Earlier quoted context omitted.
This is why we have HSMs. It can in fact be "impossible" to steal ones crypto keys.
Yeah, but "stealing" them isn;t the NSA's only avenue to acquire them. With Lavabit they just said "give us the keys so we can snoop all we want" - I suspect very few of us would be able to resist like Levinson did (as in, shut your company and livelihood down, and hope they don't throw you in jail for doing so). (Fortunately, most of us won't have users with as much heat coming down on them as Snowden, but if you're…
ProtonMail now the maintainer of OpenPGPjs email encryption library
21–30 of 30 posts
Re: ProtonMail now the maintainer of OpenPGPjs email encryption library
#22So my first reaction there was "there goes another non-five eyes (or nine or fourteen eyes) hosted mail service who've just painted a (or another) great big target on themselves to attract even more NSA scrutiny". (Second reaction was "Crypto in the browser in Javascript _again?_ Didn't was already point out this is 'doing it wrong'?")
Re: ProtonMail now the maintainer of OpenPGPjs email encryption library
#23Also Javascript based client applications installed locally are becoming more common (think about Atom etc). Maybe we will soon also see Javascript based desktop IMAP client.
Re: ProtonMail now the maintainer of OpenPGPjs email encryption library
#24Earlier quoted context omitted.
Yeah, but "stealing" them isn;t the NSA's only avenue to acquire them. With Lavabit they just said "give us the keys so we can snoop all we want" - I suspect very few of us would be able to resist like Levinson did (as in, shut your company and livelihood down, and hope they don't throw you in jail for doing so). (Fortunately, most of us won't have users with as much heat coming down on them as Snowden, but if you're…
"stealing" is the only path the NSA can take in the case of ProtonMail, due to their servers being hosted in Switzerland and not within the borders of a nation that has a strong relationship with the US intelligence community.
Or maybe I'm just in a way too "the whole world is fucked" mood today...
Re: ProtonMail now the maintainer of OpenPGPjs email encryption library
#25Reminder for the obvious: Javascript is now longer just for web browsers and GPG is not just for email. GPG is also used in B2B scenarios where files are being passed between between servers. Also Javascript based client applications installed locally are becoming more common (think about Atom etc). Maybe we will soon also see Javascript based desktop IMAP client.
Nylas N1 is an example of this (and excellent, might I add)!
Re: ProtonMail now the maintainer of OpenPGPjs email encryption library
#26Re: ProtonMail now the maintainer of OpenPGPjs email encryption library
#27Earlier quoted context omitted.
If I'm the NSA, I'd already have stolen Protonmail's HSTS pinned cert's private key (possibly by burning a zero day getting into one of their web servers, possibly by "asking nicely" to some tech employee there for whom I had appropriate leverage). But yeah - short of nation-state or very high level LEO (who're just piggybacking on their local NSA equivalent), HSTS with pinned certs is as close to "secure" as we have…
This is why we have HSMs. It can in fact be "impossible" to steal ones crypto keys.
Re: ProtonMail now the maintainer of OpenPGPjs email encryption library
#28Reminder for the obvious: Javascript is now longer just for web browsers and GPG is not just for email. GPG is also used in B2B scenarios where files are being passed between between servers. Also Javascript based client applications installed locally are becoming more common (think about Atom etc). Maybe we will soon also see Javascript based desktop IMAP client.
Re: ProtonMail now the maintainer of OpenPGPjs email encryption library
#29Re: ProtonMail now the maintainer of OpenPGPjs email encryption library
#30Reminder for the obvious: Javascript is now longer just for web browsers and GPG is not just for email. GPG is also used in B2B scenarios where files are being passed between between servers. Also Javascript based client applications installed locally are becoming more common (think about Atom etc). Maybe we will soon also see Javascript based desktop IMAP client.
> Javascript based desktop IMAP client Nylas N1 is an example of this (and excellent, might I add)! https://nylas.com/
Here's a blog post with more details about Nylas N1 and PGP: https://nylas.com/blog/pgp