Live data from Hacker News

Why ProtonMail is more secure than Gmail

protonmail.com

81–90 of 314 posts

Re: Why ProtonMail is more secure than Gmail

#82
post #41

Threat model, threat model, threat model. There are some people for whom "The government is literally after me, personally" is a valid threat model. There are some people for whom "Google employees with privileged access to Gmail are conspiring to be after me, personally" (one assumes there's a two-person rule for access to individual inboxes or deploying code that scans inboxes) is also a valid threat model. However…

> "Google employees with privileged access to Gmail are conspiring to be after me, personally" I thought employees do not have access to user data. Can anyone comment on this?

If there is a will, there is a way. It's all about trust, but I'm sure st least publicly they have stated employees do not have that access.

Re: Why ProtonMail is more secure than Gmail

#83
post #57
post #41

Threat model, threat model, threat model. There are some people for whom "The government is literally after me, personally" is a valid threat model. There are some people for whom "Google employees with privileged access to Gmail are conspiring to be after me, personally" (one assumes there's a two-person rule for access to individual inboxes or deploying code that scans inboxes) is also a valid threat model. However…

I think what's telling here is that the blog post does not point to Protonmail's own threat model. https://protonmail.com/blog/protonmail-threat-model/ Which says don't use it if you are up against state actors and: "Sensitive business communications – You have sensitive business information that you want to make sure is protected from competitors and other malicious parties. For example, you fear a competitor may wa…

I'm not sure there is a legal mechanism to force ProtonMail to add a backdoor...

> "Nearly every country in the world has laws governing lawful interception of electronic communications. In Switzerland, these regulations are set out in the Swiss Federal Act on the Surveillance of Postal and Telecommunications Traffic (SPTT) last revised in 2012. In the SPTT, the obligation to provide the technical means for lawful interception is imposed only on Internet access providers, so ProtonMail, as a mere Internet application provider, is completely exempt from the SPTT’s scope of application. This means that under Swiss law, ProtonMail cannot be compelled to backdoor our secure email system."

https://protonmail.com/blog/switzerland/

Re: Why ProtonMail is more secure than Gmail

#84
post #41

Threat model, threat model, threat model. There are some people for whom "The government is literally after me, personally" is a valid threat model. There are some people for whom "Google employees with privileged access to Gmail are conspiring to be after me, personally" (one assumes there's a two-person rule for access to individual inboxes or deploying code that scans inboxes) is also a valid threat model. However…

> "Google employees with privileged access to Gmail are conspiring to be after me, personally" I thought employees do not have access to user data. Can anyone comment on this?

It's happened before: https://techcrunch.com/2010/09/14/google-engineer-spying-fir... If a person has enough access, and they have to, given that someone has to have admin access.

Re: Why ProtonMail is more secure than Gmail

#85
post #54

Earlier quoted context omitted.

Yes. But you enter the second password into the Proton webapp if you use it so it's not exactly beyond their reach.

You are correct in your assessment, but this statement holds true for any application. You must read the source before executing it -- and en suite you need to trust the hardware that's executing said code. As it stands you don't send your password to proton -- they send you an encrypted private key that the password you type decrypts (at email creation time you generated that private key in your browser via openppg.…

It's true for applications delivered live (mostly webapps). For vast majority of apps, I expect that at least the package maintainer at least glanced at the changes before building a new version. This is hardly foolproof but there is another layer of verification.

Re: Why ProtonMail is more secure than Gmail

#86

Earlier quoted context omitted.

> "I don't want to lose access to my email" (remember that availability is a part of security!). Really? You've heard just as many stories of unexpected Google account closures as I have. I'm quite confident ProtonMail just don't do that. And if they did, you'd have a much more credible chance of talking to a human and rectifying the situation.

Actually ProtonMail does do this. They can't read your email so they can't know if you're actually abusing it via their terms of service. Thus if you file complaints against users ProtonMail will actually suspend the account without evidence until you clear your name. It's abused fairly regularly in fact.

Hmm... Could you provide a source? I don't think they do this. At least not for paid accounts with a long history.

Re: Why ProtonMail is more secure than Gmail

#88
post #70
post #46

Earlier quoted context omitted.

They do for their new Advanced Protection Program[1]. The regular Gmail service is not really marketed to the security concious users. It's like comparing Android to Qubes OS. Not really fair. For what they are, Google products are surprisingly secure. [1] https://landing.google.com/advancedprotection/

Qubes has a nice fat attack surface known as the hypervisor. I'm skeptical when people point to this as the panacea of computing security.

In practice it's a rather thin attack surface and serious cloud providers rely on it so it's both well-tested and any exploit can be used on much more valuable targets than your OS.

It's not a panacea. There are physical threats, there are threats from the very hardware you're using. But, like it says on the box, it is a reasonably secure operating system.

Re: Why ProtonMail is more secure than Gmail

#89
post #64

Earlier quoted context omitted.

> "I don't want to lose access to my email" (remember that availability is a part of security!). Arent there many (difficult to judge how many) cases of people losing access to their Google account, and therefore about everything they had online (photos, email, videos, etc...). That is also scary enough, especially when it happens randomly with no clear reason why and the support of Google seems to be limited to send…

> the support of Google seems to be limited to sending info via forms in the hope of a future human interaction People underestimate the power of a calm, deliberate letter sent by post with an elected representative or two copied.

Why include the elected representatives? Is that an implied threat of “reinstate my email or these legislators will regulate you into being a public utility”?

Re: Why ProtonMail is more secure than Gmail

#90
post #9

Hows the spam filter? I fell in love with the idea of switching to other services before on their marketing copy but I'm back in Gmail. It all rests on how good the spam filtering is by default not after I've received x good and y bad emails. Unfortunately in this case it sounds like there might be a tradeoff between securing my internet postcards[1] and training spam filters. [1] and that's all they are really, post…

> by default not after I've received x good and y bad emails That's fair for you to demand. I run my own personal email server with SpamAssassin and I definitely got a lot of spam in the first week. Then I told SA to learn what spam and ham looks like based on what I received and it's been excellent ever since. I have retrained it about once every 2 years but it's really not that bad. Personally, I'm happy to manuall…

Yup essentially my requirements are simply "I don't want to spend time on my spam filter"

In a previous life/job I set up, administered, and maintained mail servers. I don't have an exact count but high tens to low hundreds over multiple clients.

I think that's one skill I'm completely burned out on for personal use. Capable, but not willing.

Post reply on HN