Earlier quoted context omitted.
It certainly does, but require client software that's capable to decrypt the data. I think almost every desktop mail client support S/MIME. Many support PGP/MIME, using plugin/extension or natively. Unfortunately, the situation is much worse on mobile. Anyway, if the client software is capable - which is rarely true but sometimes is the case - any classic mail server can store everything encrypted. If you self-host -…
Right, I was going by their knowledge base article titled ‘IMAP, SMTP, and POP3 setup’ where they say: At this time Protonmail does not support IMAP/SMTP or POP3 due to the technology ProtonMail utilizes within web browsers to encrypt and decrypt your messages. We apologize for the inconvenience and are working on creative solutions to allow IMAP/SMTP use. https://protonmail.com/support/knowledge-base/imap-smtp-and-.…
Why ProtonMail is more secure than Gmail
171–180 of 314 posts
Re: Why ProtonMail is more secure than Gmail
#172Earlier quoted context omitted.
That sounds a bit formalistic and abstract to me. Perhaps you could educate us on which specific threats you think we should pay attention to when choosing between Gmail and Protonmail. What are some specific threats that Gmail defends us against more effectively than Protonmail?
Off the top of my head I think the number 1 "threat" that Google doesn't protect you from is privacy. They are actively watching your email with algorithms to use for advertising purposes. On the other hand, they have more resources than anyone else to protect against things like DDOS, nation-state hacking/phishing, and physical disasters. They also have a legion of lawyers to protect against improper legal requests,…
https://blog.google/products/gmail/g-suite-gains-traction-in...
Re: Why ProtonMail is more secure than Gmail
#173While I love ProtonMail as an effort to popularize security for end-users and trying to come up with smart technologies to achieve that, the whole risk model behind the writeup barely stands scrutiny. What's worrying, ProtonMail (who declare security a first-class feature) use "features" instead of systems to define security of their service. If you think of it for a second, web crypto (protection against intermediar…
PM team here, we just made an account to comment. We actually agree with some of the points made above, but we'd like to add the following commentary... Encrypting email while making it more usable than PGP is hard. There's no getting around that. Web crypto is always going to have some shortcomings, but web mail is on the rise, and at the end of the day, web crypto is better than no crypto. That said, we have been w…
Shoot me a message if you're interested in implementing something like that in ProtonMail.
Re: Why ProtonMail is more secure than Gmail
#174Very nice. One question though: how can we check if what they say is true? Is their client open-source? Also, would it be possible that if I open an email on an Android device, that Google still could read the email?
For the first question: https://github.com/ProtonMail/WebClient For the second, it is unlikely, spying on third party app is not in the ToS of android, and if google (or any big tech company, really) is caught doing something not in the ToS, it will cause a PR shitstorm. I have a Proton Mail account since 2014, but i never really used it. I might give it a try again today.
Re: Why ProtonMail is more secure than Gmail
#175The biggest obstacle in becoming secure with email is all of the other people you correspond with over email.
Re: Why ProtonMail is more secure than Gmail
#176Earlier quoted context omitted.
It's happened before: https://techcrunch.com/2010/09/14/google-engineer-spying-fir... If a person has enough access, and they have to, given that someone has to have admin access.
Around 100 people have root @ Google. They get a tshirt with it on. With months of effort researching tripwires and auditing systems, any of them could read your mail. There's a pretty good chance they'd get caught by some auditing or alerting system they were unaware of though. Many of those systems are kept secret from employees for obvious reasons. Any two employees collude to much more easily read your mail. Ther…
A convenient way to put a target on your back. What benefit does this have to their security? Accountability?
Re: Why ProtonMail is more secure than Gmail
#177Earlier quoted context omitted.
It's happened before: https://techcrunch.com/2010/09/14/google-engineer-spying-fir... If a person has enough access, and they have to, given that someone has to have admin access.
