Live data from Hacker News

Russia blocks ProtonMail

reuters.com

41–50 of 186 posts

Re: Russia blocks ProtonMail

#41
post #3

I've been considering leaving Gmail for a privacy focused email service but it seems so difficult to switch. So many accounts and services have my Gmail registered, I don't think I could collect them all. Can anybody using ProtonMail (or any other privacy focused email) recommend it? I feel like choosing an email provider these days is as serious as choosing a bank.

One "downside" is having to run the local bridge application that proxies / decrypts your emails if you want a regular desktop client (say thunderbird) connect to it. Other than that haven't had any problems. Also the android app is really nice and so is the web client. Been running gmail and proton side by side for over a year, slowly moving all accounts and redirecting contacts to my proton address. Really suggest…

Same, and also +1 to custom domain.

However - the local bridge has been crashing over the last several days for unknown reasons.

And, there are many sites which will not recognize @protonmail addresses as valid when signing up.

I am in the process of weaning off gmail completely - but expect it to take a lot longer than expected.

Ive already given up chrome completely on desktop - and run brave and ff.

I wish there were a way to just delete my entire online presence and start a new one.

Re: Russia blocks ProtonMail

#42

Earlier quoted context omitted.

Not really, most people that use ProtonMail "heard" it was safe but aren't using VPNs daily and would probably struggle to find out how to incorporate it into their daily routine correctly with split tunneling. The smart people host their own email, not rely on someone else.

the smart people live in a plastic oil tank buried under four feet of peat

Hang on, I need to call my peat guy, who assured me that one meter was sufficient. Also, you have to line that tank with shotcrete.

Hosting locations matter when you are buying network-delivered services. Even if it is trivial to bypass for the user, this one time, jurisdictional risk to the provider is something that you have to consider as a factor when comparing competitors and self-host options.

Re: Russia blocks ProtonMail

#43
post #40
post #30

"Roskomnadzor said that ProtonMail had refused to provide Russian authorities with information on the owners of email accounts allegedly associated with fake bomb threats." I know ProtonMail is denying they got requests but hopefully this is a good advertisement for their willingness to protect individuals.

And if those bomb threats proved right and people get killed? Would you still praise Proton for not working with Law enforcement?

I hope so. When the phone system was manually-operated switch boards, should the phone companies have been responsible for listening to every call and reporting suspicious activity to the police?

Re: Russia blocks ProtonMail

#44
post #4

Generally speaking, the type of person who uses ProtonMail is also the type of person who will trivially bypass this block.

Not really, most people that use ProtonMail "heard" it was safe but aren't using VPNs daily and would probably struggle to find out how to incorporate it into their daily routine correctly with split tunneling. The smart people host their own email, not rely on someone else.

For non-technical reasons, it is not always possible to self-host emails unfortunately.

Re: Russia blocks ProtonMail

#45
post #15

I know it's easy to play conspiracy, but after watching this piece [0] on "active measures", it wouldn't surprise me that FSB finally found a way to hack proton mail, or the way to circumvent the block will expose some part of it. Hence this measure. [0] https://www.nytimes.com/2018/11/12/opinion/russia-meddling-d...

[deleted]

Re: Russia blocks ProtonMail

#46

Earlier quoted context omitted.

the smart people live in a plastic oil tank buried under four feet of peat

Hang on, I need to call my peat guy, who assured me that one meter was sufficient. Also, you have to line that tank with shotcrete. Hosting locations matter when you are buying network-delivered services. Even if it is trivial to bypass for the user, this one time, jurisdictional risk to the provider is something that you have to consider as a factor when comparing competitors and self-host options.

indeed!

and when a lot of people are talking about 'self-hosting' they're mostly talking about a VPS they rent from some provider who could vanish just as easily as Proton can. I'd like to see the numbers on how many self-hosting evangelists (I don't mean that term pejoratively. I think self-hosting is great) are actually talking about metal they physically control.

Re: Russia blocks ProtonMail

#47
post #40
post #30

"Roskomnadzor said that ProtonMail had refused to provide Russian authorities with information on the owners of email accounts allegedly associated with fake bomb threats." I know ProtonMail is denying they got requests but hopefully this is a good advertisement for their willingness to protect individuals.

And if those bomb threats proved right and people get killed? Would you still praise Proton for not working with Law enforcement?

I would.

It's not Protonmail who's to be blamed for the potential attack and deaths. There are series of events that lead to people deciding to be terrorists. I'd focus on those reasons rather than hotfixing stuff by exposing 99.9% of other Protonmail users.

I would never opt in to affect 99.9% of users because of 0.01% of users. We are all educated enough through events in recent history that clearly tell us how similar use cases lead to abuse, every single time without exception.

Given these constraints, Russia's decision to block Protonmail is perfectly fine and the only logical outcome.

Re: Russia blocks ProtonMail

#48
post #40
post #30

"Roskomnadzor said that ProtonMail had refused to provide Russian authorities with information on the owners of email accounts allegedly associated with fake bomb threats." I know ProtonMail is denying they got requests but hopefully this is a good advertisement for their willingness to protect individuals.

And if those bomb threats proved right and people get killed? Would you still praise Proton for not working with Law enforcement?

Any tool/service private and strong enough to protect political dissidents, opposition journalists and all the 'right kind of people' will inevitably be used by criminals as well. If they can choose to reveal information about one group they can be forced to reveal information about anyone.

The only real way around that is to make it private, invite only, and vetted and only invite people with a large enough public presence to be able to have a chance at figuring out if they're the 'right kind of person' which means it can't be open to the average person.

Re: Russia blocks ProtonMail

#49
post #43
post #40

Earlier quoted context omitted.

And if those bomb threats proved right and people get killed? Would you still praise Proton for not working with Law enforcement?

I hope so. When the phone system was manually-operated switch boards, should the phone companies have been responsible for listening to every call and reporting suspicious activity to the police?

That's not the same scenario. Your scenario involves listening to everyone. The GP's scenario involves listening to a specific person with probable cause.

Re: Russia blocks ProtonMail

#50
post #15

I know it's easy to play conspiracy, but after watching this piece [0] on "active measures", it wouldn't surprise me that FSB finally found a way to hack proton mail, or the way to circumvent the block will expose some part of it. Hence this measure. [0] https://www.nytimes.com/2018/11/12/opinion/russia-meddling-d...

> it wouldn't surprise me that FSB finally found a way to hack proton mail

Well, I certainly wouldn't consider that such a big achievement[1]:

> German security expert Thomas Roth published a video over the weekend showing how he exploited a trivial vulnerability found in ProtonMail's systems: using the Chrome web browser's developer mode, he was able to edit an outgoing message to embed arbitrary JavaScript code, which was executed in a would-be victim's browser when opened within the ProtonMail.ch site.

> Roth said he had released the video now because ProtonMail had fixed various flaws he reported back in May via email. However, the Swiss consortium hadn't credited or warned users of his discovery, he claimed, hence his open disclosure of the bugs.

> "The reason I posted the video was because they did not communicate the security problems to their users – and did not even notify me when the bugs were patched," Roth told The Register.

> The researcher said he had reported five vulnerabilities including a cross-site request forgery bug that apparently allowed an attacker to change victims' email signatures, further opening them to malicious cross-site scripts.

[1] https://www.theregister.co.uk/2014/07/07/protonmail_fail_jav...

Post reply on HN