. And you do pay for Gmail with your data, so let's at least get the comparison right. The final cost/benefit analysis is your choice of course, but Gmail is not free
48.
▲
by
bartbutler
9y ago
ProtonMail does have filters...am I missing something?
49.
▲
by
bartbutler
9y ago
Aha, I misunderstood the original comment.
50.
▲
by
bartbutler
9y ago
Depends what qualifies as a quantum computer. It is questionable whether current 'quantum computers' deserve the name.
51.
▲
by
bartbutler
9y ago
So, that's a conclusion but no reasoning behind it, therefore it's impossible to evaluate critically.
52.
▲
by
bartbutler
9y ago
What certificate error? Neither https://openpgpjs.org nor the link here have a certificate error for me. Maybe you are being MITMed...
53.
▲
by
bartbutler
9y ago
For internal use we had all RSA keys so it was fine. For external use we have to support what everyone uses, and there is a variety as you know. Saying "hey, you can use PGP but all your friends have to have RSA keys" is not a rec
54.
▲
by
bartbutler
9y ago
This is about to change dramatically.
55.
▲
by
bartbutler
9y ago
It's BGP routing, and requests only (not responses). Radware, which is not Mossad, does not do our TLS termination--we do.
56.
▲
by
bartbutler
9y ago
ProtonMail is not a US company.
57.
▲
by
bartbutler
9y ago
We have never used RoundCube in the project's history. You must be thinking of someone else.
58.
▲
by
bartbutler
9y ago
I have a legacy ones in case old/forgotten contacts send me a message, but they all forward to ProtonMail.
59.
▲
by
bartbutler
9y ago
It means that the crypto is certainly more solid (roll-your-own is a terrible idea in cryptography) and can in principle interoperate with other OpenPGP implementations, at least once the client supports it. I like ProtonMail a lot, but ful
60.
▲
by
bartbutler
9y ago
It's going to be less secure than native clients, for sure. ProtonMail has native mobile clients though, and will have a desktop one (IMAP/SMTP bridge) soon, which should alleviate webmail concerns.
More ›