There's regular security solutions then there's those meant to stop High Strength Attackers. I warned ProtonMail's team and infrastructure wouldn't handle the latter. I was expecting stealth 0-days, though, given there's DDOS mitigations available. That they went down due to DDOS was a bit of a surprise. "Cost estimates for these solutions are around $100,000 per year since there are few service providers able to fig…
You mentioned that you warned ProtonMail's team about High Strength Attackers. What else did you warn them about? What other security flaws do they have in your opinion?
Here's a specific example where I try to make a step-by-step guide for high assurance Tor without knowing its internals. Just drew on my prior work:
https://www.schneier.com/blog/archives/2014/09/identifying_d...
Hope what High Assurance Security takes is more clear now. Unless you get lucky (eg GPG), you need high assurance to resist TLA's successfully and that might just be delaying inevitable. Still need monitoring & tamper-detection.