Live data from Hacker News

Why ProtonMail is more secure than Gmail

protonmail.com

141–150 of 314 posts

Re: Why ProtonMail is more secure than Gmail

#141

Earlier quoted context omitted.

Uncle Sam can root your machine. If Uncle Sam is the threat vector you're better off using pen and paper.

Uncle Sam can't root everyone's machines at once. If Uncle Sam wants mass surveillance it's going be through the provider.

Intel Management Engine.

Re: Why ProtonMail is more secure than Gmail

#142

Earlier quoted context omitted.

Right, Snowden weakened US national security. He clued in the public to important secrets related to our intel operations, and ticked off public backlash against our intelligence agencies. Now, Snowden sits comfortably in a country who is actively hacking us. I’d bet my life that high school students from St. Petersburg have more reverse engineering skills than all US undergrads, at least those who are now interested…

Just watch how I get down voted here. Tells you a lot about the culture here.

The HN community has quite a wide variety of views and tends to value civil, considered, constructive discourse (as well as refraining from commenting on down votes). Tone as well as content go a long way: there have been plenty of comments over the years that are critical of Snowden. Choosing to use a pejorative nickname and phrases like "HN worships" don't do anything to promote your argument. You're choosing to participate on HN, and are therefore part of the community and its culture. I doubt you include yourself when you say "HN worships", yet you're participating here. Consider that there may be others on HN who wouldn't categorize their opinions of Snowden as "worshipping" either. (And there definitely are.)

You mention the "divide and wreck of culture of this nation", which indicates to me that you care about such things. Are the comments you've posted going to do anything to make this better? Likely not: people who agree with you are likely going to continue to agree with you, and those that don't are likely to write you off due to how you're presenting yourself. If your goal is to help make things better, I encourage you to think on ways you might be more effective. People may not necessarily agree with the positions you hold, but they may also have reasoned and nuanced reasons for holding the positions they do.

Re: Why ProtonMail is more secure than Gmail

#143

Earlier quoted context omitted.

It can be simplified to: Gmail + 0$ per month = zero privacy for you and anyone who emails you, plus Uncle Sam has full access to your life. Protonmail + 4$ per month = you will never see ads for a like the one you just bought, plus you will be driving Uncle Sam crazy!

Uncle Sam can root your machine. If Uncle Sam is the threat vector you're better off using pen and paper.

Uncle Sam can read paper. If Uncle Sam is the threat vector you're better off using telepathy.

In other words, your comment is pointless.

Re: Why ProtonMail is more secure than Gmail

#144
post #142

Earlier quoted context omitted.

Just watch how I get down voted here. Tells you a lot about the culture here.

The HN community has quite a wide variety of views and tends to value civil, considered, constructive discourse (as well as refraining from commenting on down votes). Tone as well as content go a long way: there have been plenty of comments over the years that are critical of Snowden. Choosing to use a pejorative nickname and phrases like "HN worships" don't do anything to promote your argument. You're choosing to pa…

You seem to have good writing skills. Can you now respond to my post whereby I’ve made the claim that Snowden has committed treason, weakened US national security, and possibly ticked off a decline in interest for working for US intelligence?

If the public is aware of our intel capabilities as a direct result of Snowden’s action, it seems close to certain that my points are correct.

Re: Why ProtonMail is more secure than Gmail

#145
post #83
post #57

Earlier quoted context omitted.

I think what's telling here is that the blog post does not point to Protonmail's own threat model. https://protonmail.com/blog/protonmail-threat-model/ Which says don't use it if you are up against state actors and: "Sensitive business communications – You have sensitive business information that you want to make sure is protected from competitors and other malicious parties. For example, you fear a competitor may wa…

I'm not sure there is a legal mechanism to force ProtonMail to add a backdoor... > "Nearly every country in the world has laws governing lawful interception of electronic communications. In Switzerland, these regulations are set out in the Swiss Federal Act on the Surveillance of Postal and Telecommunications Traffic (SPTT) last revised in 2012. In the SPTT, the obligation to provide the technical means for lawful in…

If a government really wanted access to a specific user's ProtonMail account, couldn't they get a court order from a domestic CA, say Verisign, to generate a fake certificate that they can use to MITM a browser session, and deliver key-stealing javascript to the user? I'm not sure what the state of certificate pinning is, but it seems that for the "uber security conscious users" they have instructions to check the SHA-1 fingerprints[0] manually. I feel like there are just an infinite number of technical ways a state actor with unbounded resources and legal access to basically every authority and pipe that operates the internet could MITM a service like this without compelling ProtonMail to do anything.

[0]https://protonmail.com/support/knowledge-base/protonmails-ss...

Re: Why ProtonMail is more secure than Gmail

#147
post #64

Earlier quoted context omitted.

> "I don't want to lose access to my email" (remember that availability is a part of security!). Arent there many (difficult to judge how many) cases of people losing access to their Google account, and therefore about everything they had online (photos, email, videos, etc...). That is also scary enough, especially when it happens randomly with no clear reason why and the support of Google seems to be limited to send…

> Arent there many (difficult to judge how many) cases of people losing access to their Google account, and therefore about everything they had online (photos, email, videos, etc...). That is also scary enough, especially when it happens randomly with no clear reason why and the support of Google seems to be limited to sending info via forms in the hope of a future human interaction. There are, but that's not incorpo…

Denial of service (or access) is one of several possible security threats.

Unauthorised access, content modification or deletion, impersonation, and several other categories of security policy violations are also fairly typical.

Re: Why ProtonMail is more secure than Gmail

#148
Anyone thinks this would interfere with their security? https://www.reddit.com/r/ProtonMail/comments/6ru9pf/ive_had_...

> The final nail in the coffin for me is this page right here: https://protonmail.com/blog/transparency-report/ Can I draw your attention to this sentence: "After reviewing the relevant evidence forwarded by US authorities, criminal intent was apparent, so Proton Technologies AG decided to comply with the data request"

Re: Why ProtonMail is more secure than Gmail

#149
post #31

Earlier quoted context omitted.

What is a "trust bundle"?

To add to the trust bundle a vendor needs to be accredited. The trust bundle holds the public key for every "email" address.

So it's a PKI, except obfuscated by a bunch of health industry acronyms and "accredited" logos?

Re: Why ProtonMail is more secure than Gmail

#150

Earlier quoted context omitted.

It's probably because you're calling him snow dog.

Edited, thanks. I doubt the downvotes will be undone, though.

Thanks for editing your post. With respect to the voting, unfortunately that's partly an artifact of viewing the site. Unless people are following the thread, they aren't likely to see an edit. There is an option in account settings which permits including a delay before a comment is made visible. This allows a period of time where you can edit the comment before others view it. This can help if you've dashed off a comment in the heat of the moment, reflect, and rewrite it with a cooler head. Admittedly, it doesn't help if the comment has already been viewed, but it may prevent some of what you experienced.
Post reply on HN