Live data from Hacker News

ProtonMail includes Google Recaptcha for login

github.com

261–270 of 308 posts

Re: ProtonMail includes Google Recaptcha for login

#261

Earlier quoted context omitted.

This sort of comment is frustrating. How many times has XYZ site had broken search? It seems to _not_ be a trivial problem still.

> This sort of comment is frustrating. How many times has XYZ site had broken search? I can't even think of any? But also search isn't a core feature for the vast majority of sites. Something can be easy and still break if nobody cares very much. Edit: Actually I can think of search breaking on one site that was notoriously badly run and had 0 to 1 part-time devs. That's not a flattering comparison. Edit 2: So could…

Not a website, but...Windows 10?? Highest market share OS, billions of $ worth of engineering time behind it and due to recent changes, search is pretty much a core feature of the OS. And I'm not even talking about file search here, which is indeed a hard-ish problem (although `locate ... | grep ...` seems to do well enough on Linux) - this is just a simple word search through a list of programs that's usually under 100 items long. And it's still broken most of the time.

Then there's MDN - a documentation site, whose 2nd most important function should be search. Yet, despite DuckDuckGo (a general-purpose search engine!) consistently finding the exact results I want, MDN's built-in search often misses even titles that are searched for verbatim.

If it weren't almost 2am and I weren't running almost entirely on caffeine, I'd probably be able to think of a few more.

Re: ProtonMail includes Google Recaptcha for login

#262
post #253

Earlier quoted context omitted.

I'm going to put you on a spot a bit, because this seems important to ProtonMail's viability, and I want you to keep succeeding... > Obviously Google still gets some information, but we do all we can to limit this. When you cause a request to be made for ReCaptcha, it seems that you're leaking enough information to (in many cases) link a possibly-pseudonymous Protonmail account to an identifiable individual. (For exa…

The points made in this post mirror my own, and this incident has caused my trust of sound privacy focus design and implementation on the part of Proton to diminish somewhat. Any small leakage of data/activity/identity is unacceptable to those of us who know how this information can be taken advantage of, and choice Proton specifically to avoid that happening.

As a community driven, open source company, resource allocation is determined through community feedback. As mentioned in another post, reCaptcha has been used for anti-abuse in Proton since 2014. The community cares about this, but it's never been the highest voted item [1].

However, it's something our team cares about. That's why 6 months ago, we started preparing to migrate to hcaptcha, even though removing reCaptcha wasn't the most pressing community demand. This work is on track to be completed in the next few weeks. We are sure that after we switch to hcaptcha, on the community voting forum, there will be a "do not use hcaptcha" suggestion, which will then start to collect votes. When it collects enough votes, we will duly allocate resources towards building our own captcha, because that's what it means to be a community driven company.

[1] https://protonmail.uservoice.com/forums/284483-protonmail/su...

Re: ProtonMail includes Google Recaptcha for login

#263

Earlier quoted context omitted.

I'm not saying you're wrong, but that particular source is well known for making big claims with insufficient evidence, and it reads like it was written by a conspiracy theorist. Many of the author's claims have already been (imo, pretty solidly) refuted by Proton. Disclaimer: using protonmail until my current subscription runs out, then selfhosting

Self hosting these days is almost impossible because most email providers like gmail and yahoo mail will automatically move your emails to spam. It’s all based on IP address and how reliable that IP address is. Self hosting guarantees that all your sent email will end up in spam folders.

It's not trivial, but it's doable.

Excision Mail which runs on OpenBSD hits the majority of what you need technically. https://github.com/Excision-Mail/Excision-Mail

The bigger problem is finding a hosting provider that hasn't had their entire space blacklisted.

For that, you're likely going to have to pick a "responsible" provider, have a couple of rounds of back and forth with them to prove you're neither an idiot nor a spammer, and ask them to manually open the port for you. And they're going to demand something that will tie to identity.

Re: ProtonMail includes Google Recaptcha for login

#264

Earlier quoted context omitted.

I'm not saying you're wrong, but that particular source is well known for making big claims with insufficient evidence, and it reads like it was written by a conspiracy theorist. Many of the author's claims have already been (imo, pretty solidly) refuted by Proton. Disclaimer: using protonmail until my current subscription runs out, then selfhosting

Doesn’t self-hosting also have privacy downsides, being that all the hardware is tied to you? I’d imagine whatever minor resistance to wiretapping a multiuser site gave regarding privacy of non-investigated individuals would disappear.

> Doesn’t self-hosting also have privacy downsides, being that all the hardware is tied to you?

Sure. But I'm not worried about someone who has an actual warrant for ME getting at stuff.

What I want to stop is some random law enforcement idiot from Dipshitsville, Texas, from sending an electronic request to Google for "every email with the word "abortion" and "protest" in it" who promptly turns over all my email.

If you want my email, you're gonna have to get up off your chair, file a warrant with somebody's name on it in front of a judge, crossfile in some different legal jurisdictions, and have someone come seize my machines.

That will stop most everybody short of NSA.

If your threat is the NSA, you're screwed anyway. If they can't get at your email legitimately, they'll just fabricate the evidence they need against you.

Re: ProtonMail includes Google Recaptcha for login

#265
post #264

Earlier quoted context omitted.

Doesn’t self-hosting also have privacy downsides, being that all the hardware is tied to you? I’d imagine whatever minor resistance to wiretapping a multiuser site gave regarding privacy of non-investigated individuals would disappear.

