Live data from Hacker News

Why ProtonMail is more secure than Gmail

protonmail.com

121–130 of 314 posts

Re: Why ProtonMail is more secure than Gmail

#121

Earlier quoted context omitted.

It can be simplified to: Gmail + 0$ per month = zero privacy for you and anyone who emails you, plus Uncle Sam has full access to your life. Protonmail + 4$ per month = you will never see ads for a like the one you just bought, plus you will be driving Uncle Sam crazy!

Uncle Sam can root your machine. If Uncle Sam is the threat vector you're better off using pen and paper.

That costs Uncle Sam resources at scale.

Re: Why ProtonMail is more secure than Gmail

#122
post #70
post #46

Earlier quoted context omitted.

They do for their new Advanced Protection Program[1]. The regular Gmail service is not really marketed to the security concious users. It's like comparing Android to Qubes OS. Not really fair. For what they are, Google products are surprisingly secure. [1] https://landing.google.com/advancedprotection/

Qubes has a nice fat attack surface known as the hypervisor. I'm skeptical when people point to this as the panacea of computing security.

That sounds to me like a very small attack surface.

Updating a hypervisor is far easier than e.g. updating hundreds of statically compiled executables.

Re: Why ProtonMail is more secure than Gmail

#123

Does anyone know how they reconcile "zero-knowledge" and allowing people to log in? Do they encrypt your private key with a KDF of your password or something?

They use SRP for authentication, and yes, your private key is encrypted with a key derived from your passphrase.

https://protonmail.com/blog/encrypted_email_authentication/

Re: Why ProtonMail is more secure than Gmail

#124

Just a reminder that for it to work both the recipient and sender need to use Protonmail... across the full e-mail thread.

All your emails are stored encrypted with your public key when on ProtonMail's servers. And they do support end-to-end encryption with other email providers (with a user-specified passphrase).

Re: Why ProtonMail is more secure than Gmail

#125
post #54

Earlier quoted context omitted.

Yes. But you enter the second password into the Proton webapp if you use it so it's not exactly beyond their reach.

You are correct in your assessment, but this statement holds true for any application. You must read the source before executing it -- and en suite you need to trust the hardware that's executing said code. As it stands you don't send your password to proton -- they send you an encrypted private key that the password you type decrypts (at email creation time you generated that private key in your browser via openppg.…

The lack of code signing in web apps and the added attack surface of having your web and application server (which are in control of the code that users run) exposed to the internet matter a lot in this context.

Attacks on build systems of native applications aren't unheard of (CCleaner, that Ukrainian tax software, etc.), but it's far more involved and more likely to be detected, whereas web app backdoors can easily be delivered exclusively to the target and only for as long as needed to pull off the attack.

Re: Why ProtonMail is more secure than Gmail

#126
post #2

This post would be improved by discussing that their [threat model]( https://en.wikipedia.org/wiki/Threat_model ) is so different than Google's that it regards some of Google's business practices as threats. And that, in turn, there are threats that Google treats as much bigger threats, bringing their own world-class security team to. Calling this fundamental difference in approach "more secure" manipulates the less-…

That sounds a bit formalistic and abstract to me. Perhaps you could educate us on which specific threats you think we should pay attention to when choosing between Gmail and Protonmail. What are some specific threats that Gmail defends us against more effectively than Protonmail?

Off the top of my head I think the number 1 "threat" that Google doesn't protect you from is privacy. They are actively watching your email with algorithms to use for advertising purposes.

On the other hand, they have more resources than anyone else to protect against things like DDOS, nation-state hacking/phishing, and physical disasters. They also have a legion of lawyers to protect against improper legal requests, however they will roll right over for a government if it's legal.

Protonmail is on point with the privacy, but their security engineering team is probably less than 1/10th that of Google's.

Re: Why ProtonMail is more secure than Gmail

#127
post #84

Earlier quoted context omitted.

> "Google employees with privileged access to Gmail are conspiring to be after me, personally" I thought employees do not have access to user data. Can anyone comment on this?

It's happened before: https://techcrunch.com/2010/09/14/google-engineer-spying-fir... If a person has enough access, and they have to, given that someone has to have admin access.

Around 100 people have root @ Google. They get a tshirt with it on.

With months of effort researching tripwires and auditing systems, any of them could read your mail.

There's a pretty good chance they'd get caught by some auditing or alerting system they were unaware of though. Many of those systems are kept secret from employees for obvious reasons.

Any two employees collude to much more easily read your mail. There's probably ~1000 people in that position (not only the gmail team, but anyone who writes any kind of library code used by any of the databases, datastores, or application servers). They would leave audit records though, although they might go unnoticed.

Re: Why ProtonMail is more secure than Gmail

#128

The engineer in me loves the promised End-End encryption and all the cool stuff. But, the inconvenience of "unable to search contents of emails" is a deal breaker towards encrypted email for me. My primary concern was Google/Microsoft scraping my emails to build a profile of me. My emails could give away very personal information that I do not want to be used for advertising. My money finally went to Fastmail. Excell…

You can totally search email contents with ProtonMail -- it just does it clientside. I just tested with my 125MB of emails and it was fast (under 1s) but maybe if you have more emails it could be slower.

Re: Why ProtonMail is more secure than Gmail

#129

Earlier quoted context omitted.

It can be simplified to: Gmail + 0$ per month = zero privacy for you and anyone who emails you, plus Uncle Sam has full access to your life. Protonmail + 4$ per month = you will never see ads for a like the one you just bought, plus you will be driving Uncle Sam crazy!

Uncle Sam can root your machine. If Uncle Sam is the threat vector you're better off using pen and paper.

Uncle Sam can't root everyone's machines at once. If Uncle Sam wants mass surveillance it's going be through the provider.

Re: Why ProtonMail is more secure than Gmail

#130

Earlier quoted context omitted.

It can be simplified to: Gmail + 0$ per month = zero privacy for you and anyone who emails you, plus Uncle Sam has full access to your life. Protonmail + 4$ per month = you will never see ads for a like the one you just bought, plus you will be driving Uncle Sam crazy!

Uncle Sam can root your machine. If Uncle Sam is the threat vector you're better off using pen and paper.

This comment seems to conflate resistance to mass surveillance with resistance to targeted surveillance. It's almost as if the fact that I'll never be able to resist a targeted attack means that I shouldn't attempt to have any privacy at all, but surely that's not right.

Encrypted messaging apps and services like ProtonMail have never been primarily to help people with Snowden's threat model. They're for people like you and me to reclaim a semblance of privacy, and they work even with "Uncle Sam" as the threat model in a limited, dragnet surveillance sense.

Post reply on HN