Live data from Hacker News

ProtonMail takes aim at Google with an encrypted calendar

venturebeat.com

101–110 of 154 posts

Re: ProtonMail takes aim at Google with an encrypted calendar

#101
post #91

Earlier quoted context omitted.

For me it was their app just being so far behind Fastmail. If they had a better app I'd gladly pay. I just can't stomach gmail anymore and Fastmail was next best.

Amusingly enough, Fastmail is a web app wrapped in WKWebview and Protonmail is a truly native app. Based on comments over in /r/protonmail there's some redesigns coming for the apps that should hopefully improve on the creature comforts.

I hope this is true because I like the privacy aspect of protonmail and would pay for it in that case.

Re: ProtonMail takes aim at Google with an encrypted calendar

#102
post #90
post #9

Article is light on the details, but ProtonMail has published some here: https://protonmail.com/blog/protoncalendar-security-model/ > This calendar key will then be symmetrically encrypted (PGP standard) using a 32-byte passphrase that is randomly generated on your device. Once it is encrypted, your calendar key will be stored on the ProtonCalendar backend server. 32-byte passphrase: might be fine, depending on what…

What are your thoughts on Protonmail's security in general? Specifically this part from their whitepaper https://pbs.twimg.com/media/EKpHwB-WwAE4YN0?format=png&name=... This is a bad idea right? We aren't supposed to decrypt then verify usually, correct? I'm told this is standard for implementations of OpenPGP, but it just seems like a horrible design (of course OpenPGP itself is probably bad). https://protonmail.com…

I didn't write https://latacora.micro.blog/2019/07/16/the-pgp-problem.html (the writing is too good, a giveaway that it's a 'tptacek joint) but I did review it and helped shape its contents and generally subscribe to its message :) In particular you are correct, and specifically GPG's MDC thing is some weird nonsense that does not deserve to be in use in 2019, let alone being in a product that describes itself as having top-notch security.

(Mostly I think I get why Protonmail does what it does, but GPG+email is a losing horse. It also doesn't help that protonmail addresses are a mild predictor for content not worth reading. I haven't quite had Popehat's experience of protonmail being a proxy for overt, virulent white supremacy, but... certainly have seen it be a proxy for poorly informed opinions on security :-))

Re: ProtonMail takes aim at Google with an encrypted calendar

#103

I recently left ProtonMail and went back to Fastmail. My reason was that they will never be able to fully support IMAP and now CalDAV because of the encryption they use. I grew to accept that email is not for secure messaging and my paranoia of "I'm being watched" just went away. If you need secure messaging, use something other than email.

"Secure messaging" is a fantasy. Nothing is 100% secure. The question then becomes, how much security is important to you? Personally I prefer a marginal level of security with encrypted email over no security at all. Your argument is the same as saying, "well they might as well store our passwords in plain text since encrypted passwords often get leaked or hacked anyway".

Re: ProtonMail takes aim at Google with an encrypted calendar

#104
post #102
post #90

Earlier quoted context omitted.

What are your thoughts on Protonmail's security in general? Specifically this part from their whitepaper https://pbs.twimg.com/media/EKpHwB-WwAE4YN0?format=png&name=... This is a bad idea right? We aren't supposed to decrypt then verify usually, correct? I'm told this is standard for implementations of OpenPGP, but it just seems like a horrible design (of course OpenPGP itself is probably bad). https://protonmail.com…

I didn't write https://latacora.micro.blog/2019/07/16/the-pgp-problem.html (the writing is too good, a giveaway that it's a 'tptacek joint) but I did review it and helped shape its contents and generally subscribe to its message :) In particular you are correct, and specifically GPG's MDC thing is some weird nonsense that does not deserve to be in use in 2019, let alone being in a product that describes itself as hav…

Setting aside the technical issues for a moment, your last point is interesting to me.