> Doesn’t self-hosting also have privacy downsides, being that all the hardware is tied to you? Sure. But I'm not worried about someone who has an actual warrant for ME getting at stuff. What I want to stop is some random law enforcement idiot from Dipshitsville, Texas, from sending an electronic request to Google for "every email with the word "abortion" and "protest" in it" who promptly turns over all my email. If…

> If your threat is the NSA, you’re screwed anyway. If they can’t get at your email legitimately, they’ll just fabricate the evidence they need against you.

The NSA doesn’t need evidence; you must have them confused with the FBI.

Re: ProtonMail includes Google Recaptcha for login

#266
post #97

Earlier quoted context omitted.

It used to be the case that both ProtonMail and FastMail were frequently recommended on HN. So, how is FastMail doing in comparison?

I'm not entirely happy with fastmail. Too much of legitimate mail ends up in Spam. They even put aliexpress mails to spam, that kind of domain surely must be whitelisted. I'd prefer more spam in inbox, because right now I have to check spam every the time to ensure that nothing is lost.

To be fair, 70% of what I get from AliExpress is actually spam, despite having disabled all the email switches I could find. For each order, I get 3-5 near-useless emails and every visit to the site results in a week or two of "abandoned cart recovery" emails.

Re: ProtonMail includes Google Recaptcha for login

#267

Earlier quoted context omitted.

The points made in this post mirror my own, and this incident has caused my trust of sound privacy focus design and implementation on the part of Proton to diminish somewhat. Any small leakage of data/activity/identity is unacceptable to those of us who know how this information can be taken advantage of, and choice Proton specifically to avoid that happening.

As a community driven, open source company, resource allocation is determined through community feedback. As mentioned in another post, reCaptcha has been used for anti-abuse in Proton since 2014. The community cares about this, but it's never been the highest voted item [1]. However, it's something our team cares about. That's why 6 months ago, we started preparing to migrate to hcaptcha, even though removing reCapt…

That post and the comments seem to not be aware of the privacy/security risks. And the official response seems to miss it:

> In our setup, reCaptcha is served from a sandboxed iframe, which prevents it from being able to interfere with our java script, so it does not pose a privacy or security risk.

You might perceive low user demand for this change because your users assume that you handle the privacy/security risks, and assume that the only issue is annoyance.

Re: ProtonMail includes Google Recaptcha for login

#268

Earlier quoted context omitted.

That's what you get for making stupid decisions based on ideology instead of facts. Protonmail says it very clearly that all mail is encrypted on their servers. If you expect search functionality from them you don't get encryption. You bought into some random surveillance state propaganda. Google isn't interested in the mail of your random startup, they are happy expanding their cloud footprint. In return you get goo…

Choosing something you ideologically do not support is not sane

I don't ideologically support exploitation of workers, using unclean energy sources and the "proof of work" model of education. Yet, I need many modern gadgets, have no carbon-neutral way of crossing the country other than biking for 2 weeks and need a university degree to get a job that allows me to live well.

Blindly choosing ideology over self-preservation is what isn't sane here.

Re: ProtonMail includes Google Recaptcha for login

#269

Earlier quoted context omitted.

Full-text search within the average amount of a single user's emails is trivial and fast on any modern PC. Smartphones do it for autocompletion suggestions every time you type a letter. The only thing taking longer than a few milliseconds is the initial indexing.

Doesn't that assume you _have_ all of the emails on your device on order to search them? I know for a fact, Gmail on my phone doesn't have the ~15 years of email in my account downloaded. I bet that would take significantly longer to download than the actual search would would take to perform. If the things to be searched aren't already on the client, a client side search doesn't seem too useful to me, regardless of…

Yeah by default Gmail on your phone only keeps like 30 days of mail iirc

Re: ProtonMail includes Google Recaptcha for login

#270
post #47

When I started my company we chose to use Protonmail. My advice to anyone who wants secure email: don't use protonmail. The email search is completely useless. I don't understand how it can possibly be so difficult to do a substring search on a corpus and rank them in some kind of sane way. Searching for old emails based on content is an exercise in futility. After a few years of using an email service, search become…

That's what you get for making stupid decisions based on ideology instead of facts. Protonmail says it very clearly that all mail is encrypted on their servers. If you expect search functionality from them you don't get encryption. You bought into some random surveillance state propaganda. Google isn't interested in the mail of your random startup, they are happy expanding their cloud footprint. In return you get goo…

> Google isn't interested in the mail of your random startup

On the contrary: Google is absolutely interested in your startup's email, just not the content you think. They don't care about Susan writing to HR about vacation days, but they absolutely care about your IT manager's correspondences with that Oracle rep that's trying to sell you their cloud offering. That way, Google can advertise the shit out of their competing offerings to you in order to "steal" you as a customer from their competitors.

> Product-wise there is not a thing wrong in the world with GMail.

I'm guessing you haven't been around HN for long enough to hear the myriad of horros stories about entire GSuite orgs being deleted because of things like a false-positive abuse detection on an employee's private account or one pirated movie uploaded by an employee by accident. And how none of them were able to even reach support without going through personal connections at big G (and even then, few were able to get things fixed).

Google is a faceless corporation, managed more by algorithms than by people. You don't need an ideology to tell you why that's bad.

Post reply on HN