Live data from Hacker News

ProtonMail includes Google Recaptcha for login

github.com

1–10 of 308 posts

Re: ProtonMail includes Google Recaptcha for login

#2
Last week ProtonMail integrated Google's Recaptcha to their Login Page.

As a project that advocates Privacy and Security, and was an immediate response to the Snowden Leaks, I find this kinda ironic that they now set the Google PREFs cookie for all of their users - while they still maintain the same marketing on their website.

And well, I am looking for new options now, I guess.

Re: ProtonMail includes Google Recaptcha for login

#3

Last week ProtonMail integrated Google's Recaptcha to their Login Page. As a project that advocates Privacy and Security, and was an immediate response to the Snowden Leaks, I find this kinda ironic that they now set the Google PREFs cookie for all of their users - while they still maintain the same marketing on their website. And well, I am looking for new options now, I guess.

Have you contacted them? It doesn’t take a whole team of people to implement recaptcha. Could just be the mistake of one engineer who was tasked to “add a captcha to the login form”.

I hope you don’t assume the worst without investigating further.

Re: ProtonMail includes Google Recaptcha for login

#4
post #3

Last week ProtonMail integrated Google's Recaptcha to their Login Page. As a project that advocates Privacy and Security, and was an immediate response to the Snowden Leaks, I find this kinda ironic that they now set the Google PREFs cookie for all of their users - while they still maintain the same marketing on their website. And well, I am looking for new options now, I guess.

Have you contacted them? It doesn’t take a whole team of people to implement recaptcha. Could just be the mistake of one engineer who was tasked to “add a captcha to the login form”. I hope you don’t assume the worst without investigating further.

They could have also just opted for hCaptcha, which is both much more private and doesn't excessively punish people who reduce their fingerprint.

Re: ProtonMail includes Google Recaptcha for login

#6
post #3

Last week ProtonMail integrated Google's Recaptcha to their Login Page. As a project that advocates Privacy and Security, and was an immediate response to the Snowden Leaks, I find this kinda ironic that they now set the Google PREFs cookie for all of their users - while they still maintain the same marketing on their website. And well, I am looking for new options now, I guess.

Have you contacted them? It doesn’t take a whole team of people to implement recaptcha. Could just be the mistake of one engineer who was tasked to “add a captcha to the login form”. I hope you don’t assume the worst without investigating further.

If one single person is allowed to add a privacy compromising service to one of the most important pages on their website (the login page) then there are deep, fundamental flaws in the organization that brings into question the security of the entire platform.

Re: ProtonMail includes Google Recaptcha for login

#7
post #5

That stinks. I'm on Fastmail but its hard point has to do with being based in Australia and the recent government efforts of forcing entities to comply with police inquiries. Fastmail's side of the story: https://fastmail.blog/legal-policy/aabill-and-fastmail/

Being subject to state surveillance and surveillance capitalism are related but different concerns.

Re: ProtonMail includes Google Recaptcha for login

#9
post #3

Last week ProtonMail integrated Google's Recaptcha to their Login Page. As a project that advocates Privacy and Security, and was an immediate response to the Snowden Leaks, I find this kinda ironic that they now set the Google PREFs cookie for all of their users - while they still maintain the same marketing on their website. And well, I am looking for new options now, I guess.

Have you contacted them? It doesn’t take a whole team of people to implement recaptcha. Could just be the mistake of one engineer who was tasked to “add a captcha to the login form”. I hope you don’t assume the worst without investigating further.

Well, if something like this doesn't get caught down the production line, they might have bigger issues regarding security.

But I agree with you, I think I should give them a chance to respond to this. Personally, I think this is a serious issue.

I opened up a GitHub issue for their frontend (as they do not have any security disclosure contact possibility as it seems): https://github.com/ProtonMail/WebClient/issues/242

Post reply on HN