Live data from Hacker News

Why ProtonMail is more secure than Gmail

protonmail.com

101–110 of 314 posts

Re: Why ProtonMail is more secure than Gmail

#101
post #71
post #57

Earlier quoted context omitted.

I think what's telling here is that the blog post does not point to Protonmail's own threat model. https://protonmail.com/blog/protonmail-threat-model/ Which says don't use it if you are up against state actors and: "Sensitive business communications – You have sensitive business information that you want to make sure is protected from competitors and other malicious parties. For example, you fear a competitor may wa…

This attack actually happened years ago at a company called Hushmail. Law enforcement had the encrypted email provider serve malicious code to the target which leaked the secret key.

This.

Re: Why ProtonMail is more secure than Gmail

#103
Here's the thing with email. You can sign up for Protonmail ... but you've still got to use email to correspond with others. And in all likelihood many of those individuals will be on GMail or some other less-secure provider unless you're using Protonmail as an enterprise solution, in which case the ratio of "secured" vs. "unsecured" recipients would likely tilt towards secured.

Email is insecure, and most users don't even consider security when using it. I've seen my own social security numbers sent out via email. I've seen corporate card credit card numbers sent via emial. I've seen other confidential financial documents and a myriad of other things sent via email by people who didn't know or didn't care that the method of transmission isn't secure because frequently it's not their information at risk. In my experience, medical data is treated differently because there are laws around how it can be communicated and stored. Until there's regulation placed around other pieces of information, and those laws get enforced, I don't know that people will change how they use and abuse email.

Re: Why ProtonMail is more secure than Gmail

#104
Zero Knowledge Encryption

So what happens if, say a hacker breaches the systems and makes an interception at the SMTP level... before they encrypt? They then can read your mail before ProtonMail encrypts it...

There is a lot of marketing bumpf on this page without any link to detail.

Re: Why ProtonMail is more secure than Gmail

#105
post #2

This post would be improved by discussing that their [threat model]( https://en.wikipedia.org/wiki/Threat_model ) is so different than Google's that it regards some of Google's business practices as threats. And that, in turn, there are threats that Google treats as much bigger threats, bringing their own world-class security team to. Calling this fundamental difference in approach "more secure" manipulates the less-…

That sounds a bit formalistic and abstract to me. Perhaps you could educate us on which specific threats you think we should pay attention to when choosing between Gmail and Protonmail.

What are some specific threats that Gmail defends us against more effectively than Protonmail?

Re: Why ProtonMail is more secure than Gmail

#106
post #71
post #57

Earlier quoted context omitted.

I think what's telling here is that the blog post does not point to Protonmail's own threat model. https://protonmail.com/blog/protonmail-threat-model/ Which says don't use it if you are up against state actors and: "Sensitive business communications – You have sensitive business information that you want to make sure is protected from competitors and other malicious parties. For example, you fear a competitor may wa…

This attack actually happened years ago at a company called Hushmail. Law enforcement had the encrypted email provider serve malicious code to the target which leaked the secret key.

Hushmail operates out of Canada, though. Jurisdiction matters a lot here since Switzerland has a reputation for making it difficult for foreign governments.

Re: Why ProtonMail is more secure than Gmail

#107

While I love ProtonMail as an effort to popularize security for end-users and trying to come up with smart technologies to achieve that, the whole risk model behind the writeup barely stands scrutiny. What's worrying, ProtonMail (who declare security a first-class feature) use "features" instead of systems to define security of their service. If you think of it for a second, web crypto (protection against intermediar…

+1 while it's nice that you're email at rest is secure most of your personal email is getting sent to someone with a gmail account anyway - perhaps defeating the whole exercise

Re: Why ProtonMail is more secure than Gmail

#108
post #31

I have to mention the Direct Project. This is secure email that is in use today by a vast number of healthcare professionals. https://www.healthit.gov/providers-professionals/faqs/what-d... It uses trust bundles that hold the public key. Identity is vetted so there is no spam and it helps guarantee you are communicating with the right person. https://www.directmdemail.com/info/how-it-works/Direct-excha... edit: I wou…

What is a "trust bundle"?

Trust bundles also represent "networks" of people. Networks can be run by different organizations with different requirements.

Here is the most popular one. https://services.directtrust.org/about_accredited_bundle/

Re: Why ProtonMail is more secure than Gmail

#109
post #44

The end-to-end encryption is only between protonmail addresses, in practice when you email people with gmail/hotmail/yahoo etc. it doesn't matter if protonmail can't read the e-mail, the other party can. (Their solution for that is to send an e-mail that contains a password-protected link with the actual message [0], I find this procedure inconvenient.) Gmail could be as secure as Protonmail by using PGP yourself [1]…

Regarding DDOS, ProtonMail has since installed a mitigation system to prevent this.

https://protonmail.com/support/knowledge-base/email-ddos-pro...

Re: Why ProtonMail is more secure than Gmail

#110
post #53

Earlier quoted context omitted.

More importantly they give any government agency free access without any warrant to fulltext search any customer. US law interpretation of IMAP. Only with a POP3 service you are safe.

"Without any warrant": what do you mean?

Under the Stored Communications Act, law enforcement may get emails or other information under third party control with only a subpoena.

Retrieving email via the POP3 protocol typically deletes the email upon retrieval, making it impossible for the third party to comply with requests for already-retrieved emails.

Post reply on HN