Live data from Hacker News

ProtonMail includes Google Recaptcha for login

github.com

221–230 of 308 posts

Re: ProtonMail includes Google Recaptcha for login

#221
A few weeks ago I noticed that Reddit also started using Google Recaptcha for account creation.

Even though I only saw it on creation, and not on login, the possibility of associating a strong identifying fingerprint with a presumably anonymous throwaway user account was concerning.

Re: ProtonMail includes Google Recaptcha for login

#222
post #97
post #47

When I started my company we chose to use Protonmail. My advice to anyone who wants secure email: don't use protonmail. The email search is completely useless. I don't understand how it can possibly be so difficult to do a substring search on a corpus and rank them in some kind of sane way. Searching for old emails based on content is an exercise in futility. After a few years of using an email service, search become…

It used to be the case that both ProtonMail and FastMail were frequently recommended on HN. So, how is FastMail doing in comparison?

I just switched back to Fastmail after a year of testing alternatives (mailbox.org, Private Email [a Namecheap company], Runbox, and Zoho Mail) and I'm quite happy with it.

Re: ProtonMail includes Google Recaptcha for login

#223

A few comments about this. A very small fraction of logins get the CAPTCHA challenge. We, and other services, face unrelenting brute force attacks on our login endpoints. If you are seeing a CAPTCHA on login, chances are that something about your connection is suspicious to our system. It's far from perfect, and we continue to improve it, but at most a percent or two of users are seeing CAPTCHA at any time. The CAPTC…

Why / Who is DDOS'ing protonmail? Is it just a consequence of having a sass a certain size that you become a target?

Re: ProtonMail includes Google Recaptcha for login

#224
post #203

Earlier quoted context omitted.

> If you expect search functionality from them you don't get encryption. It’s not as if the client can’t maintain an encrypted index, they just haven’t implemented it. Also, apart from all of the important advantages of encryption, there’s always the privacy angle compared to Gmail: Google uses mail to target ads and scrape purchases, which a lot of people don’t want.

I think a full index of the contents of hundreds or thousands of emails and their attachments is soon going to take a lot of space and be slow on a mobile device. Also if you have multiple clients, which one is going to update the index and how do they sync up? Building index on a mobile device potentially kills its battery esp. if it needs to index pdfs and images. So it needs to be done while charging over night wh…

> I think a full index of the contents of hundreds or thousands of emails and their attachments is soon going to take a lot of space and be slow on a mobile device.

I initially read “hundreds of thousands” and would have agreed that it might be a problem for those rare users (not even sure about that), but no, “hundreds or thousands” is a trivial amount of data. Normal mailbox operations already need to synchronize state; you just apply index operations along with this. (As for indexing PDFs and images, I don’t expect that in a basic implementation, or maybe ever. Doesn’t mean the entire feature should be missing.)

Which is why other services (e.g. Tutanota) have already implemented it, and also manage encrypt things like subject lines, which Protonmail doesn’t (!).

Re: ProtonMail includes Google Recaptcha for login

#225
post #138

Earlier quoted context omitted.

This seems to be assuming bad faith, you've changed a complaint of a missing feature into a different request for a new feature (because contacting support is inconvenient), which are two different things. It would be best to not confuse the issue, and to focus on doing what you can to support the feature request, if that's what you're interested in having.

If you have to contact support to stop paying for an account you're not using, that's definitely a missing feature.

That seems like a misreading, the very toplevel post says that you can stop paying by deleting all the data. Then the response says you can also do that by contacting support. Did I miss something?

Re: ProtonMail includes Google Recaptcha for login

#226
post #211
post #138

Earlier quoted context omitted.

This seems to be assuming bad faith, you've changed a complaint of a missing feature into a different request for a new feature (because contacting support is inconvenient), which are two different things. It would be best to not confuse the issue, and to focus on doing what you can to support the feature request, if that's what you're interested in having.

I don't know how anyone could look at protonmail's responses and not assume bad faith. They're obfuscating the issue so they can make technically correct but effectively useless excuses for crappy behaviour.

I'm not sure what you mean -- it makes sense to me that if you are paying for an email service, they would continue to charge you as long as you store and access those emails in their server, and they would have to take steps to prevent abuse from people who might try to store too much data. Can you be more specific about what the behavior is? Maybe you could show a good way that another email provider has solved this, and provide a helpful guide as to how they could implement that?

Re: ProtonMail includes Google Recaptcha for login

#227
post #217

Earlier quoted context omitted.

Please be more concrete. What exactly is the risk here? That Google can look into the logs and infer a Mac OS Bigsur with Chrome v90 is logging into proton mail today at x:xx pm?

Google is discovering that this particular user is ripe for advertising security related products.

So the ultimate risk of using ReCAPTCHA on proton mail is that Google might find out I'm more tech savvy than the average? Fine by me.

Re: ProtonMail includes Google Recaptcha for login

#228

A few comments about this. A very small fraction of logins get the CAPTCHA challenge. We, and other services, face unrelenting brute force attacks on our login endpoints. If you are seeing a CAPTCHA on login, chances are that something about your connection is suspicious to our system. It's far from perfect, and we continue to improve it, but at most a percent or two of users are seeing CAPTCHA at any time. The CAPTC…

You can try https://www.hcaptcha.com as an alternative.

How are they better? Do they have better privacy policies?

Re: ProtonMail includes Google Recaptcha for login

#229

A few comments about this. A very small fraction of logins get the CAPTCHA challenge. We, and other services, face unrelenting brute force attacks on our login endpoints. If you are seeing a CAPTCHA on login, chances are that something about your connection is suspicious to our system. It's far from perfect, and we continue to improve it, but at most a percent or two of users are seeing CAPTCHA at any time. The CAPTC…

Why / Who is DDOS'ing protonmail? Is it just a consequence of having a sass a certain size that you become a target?

I’d be curious as well, but chances are they’re experiencing credential stuffing attacks or dictionary attacks against account passwords.

Re: ProtonMail includes Google Recaptcha for login

#230

A few comments about this. A very small fraction of logins get the CAPTCHA challenge. We, and other services, face unrelenting brute force attacks on our login endpoints. If you are seeing a CAPTCHA on login, chances are that something about your connection is suspicious to our system. It's far from perfect, and we continue to improve it, but at most a percent or two of users are seeing CAPTCHA at any time. The CAPTC…

Maybe some basic stats would concretize the problem for some commenters.

E.g. What was the ratio of failed logins to successful ones before implementing captcha? Now that you've implemented captcha, what is that ratio among the population of users not presented with captcha, compared to to population that is? How many attempts did adding the captcha stop?

Post reply on HN