Live data from Hacker News

Security experts declare all Proton apps secure after security audit

protonmail.com

1–10 of 49 posts

Re: Security experts declare all Proton apps secure after security audit

#2
Unfortunately users declare Protonmail barely usable in terms of features and UX. After a decade of this, I’m shifting back to IMAP. My use case is better off with GPG than with Protonmail. I can’t usefully function without integration into the rest of my Mac or iOS. A secure walled garden with Apps that get worse over time? I’ll go with Apple’s version.

Re: Security experts declare all Proton apps secure after security audit

#3
Declaring it secure after an audit is like writing 100% coverage tests and saying it's bug-free. You can't prove absence, only presence.

This title is the definition of sensationalism and only by reading the article do you find the truth: "Their tests uncovered no major issues or security vulnerabilities". This is a bad look for them and I'm wary of their company now...

Re: Security experts declare all Proton apps secure after security audit

#4
post #2

Unfortunately users declare Protonmail barely usable in terms of features and UX. After a decade of this, I’m shifting back to IMAP. My use case is better off with GPG than with Protonmail. I can’t usefully function without integration into the rest of my Mac or iOS. A secure walled garden with Apps that get worse over time? I’ll go with Apple’s version.

[deleted]

Re: Security experts declare all Proton apps secure after security audit

#5
post #2

Unfortunately users declare Protonmail barely usable in terms of features and UX. After a decade of this, I’m shifting back to IMAP. My use case is better off with GPG than with Protonmail. I can’t usefully function without integration into the rest of my Mac or iOS. A secure walled garden with Apps that get worse over time? I’ll go with Apple’s version.

Protonmail user here, and I haven't declared any such thing. The complaints I see tend to center around the assumption that using the service is exactly the same as any other service, despite the lengths they go to tell you how it's different. The service and the app is very usable and there are more than enough features, without them getting in the way. I use the app and the bridge; both have served me well.

Re: Security experts declare all Proton apps secure after security audit

#6
Technical nitpick purely on the wording of the title: the pentesters declared that "no important security issues were found during the pentest". Unfortunately in our current world that's about as good as you're going to get for a large software system, but that does not necessarily mean that Proton is secure. There could still be undiscovered vulnerabilities.

Re: Security experts declare all Proton apps secure after security audit

#7
ProtonMail has a bad history of irresponsible sensationalism. It’s like constantly marketing yourself as the most private e-mail service “built by CERN scientists” but who will give information about you to authorities:

https://www.engadget.com/protonmail-climate-activist-ip-swis...

I know that ProtonMail doesn’t claim to protect your IP address, but I don’t expect the average user to make that distinction.

This is another dumb article. Getting your service tested for vulnerabilities is good hygiene but it shouldn’t be used as marketing material to make users think your service is Fort Knox.

Re: Security experts declare all Proton apps secure after security audit

#8

ProtonMail has a bad history of irresponsible sensationalism. It’s like constantly marketing yourself as the most private e-mail service “built by CERN scientists” but who will give information about you to authorities: https://www.engadget.com/protonmail-climate-activist-ip-swis... I know that ProtonMail doesn’t claim to protect your IP address, but I don’t expect the average user to make that distinction. This is a…

> ProtonMail has a bad history of irresponsible sensationalism. It’s like constantly marketing yourself as the most private e-mail service “built by CERN scientists” but who will give information about you to authorities:

Well, conflating "security" with "following the law" seems odd. Do anyone realistically expect a legally incorporated company to not follow laws? They have to respond to lawful requests, otherwise there will be no business at all.

As long as they fight against unlawful requests, they are what they make out to be. If they're found to be spying on their users when it's not lawfully requested, then you have some bite in your argument. But otherwise, I'm not sure what you expect them to do.

By the way, they seem to be pretty upfront about how they collaborate with law enforcement, at least according to https://protonmail.com/law-enforcement Maybe it wasn't like that in 2021 when the article you linked was published?

In the end, if you rely on any single company for both your security and privacy, you're playing a loosing game. Not hiding your IP when signing up for something when you're planning to do illegal activities? Maybe time to reconsider your opsec strategy.

Re: Security experts declare all Proton apps secure after security audit

#10

Declaring it secure after an audit is like writing 100% coverage tests and saying it's bug-free. You can't prove absence, only presence. This title is the definition of sensationalism and only by reading the article do you find the truth: "Their tests uncovered no major issues or security vulnerabilities". This is a bad look for them and I'm wary of their company now...

I agree with you that the title is a bit sensationalist. But if independent security audits with no major issues uncovered cannot make you claim something is secure, when can you claim something as secure? Or are you of the opinion that nothing ever can be claimed to be secure as there can always be holes that could be uncovered in the future?

Using openssh as an example, would you say it's secure when you're using public keys for the authentication? Their track record seems pretty good for the last years, but there might still be uncovered vulnerabilities, could it still claim to be secure?

Post reply on HN