Live data from Hacker News

Improved Authentication for Email Encryption and Security

protonmail.com

51–60 of 77 posts

Re: Improved Authentication for Email Encryption and Security

#51

Earlier quoted context omitted.

>Why is this any different Nobody says it's different >Why isn't this only an open-source, native app (where I can load a specific, known version instead of whatever is on the server). OK, let's suppose you're using a native app. One day vendor issues an update with some critical vulnerability patched. Unfortunately, another vulnerability (or even backdoor) sneaks into this update for whatever reasons. How is this an…

> Nobody says it's different They why do all the extra work for no gain in security? I think the sibling comment address your next comment well.

There's a difference between an active attacker and a passive MITM attacker. Doing this for the web app in addition to the native apps helps prevent a passive MITM attack from stealing login credentials.

Re: Improved Authentication for Email Encryption and Security

#52
post #40

Earlier quoted context omitted.

> With also using ProtonMail, I would expect to be on a government list of some sort. Are you aware what kind of idea you are circulating here? It's the kind of idea citizens in totalitarian states would circulate, probably even in the hope to score points from their dictator, for participating in instilling "order". Dude, wake up. This is sick .

In a world where both large Internet companies and governments collect meta data, possible collect more than meta data, set up fake cell towers, etc., I think it is naive to not think that they are also collecting statistics on the use of encryption. Perhaps you misunderstood me?

You're basically suggesting that using tools that strengthen democracy is to our disadvantage, because it does not please the government, and that we should therefor not use them to defend our rights. Basically, we should accept being manipulated by fear.

Re: Improved Authentication for Email Encryption and Security

#53
post #52

Earlier quoted context omitted.

In a world where both large Internet companies and governments collect meta data, possible collect more than meta data, set up fake cell towers, etc., I think it is naive to not think that they are also collecting statistics on the use of encryption. Perhaps you misunderstood me?

You're basically suggesting that using tools that strengthen democracy is to our disadvantage, because it does not please the government, and that we should therefor not use them to defend our rights. Basically, we should accept being manipulated by fear.

There is a difference between pointing out how surveillance works and saying it's good.

Re: Improved Authentication for Email Encryption and Security

#54

"In ProtonMail’s one-password mode, the mailbox password is derived from the login password via a one-way cryptographic password hash." I wondered why they didn't do this. As a customer, this is a welcome change. One thing that is of general concern to me: I tend to use a lot of encrypted traffic because much of my work is done on SSH shells to servers, and some of my customers request encrypting work files and use V…

"What our government should do is a moon-shot level of effort to promote strong encryption and very robust digital infrastructure."

They did. It was called the Computer Security Initiative. It was the culmination of efforts starting with Anderson Report that collectively invented INFOSEC and deployed high-assurance versions. Early releases were secure messaging, the BLACKER VPN, MLS endpoints, private databases, and so on. Industry ignored it in favor of cheapest, fanciest products with features moving at explosive pace. Congress's (or DOD's) COTS mandate and NSA's MISSI initiative finished it off by reducing government contracts for high-security product.

So, it's been done here before. It would work again. Just no will to do it on top esp with Microsoft and IBM's lobbying. ;) At least the papers on requirements and methods for achieving that were all published. Some still use the methods in commercial sector and CompSci. The first, secure systems are still available comnercially on not-so-secure hardware (i.e. Intel). Just almost no uptake in FOSS for such methods despite a labor advantage.

Re: Improved Authentication for Email Encryption and Security

#55
post #3

how practical is it to drop GMail for these guys? I'm tied fairly heavily to the Google ecosystem (Chome, Play, Finance, etc etc). They already have a mountain of data on me, but I really want to start taking encryption and privacy more seriously.

So I've actually been transitioning my personal communications over to Protonmail (on a custom domain to future proof the address), and keeping Gmail for transactional emails (because of utility in Inbox grouping, Google Now, etc).

I've realized that I don't really care about Google having access to my transactional mail (things knowable from third parties anyways), but do want personal communications properly encrypted. Basically, I've only moved over my "priority inbox," and keep using Gmail for junk.

Very satisfied with Protonmail though. Especially knowing they are working on fixing their lock-in issues.

Re: Improved Authentication for Email Encryption and Security

#56
post #29
post #18

Earlier quoted context omitted.

PGP is quite difficult to use by most people, and it doesn't even support forward secrecy, which is a huge weakness. It will never be used by more than a core group of highly technical, which is maybe less than 0.01% of the population. If we're to push end-to-end encryption to the masses, then we ought to try to get forward secrecy in it, and it should be quite invisible to the user. That's not to say that ProtonMail…

I would like something better then GPG as well, but at the moment I have a group of contacts that I would like to write GPG with. If you have a replacement for GPG and E-Mail please tell me what it is.

Possibly bitmessage.

But adoption is even worse than pgp

Re: Improved Authentication for Email Encryption and Security

#57
post #55
post #3

how practical is it to drop GMail for these guys? I'm tied fairly heavily to the Google ecosystem (Chome, Play, Finance, etc etc). They already have a mountain of data on me, but I really want to start taking encryption and privacy more seriously.

So I've actually been transitioning my personal communications over to Protonmail (on a custom domain to future proof the address), and keeping Gmail for transactional emails (because of utility in Inbox grouping, Google Now, etc). I've realized that I don't really care about Google having access to my transactional mail (things knowable from third parties anyways), but do want personal communications properly encryp…

It's worth noting that "things knowable from third parties" and "an aggregation of all your things knowable from third parties" are very different risk profiles, if that's the deciding factor for anyone.

Re: Improved Authentication for Email Encryption and Security

#58

"In ProtonMail’s one-password mode, the mailbox password is derived from the login password via a one-way cryptographic password hash." I wondered why they didn't do this. As a customer, this is a welcome change. One thing that is of general concern to me: I tend to use a lot of encrypted traffic because much of my work is done on SSH shells to servers, and some of my customers request encrypting work files and use V…

"What our government should do is a moon-shot level of effort to promote strong encryption and very robust digital infrastructure." They did. It was called the Computer Security Initiative. It was the culmination of efforts starting with Anderson Report that collectively invented INFOSEC and deployed high-assurance versions. Early releases were secure messaging, the BLACKER VPN, MLS endpoints, private databases, and…

[deleted]

Re: Improved Authentication for Email Encryption and Security

#59
Hello guys and how are you doing today, Do you need require the services of an accomplished and professional hacker for any of the following:

-Facebook account hacking -Instagram account hacking -Mobile phone hacking -Whatsapp hacking -Kik account hacking -GPS tracking -Website hacking -Bank account hacking -Account recovery -DDOS attack -Email account hacking

Then you should contact:danielwellingtonhacks@gmail.com for his professional services. He is one of the best hackers out there.

Re: Improved Authentication for Email Encryption and Security

#60
post #3

how practical is it to drop GMail for these guys? I'm tied fairly heavily to the Google ecosystem (Chome, Play, Finance, etc etc). They already have a mountain of data on me, but I really want to start taking encryption and privacy more seriously.

If you use any US based services, and likely any five-eyes services (maybe +Germany, Japan, SK, and much of EU, UK), everything is fed into some sophisticated networks.

For example, just because DuckDuckGo doesn't track you doesn't mean they don't feed their search results into their networks.

The benefit is reducing the footprint in other networks, like advertisement profiling, and the third-party data in the commercial data brokerage sectors.

Post reply on HN