Live data from Hacker News

Why ProtonMail is more secure than Gmail

protonmail.com

281–290 of 314 posts

Re: Why ProtonMail is more secure than Gmail

#281

Earlier quoted context omitted.

It can be simplified to: Gmail + 0$ per month = zero privacy for you and anyone who emails you, plus Uncle Sam has full access to your life. Protonmail + 4$ per month = you will never see ads for a like the one you just bought, plus you will be driving Uncle Sam crazy!

Uncle Sam can root your machine. If Uncle Sam is the threat vector you're better off using pen and paper.

From my favourite ever Usenix paper:

https://www.usenix.org/system/files/1401_08-12_mickens.pdf

Threat: The Mossad doing Mossad things with your email account

Solution:

* Magical amulets?

* Fake your own death, move into a submarine?

* YOU’RE STILL GONNA BE MOSSAD’ED UPON

Re: Why ProtonMail is more secure than Gmail

#282
post #84

Earlier quoted context omitted.

It's happened before: https://techcrunch.com/2010/09/14/google-engineer-spying-fir... If a person has enough access, and they have to, given that someone has to have admin access.

Around 100 people have root @ Google. They get a tshirt with it on. With months of effort researching tripwires and auditing systems, any of them could read your mail. There's a pretty good chance they'd get caught by some auditing or alerting system they were unaware of though. Many of those systems are kept secret from employees for obvious reasons. Any two employees collude to much more easily read your mail. Ther…

It's likely that reading Gmail data and other sensitive actions require significantly less privilege than some Google-wide "root".

Re: Why ProtonMail is more secure than Gmail

#283
post #162

Earlier quoted context omitted.

This comment seems to conflate resistance to mass surveillance with resistance to targeted surveillance. It's almost as if the fact that I'll never be able to resist a targeted attack means that I shouldn't attempt to have any privacy at all, but surely that's not right. Encrypted messaging apps and services like ProtonMail have never been primarily to help people with Snowden's threat model. They're for people like…

> They're for people like you and me to reclaim a semblance of privacy, and they work even with "Uncle Sam" as the threat model in a limited, dragnet surveillance sense. They don't work, because the US government's modus operandi is compromising machines or forcing users to provide access to their encrypted data. It's unclear to me why, if you take as premise a government capable of forcing one of the most valuable o…

"They don't work, because the US government's modus operandi is compromising machines or forcing users to provide access to their encrypted data."

I'm not so sure - at least as recently as 2013, Lavabit showed that even top level US govt targets had some realistic reliance on properly encrypted 3rd party email providers...

The "dragnet" is the thing that's potentially useful - if it's difficult enough for them, they can't do warrantless "full take" surveillance - even for non US citizens, then choose to individually target you later based on a complete historical record being open to keyword/"selector" based searches.

(And for the appropriately paranoid - even Levison's comments back then suggested the thing he was prepared to fight and maybe go to jail for was handing over the SSL key that'd have exposes _all_ users. Reading it the right way suggests he may have sold Snowden out on his own - and I can't exactly say I wouldn't have done so myself in his position - but he was principled enough to not hand over the keys to the entire userbases's security. I sincerely hope _I_ never have the protection of privacy of a user like Snowden being my responsibility while the full pressure of the US government bears down on me. I strongly suspect my strongly-held personal principles would not stand up to that...)

Re: Why ProtonMail is more secure than Gmail

#284
post #162

Earlier quoted context omitted.

> They're for people like you and me to reclaim a semblance of privacy, and they work even with "Uncle Sam" as the threat model in a limited, dragnet surveillance sense. They don't work, because the US government's modus operandi is compromising machines or forcing users to provide access to their encrypted data. It's unclear to me why, if you take as premise a government capable of forcing one of the most valuable o…

"Put another way, I find the concept of a government willing to force Google to give up data but unwilling to use operational vulnerabilities to achieve the same thing to be contrived - how is this not just an arbitrary line in the sand?" In the US we have a constitution the prohibits searches of our papers without a warrant signed by a judge. It might be out of fashion is some circles, but the rule of law and not ju…

With the current legal uncertainty around whether your fingerprint or retina scan locking your device has the same legal protection as a passcode - do you _really_ think every Three Letter Agency isn't operating under flimsy legal advice that "papers" does not include anything stored digitally? "The rule of law" is _very_ open to interpretation... (And it's not like parallel construction isn't a well known tool used to hide questionably legal (or outright illegal) law enforcement activity from whatever limited oversight they have anyway... A "Superior system of governance"? My opinion differs somewhat there...)

Re: Why ProtonMail is more secure than Gmail

#285

Earlier quoted context omitted.