One of the things that bugs me about security/privacy discussions is the rampant paranoia and misinformation, and it tends to be the louder voice in the discussions lately. I have to wonder if Protonmail being such a visible figure means that it attracts people who're inclined to fall under the aforementioned.

i.e, the people who use Protonmail for mostly innocuous reasons just don't say anything, so the poorly informed bits float to the top.

It's like apartment ratings, I guess - nobody writes a rating for a good one.

Disclaimer: I interviewed with PM last year and was offered a role, but for various life reasons didn't take it. They're pretty smart people though so I'm inclined to give the team the benefit of the doubt - I don't think any of this influences my comment above, but worth noting.

Re: ProtonMail takes aim at Google with an encrypted calendar

#105
post #53

Earlier quoted context omitted.

Calendars are software so directly related to time, I'm not surprised. There are so many edge cases. Timezones, daylight savings time. The fact that so many regions don't use the same standards. We alter year length with leap years and doing things like adding leap seconds. Time is a nightmare to program around.

I somewhat believe our society would be easier if we had a better, simpler standard for time.

there are a lot of reasons why you probably couldn't come up with a better time standard, but the most compelling to me is this: no matter how elegant the new system is, everything would still need to be backwards compatible with "legacy" time. unless your calendar only needs to handle dates after the new standard was introduced, the implementation will be more complicated than just sticking with the shitty system we already have.

Re: ProtonMail takes aim at Google with an encrypted calendar

#106
post #24
post #3

Did anyone else notice ProtonMail being used in the movie "Knives Out" to send the ransom note? Cracked me up..

Not that surprising. It was also shown on mr. robot a few years ago.

mr robot is uncommonly good about depicting technology and security practices. it also shows elliot booting into kali linux, despite most viewers having no idea what that is.

Re: ProtonMail takes aim at Google with an encrypted calendar

#107

I lost a lot of faith in Proton when I learned how much funding they took from the EU. It just runs entirely counter to evidence we’ve seen of Snowden, 5eyes/14eyes, and other programs that the EU truly wants end to end encrypted comms for people. Am I wrong to be skeptical? Edit: oh apparently I’m wrong to even suggest something we have other examples of

you could say the same thing about tor, which was originally developed by the us military. it could be a long-term honeypot with backdoors, or it could be that giving it to the general public makes it more useful for state-sponsored clandestine operations. hard to say, really.

Re: ProtonMail takes aim at Google with an encrypted calendar

#108
post #53

Earlier quoted context omitted.

I somewhat believe our society would be easier if we had a better, simpler standard for time.

there are a lot of reasons why you probably couldn't come up with a better time standard, but the most compelling to me is this: no matter how elegant the new system is, everything would still need to be backwards compatible with "legacy" time. unless your calendar only needs to handle dates after the new standard was introduced, the implementation will be more complicated than just sticking with the shitty system we…

I think the only realistic strict improvement is abolishing Daylight Savings Time everywhere. In a calendar, you don't really care about past events, though a good calendar will probably need to handle it, but most people would benefit from eliminating that occasional complexity.

Re: ProtonMail takes aim at Google with an encrypted calendar

#109
post #85
post #53

Earlier quoted context omitted.

I somewhat believe our society would be easier if we had a better, simpler standard for time.

I've spent much more time than I care to admit researching calendars, the general counting of time from seconds to centuries — actually, ahem, from the Planck time unit to the age of the universe. I find that there would be elegance in having a metric system aligned with "natural" dimensionless units, orders of magnitudes. Suffice it to say, not only are you 100% right, but there are many easier and better systems we…

I have similar thoughts thinking about currency. It seems incredible to me that we (in the UK) ever managed to pull off decimalization!

Re: ProtonMail takes aim at Google with an encrypted calendar

#110

I recently left ProtonMail and went back to Fastmail. My reason was that they will never be able to fully support IMAP and now CalDAV because of the encryption they use. I grew to accept that email is not for secure messaging and my paranoia of "I'm being watched" just went away. If you need secure messaging, use something other than email.

Same here. Unless all parties use the same encrypted email service, this made no sense to me actually.
Post reply on HN