Live data from Hacker News

End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem

brokencloudstorage.info

101–105 of 105 posts

Re: End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem

#101
post #42
post #32

Earlier quoted context omitted.

How else would you do client side crypto for a website if not with JavaScript, isn't that kind of the point of how Proton does E2EE?

Crypto for websites is completely broken (because the server can serve you whatever it wants), so doing crypto for websites at all is suspicious.

this can be mitigated by using a browser addon to calculate and verify the web js content is matching the hash in a public code repo. That is how CTemplar Mail does it.

I'm disappointed they haven't implemented something like this.

Re: End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem

#102
post #15

Earlier quoted context omitted.

I have not seen this take before, do you have any pointers to someone making this claim?

Founders with US affiliation/physicist creating crypto products [1], faulty claims how the relevant Swiss law (BÜPF) applies to them [2], doing crypto in JavaScript on the client side, etc. To me, this smells like Crypto AG [3][4]. [1] https://proton.me/about/team [2] https://steigerlegal.ch/2019/07/27/protonmail-transparenzber... [3] https://en.wikipedia.org/wiki/Crypto_AG [4] https://en.wikipedia.org/wiki/Operation…

We are not affiliated with Crypto AG. Our encryption occurs client-side, our cryptographic code is open source, and our tech can and has been independently verified.

Re: End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem

#103

Earlier quoted context omitted.

Is the suggestion that founders who have US affiliation are automatically in bed with three letter agencies?

If they're physically located in the US, they have no way to stop (legal) coercion by the TLAs yeah?

We aren't physically located in the US.

Re: End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem

#104

Earlier quoted context omitted.

In account creation, requiring a phone number for “spam prevention” on Tor There was some deanonymizing like that, phone or credit card

it is possible to get google captchas as verification on some nodes however it is rare and was easier in the past. I'm disappointed that they haven't used there own captchas but maybe they will in the future.

We (Proton) have had our own CAPTCHA for a year or more now.

Re: End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem

#105

Earlier quoted context omitted.

If they're physically located in the US, they have no way to stop (legal) coercion by the TLAs yeah?

We aren't physically located in the US.

Who's the "we" in this context? :)
Post reply on HN