Live data from Hacker News

Why ProtonMail is more secure than Gmail

protonmail.com

211–220 of 314 posts

Re: Why ProtonMail is more secure than Gmail

#211
post #64
post #41

Threat model, threat model, threat model. There are some people for whom "The government is literally after me, personally" is a valid threat model. There are some people for whom "Google employees with privileged access to Gmail are conspiring to be after me, personally" (one assumes there's a two-person rule for access to individual inboxes or deploying code that scans inboxes) is also a valid threat model. However…

> "I don't want to lose access to my email" (remember that availability is a part of security!). Arent there many (difficult to judge how many) cases of people losing access to their Google account, and therefore about everything they had online (photos, email, videos, etc...). That is also scary enough, especially when it happens randomly with no clear reason why and the support of Google seems to be limited to send…

Nobody writes about the times where they successfully and painlessly got back access to their account after forgetting their password.

If a service has thousands of times more users than another, you'll expect weird edge cases to show up thousands of times more often.

Re: Why ProtonMail is more secure than Gmail

#212
post #83
post #57

Earlier quoted context omitted.

I think what's telling here is that the blog post does not point to Protonmail's own threat model. https://protonmail.com/blog/protonmail-threat-model/ Which says don't use it if you are up against state actors and: "Sensitive business communications – You have sensitive business information that you want to make sure is protected from competitors and other malicious parties. For example, you fear a competitor may wa…

I'm not sure there is a legal mechanism to force ProtonMail to add a backdoor... > "Nearly every country in the world has laws governing lawful interception of electronic communications. In Switzerland, these regulations are set out in the Swiss Federal Act on the Surveillance of Postal and Telecommunications Traffic (SPTT) last revised in 2012. In the SPTT, the obligation to provide the technical means for lawful in…

IANAL, but that just seems to say that under that particular law (SPTT), Internet access providers have to provide the technical means for lawful interception. It does not say that no other entity has to provide the technical means for lawful interception.

In other words, the law does not say that ProtonMail is exempt for having to provide lawful interception. They might still have to do so, based on some other law.

Further, it's quite conceivable that unlawful means (such as blackmail, threats, or bribery) could be used to coerce ProtonMail. That's not to mention perfectly lawful means of enticing them -- like appealing to their patriotism, willingness to help in a critical investigation, or demonstrating some credible threat.

Re: Why ProtonMail is more secure than Gmail

#213

Earlier quoted context omitted.

Intel Management Engine.

That is only remotely exploitable if you use Intel network cards. There’s a reason all my systems use other cards, and are behind a hardware firewall specifically configured for my use cases.

There is still a possibility, a scenario only a crazy conspiracy theorist could imagine a few years back, but I believe the current development of closed chipsets could soon allow remote penetration into any machine using any network card by any vendor, and in a way that nobody can even sniff the suspicious traffic over the network. It seems really complicated, if not impossible, but I'm starting to think it can be done if one has full access to the chipsets and their firmware (users, admins and developers don't, vendors and their "partners" do).

Let's assume a system where every piece of hardware has a closed device driver, or part of it, CPU included. We're there, or very close. It's not that hard to imagine a system within the system that can access data (hard drives have closed blobs), read passwords before they are encrypted through keylogging (USB sniffing), make screenshots of the desktop (video card closed blobs) and send them wherever they're instructed to (network card blobs), not to mention downloading and executing arbitrary code.

Now one could object that the traffic could be easily intercepted, but what if all network chipsets of all vendors, including those inside routers, had a small set of instructions to intercept any magic packet satisfying some rules and treat it differently. Let's say send it to some hardcoded addresses without counting them or reporting them to user applications; even leds on front panels would not report those packets passing through. The only way to realize something fishy is going on would be by tapping physically into the network cable using non-network dedicated chipsets, say very fast digital analyzers, decode all traffic and match it with what a normal sniffer would report.

I admit this is a crazy scenario, but if an entity with nearly infinite resources had the power to force any hardware vendor to put spying hardware/firmware into every machine, wouldn't it attempt to do something like that?

