Live data from Hacker News

Protonmail can delete the wrong email and nobody cares

github.com

101–110 of 254 posts

Re: Protonmail can delete the wrong email and nobody cares

#102

This is such a serious bug in the context of email that the surely must take this out of stable status?

They don't have anything to replace it with yet. They appear happy to leave it in place being buggy instead of removing it and really upset a lot of people.

Re: Protonmail can delete the wrong email and nobody cares

#103
post #74

Could the title be update to contain the word bridge as the issue is in the Protonmail bridge application and not on Protonmail itself. The entire title is clickbaity, but adding the birdge moves it away from being misleading.

Read the issues, it’s happening to people using the web ui too.

I don't think that was the intention of the submitter, but IMO it's significant enough that you providing a link to such an issue would be welcome and appreciated.

Re: Protonmail can delete the wrong email and nobody cares

#104
post #8

They also don’t care about locking you permanently out of your own e-Mail with no warning, for no reason, with no recourse. Honestly - there are far better options out there. They’re not in anyway a responsible enough business to manage an e-mail service. It’s run more like a hobby project than critical infrastructure.

What are those better options that HN likes? I just switched all my accounts to protonmail, but stories like this make me want to reconsider. The fact that they won't allow me to set up a forwarding rule in case I want to switch again doesn't help.

I've been using Purelymail for quite a while now and I've been happy with it.

Re: Protonmail can delete the wrong email and nobody cares

#105
post #90

Earlier quoted context omitted.

Can hashes not collide? Would that not cause problems?

In practice the odds can be astronomically low, as in lower than the odds that an asteroid collides with Earth right now and the entire humanity becomes extinct. But only for hashes without known vulnerabilities. For a vulnerable hash like md5, an attacker can find a collision in a few seconds.

I only say this in case anyone reads your message and gets the wrong idea. Currently, there is no feasible preimage attack for MD5. You can easily generate two colliding inputs, but cannot, given a hash, find an input to generate that hash.

And I don't believe that accidental MD5 collisions are something to worry about.

Re: Protonmail can delete the wrong email and nobody cares

#108
Not specific to this bug, but I recently setup a hosted Protonmail account with a custom domain and got myself and my wife on it because we do not trust G suite and don’t want all our eggs in one basket.

We both use the native mobile app and web based mail client.

In general it’s useable but the search functionality is useless. I’m hoping they’ll improve it.

Re: Protonmail can delete the wrong email and nobody cares

#109
I've suffered from exactly the same issues with Protonmail Bridge, and just this last weekend I decided (reluctantly) to move to a more standard mail provider (I chose Mailbox.org).

Aside from the UID issue discussed I also had problems with Bridge not supporting my particular use-cases. I created my own fork (see https://github.com/polaris64/proton-bridge) to work around some limitations and to add features, but maintaining this was too much work, especially as paying for a mail provider was supposed to reduce maintenance burden. I have had a pull request open since the 23rd of June to merge these to the upstream version, but so far I haven't received any comments from the Proton team.

I like ProtonMail, I just wish Bridge was more standards-compliant.

Post reply on HN