Live data from Hacker News

Russia blocks ProtonMail

reuters.com

171–180 of 186 posts

Re: Russia blocks ProtonMail

#171
ProtonMail has also been blocked in the Luhansk and the Donetsk People's Republic. Few will notice it. The people who live in those unrecognised states mostly use Yandex Mail, Mail.ru and Gmail.

Re: Russia blocks ProtonMail

#172

Earlier quoted context omitted.

The difference was that number one Lavabit was made by a US citizen, and its servers were in the USA. Number two, Lavabit kept all keys to your email at their own premises and could de-crypt your email on their side. Protonmail cannot do so, because your password is a part of they key to decrypt email, and they do not know it, nor they can crack it in a reasonable amount of time, so AFAIK there is nothing they can pr…

If you access ProtonMail via their web app, all that's needed to steal your password and decrypt email at will is a few quick changes to the index.html they serve you. This could be targeted to specific users, and once the password is exfiltrated, the page can be reloaded, leaving no trace of the attack. Anyone with access to ProtonMail's back end code or infrastructure could do this. So at least in the case of their…

> If you access ProtonMail via their web app, all that's needed to steal your password and decrypt email at will is a few quick changes to the index.html they serve you. This could be targeted to specific users, and once the password is exfiltrated, the page can be reloaded, leaving no trace of the attack. Anyone with access to ProtonMail's back end code or infrastructure could do this. So at least in the case of their web app, they could absolutely provide LE with whatever they wanted in a way that would be quite difficult for the average user to detect.

There is no such issue if you use https://github.com/vladimiry/ElectronMail desktop app as it comes with static resources built on the CI server from the official source code repositories and embedded in then installation packages, see https://github.com/vladimiry/ElectronMail/issues/79 for details. See here https://github.com/vladimiry/ElectronMail/blob/d974b43908e10... the "ProtonMail Version 4.0-beta Web UI" versions embedded in the most recent v4.2.1 release.

The way of verifying that the installation packages attached to the releases have been assembled from the source code is being provided, see https://github.com/vladimiry/ElectronMail/issues/183.

And finally, the app is fully open-source creature, so anyone could assembly own package.

Re: Russia blocks ProtonMail

#173
post #126

Earlier quoted context omitted.

The difference was that number one Lavabit was made by a US citizen, and its servers were in the USA. Number two, Lavabit kept all keys to your email at their own premises and could de-crypt your email on their side. Protonmail cannot do so, because your password is a part of they key to decrypt email, and they do not know it, nor they can crack it in a reasonable amount of time, so AFAIK there is nothing they can pr…

As long as you don't control the JavaScript that handles your keys, they can do whatever they like.

This case has been handled in ElectronMail. See https://news.ycombinator.com/item?id=22190710 for details.

Re: Russia blocks ProtonMail

#174
post #126

Earlier quoted context omitted.

As long as you don't control the JavaScript that handles your keys, they can do whatever they like.

I actually do. I don't use their app, only the website. Their JS files are served from my own webserver so I do know their content. Besides, nothing stops someone super-paranoid to check the JS code upon login before they put their password in.

[deleted]

Re: Russia blocks ProtonMail

#175
post #94

Well, that in my eyes is a very solid advertising in favour of ProtonMail. And it's not like Russians, Chinese and generally people in countries whose governments are in the habit of censoring the internet aren't used to using Tor and/or VPNs to dodge censorship.

>Well, that in my eyes is a very solid advertising in favour of ProtonMail. In context of 5/9/14+ eyes, the nomenclature of solid advertising might differ from your interpretation, where perceptions matter ─ ranging from honeypots, compromised Tor exit nodes to dubious VPN providers, absence of warrant canaries to flawed encryption products etc. It is probably best to exercise caution and remain sceptical, rather tha…

wow, you are one eloquent writer. i just like reading your comments for the structure of the prose.

write something!

Re: Russia blocks ProtonMail

#176

Earlier quoted context omitted.

Because if the tip is non-anonymous, the person making it is automatically the only known suspect. It's not the difference between anonymous tip and non-anonymous tip, but between anonymous tip and no tip at all, because no one wants to be punished for doing the right thing. Remember Richard Jewell from the Atlanta Olympics?

It's so sad, but that's why I wrote that protection of the person who called in is crucial. But with cases like this I understand why people don't trust the police with reporting bombs.

Some people don't trust the police with anything at all.

They aren't wrong. Federal circuit judges and the Supreme Court have ruled that police have no duty to protect anyone in particular. They routinely suffer no meaningful negative consequences for serious failures in their work, including killing people who are unarmed, not resisting, and not suspected of committing any crime.

And after the Boston police screwed up the Mooninite promotion for Cartoon Network in 2007... well, it's enough to say that Turner had to pay for and publicly apologize for the police response to their fancy LED-illuminated handbills--absolutely Kafkaesque.

If I ever find a suspicious package, I'll certainly alert bystanders to retreat. I'll pull the firm alarm on my way out. I'll call the firefighters. I'll call the local newspaper and television station newsrooms. I might even call the triage nurse at the nearest ER. But someone else can be the one to call the cops.

Re: Russia blocks ProtonMail

#177
post #78

Earlier quoted context omitted.

Given that the police wanted information after having already received the threats, they had to have requested some combination of historical and future data. They almost certainly wanted historical data primarily so that they could find the person who sent the threats. There's no way to satisfy requests for historical data without capturing data from everyone.

> There's no way to satisfy requests for historical data without capturing data from everyone. That's not what GGGP suggested. He suggested that they give data for specific people that they already have. You are setting up a strawman here.

> He suggested that they give data for specific people that they already have.

...how were they to know to capture data from those specific people before being asked?

Re: Russia blocks ProtonMail

#178
It's a nothing more than advertising of a great privacy service, if totalitarian states like TerroRussia and China block it.

I'm a happy Premium user.

PS It's funny to hear some accusations about terrorism from our state, officially supporting terrorism. Yes, I'm Russian if any.

Re: Russia blocks ProtonMail

#179

Earlier quoted context omitted.

> There's no way to satisfy requests for historical data without capturing data from everyone. That's not what GGGP suggested. He suggested that they give data for specific people that they already have. You are setting up a strawman here.

> He suggested that they give data for specific people that they already have. ...how were they to know to capture data from those specific people before being asked?

They don't need to. They only need to turn over data they already have for that user and potentially any future data that is generated for that user. Wiretaps work the same way.

Re: Russia blocks ProtonMail

#180
post #44

Earlier quoted context omitted.

For non-technical reasons, it is not always possible to self-host emails unfortunately.

Like what?

I've heard it's relatively common to get allocated an IP that has previously been abused by spammers, or certain providers will reject incoming mail from IPs that have no reputation (but then how can you build reputation?).
Post reply on HN