Earlier quoted context omitted.
I agree that people should read the linked comments. I did not find the the evidence to be as clear cut or damning as OP seems to think at all after reading through it. Most claims are also put forward by a co founder of Private Internet Access. A direct competitor.
This is exactly my thoughts as well. rasengan is the cofounder and thus is very biased against ProtonMail since they're a competitor.
OpenPGPjs has passed an independent security audit
111–120 of 128 posts
Re: OpenPGPjs has passed an independent security audit
#112Earlier quoted context omitted.
Nope, it wasn't a library, this was a SaaS website running an open source codebase that was browsable on GitHub.
Well, it might have been Airborn.io, the Google Docs competitor that this library grew out of.
Re: OpenPGPjs has passed an independent security audit
#113Earlier quoted context omitted.
This sort of racism is not acceptable.
Eastern Europe, from which ProtonVPN is operated as a legal entity without the knowledge of its users, is an entirely different jurisdiction from Switzerland in terms of privacy and data retention laws.
Eastern Europe is not a jurisdiction.
Re: OpenPGPjs has passed an independent security audit
#114Earlier quoted context omitted.
Eastern Europe, from which ProtonVPN is operated as a legal entity without the knowledge of its users, is an entirely different jurisdiction from Switzerland in terms of privacy and data retention laws.
>Eastern Europe, from which ProtonVPN is operated as a legal entity without the knowledge of its users, is an entirely different jurisdiction from Switzerland in terms of privacy and data retention laws. Eastern Europe is not a jurisdiction.
Re: OpenPGPjs has passed an independent security audit
#115Not that it matters. They could silently replace it with a backdoored script and your browser would never tell you it happened. And to preempt the ProtonMail rep who is probably going to respond to this comment, I know that you can run the web app on localhost. But that doesn't mean that users who don't are any more secure.
Re: OpenPGPjs has passed an independent security audit
#116Earlier quoted context omitted.
There is nothing wrong with data mining itself. It's completely neutral technology. You are just thrwoing shade with link flooding (those who read the links find out that they don't credibly confirm what you say). Tesonet provides all kinds of services, like hosting, software development and cybersecurity for it's customers.
> There is nothing wrong with data mining itself. It's completely neutral technology. Tesonet's Oxylabs offers "10+ Million Mobile IPs in Every Country and Every City in the World"[1], which might explain why ProtonVPN, whose Android app is signed by Tesonet[2], is a free service. This is how Luminati, Tesonet's largest competitor in Residential Proxies, operates: it provides a free VPN service, Hola VPN, and then co…
Re: OpenPGPjs has passed an independent security audit
#117Earlier quoted context omitted.
Attack vectors for replacing Chrome: - Hack Google Attack vectors for replacing OpenPGPjs: - Hack the servers hosting OpenPGPjs - Hack the browser to inject or replace content across domains, sandboxes, other security barriers It's a subtle difference, but delivering applications dynamically via web browsing is much more precarious than natively hosted applications. Another way to think of it is if your entire Linux…
> Attack vectors for replacing Chrome: > - Hack Google - NSL Google (If you're a high-enough value target and your adversary is the US Government. But in _that_ case you've probably already lost - you might just not know it yet. I wonder if Snowden uses Chrome or lets it autoupdate?)
Re: OpenPGPjs has passed an independent security audit
#118Earlier quoted context omitted.
Does OpenPGPjs use WebCrypto to create keys which are not extractable? That's the big win here if you can make it impossible for a compromised client to leak keys which were used before/after the compromise.
This also means you can't use another computer or that your key is lost if you clear browser data. Unless you'd do backups but I doubt this is standard procedure of ProtonMail users.
What PGP really needs is a modern security model so you'd have many device keys registered to an identity rather than requiring the risk of spreading copies around. I think I have IIRC 8 GPG subkeys currently (6 of them being Yubikeys) and every aspect of that toolchain is unacceptable in the modern era.
Re: OpenPGPjs has passed an independent security audit
#119Not that it matters. They could silently replace it with a backdoored script and your browser would never tell you it happened. And to preempt the ProtonMail rep who is probably going to respond to this comment, I know that you can run the web app on localhost. But that doesn't mean that users who don't are any more secure.
Re: OpenPGPjs has passed an independent security audit
#120Earlier quoted context omitted.
This is exactly my thoughts as well. rasengan is the cofounder and thus is very biased against ProtonMail since they're a competitor.
ProtonVPN is no competitor to Private Internet Access in terms of the size and the number of users. If you were a co-founder of PIA, would you risk your reputation by publicly providing false accusations against a company 1/100 of the size of yours?