Around 100 people have root @ Google. They get a tshirt with it on. With months of effort researching tripwires and auditing systems, any of them could read your mail. There's a pretty good chance they'd get caught by some auditing or alerting system they were unaware of though. Many of those systems are kept secret from employees for obvious reasons. Any two employees collude to much more easily read your mail. Ther…
Re: Why ProtonMail is more secure than Gmail
#178Earlier quoted context omitted.
Uncle Sam can root your machine. If Uncle Sam is the threat vector you're better off using pen and paper.
Uncle Sam can’t dragnet root everyone’s machine, but they can (and do) dragnet surveil large email providers not focused on security. “The government can hack anyone, just give up” is a dumb objection if you view security from an economic perspective. Defenders have a huge advantage over attackers that we aren’t sufficiently taking advantage of yet.
I am not sure I understand the “fear” of the US government. Do we have cases of “normal” people being harmed from NSA type activities? We’ve had a ton of cases of normal people being harmed from non-government “hackers,” so, from a risk management perspective it seems silly to prioritize surveillance avoidance over garden variety thieves. To think Proton has the same level of experience and technology that Google has is a bit naïve.
And server location doesn’t particularly mean much. Plenty of Swiss banks have been compelled to turn over US citizen information due to FATCA — it’s not a stretch that a legitimate request for information by the US government would be honored by the Swiss if it pertains to a US citizen. For non-US citizens, there might be some benefit to an offshore server, however email is generally not the weakest link in surveillance. Also, you’d need to ensure that all your recipients are also using non-US as well as non-British, or non-French systems as well.
US surveillance is in the spotlight, but France and the UK are equally aggressive, if not more so since the actual laws in the UK and France are much more liberal in terms of allowing government to intercept communications. The French law doesn’t even require a judge (secret or not.)
https://www.recode.net/2015/11/14/11620670/france-has-a-powe...
And then there is this law In Switzerland— backed by almost 70% of voters:
http://www.bbc.com/news/world-europe-37465853
I think Proton is a nice alternative, but other than effective marketing, there isn’t much differentiation from paid Google Apps/Gmail plans. Comparing “free” gmail with Proton isn’t exactly honest, comparing paid gmail to Proton is probably a more valuable comparison.
With Gmail, for example, it’s possible to get a Business’s Associates Agreement for HIPAA compliance.. which means that it’s possible to have email that’s more secure than “normal” free Gmail. Of course HIPAA isn’t relevant to government surveillance, but really, how many people are actually at risk from the NSA? If that concern is part of your risk profile, then perhaps you ought to be living in a Tora Bora cave with messages being delivered encoded with a one time pad. If you are worried about your Antifa or KKK meeting minutes being intercepted, it’s likely Proton isn’t going to be much help.
Re: Why ProtonMail is more secure than Gmail
#179Here's the thing with email. You can sign up for Protonmail ... but you've still got to use email to correspond with others. And in all likelihood many of those individuals will be on GMail or some other less-secure provider unless you're using Protonmail as an enterprise solution, in which case the ratio of "secured" vs. "unsecured" recipients would likely tilt towards secured. Email is insecure, and most users don'…
This is true of the marginal utility of the first and last element in a network effect. We might as well push for a paradigm where hosts have no access to data rather than, in 1950 say "Why should I join the internet, there are no other computers on it"
Re: Why ProtonMail is more secure than Gmail
#180Threat model, threat model, threat model. There are some people for whom "The government is literally after me, personally" is a valid threat model. There are some people for whom "Google employees with privileged access to Gmail are conspiring to be after me, personally" (one assumes there's a two-person rule for access to individual inboxes or deploying code that scans inboxes) is also a valid threat model. However…
A lot of people in our industry and others have this same model. It is not that the NSA is after you. It's local law enforcement. In our case, SEC and FBI. For average users, local LE will not have 0 days or anything special. Protonmail is out of reach for a lot of LE and that is important.
The best choice for us when we're fully operational is to run a Protonmail-like setup, self-hosted. Deal with mail issues and spam. It is a pain!