Live data from Hacker News

Viewing profile — bartbutler

bartbutler

HN member
Joined
Sun, Dec 04, 2016, 7:42 PM UTC
HN karma
209
Public activity
76 items

About bartbutler

No profile information was provided.

Recent public activity

  1. comment
    Comment #46731891

    That's not a bad idea, I'll see what people think. Note that clicking on the unsubscribe link will unsubscribe you to whatever comms preference was specified in the sending and tel…

  2. comment
    Comment #46731474

    Hey, Proton CTO here. There was a bug, and we fucked up. Support should have reported it up the chain and acknowledged this. Things happen, especially at scale, but we take comms c…

  3. comment
    Comment #41879470

    We (Proton) have had our own CAPTCHA for a year or more now.

  4. comment
    Comment #41879468

    We aren't physically located in the US.

  5. comment
    Comment #40866140

    We do support automatic forwarding, have since last fall.

  6. comment
    Comment #40040571

    The author mentioned WKD but was mistaken. The culprit was keys.openpgp.org, not WKD.

  7. comment
    Comment #40000129

    Proton does this.

  8. comment
    Comment #36389207

    There aren't any links between Proton and Crypto AG, none at all.

  9. comment
    Comment #33441315

    This is Bart, Proton CTO here. For clarity, the issue mentioned here only impacts Proton Mail Bridge, our desktop IMAP/SMTP gateway to Proton Mail encrypted email. The fact that Br…

  10. comment
    Comment #31515328

    As of a month or two ago, it does not redirect to the cleartext site and stays on .onion.

  11. comment
    Comment #27436878

    UI refresh, SSO/persistent sessions, and because this crowd might care, the whole app was rewritten from scratch to transition from Angular v1 to React, which simply had to be done…

  12. comment
    Comment #19751322

    We are aware of the the issues brought up in [0] and [1]. As suggested in [2], we are already considering to switch to an implementation in WebAssembly to mitigate the possibility …

  13. comment
    Comment #18565577

    Hi there, I'll ask someone to reach out. In the future, please file a support ticket at: protonmail.com/support-form

  14. comment
    Comment #18535001

    It's not a small use case for corporate users where the internal mail is all encrypted. We also have full PGP support and the bridge is fully integrated with this, so we hope the g…

  15. comment
    Comment #18531700

    We (ProtonMail) don't provide a server-side IMAP/SMTP interface because we don't want to see your cleartext mail. And if you are doing the encryption and key management yourself lo…

  16. comment
    Comment #18470345

    We sent out an update about security features.

  17. comment
    Comment #18280466

    It is something we'd like to do, but it's still a little experimental and it hasn't gotten to the top of our priority list yet.

  18. comment
    Comment #18061426

    1. ProtonMail implements the OpenPGP standard and is fully interoperable with other OpenPGP email systems. 2. The web app is a single page application so it does not reload on ever…

  19. comment
    Comment #17779570

    I also think exploiting it would be extremely difficult. IIRC, it was NIST ECC curves which are hard to make constant time and do not have WebCrypto primitives. We are still going …

  20. comment
    Comment #17775663

    You are confusing crypto primitives with a high-level spec like OpenPGP. OpenPGPjs used WebCrypto and node crypto libraries when available for primitives. You still need a library …

  21. comment
    Comment #17775656

    You are confusing crypto primitives with a high-level spec like OpenPGP. OpenPGPjs used WebCrypto and node crypto libraries when available for primitives. You still need a library …

  22. comment
    Comment #17619992

    Import/export tool is in beta now and will be available for all users on launch. Export is available now via the web interface but it's a little clunky. The reason this stuff is co…

  23. comment
    Comment #17619949

    These are good points, though at this point I think it does make sense to wait a bit to clean up the deprecated stuff, given that a lot was waiting on this release and we'll probab…

  24. comment
    Comment #17615090

    1. Mobile apps are native, not web views 2. That's not what the TLS key was subpoenaed for--it was a very different system with a set of vulnerabilities we don't have, including a …

  25. comment
    Comment #17615056

    > You're expecting us to believe nobody on your team would take a payout from or be coerced by US LEO's or spooks. That's crazy. No, we're saying that we don't store the data partl…