Live data from Hacker News

ProtonMail includes Google Recaptcha for login

github.com

291–300 of 308 posts

Re: ProtonMail includes Google Recaptcha for login

#291

A few comments about this. A very small fraction of logins get the CAPTCHA challenge. We, and other services, face unrelenting brute force attacks on our login endpoints. If you are seeing a CAPTCHA on login, chances are that something about your connection is suspicious to our system. It's far from perfect, and we continue to improve it, but at most a percent or two of users are seeing CAPTCHA at any time. The CAPTC…

> A very small fraction of logins get the CAPTCHA challenge. We, and other services, face unrelenting brute force attacks on our login endpoints. If you are seeing a CAPTCHA on login, chances are that something about your connection is suspicious to our system.

IME CAPTCHA will make your internet use unbearable if you a) are from a non-Western geo-location or b) you use a VPN. VPNs like the service you provide, which a fair number of your email users probably avail. It's fair to say a smaller number of "internet users" get CAPTCHA hell (which i also doubt), but I wonder if the ratio of Proton* users actually skews the other way.

Re: ProtonMail includes Google Recaptcha for login

#292

Earlier quoted context omitted.

Maybe some basic stats would concretize the problem for some commenters. E.g. What was the ratio of failed logins to successful ones before implementing captcha? Now that you've implemented captcha, what is that ratio among the population of users not presented with captcha, compared to to population that is? How many attempts did adding the captcha stop?

We were a bit surprised by the sudden reaction today. We have been using reCaptcha as one tool (among many) to fight abuse for years now. For example, here's a thread from 4 years ago mentioning it [1]. It is triggered most often for signup, but it can also appear for password reset, username lookup, sending mail, payments, login, and any other api routes which can be abused. That said, we can also understand the rea…

> For security reasons, we can't say too much, but some truly massive residential IP botnets have appeared in recent years and can make millions of attempts per day

Ah yes. All those insecure IoT and unpatched/unpatchable routers that are discoverable on shodan and ultimately end up joining giant botnets. They are a plague not just to ProtonMail.

TBH, I’ve never seen a Captcha. But then I’d tend to use your service via mutt/bridge or the iOS app. And I have MFA enabled.

Re: ProtonMail includes Google Recaptcha for login

#293

Earlier quoted context omitted.

Maybe some basic stats would concretize the problem for some commenters. E.g. What was the ratio of failed logins to successful ones before implementing captcha? Now that you've implemented captcha, what is that ratio among the population of users not presented with captcha, compared to to population that is? How many attempts did adding the captcha stop?

We were a bit surprised by the sudden reaction today. We have been using reCaptcha as one tool (among many) to fight abuse for years now. For example, here's a thread from 4 years ago mentioning it [1]. It is triggered most often for signup, but it can also appear for password reset, username lookup, sending mail, payments, login, and any other api routes which can be abused. That said, we can also understand the rea…

> For security reasons, we can't say too much

Obscuring reasons due to security. Sounds like a security through obscurity type of thing.

Re: ProtonMail includes Google Recaptcha for login

#294

Earlier quoted context omitted.

That’s what per-IP and per-user rate limiting is for—by themselves, those two are close to sufficient. Any form of CAPTCHA would be a terrible sole defence (such things don’t block bots, they just make it a bit more expensive and help a bit with drive-by attacks), and adds very little for defence-in-depth, while introducing new problems where you inconvenience and block access to your real customers. I find the inclu…

Per user does not help when doing credential stuffing - the attacker tries known credentials from a leak, it’s not random cracking. Per IP blocks can be circumvented by using a botnet and slowing your attack.

Those things are why I said close to sufficient, not sufficient. For best results you will want some other form of behaviour analysis also. But reCAPTCHA suffers from serious problems too; it’s easy to find turn-key reCAPTCHA-solving services at under $1 per thousand. So reCAPTCHA is a deterrent, but far from inviolate, and for most of the kinds of attacks we’re talking about here it’s not even a particularly severe deterrent. (It would be for comment spam, since the value of each attempted submission is negligible, but for credential stuffing the expected value of each attempt is much higher.)

