Live data from Hacker News

OpenPGPjs has passed an independent security audit

protonmail.com

111–120 of 128 posts

Re: OpenPGPjs has passed an independent security audit

#111
post #86
post #19

Earlier quoted context omitted.

I agree that people should read the linked comments. I did not find the the evidence to be as clear cut or damning as OP seems to think at all after reading through it. Most claims are also put forward by a co founder of Private Internet Access. A direct competitor.

This is exactly my thoughts as well. rasengan is the cofounder and thus is very biased against ProtonMail since they're a competitor.

ProtonVPN is no competitor to Private Internet Access in terms of the size and the number of users. If you were a co-founder of PIA, would you risk your reputation by publicly providing false accusations against a company 1/100 of the size of yours?

Re: OpenPGPjs has passed an independent security audit

#112
post #105

Earlier quoted context omitted.

Nope, it wasn't a library, this was a SaaS website running an open source codebase that was browsable on GitHub.

Well, it might have been Airborn.io, the Google Docs competitor that this library grew out of.

I was definitely asleep at the keyboard as it definitely was airborn.io. Thanks.

Re: OpenPGPjs has passed an independent security audit

#113
post #109
post #103

Earlier quoted context omitted.

This sort of racism is not acceptable.

Eastern Europe, from which ProtonVPN is operated as a legal entity without the knowledge of its users, is an entirely different jurisdiction from Switzerland in terms of privacy and data retention laws.

>Eastern Europe, from which ProtonVPN is operated as a legal entity without the knowledge of its users, is an entirely different jurisdiction from Switzerland in terms of privacy and data retention laws.

Eastern Europe is not a jurisdiction.

Re: OpenPGPjs has passed an independent security audit

#114
post #113
post #109

Earlier quoted context omitted.

Eastern Europe, from which ProtonVPN is operated as a legal entity without the knowledge of its users, is an entirely different jurisdiction from Switzerland in terms of privacy and data retention laws.

>Eastern Europe, from which ProtonVPN is operated as a legal entity without the knowledge of its users, is an entirely different jurisdiction from Switzerland in terms of privacy and data retention laws. Eastern Europe is not a jurisdiction.

As a Eastern European myself, I chose not to single out Lithuania, because most of the region is now in the EU.

Re: OpenPGPjs has passed an independent security audit

#115

Not that it matters. They could silently replace it with a backdoored script and your browser would never tell you it happened. And to preempt the ProtonMail rep who is probably going to respond to this comment, I know that you can run the web app on localhost. But that doesn't mean that users who don't are any more secure.

How would you implement a secure webmail such that it satisfies your complaint?

Re: OpenPGPjs has passed an independent security audit

#116
post #76
post #36

Earlier quoted context omitted.

There is nothing wrong with data mining itself. It's completely neutral technology. You are just thrwoing shade with link flooding (those who read the links find out that they don't credibly confirm what you say). Tesonet provides all kinds of services, like hosting, software development and cybersecurity for it's customers.

> There is nothing wrong with data mining itself. It's completely neutral technology. Tesonet's Oxylabs offers "10+ Million Mobile IPs in Every Country and Every City in the World"[1], which might explain why ProtonVPN, whose Android app is signed by Tesonet[2], is a free service. This is how Luminati, Tesonet's largest competitor in Residential Proxies, operates: it provides a free VPN service, Hola VPN, and then co…

This can easily be checked with tools like Wireshark. It's not hard to verify whether you are being used as an exit node for web scrapping or not.

Re: OpenPGPjs has passed an independent security audit

#117
post #94

Earlier quoted context omitted.

Attack vectors for replacing Chrome: - Hack Google Attack vectors for replacing OpenPGPjs: - Hack the servers hosting OpenPGPjs - Hack the browser to inject or replace content across domains, sandboxes, other security barriers It's a subtle difference, but delivering applications dynamically via web browsing is much more precarious than natively hosted applications. Another way to think of it is if your entire Linux…

> Attack vectors for replacing Chrome: > - Hack Google - NSL Google (If you're a high-enough value target and your adversary is the US Government. But in _that_ case you've probably already lost - you might just not know it yet. I wonder if Snowden uses Chrome or lets it autoupdate?)

That's a good question. I don't think the government cares enough about snowden to do that. Snowden's damage has been done. It can't be reversed. Imo, they'd be much more interested to preemptively shutdown all future would-be Snowdens.

Re: OpenPGPjs has passed an independent security audit

#118
post #87
post #61

Earlier quoted context omitted.

Does OpenPGPjs use WebCrypto to create keys which are not extractable? That's the big win here if you can make it impossible for a compromised client to leak keys which were used before/after the compromise.

This also means you can't use another computer or that your key is lost if you clear browser data. Unless you'd do backups but I doubt this is standard procedure of ProtonMail users.

That's true assuming that the browser doesn't offer any way to manage that using e.g. Chrome/Firefox Sync.

What PGP really needs is a modern security model so you'd have many device keys registered to an identity rather than requiring the risk of spreading copies around. I think I have IIRC 8 GPG subkeys currently (6 of them being Yubikeys) and every aspect of that toolchain is unacceptable in the modern era.

Re: OpenPGPjs has passed an independent security audit

#119

Not that it matters. They could silently replace it with a backdoored script and your browser would never tell you it happened. And to preempt the ProtonMail rep who is probably going to respond to this comment, I know that you can run the web app on localhost. But that doesn't mean that users who don't are any more secure.

Hopefully web packages⁽¹⁾ can eventually solve this issue.

1. https://github.com/WICG/webpackage

Re: OpenPGPjs has passed an independent security audit

#120
post #111
post #86

Earlier quoted context omitted.

This is exactly my thoughts as well. rasengan is the cofounder and thus is very biased against ProtonMail since they're a competitor.

ProtonVPN is no competitor to Private Internet Access in terms of the size and the number of users. If you were a co-founder of PIA, would you risk your reputation by publicly providing false accusations against a company 1/100 of the size of yours?

No but there's incentive to provide many small half-truths out of context to shape the narrative into one beneficial for yourself want.
Post reply on HN