This comment seems to conflate resistance to mass surveillance with resistance to targeted surveillance. It's almost as if the fact that I'll never be able to resist a targeted attack means that I shouldn't attempt to have any privacy at all, but surely that's not right. Encrypted messaging apps and services like ProtonMail have never been primarily to help people with Snowden's threat model. They're for people like…

> This comment seems to conflate resistance to mass surveillance with resistance to targeted surveillance. ProtonMail doesn't meaningfully address the mass surveillance aspect, though. Most emails still hit its servers in plain-text form. Encrypting once it hits their server doesn't help the mass surveillance aspect, it only helps the targeted surveillance when a warrant comes in. And if you're willing/able to get ev…

And sadly - if someone emails a PGP encrypted mail to a protommail address using a key the recipient knows but protonmail doesn't - it doesn't work. Protonmail gives an "unable to decrypt" error, and doesn't hand over the encrypted body...

For me - I think they're useful protecting against dragnet "full take" surveillance (especially since I'm a non-US citizen, so am considered "fair game" for warrantless surveillance), but I don't for a moment think they'll protect me from any sort of state actor level interest targeting me specifically (I'm still gonna get Mossad`ed upon...)

(In more paranoid moments, I suspect that the first "dragnet" protection quite probably makes the second "targeted interest in _me_" more likely...)

Re: Why ProtonMail is more secure than Gmail

#286
ProtonMail seems very nice, however, I'm concerned about if it is truly private.

ProtonMail has being known to shutdown accounts related to right wing, anti-semantic groups. Granted that those are extreme group. However, it will become a very slippery slop. http://govtslaves.com/2017-08-29-eff-warns-that-banning-extr...

"I do not agree with what you have to say, but I'll defend to the death your right to say it."

Evelyn Beatrice Hall

Re: Why ProtonMail is more secure than Gmail

#287
post #44

The end-to-end encryption is only between protonmail addresses, in practice when you email people with gmail/hotmail/yahoo etc. it doesn't matter if protonmail can't read the e-mail, the other party can. (Their solution for that is to send an e-mail that contains a password-protected link with the actual message [0], I find this procedure inconvenient.) Gmail could be as secure as Protonmail by using PGP yourself [1]…

STARTTLS is used though.

Re: Why ProtonMail is more secure than Gmail

#288
post #18

The engineer in me loves the promised End-End encryption and all the cool stuff. But, the inconvenience of "unable to search contents of emails" is a deal breaker towards encrypted email for me. My primary concern was Google/Microsoft scraping my emails to build a profile of me. My emails could give away very personal information that I do not want to be used for advertising. My money finally went to Fastmail. Excell…

Didn't Google stop scanning Gmail for ads targeting? https://www.nytimes.com/2017/06/23/technology/gmail-ads.html

Only for business users (i.e. custom Google Apps domains)

Re: Why ProtonMail is more secure than Gmail

#289

Earlier quoted context omitted.

If a government really wanted access to a specific user's ProtonMail account, couldn't they get a court order from a domestic CA, say Verisign, to generate a fake certificate that they can use to MITM a browser session, and deliver key-stealing javascript to the user? I'm not sure what the state of certificate pinning is, but it seems that for the "uber security conscious users" they have instructions to check the SH…

EV certificates must be submitted to CT logs, which means ProtonMail and the public will be able to detect the malicious certificate. If it's not a EV certificate, the browser user interface changes and a security-conscious user may notice. That said, if a powerful government is after a user specifically, it is just a matter of time and effort before the government gets in.

> If it's not a EV certificate, the browser user interface changes and a security-conscious user may notice.

This is often used as an argument by EV advocates, but it doesn't hold up under scrutiny. An attacker with access to a non-EV certificate can selectively intercept only connections for subresources of the targeted site (i.e. JavaScript). The "main" connection would still use the EV certificate and thus show the browser indicator. This attack was first made public in 2008[1] and has been further refined in later work[2].

HPKP and the Expect-CT header provide some viable mitigations for this. That said, it seems unlikely to me that a nation-state adversary would choose to attack at the Web PKI level in this scenario. Compromising ProtonMail or the user's device would probably cheaper and less likely to be detected.

[1]: http://w2spconf.com/2008/papers/s2p1.pdf

[2]: https://www.blackhat.com/presentations/bh-usa-09/SOTIROV/BHU...

Re: Why ProtonMail is more secure than Gmail

#290

Earlier quoted context omitted.

Why would the cigar seller ask to show me an ad for a STOP SMOKING CIGARS product? Also as I said, this showed up in Youtube the day after I ordered and the email hit my gmail. Never seen those ads before.

The cigar seller sells its customer list to a data broker or uses a third party service that does the same (e.g. it uses your email address as a user identifier in a third party analytics product). Then advertisers buy that data.

The sold it in less then 24 hours?
Post reply on HN