Live data from Hacker News

ProtonMail now offers elliptic curve cryptography

protonmail.com

81–90 of 148 posts

Re: ProtonMail now offers elliptic curve cryptography

#81

Earlier quoted context omitted.

It's a valid concern, though in my case there's no other means to check the ownership albeit being flawed one; note that me having a valid login password/ or not doesn't seem have any impact on me recovering the password as I contacted them using web form support.

Oh, you're on a free account? So you think it'd be stronger protected if you're paying due to probably having a CC etc tied?

I don't think that would have made any difference, if someone with malicious agenda wanted to gain access to my email account.

It all depends upon how much trust, my initial answer to the question 'When you account was created'; I'm 90% sure I have correct year & 70 % on the month (I gave another month as well).

If that answer really did create some trust, then there's something; if not then I'm quite sure anyone can hijack an account without recovery email if they are able to guess few email ids correctly.

Re: ProtonMail now offers elliptic curve cryptography

#82
post #65
post #57

Earlier quoted context omitted.

Sure: that’s WebCrypto. The main problem it solves is that you don’t really want your AES implementation to be in JS which is only a small part of the problem. You still have the problem that the site would be telling you to do with all of that good crypto, and you still need to do key management. You could do all of this well if WebCrypto was good and you had a WebExtension, or an Electron app, or some other way whe…

Interestingly there is such an extension: https://github.com/tasn/webext-signed-pages tl;dr version is one pins all resources on the page with Subresource Integrity hashes and signs the page. The extension verifies the signature matches before rendering anything.

Neat! I haven't audited it but a quick look through the README suggests the approach is sound.

Re: ProtonMail now offers elliptic curve cryptography

#83

Earlier quoted context omitted.

Correct, existing emails become inaccessible when the mailbox is reset. Can be recovered though, if there's a backup & the original decryption password is found again.

But is your threat model someone reading your old email? For most people the big risk is that their email can be leveraged to gain access to banks, social media etc through password resets.

I agree, access to other accounts is of greater threat.

When I created this account, I wanted to build upon the premise of privacy of proton mail & so I created using VPN, with no personal link whatsoever (hence no recovery email).

Unfortunately when my decryption password failed, I had no means of recovery until I attempted to talk through support successfully.

Re: ProtonMail now offers elliptic curve cryptography

#84

This announcement is an example of why I am not using ProtonMail anymore. There are a lot of things they do that sound very good on marketing materials, but upon examination are security theater. For example, they claim, "We have chosen a particular elliptic curve system known as X25519, which is fast, secure, and particularly resistant to timing attacks. It’s simple to implement". However, previously they've said th…

Out of curiosity, what did you switch to? I'd like to leave Gmail and Proton Mail seems to be pretty well recommended. Is Fast Mail a better option?

I moved to fastmail from gmail to slightly de-google my life.

The biggest issue i've had so far is the search is terrible, and the spam filtering has many more false positives.

Re: ProtonMail now offers elliptic curve cryptography

#85

This announcement is an example of why I am not using ProtonMail anymore. There are a lot of things they do that sound very good on marketing materials, but upon examination are security theater. For example, they claim, "We have chosen a particular elliptic curve system known as X25519, which is fast, secure, and particularly resistant to timing attacks. It’s simple to implement". However, previously they've said th…

Out of curiosity, what did you switch to? I'd like to leave Gmail and Proton Mail seems to be pretty well recommended. Is Fast Mail a better option?

I am happy with posteo.de.

Re: ProtonMail now offers elliptic curve cryptography

#86

Earlier quoted context omitted.

One major issue with the iOS client is that it cannot handle more than one Inbox. So, if you use two accounts (e.g. home and work), you can only be logged in in one at a time, and have to go through the full sign-in-sign-out process each time you want to switch. And my understanding is that the iOS app doesn't actually cache email offline, so it's not terribly possible to work on an airplane, etc. Also, understand th…

Same with Android, only one account in free version. But I think when switched to pro, one can use more than 1 proton mail account in their app.

My understanding is that this isn't a free/pro distinction, but a "Feature on the Roadmap". But I'd be delighted to find out I'm wrong.

Re: ProtonMail now offers elliptic curve cryptography

#87

This announcement is an example of why I am not using ProtonMail anymore. There are a lot of things they do that sound very good on marketing materials, but upon examination are security theater. For example, they claim, "We have chosen a particular elliptic curve system known as X25519, which is fast, secure, and particularly resistant to timing attacks. It’s simple to implement". However, previously they've said th…

NIST curves like P-256 is generally not considered trustworthy, which is why the general consensus is to use Ed25519 for any elliptic curve cryptography. Using Ed25519 is by popular opinion the right choice. However, the concern about their use of indutny's library and the comment you link to is entirely separate. Choosing to have timing attacks for performance in a cryptographic library seems absolutely absurd, and…

I tweeted "They would have been better off with P-256, since that uses WebCrypto" after I inspected OpenPGP.js code because it's already implemented there (since it needs to support decryption from senders that use different curves) and uses WebCrypto API implementation. To me, it's a safer choice than the `elliptic` npm package that they use for X25519.

If WebCrypto supported X25519, their choice would be a no-brainer, as 25519 is a safer curve (https://safecurves.cr.yp.to/). But P-256 is definitely not considered untrustworthy — see tptacek's reply — and at least Chrome implementation (BoringSSL) is good. (Browsers use the same implementation for TLS and P-256 is the most popular curve for TLS right now. In fact, delivery of their JavaScript code to browsers already depends on P-256 due to TLS.)

Regardless of the choice, my main concern is that they advertise X25519 as timing safe, while not having a timing safe implementation. This is a red flag.

Disclaimer: I ported TweetNaCl (which uses 25519) to JavaScript. The port intends to be "algorithmically" constant-time, but doesn't guarantee real-life timing safety due to JS.

Re: ProtonMail now offers elliptic curve cryptography

#88
post #2

Anyone using ProtonMail regularly? I created an account but haven’t used it much. How are your experiences? Any iOS users who can comment on their experience with proton mail and the default mail client? I don’t went to switch to something that won’t be around in a decade or so.

I've been using ProtonMail for a couple of years. iOS client is usable and works fine. Web interface works fine with any browser I tried, including on Linux.

I had problems with Bridge on MacOS, but after learning that Apple Mail is reporting all e-mail metadata to Apple I stopped using it altogether. Don't know if ProtonMail fixed Bridge since then.

Re: ProtonMail now offers elliptic curve cryptography

#89
post #2

Anyone using ProtonMail regularly? I created an account but haven’t used it much. How are your experiences? Any iOS users who can comment on their experience with proton mail and the default mail client? I don’t went to switch to something that won’t be around in a decade or so.

I use it regularly for both personal and professional use. I now use the pm.me domain for my professional account, since it is easier to share (e.g. phone calls, SMS).

Re: ProtonMail now offers elliptic curve cryptography

#90

This announcement is an example of why I am not using ProtonMail anymore. There are a lot of things they do that sound very good on marketing materials, but upon examination are security theater. For example, they claim, "We have chosen a particular elliptic curve system known as X25519, which is fast, secure, and particularly resistant to timing attacks. It’s simple to implement". However, previously they've said th…

>"There are a lot of things they do that sound very good on marketing materials, but upon examination are security theater."

Indeed like still pushing the trope that since their datacenters are located in Switzerland they are able to provide more privacy protections. This is even mentioned on their homepage, and of course this hasn't been true in a few years now.[1]

[1] https://www.bbc.com/news/world-europe-37465853

Post reply on HN