Re: ProtonMail includes Google Recaptcha for login

#295
post #288

A few comments about this. A very small fraction of logins get the CAPTCHA challenge. We, and other services, face unrelenting brute force attacks on our login endpoints. If you are seeing a CAPTCHA on login, chances are that something about your connection is suspicious to our system. It's far from perfect, and we continue to improve it, but at most a percent or two of users are seeing CAPTCHA at any time. The CAPTC…

There are countless alternatives. Why did you choose Google? > TL;DR It's a small fraction of users who are affected Yes, though any of your users can be affected, randomly, without warning.

There actually aren't countless, almost all of them have been broken (many by Google actually), there's just one alternative, hcaptcha, which has been around only the past couple years. Back in 2014 when we first added the captcha for too many api requests, there was no other option.

Re: ProtonMail includes Google Recaptcha for login

#296
post #293

Earlier quoted context omitted.

We were a bit surprised by the sudden reaction today. We have been using reCaptcha as one tool (among many) to fight abuse for years now. For example, here's a thread from 4 years ago mentioning it [1]. It is triggered most often for signup, but it can also appear for password reset, username lookup, sending mail, payments, login, and any other api routes which can be abused. That said, we can also understand the rea…

> For security reasons, we can't say too much Obscuring reasons due to security. Sounds like a security through obscurity type of thing.

I don’t think you quite understand what security through obscurity means. It’s not an invitation to help malicious actors pen-test your system by publishing information about it.

Re: ProtonMail includes Google Recaptcha for login

#297
post #56
post #47

When I started my company we chose to use Protonmail. My advice to anyone who wants secure email: don't use protonmail. The email search is completely useless. I don't understand how it can possibly be so difficult to do a substring search on a corpus and rank them in some kind of sane way. Searching for old emails based on content is an exercise in futility. After a few years of using an email service, search become…

I’ll second this, I love the idea of proton mail but the product isn’t anywhere close to ready for daily driving. Great for the occasional should it arise however. Encryption should be a selling point and it seems like they use it more as an excuse.

I've been using protonmail as my mail email service for probably close to 6 years. Earlier iterations of the UI were obviously basic but it's perfectly functional now and works very well and certainly not for "occasional use". The web client UI is great and has come on leaps and bounds particularly of late.

The mobile app has some way to go but more than adequate for daily use because I'm using it daily.

Re: ProtonMail includes Google Recaptcha for login

#298
post #217
post #214

Earlier quoted context omitted.

Protonmail goal is to preserve privacy, while Google's goal is to collect your private data.

Please be more concrete. What exactly is the risk here? That Google can look into the logs and infer a Mac OS Bigsur with Chrome v90 is logging into proton mail today at x:xx pm?

Google has history of this user logging to protonmail including ip adresses. Google gives that log to US agency, US agency correlates that log with the log coming from ISP and identifies the user.

Re: ProtonMail includes Google Recaptcha for login

#299
post #217
post #214

Earlier quoted context omitted.

Protonmail goal is to preserve privacy, while Google's goal is to collect your private data.

Please be more concrete. What exactly is the risk here? That Google can look into the logs and infer a Mac OS Bigsur with Chrome v90 is logging into proton mail today at x:xx pm?

They can correlate your login timestamps with emails you send to gmail users and identify your protonmail account.

Re: ProtonMail includes Google Recaptcha for login

#300

Earlier quoted context omitted.

As a community driven, open source company, resource allocation is determined through community feedback. As mentioned in another post, reCaptcha has been used for anti-abuse in Proton since 2014. The community cares about this, but it's never been the highest voted item [1]. However, it's something our team cares about. That's why 6 months ago, we started preparing to migrate to hcaptcha, even though removing reCapt…

This is an irresponsible statement to me. Each time you face such kind of issue, you can claim that community allows me to do that. But Protonmail is a professional company who should take the final responsibility. Please be professional.

It's a perfectly professional and honest response. They're taking responsibility AND giving you a rationale. Your comment is the unprofessional one if anything.
Post reply on HN