Live data from Hacker News

ProtonMail's encrypted email is now available to all

engadget.com

41–50 of 111 posts

Re: ProtonMail's encrypted email is now available to all

#41
The fundamental problem with e2e encrypted email, outside of the many technical limitations, is that the encryption is only as strong as the weakest link. Every member of an email chain must support the e2e encryption in order for it to work. One unencrypted sender/receiver is sufficient to break the whole model.

So if you want encrypted email, you can only communicate with other people using the same encrypted email stack.

What's the point of that? If you're paranoid enough to the point that you're using encrypted email and you can convince all your correspondents to use it as well, then you have far better options available to you than email.

It really makes no sense to me... It's 2016, there are thousands of ways to communicate online, many of them encrypted. Why force the use of email?

We would all be far better off if we just assumed that all email is public. If you need private communication, don't use email.

Re: ProtonMail's encrypted email is now available to all

#42

The fundamental problem with e2e encrypted email, outside of the many technical limitations, is that the encryption is only as strong as the weakest link. Every member of an email chain must support the e2e encryption in order for it to work. One unencrypted sender/receiver is sufficient to break the whole model. So if you want encrypted email, you can only communicate with other people using the same encrypted email…

The way Protonmail and co try to solve this problem is by sending the non-protonmail recipient a notification email, with "click here to read". From https://protonmail.com/security-details :

"We support sending encrypted communication to non-ProtonMail users via symmetric encryption. When you send an encrypted message to a non-ProtonMail user, they receive a link which loads the encrypted message onto their browser, which they can decrypt using a passphrase that you have shared with them. You can also send unencrypted messages to Gmail, Yahoo, Outlook and others, just like regular email."

Re: ProtonMail's encrypted email is now available to all

#43
post #24

Some bad signs: 1. Hosted in Switzerland is advertised as a security feature. The point of e2e is that the servers are untrusted. If you need a "good jurisdiction" for your servers, it means they must be trusted. That's a problem, because sadly there are no good jurisdictions in today's world, and your jurisdiction doesn't help you if your servers are hacked. 2. It's webmail. That means the security of whatever e2e t…

1. You still need a good jurisdiction to avoid being compelled by public or secret courts to damage your users. Switzerland is pretty reasonable about their privacy stance and LI requests. The flip is that, outside Five Eyes, the TAREX teams can target them along with whatever TAO wants to throw in. No restrictions. They better know strong INFOSEC.

2. Webmail complaint is probably legit. That does in nation-state's targets over time. Might be a compromise, though, to up baseline of those that absolutely refuse to use other stuff.

3. Most of the new services have this problem. It's like they have more enthusiasm or business savvy than actual INFOSEC skill. There's many schemes proven in field or pentesting they can copy. Yet, inspired by the one that failed? (Rolls eyes)

I'm just using GPG over MyKolab for now. Keep them untrusted but in jurisdiction with lower availability risks from takedowns. I encourage you to keep up your own great work with addition of cross-platform desktop stuff. Maybe people like me will finally get off GPG for something less horrible to use but scares NSA just as much. ;)

Re: ProtonMail's encrypted email is now available to all

#44
post #24

Some bad signs: 1. Hosted in Switzerland is advertised as a security feature. The point of e2e is that the servers are untrusted. If you need a "good jurisdiction" for your servers, it means they must be trusted. That's a problem, because sadly there are no good jurisdictions in today's world, and your jurisdiction doesn't help you if your servers are hacked. 2. It's webmail. That means the security of whatever e2e t…

Is there a "better" free alternative webmail?

You should consider all of them insecure and big time snoops if free and/or webmail. If webmail, best you can do is use a paid service with antisnooping in terms of service and preferrably local laws. Just reduces number that will attack you. Anything further requires using something like PGP/GPG over that so they can't read it. Strong endpoint security, too.

Re: ProtonMail's encrypted email is now available to all

#45
post #24

Some bad signs: 1. Hosted in Switzerland is advertised as a security feature. The point of e2e is that the servers are untrusted. If you need a "good jurisdiction" for your servers, it means they must be trusted. That's a problem, because sadly there are no good jurisdictions in today's world, and your jurisdiction doesn't help you if your servers are hacked. 2. It's webmail. That means the security of whatever e2e t…

> "it does seem that (much like Lavabit), the service is built on the premise of "won't" read your mail rather than "can't" read your mail."

Can you help me understand this comment? I get that the usual problem with webmail is that it's "plaintext in, plaintext out"... So you just have to trust the server operator that they're actually encrypting anything, doing it well, not compromised, etc.

