Live data from Hacker News

ProtonMail: End-to-end encrypted email

protonmail.ch

11–20 of 51 posts

Re: ProtonMail: End-to-end encrypted email

#13
> https://protonmail.ch/blog/protonmail-threat-model/

I'm always skeptical of browser/JS based crypto, but it is nice to see that they're at least upfront with the risks involved in doing such a thing.

They probably downplay the risk of a MITM attack a little much, but otherwise I'm glad to see they're realistic about possible weaknesses of the platform.

Re: ProtonMail: End-to-end encrypted email

#14
Wonder what the cost is going to be when it goes live.

Running infrastructure in those DC's can't be cheap (compared to regular co-lo facilities). Thats on top of probably having to deploy more gear (or higher perf gear than a regular email provider) since the work load is probably CPU heavy.

Re: ProtonMail: End-to-end encrypted email

#15
post #2

The security details page[1] makes for interesting reading. Hopefully the new norm is 'E2E' encryption. It's actually starting to feel inevitable, and the hopelessness that followed in the wake of the 'Summer of Security' is perhaps evaporating bit by bit, through universal encryption, bit by bit. - [1] https://protonmail.ch/pages/security_details.php

> Messages are stored on ProtonMail servers in encrypted format. They are also transmitted in encrypted format between our server and users’ browsers . Messages between ProtonMail users are transmitted in encrypted form completely within our secured server network . Because they never leave our secured environment , there is no possibility to intercept the encrypted messages enroute. Emphasis mine. That doesn't sound…

Read on. It goes on to advise how they allow encrypted mail being sent to external providers, as well as self-destructing messages. The blurb also discusses the limitations of the system quite openly.

This part is only noting that inter-user messages never even leave their 'secured environment'. By all accounts it does seem as well secured as any other provider I've looked into.

Re: ProtonMail: End-to-end encrypted email

#16
So, if I send an ecrypted protonmail to someone else's yahoo mail, what happens? Is it only encrypted in the protonmail ecosystem?

True end to end encryption would mean everything is transferred as an encypted thing, and only people with a key can open it. If any email you send out ultimately is unencrypted so that the other side can read it, we aren't much closer than where we started are we?

If an email ends up in an unencrypted IMAP mailbox on a server somewhere, how is that more secure than what happens now?

Re: ProtonMail: End-to-end encrypted email

#17

> https://protonmail.ch/blog/protonmail-threat-model/ I'm always skeptical of browser/JS based crypto, but it is nice to see that they're at least upfront with the risks involved in doing such a thing. They probably downplay the risk of a MITM attack a little much, but otherwise I'm glad to see they're realistic about possible weaknesses of the platform.

Yes, but they are clearly playing a bit fast-and-loose with things here. The whole point of end-to-end encryption is that it's a "trust no third parties" model (other than whoever provided your crypto software, which you can verify anyway). This is slightly better than Lavabit, but you're still trusting ProtonMail, who are providing the crypto implementation to your browser every time you use it. Depending on how it's implemented, they could potentially unilaterally revoke all your past secrecy by changing the Javascript code to capture your private keys.

Plus, they're offering self-destructing e-mails, which is impossible to provide, so already there's a bit of snake oil there. If they said, "It's not possible to provide real self-destructing e-mails, but you can set it up so that (assuming you trust us), we'll delete the messages from our servers after a certain amount of time, which is the best anyone can do." Instead they say that they are "more ephemeral than SnapChat."

Re: ProtonMail: End-to-end encrypted email

#19
This sounds really good. The only disappointment is that it seems there is no business model that allows email providers and services like this to provide Unlimited encrypted email (no limitations i.e. Gmail-esque) absolutely free to all users. I'd be willing to gamble that if anyone could sustain this for a couple years, people would leave Gmail in droves, no one I know likes having to use the USA/NSA/google/big brother tagteam, but they still don't value the invasion of privacy enough to pay for it.

Re: ProtonMail: End-to-end encrypted email

#20

So, if I send an ecrypted protonmail to someone else's yahoo mail, what happens? Is it only encrypted in the protonmail ecosystem? True end to end encryption would mean everything is transferred as an encypted thing, and only people with a key can open it. If any email you send out ultimately is unencrypted so that the other side can read it, we aren't much closer than where we started are we? If an email ends up in…

I think it sends them a note that says, "Someone at ProtonMail sent you a message - click this link and enter the password they gave you to open it!"

Presumably they'll have some way to distribute the password in some ephemeral or slightly out-of-band way. It's probably less secure than messages within their environment, but it shouldn't ever hit another mailserver in plaintext (ideally ProtonMail wouldn't even have the plaintext anyway).

Post reply on HN