"Zero Knowledge Encryption" is just a marketing term... I wish marketing would not cross wires with real crypto, it makes me skeptical that they really know what they're doing. They're not the only company doing this and they should be called out for it like spideroak [1]. ZKP[2] is real branch of cryptography and they do not use it AFAIK. [1] https://spideroak.com/articles/why-we-will-no-longer-use-the... [2] https:…
Why ProtonMail is more secure than Gmail
291–300 of 314 posts
Re: Why ProtonMail is more secure than Gmail
#292Earlier quoted context omitted.
The cigar seller sells its customer list to a data broker or uses a third party service that does the same (e.g. it uses your email address as a user identifier in a third party analytics product). Then advertisers buy that data.
The sold it in less then 24 hours?
Re: Why ProtonMail is more secure than Gmail
#293[1] https://blog.fastmail.com/2017/05/13/nyi-datacentre-move/
Re: Why ProtonMail is more secure than Gmail
#294"Zero Knowledge Encryption" is just a marketing term... I wish marketing would not cross wires with real crypto, it makes me skeptical that they really know what they're doing. They're not the only company doing this and they should be called out for it like spideroak [1]. ZKP[2] is real branch of cryptography and they do not use it AFAIK. [1] https://spideroak.com/articles/why-we-will-no-longer-use-the... [2] https:…
Re: Why ProtonMail is more secure than Gmail
#295Earlier quoted context omitted.
>"They're also based in Germany, which is nice." They're based in Switzerland which is no longer a safe haven, although ProtonMail seems to still trade on the idea that it is. See: https://www.theguardian.com/world/2016/sep/25/switzerland-vo...
I meant mailbox.org is based in Germany :)
Re: Why ProtonMail is more secure than Gmail
#296Earlier quoted context omitted.
"Without any warrant": what do you mean?
Under the Stored Communications Act, law enforcement may get emails or other information under third party control with only a subpoena. Retrieving email via the POP3 protocol typically deletes the email upon retrieval, making it impossible for the third party to comply with requests for already-retrieved emails.
Re: Why ProtonMail is more secure than Gmail
#297Earlier quoted context omitted.
Under the Stored Communications Act, law enforcement may get emails or other information under third party control with only a subpoena. Retrieving email via the POP3 protocol typically deletes the email upon retrieval, making it impossible for the third party to comply with requests for already-retrieved emails.
So you think google storage systems work like your normal filesystem?
Re: Why ProtonMail is more secure than Gmail
#298A heavy amount of ProtonMail's infrastructure is in New York at NYI [1] accordingly to blog posts however they say 'ProtonMail stores user data exclusively in European countries with strong privacy protections such as Switzerland.' Now I am confused [1] https://blog.fastmail.com/2017/05/13/nyi-datacentre-move/
Re: Why ProtonMail is more secure than Gmail
#299Earlier quoted context omitted.
Well, one might reasonably ask whether "reading your mail" (as in, running an algorithm on it to try to classify phishing vs non) is a security cost or benefit. Spearphishing is a huge source of compromise at the moment; antiphishing filters might, in that view, be considered a security feature rather than a security fault. On the other hand, I have, frankly, never understood these privacy arguments. Is it a privacy…
>Is it a privacy violation if someone checks a checksum of my incoming mail against a blacklist? No, the privacy concern is about the potential for abuse if there is a known place in the world where a very detailed account of all my online (and some offline) activities, contacts, communication and personal interests is stored. It obviously arouses the interest and desires of criminals, governments, employers, politic…
So even if someone hacks into the spam filters, they won't be able to reconstruct content from your account. They _might_ have insight into things like word usage, but they won't have reconstructed sentences or the like, a priori.
You can build systems like this without having long-term storage of the content, which protects against data issues for one-time leaks.