Live data from Hacker News

Why ProtonMail is more secure than Gmail

protonmail.com

191–200 of 314 posts

Re: Why ProtonMail is more secure than Gmail

#191
post #162

Earlier quoted context omitted.

This comment seems to conflate resistance to mass surveillance with resistance to targeted surveillance. It's almost as if the fact that I'll never be able to resist a targeted attack means that I shouldn't attempt to have any privacy at all, but surely that's not right. Encrypted messaging apps and services like ProtonMail have never been primarily to help people with Snowden's threat model. They're for people like…

> They're for people like you and me to reclaim a semblance of privacy, and they work even with "Uncle Sam" as the threat model in a limited, dragnet surveillance sense. They don't work, because the US government's modus operandi is compromising machines or forcing users to provide access to their encrypted data. It's unclear to me why, if you take as premise a government capable of forcing one of the most valuable o…

"Put another way, I find the concept of a government willing to force Google to give up data but unwilling to use operational vulnerabilities to achieve the same thing to be contrived - how is this not just an arbitrary line in the sand?"

In the US we have a constitution the prohibits searches of our papers without a warrant signed by a judge. It might be out of fashion is some circles, but the rule of law and not just rule of power is quite popular and I would say a superior system of governance. Many Chinese who are acquiring assets outside of China feel the same way.

Re: Why ProtonMail is more secure than Gmail

#192

Earlier quoted context omitted.

That sounds a bit formalistic and abstract to me. Perhaps you could educate us on which specific threats you think we should pay attention to when choosing between Gmail and Protonmail. What are some specific threats that Gmail defends us against more effectively than Protonmail?

If Protonmail servers are hacked, it's game over (that could be mitigated by having verified client code, but at this time there's the web client that is served dynamically, and the mobile clients are closed source...). That is where Protonmail are at a huge disadvantage unless they have a really really good security team. Server hacking is done a dime a dozen nowadays.

That's a threat that Gmail faces as well though.

Re: Why ProtonMail is more secure than Gmail

#193
post #49

What are the security guarantees when emailing someone who does not use ProtonMail? If there is an encrypted mode, can this mode be turned off? This is critically important, and yet most of these email providers who talk up their security fail to bring it up. This article is the same.

When you send an email through ProtonMail to an unencrypted user, you have the option to encrypt the email when sends them a link to a webpage prompting them for the encryption password.

Re: Why ProtonMail is more secure than Gmail

#194
post #182
post #83

Earlier quoted context omitted.

I'm not sure there is a legal mechanism to force ProtonMail to add a backdoor... > "Nearly every country in the world has laws governing lawful interception of electronic communications. In Switzerland, these regulations are set out in the Swiss Federal Act on the Surveillance of Postal and Telecommunications Traffic (SPTT) last revised in 2012. In the SPTT, the obligation to provide the technical means for lawful in…

ProtonMail has never painted an accurate picture of the surveillance requirements in Switzerland – and laws have been and are changing too. Switzerland is not an island of privacy with regard to state surveillance – and with regard to private data privacy, it basically mirrors the European Union’s standard. According to Snowden documents, Swiss intelligence and security services are close partners with the NSA and ot…

> ProtonMail has never painted an accurate picture of the surveillance requirements in Switzerland – and laws have been and are changing too.

Do you think that's partly because, like most countries, the truth is... obfuscated.

Re: Why ProtonMail is more secure than Gmail

#195
post #51

Web based encryption. Pointless. If you trust them enough not to send you bad Javascript, you trust them not to read your emails. You trust them with your private keys. If you trust them with all that why even encrypt the mail client side?

Yep. And the same argument applies to their apps. We need an open standard with an app built by a trusted third party.

For email clients, Thunderbird is still being developed (latest release was from less than a month ago):

https://www.mozilla.org/en-GB/thunderbird/

Also, the V1.0 release of Mailpile is meant to be coming soon:

https://www.mailpile.is/

https://github.com/mailpile/Mailpile

For setting up your own email server...

https://mailinabox.email/

http://www.iredmail.org/

Re: Why ProtonMail is more secure than Gmail

#196

Earlier quoted context omitted.

That sounds a bit formalistic and abstract to me. Perhaps you could educate us on which specific threats you think we should pay attention to when choosing between Gmail and Protonmail. What are some specific threats that Gmail defends us against more effectively than Protonmail?

Off the top of my head I think the number 1 "threat" that Google doesn't protect you from is privacy. They are actively watching your email with algorithms to use for advertising purposes. On the other hand, they have more resources than anyone else to protect against things like DDOS, nation-state hacking/phishing, and physical disasters. They also have a legion of lawyers to protect against improper legal requests,…

Protonmail says they have no access to user data and so I guess that means they offer zero protection from spam and emailed threats.

One could argue that Google's filtering of spam and potentially harmful mail is a point in favor of Google.

Re: Why ProtonMail is more secure than Gmail

#197

Earlier quoted context omitted.

Except this is no longer true. Google does not read your gmail anymore. https://blog.google/products/gmail/g-suite-gains-traction-in...

From the link: "G Suite’s Gmail is already not used as input for ads personalization, and Google has decided to follow suit later this year in our free consumer Gmail service." They are definitely still reading your gmail. How else would the spam and other filters work? They can also use it under this policy for anything but "ads personalization". Machine learning, Google product integration, other recommendation not…

Well, one might reasonably ask whether "reading your mail" (as in, running an algorithm on it to try to classify phishing vs non) is a security cost or benefit.

Spearphishing is a huge source of compromise at the moment; antiphishing filters might, in that view, be considered a security feature rather than a security fault.

On the other hand, I have, frankly, never understood these privacy arguments. Is it a privacy violation if someone checks a checksum of my incoming mail against a blacklist? What if they compute a hash of my mail to check the DKIM signature? And if those are OK, why is an ML model more of a problem?

Re: Why ProtonMail is more secure than Gmail

#198

Earlier quoted context omitted.

Around 100 people have root @ Google. They get a tshirt with it on. With months of effort researching tripwires and auditing systems, any of them could read your mail. There's a pretty good chance they'd get caught by some auditing or alerting system they were unaware of though. Many of those systems are kept secret from employees for obvious reasons. Any two employees collude to much more easily read your mail. Ther…

>100 people have root @ Google. They get a tshirt with it on. A convenient way to put a target on your back. What benefit does this have to their security? Accountability?

The t-shirts are a bit of jokey swag, not an access control mechanism. ;)

Re: Why ProtonMail is more secure than Gmail

#200

Earlier quoted context omitted.

Except this is no longer true. Google does not read your gmail anymore. https://blog.google/products/gmail/g-suite-gains-traction-in...

From the link: "G Suite’s Gmail is already not used as input for ads personalization, and Google has decided to follow suit later this year in our free consumer Gmail service." They are definitely still reading your gmail. How else would the spam and other filters work? They can also use it under this policy for anything but "ads personalization". Machine learning, Google product integration, other recommendation not…

Given their vast amounts of information about mail, might their spam filter work by only examining the header? That is, of course, still 'reading' mail - though it may be an acceptable trade off for privacy minded people.

And, if it's being interpreted by a machine, does that really count as reading?

Post reply on HN