Live data from Hacker News

Why ProtonMail is more secure than Gmail

protonmail.com

91–100 of 314 posts

Re: Why ProtonMail is more secure than Gmail

#91
While I love ProtonMail as an effort to popularize security for end-users and trying to come up with smart technologies to achieve that, the whole risk model behind the writeup barely stands scrutiny. What's worrying, ProtonMail (who declare security a first-class feature) use "features" instead of systems to define security of their service.

If you think of it for a second, web crypto (protection against intermediaries and dishonest server) actually requires trusting the server, so no encryption-derived claims are sound if the server is dishonest. Any third party exploiting (or forcing legally) the server can make it dishonest and collect required keys in few simple steps. And, FWIW, if encryption is controlled by browser, adversary compromising the client itself can simply disable it.

So, while the effort is very important (and I bet they'd be around the first people who will suggest techniques for safe in-browser crypto execution), it isn't that they can be compared security-wise other than: - ethics - security policy - competence of security teams.

Isn't a level playing field for ProtonMail.

And, my final problem is, 99% of people are still outside Protonmail anyway, hence the intolerant winner argument, which ruined PGP and will ruin many optional security systems on top of convenience protocols in the foreseeable future.

Re: Why ProtonMail is more secure than Gmail

#92
post #74

Anyone remember HushMail? The end-to-end encrypted email service that didn't have the ability to decrypt your emails? They were eventually coerced to change their code and record passwords in order to gain access to an encrypted email account. ProtonMail is the same thing, give or take, just in Switzerland. They can be coerced just like anyone else. People whose lives are dependent on secure communication still need…

I'm not sure there is a legal mechanism to force ProtonMail to add a backdoor...

> "Nearly every country in the world has laws governing lawful interception of electronic communications. In Switzerland, these regulations are set out in the Swiss Federal Act on the Surveillance of Postal and Telecommunications Traffic (SPTT) last revised in 2012. In the SPTT, the obligation to provide the technical means for lawful interception is imposed only on Internet access providers, so ProtonMail, as a mere Internet application provider, is completely exempt from the SPTT’s scope of application. This means that under Swiss law, ProtonMail cannot be compelled to backdoor our secure email system."

https://protonmail.com/blog/switzerland/

Re: Why ProtonMail is more secure than Gmail

#93
post #70
post #46

Earlier quoted context omitted.

They do for their new Advanced Protection Program[1]. The regular Gmail service is not really marketed to the security concious users. It's like comparing Android to Qubes OS. Not really fair. For what they are, Google products are surprisingly secure. [1] https://landing.google.com/advancedprotection/

Qubes has a nice fat attack surface known as the hypervisor. I'm skeptical when people point to this as the panacea of computing security.

Yes, Qubes is only as secure as Xen which, itself, has had some pretty big security flaws pop up [1]. At the end of the day one has to decide what kind of trade offs they are willing to make in order to balance simple UX and security.

[1] https://blog.quarkslab.com/xen-exploitation-part-2-xsa-148-f...

Re: Why ProtonMail is more secure than Gmail

#94
post #46

Earlier quoted context omitted.

That's a fair criticism. I don't think the Gmail glossy brochure mentions its threat model either.

They do for their new Advanced Protection Program[1]. The regular Gmail service is not really marketed to the security concious users. It's like comparing Android to Qubes OS. Not really fair. For what they are, Google products are surprisingly secure. [1] https://landing.google.com/advancedprotection/

Does anyone have experience using Google’s advanced protection service? I’m wondering if it’s worth managing the dongles.

Re: Why ProtonMail is more secure than Gmail

#95
post #70
post #46

Earlier quoted context omitted.

They do for their new Advanced Protection Program[1]. The regular Gmail service is not really marketed to the security concious users. It's like comparing Android to Qubes OS. Not really fair. For what they are, Google products are surprisingly secure. [1] https://landing.google.com/advancedprotection/

Qubes has a nice fat attack surface known as the hypervisor. I'm skeptical when people point to this as the panacea of computing security.

I think the parent was talking about sandboxing and permissions

Re: Why ProtonMail is more secure than Gmail

#96
I have a paid account and only use protonmail for business and personal emails and use Gmail for anything else. 95% of the emails I get are junk anyway so I just try to separate that even more.

It seems most people care more about spam filters and search functionality than security. Which is kind of a downfall of protonmail because it probably will never have high adoption because if you want good search and spam filters then it means your emails need to be scanned by the servers.

Most people have multiple email accounts anyway, so why not use protonmail for the important emails and another service for junk account signups and everything else?

Re: Why ProtonMail is more secure than Gmail

#97

I don't understand this. Let's say I receive a newsletter from some website. That newsletter is not PGP-encrypted, so at some point the Proton Mail servers must be able to see a plaintext version of it. That means I have to trust that they never store that plaintext version. In addition, even if they immediately encrypt it and store the encrypted version, how can they do so such that only I can read it? Is the key ge…

They use your public key to encrypt and you use your private key to decrypt. Your private key is stored encrypted with your passphrase.

Re: Why ProtonMail is more secure than Gmail

#98
post #84

Earlier quoted context omitted.

> "Google employees with privileged access to Gmail are conspiring to be after me, personally" I thought employees do not have access to user data. Can anyone comment on this?

It's happened before: https://techcrunch.com/2010/09/14/google-engineer-spying-fir... If a person has enough access, and they have to, given that someone has to have admin access.

Worth noting that this occurred in 2009 (ie when gmail looked like this: https://1.bp.blogspot.com/_ZaGO7GjCqAI/SYD3g8LflXI/AAAAAAAAO...).

Re: Why ProtonMail is more secure than Gmail

#99
post #32

I don't understand this. Let's say I receive a newsletter from some website. That newsletter is not PGP-encrypted, so at some point the Proton Mail servers must be able to see a plaintext version of it. That means I have to trust that they never store that plaintext version. In addition, even if they immediately encrypt it and store the encrypted version, how can they do so such that only I can read it? Is the key ge…

The key is indeed generated from your password - to be pedantic, the key is encrypted by your password with a hardening function. I believe a copy of the key is sent to the recovery email. Not completely sure, I haven’t entered one.

The key is not sent anywhere. Your recovery mail allows you to recover access to your account, but not access to your keys. So if you ever lose your password you will also lose the ability to decrypt your mail.

Re: Why ProtonMail is more secure than Gmail

#100
post #93
post #70

Earlier quoted context omitted.

Qubes has a nice fat attack surface known as the hypervisor. I'm skeptical when people point to this as the panacea of computing security.

Yes, Qubes is only as secure as Xen which, itself, has had some pretty big security flaws pop up [1]. At the end of the day one has to decide what kind of trade offs they are willing to make in order to balance simple UX and security. [1] https://blog.quarkslab.com/xen-exploitation-part-2-xsa-148-f...

And, in turn, as secure as the hardware, with ROWHAMMER giving means to flipping bits in arbitrary memory locations, including recent work showing that one VM can flip bits in another.
Post reply on HN