Live data from Hacker News

ProtonMail now offers elliptic curve cryptography

protonmail.com

71–80 of 148 posts

Re: ProtonMail now offers elliptic curve cryptography

#71

Off topic I had a proton email created when it was announced & didn't use it. I found out that my mailbox decryption for that email id is not working (not sure how, I use password manager) & I haven't set a recovery email to recover my account. I saw a HN comment earlier telling, the user had recovered their Proton mail account by answering few questions to customer service. I attempted the same, the issue is that I…

This would worry me more than drama about one algo choice over another. Encrypting the data at rest (even it's not perfect) is probably better than letting it sit around in plain text. OTOH account hijacking is a well documented[1][2] threat. I don't like the idea that if I set up a secure password and 2FA someone could call up Protonmail and go " Uh yeah, I use, uh... Hulu? Reset my password please! " [1] https://ww…

It's a valid concern, though in my case there's no other means to check the ownership albeit being flawed one; note that me having a valid login password/ or not doesn't seem have any impact on me recovering the password as I contacted them using web form support.

Re: ProtonMail now offers elliptic curve cryptography

#72

This announcement is an example of why I am not using ProtonMail anymore. There are a lot of things they do that sound very good on marketing materials, but upon examination are security theater. For example, they claim, "We have chosen a particular elliptic curve system known as X25519, which is fast, secure, and particularly resistant to timing attacks. It’s simple to implement". However, previously they've said th…

NIST curves like P-256 is generally not considered trustworthy, which is why the general consensus is to use Ed25519 for any elliptic curve cryptography. Using Ed25519 is by popular opinion the right choice. However, the concern about their use of indutny's library and the comment you link to is entirely separate. Choosing to have timing attacks for performance in a cryptographic library seems absolutely absurd, and…

I have found no evidence that the author has changed their stance on this issue. You can find other issues that have also been closed with a brief explanation.

If the author wants to show up and say otherwise, I'm happy to take correction.

But, I'd rather have a robust implementation of a speculatively less secure scheme then have the undelivered promise of a more secure scheme papering over an insecure implementation.

Re: ProtonMail now offers elliptic curve cryptography

#73

This announcement is an example of why I am not using ProtonMail anymore. There are a lot of things they do that sound very good on marketing materials, but upon examination are security theater. For example, they claim, "We have chosen a particular elliptic curve system known as X25519, which is fast, secure, and particularly resistant to timing attacks. It’s simple to implement". However, previously they've said th…

Out of curiosity, what did you switch to? I'd like to leave Gmail and Proton Mail seems to be pretty well recommended. Is Fast Mail a better option?

Fastmail is a great service, the caveat is that they are based in Australia. Take that for what it's worth.

Re: ProtonMail now offers elliptic curve cryptography

#74
post #2

Anyone using ProtonMail regularly? I created an account but haven’t used it much. How are your experiences? Any iOS users who can comment on their experience with proton mail and the default mail client? I don’t went to switch to something that won’t be around in a decade or so.

I swapped last year around the end of November. I'm a fan of their filter DSL, which has let me keep my inbox pretty clean. I don't use desktop mail clients so the bridge thing doesn't bother me. Their web ui does just what I want it to, but their ios app doesn't seem to group conversations which is annoying.

Overall 8/10 would recommend.

Re: ProtonMail now offers elliptic curve cryptography

#75

Off topic I had a proton email created when it was announced & didn't use it. I found out that my mailbox decryption for that email id is not working (not sure how, I use password manager) & I haven't set a recovery email to recover my account. I saw a HN comment earlier telling, the user had recovered their Proton mail account by answering few questions to customer service. I attempted the same, the issue is that I…

[deleted]

Re: ProtonMail now offers elliptic curve cryptography

#76

Earlier quoted context omitted.

This would worry me more than drama about one algo choice over another. Encrypting the data at rest (even it's not perfect) is probably better than letting it sit around in plain text. OTOH account hijacking is a well documented[1][2] threat. I don't like the idea that if I set up a secure password and 2FA someone could call up Protonmail and go " Uh yeah, I use, uh... Hulu? Reset my password please! " [1] https://ww…

It's a valid concern, though in my case there's no other means to check the ownership albeit being flawed one; note that me having a valid login password/ or not doesn't seem have any impact on me recovering the password as I contacted them using web form support.

Oh, you're on a free account?

So you think it'd be stronger protected if you're paying due to probably having a CC etc tied?

Re: ProtonMail now offers elliptic curve cryptography

#77

This announcement is an example of why I am not using ProtonMail anymore. There are a lot of things they do that sound very good on marketing materials, but upon examination are security theater. For example, they claim, "We have chosen a particular elliptic curve system known as X25519, which is fast, secure, and particularly resistant to timing attacks. It’s simple to implement". However, previously they've said th…

NIST curves like P-256 is generally not considered trustworthy, which is why the general consensus is to use Ed25519 for any elliptic curve cryptography. Using Ed25519 is by popular opinion the right choice. However, the concern about their use of indutny's library and the comment you link to is entirely separate. Choosing to have timing attacks for performance in a cryptographic library seems absolutely absurd, and…

That is not at all the case. P-256 is widely used and no cryptographer seriously believes there's anything "untrustworthy" about it. Rather, the problem with P-256 is that it's easy to misuse, like most curves. It's hard to implement in constant time and the NIST P-curves generally lend themselves to invalid curve attacks, which need to be guarded against.

Curve25519 avoids these problems. But then, if you're using a naive Javascript library, you've thrown out one of the main benefits of Curve25519 already, and are left essentially with invalid curve attacks, which are not especially hard to defend against and not always even relevant to a given protocol (who could be bothered to go look at what OpenPGP.js is doing with them, I don't know).

Ed25519 is the signing curve equivalent to Curve25519/X25519. It's what you'd use to generate and verify signature, but not what you'd use for ECDH.

Re: ProtonMail now offers elliptic curve cryptography

#78

This announcement is an example of why I am not using ProtonMail anymore. There are a lot of things they do that sound very good on marketing materials, but upon examination are security theater. For example, they claim, "We have chosen a particular elliptic curve system known as X25519, which is fast, secure, and particularly resistant to timing attacks. It’s simple to implement". However, previously they've said th…

what provider, or self hosted software do you suggest as alternative?

Re: ProtonMail now offers elliptic curve cryptography

#79

This announcement is an example of why I am not using ProtonMail anymore. There are a lot of things they do that sound very good on marketing materials, but upon examination are security theater. For example, they claim, "We have chosen a particular elliptic curve system known as X25519, which is fast, secure, and particularly resistant to timing attacks. It’s simple to implement". However, previously they've said th…

Out of curiosity, what did you switch to? I'd like to leave Gmail and Proton Mail seems to be pretty well recommended. Is Fast Mail a better option?

I use Gmail for most things, because in terms of account security it's probably the best in the world.

I do not use email for discussing sensitive topics. It is not the right tool for the job.

Re: ProtonMail now offers elliptic curve cryptography

#80

Earlier quoted context omitted.

It's a valid concern, though in my case there's no other means to check the ownership albeit being flawed one; note that me having a valid login password/ or not doesn't seem have any impact on me recovering the password as I contacted them using web form support.

Oh, you're on a free account? So you think it'd be stronger protected if you're paying due to probably having a CC etc tied?

You'd think, right?

AWS doesn't even consider you the account owner despite you holding the credit card that they bill for that account.

https://news.ycombinator.com/item?id=19574672

Our industry is such a shitshow in some massive ways.

Post reply on HN