Earlier quoted context omitted.
It can be simplified to: Gmail + 0$ per month = zero privacy for you and anyone who emails you, plus Uncle Sam has full access to your life. Protonmail + 4$ per month = you will never see ads for a like the one you just bought, plus you will be driving Uncle Sam crazy!
Uncle Sam can root your machine. If Uncle Sam is the threat vector you're better off using pen and paper.
Why ProtonMail is more secure than Gmail
121–130 of 314 posts
Re: Why ProtonMail is more secure than Gmail
#122Earlier quoted context omitted.
They do for their new Advanced Protection Program[1]. The regular Gmail service is not really marketed to the security concious users. It's like comparing Android to Qubes OS. Not really fair. For what they are, Google products are surprisingly secure. [1] https://landing.google.com/advancedprotection/
Qubes has a nice fat attack surface known as the hypervisor. I'm skeptical when people point to this as the panacea of computing security.
Updating a hypervisor is far easier than e.g. updating hundreds of statically compiled executables.
Re: Why ProtonMail is more secure than Gmail
#123Does anyone know how they reconcile "zero-knowledge" and allowing people to log in? Do they encrypt your private key with a KDF of your password or something?
Re: Why ProtonMail is more secure than Gmail
#124Just a reminder that for it to work both the recipient and sender need to use Protonmail... across the full e-mail thread.
Re: Why ProtonMail is more secure than Gmail
#125Earlier quoted context omitted.
Yes. But you enter the second password into the Proton webapp if you use it so it's not exactly beyond their reach.
You are correct in your assessment, but this statement holds true for any application. You must read the source before executing it -- and en suite you need to trust the hardware that's executing said code. As it stands you don't send your password to proton -- they send you an encrypted private key that the password you type decrypts (at email creation time you generated that private key in your browser via openppg.…
Attacks on build systems of native applications aren't unheard of (CCleaner, that Ukrainian tax software, etc.), but it's far more involved and more likely to be detected, whereas web app backdoors can easily be delivered exclusively to the target and only for as long as needed to pull off the attack.
Re: Why ProtonMail is more secure than Gmail
#126This post would be improved by discussing that their [threat model]( https://en.wikipedia.org/wiki/Threat_model ) is so different than Google's that it regards some of Google's business practices as threats. And that, in turn, there are threats that Google treats as much bigger threats, bringing their own world-class security team to. Calling this fundamental difference in approach "more secure" manipulates the less-…
That sounds a bit formalistic and abstract to me. Perhaps you could educate us on which specific threats you think we should pay attention to when choosing between Gmail and Protonmail. What are some specific threats that Gmail defends us against more effectively than Protonmail?
On the other hand, they have more resources than anyone else to protect against things like DDOS, nation-state hacking/phishing, and physical disasters. They also have a legion of lawyers to protect against improper legal requests, however they will roll right over for a government if it's legal.
Protonmail is on point with the privacy, but their security engineering team is probably less than 1/10th that of Google's.
Re: Why ProtonMail is more secure than Gmail
#127Earlier quoted context omitted.
> "Google employees with privileged access to Gmail are conspiring to be after me, personally" I thought employees do not have access to user data. Can anyone comment on this?
It's happened before: https://techcrunch.com/2010/09/14/google-engineer-spying-fir... If a person has enough access, and they have to, given that someone has to have admin access.
With months of effort researching tripwires and auditing systems, any of them could read your mail.
There's a pretty good chance they'd get caught by some auditing or alerting system they were unaware of though. Many of those systems are kept secret from employees for obvious reasons.
Any two employees collude to much more easily read your mail. There's probably ~1000 people in that position (not only the gmail team, but anyone who writes any kind of library code used by any of the databases, datastores, or application servers). They would leave audit records though, although they might go unnoticed.
Re: Why ProtonMail is more secure than Gmail
#128The engineer in me loves the promised End-End encryption and all the cool stuff. But, the inconvenience of "unable to search contents of emails" is a deal breaker towards encrypted email for me. My primary concern was Google/Microsoft scraping my emails to build a profile of me. My emails could give away very personal information that I do not want to be used for advertising. My money finally went to Fastmail. Excell…
Re: Why ProtonMail is more secure than Gmail
#129Earlier quoted context omitted.
It can be simplified to: Gmail + 0$ per month = zero privacy for you and anyone who emails you, plus Uncle Sam has full access to your life. Protonmail + 4$ per month = you will never see ads for a like the one you just bought, plus you will be driving Uncle Sam crazy!
Uncle Sam can root your machine. If Uncle Sam is the threat vector you're better off using pen and paper.
Re: Why ProtonMail is more secure than Gmail
#130Earlier quoted context omitted.
It can be simplified to: Gmail + 0$ per month = zero privacy for you and anyone who emails you, plus Uncle Sam has full access to your life. Protonmail + 4$ per month = you will never see ads for a like the one you just bought, plus you will be driving Uncle Sam crazy!
Uncle Sam can root your machine. If Uncle Sam is the threat vector you're better off using pen and paper.
Encrypted messaging apps and services like ProtonMail have never been primarily to help people with Snowden's threat model. They're for people like you and me to reclaim a semblance of privacy, and they work even with "Uncle Sam" as the threat model in a limited, dragnet surveillance sense.