Re: Why ProtonMail is more secure than Gmail

#214
post #92
post #74

Anyone remember HushMail? The end-to-end encrypted email service that didn't have the ability to decrypt your emails? They were eventually coerced to change their code and record passwords in order to gain access to an encrypted email account. ProtonMail is the same thing, give or take, just in Switzerland. They can be coerced just like anyone else. People whose lives are dependent on secure communication still need…

I'm not sure there is a legal mechanism to force ProtonMail to add a backdoor... > "Nearly every country in the world has laws governing lawful interception of electronic communications. In Switzerland, these regulations are set out in the Swiss Federal Act on the Surveillance of Postal and Telecommunications Traffic (SPTT) last revised in 2012. In the SPTT, the obligation to provide the technical means for lawful in…

IANAL, but that just seems to say that under that particular law (SPTT), Internet access providers have to provide the technical means for lawful interception. It does not say that no other entity has to provide the technical means for lawful interception.

In other words, the law does not say that ProtonMail is exempt for having to provide lawful interception. They might still have to do so, based on some other law.

Further, it's quite conceivable that unlawful means (such as blackmail, threats, or bribery) could be used to coerce ProtonMail. That's not to mention perfectly lawful means of enticing them -- like appealing to their patriotism, willingness to help in a critical investigation, or demonstrating some credible threat.

Re: Why ProtonMail is more secure than Gmail

#216

Earlier quoted context omitted.

From the link: "G Suite’s Gmail is already not used as input for ads personalization, and Google has decided to follow suit later this year in our free consumer Gmail service." They are definitely still reading your gmail. How else would the spam and other filters work? They can also use it under this policy for anything but "ads personalization". Machine learning, Google product integration, other recommendation not…

So I ordered some cigars online the other day. I did this on a device not logged into google, in privacy mode. An email with the order went to my @gmail. The next day in my Youtube videos the ads where for stop smoking patches. They read email.

Google also allows ads targeting a list of emails. Could be that the cigar seller asked google to show you the ads.

Re: Why ProtonMail is more secure than Gmail

#217

The engineer in me loves the promised End-End encryption and all the cool stuff. But, the inconvenience of "unable to search contents of emails" is a deal breaker towards encrypted email for me. My primary concern was Google/Microsoft scraping my emails to build a profile of me. My emails could give away very personal information that I do not want to be used for advertising. My money finally went to Fastmail. Excell…

You can totally search email contents with ProtonMail -- it just does it clientside. I just tested with my 125MB of emails and it was fast (under 1s) but maybe if you have more emails it could be slower.

Have you tried searching for a keyword that is only in the content of the email and NOT on the subject? I tried even now. It doesn’t work for me.

Re: Why ProtonMail is more secure than Gmail

#218
post #210

Earlier quoted context omitted.

Protonmail says they have no access to user data and so I guess that means they offer zero protection from spam and emailed threats. One could argue that Google's filtering of spam and potentially harmful mail is a point in favor of Google.

SMTP has headers that are visible to the email provider while the email is in transit. The absence of logs, etc., goes far to mitigate this threat. As an added benefit, there is a lot of anti-spam functionality that can be used with only this metadata available, and only ephemerally. I don't think it's true that zero-knowledge at rest means inability to provide common email provider value adds like anti-spam.

To add to the above post, the headers have to be unencrypted, else they'd have no method to actually send the email. If it were encrypted, they'd have no idea what the address was, or who to bounce it to if the address doesn't exist.

Email headers contain a lot of information. It has the various email addresses, servers involved, ip addresses, time stamps, subject, priority, and things like that.

The body of the email is the only part that gets encrypted when encryption is in use.

Re: Why ProtonMail is more secure than Gmail

#219

I gave up on ProtonMail. The lack of a calendar means you often need to go back to using Google Calendar or Outlook.com Calendar, kind of negating the privacy benefits if you're a heavy calendar user. Secondly, its been years and you still can't store more than a single email address for a contact. This is so incredibly ridiculous that I have an extremely hard time understanding how they get away with charging what t…

Why not FastMail?

Re: Why ProtonMail is more secure than Gmail

#220
post #86

Earlier quoted context omitted.

Actually ProtonMail does do this. They can't read your email so they can't know if you're actually abusing it via their terms of service. Thus if you file complaints against users ProtonMail will actually suspend the account without evidence until you clear your name. It's abused fairly regularly in fact.

Hmm... Could you provide a source? I don't think they do this. At least not for paid accounts with a long history.

Can start here: https://twitter.com/protonmail/status/900097982212845570

There are a lot of cases but I'm at work and can't spend too much time collecting much. The gist however is that they are bound by Swiss speech laws, which are very ambiguous. "Inciting violence" is one such example, but of course, they can't see what you are supposedly inciting, so they suspend you.

Post reply on HN