But if that's the problem, why isn't the answer to have client side code handling the encryption? From skimming the page source and reading https://protonmail.com/security-details, that's exactly what Protonmail does.

First you use a username/password to authenticate with protonmail - that's cleartext in/out - this only determines which account you are accessing. Once you're authenticated, your browser runs an open source AngularJS application, which asks you for a separate, client-side-only password. Once you've authenticated, your browser only sends/receives cyphertext.

I know you by reputation and I'm a big fan of your work... so I assume I'm missing something. Am I misunderstanding the problem? What am I missing here?

Re: ProtonMail's encrypted email is now available to all

#46
post #10
post #4

I remember when people used to flick to HushMail as the preferred encrypted e-mail provider. Where are they now?

HushMail... wow, that's some history right there. Anyways, they got in bed with feds, and that was pretty much the end of that.. http://www.wired.com/2007/11/encrypted-e-mai

"Even we cannot read your e-mails!"

Exactly what those guys said 10 years ago, and exactly what Proton is saying now.

What is different?

Re: ProtonMail's encrypted email is now available to all

#47
post #39

Earlier quoted context omitted.

Would you care to comment on Cyph [1]? They claim that they are able to approximate client side programs that provide e2e but in a non-plugin browser environment [2]. I know tptacek doesn't like it but he wasn't willing to go into a detailed account of why. [1] https://cyph.com [2] https://docs.google.com/document/d/1XVh4ALXhbfxi70QSUY-xHcla...

Hah. I had some time to think about that interaction and concluded (after a chat with a few peers at AppSec Cali) that he and I simply differ in mentality. I understand where he's coming from about the risks posed by that level of flexibility in the execution environment, but I'm also more prone to push for the idea that making encryption more convenient for all justifies taking some risks in terms of the execution e…

You guys seem to remember more about "this interaction" than I do. Someone want to bring me up to speed?

Re: ProtonMail's encrypted email is now available to all

#48
post #18
post #13

> The app is a good example that even if they government forces US companies like Apple to create backdoors, users will still have communication options that the government can't crack. If you're interested, it's now available for Android, iOS or the web. That is immensely misleading. If some adversary has a backdoor in the OS/platform, then in many cases no amount of encryption will save you.

If you input your encryption passphrase on a keylogged device, your entire encryption userspace falls apart.

not if you do your crypto on a dongle (such as a yubikey), at which point they also need physical access to get the private key.

It's perfectly viable for services like protonmail to allow 2FA via a dongle which would not be compromised permanently by a totally pwned userspace.

Re: ProtonMail's encrypted email is now available to all

#49
post #24

Some bad signs: 1. Hosted in Switzerland is advertised as a security feature. The point of e2e is that the servers are untrusted. If you need a "good jurisdiction" for your servers, it means they must be trusted. That's a problem, because sadly there are no good jurisdictions in today's world, and your jurisdiction doesn't help you if your servers are hacked. 2. It's webmail. That means the security of whatever e2e t…

> "it does seem that (much like Lavabit), the service is built on the premise of "won't" read your mail rather than "can't" read your mail." Can you help me understand this comment? I get that the usual problem with webmail is that it's "plaintext in, plaintext out"... So you just have to trust the server operator that they're actually encrypting anything, doing it well, not compromised, etc. But if that's the proble…

If you have an installable client that performs the encryption, yes. But if the encryption is driven by Javascript that is or can be loaded when you hit the website, then no: the application is only as secure as the HTTP connection you rely on to deliver the code to you every time you hit the site.

Re: ProtonMail's encrypted email is now available to all

#50
post #24

Some bad signs: 1. Hosted in Switzerland is advertised as a security feature. The point of e2e is that the servers are untrusted. If you need a "good jurisdiction" for your servers, it means they must be trusted. That's a problem, because sadly there are no good jurisdictions in today's world, and your jurisdiction doesn't help you if your servers are hacked. 2. It's webmail. That means the security of whatever e2e t…

> "it does seem that (much like Lavabit), the service is built on the premise of "won't" read your mail rather than "can't" read your mail." Can you help me understand this comment? I get that the usual problem with webmail is that it's "plaintext in, plaintext out"... So you just have to trust the server operator that they're actually encrypting anything, doing it well, not compromised, etc. But if that's the proble…

The problem is that they're trusting the integrity of that client-side code to their servers on each use, which is in practice not meaningfully different from a traditional non-E2EE email service.

The only difference in attack pattern, in the event of a server compromise, would be that the attacker would have to send you a line of JS to steal your password/key before reading your emails.

Post reply on HN