Live data from Hacker News

ProtonMail takes aim at Google with an encrypted calendar

venturebeat.com

111–120 of 154 posts

Re: ProtonMail takes aim at Google with an encrypted calendar

#111
post #97

I recently left ProtonMail and went back to Fastmail. My reason was that they will never be able to fully support IMAP and now CalDAV because of the encryption they use. I grew to accept that email is not for secure messaging and my paranoia of "I'm being watched" just went away. If you need secure messaging, use something other than email.

Same deal, I loved the service but I don’t love living in my browser. I wanted IMAP and eventually that meant installing an app that ran a local IMAP sever that your client needed to connect to. I suppose it’s a limitation of the protocol, and it’s good that protonmail doesn’t store your emails plaintext. However, they know the encryption keys...and so will any attacker. I went to the Office 365 email package because…

> However, they know the encryption keys...and so will any attacker.

I might be mistaken, but my understanding is that they encrypt your encryption keys using your password within the browser. They only store the encrypted blob and thus they are unable to decrypt any emails.

Having said that, since emails come in unencrypted anyway, they can, in theory, log everything there. Including the sender, receiver and what the email contains.

Re: ProtonMail takes aim at Google with an encrypted calendar

#112

I recently left ProtonMail and went back to Fastmail. My reason was that they will never be able to fully support IMAP and now CalDAV because of the encryption they use. I grew to accept that email is not for secure messaging and my paranoia of "I'm being watched" just went away. If you need secure messaging, use something other than email.

Please note that Fastmail is an Australian service. I would not trust Fastmail with my email privacy. Not because of the company, but because of the encryption laws in Australia.

Food for thought.

Re: ProtonMail takes aim at Google with an encrypted calendar

#113
post #53

Earlier quoted context omitted.

Calendars are software so directly related to time, I'm not surprised. There are so many edge cases. Timezones, daylight savings time. The fact that so many regions don't use the same standards. We alter year length with leap years and doing things like adding leap seconds. Time is a nightmare to program around.

I somewhat believe our society would be easier if we had a better, simpler standard for time.

Technically I’d agree. In practice I think people would progressively bring back crazy use cases and requests that would need to be dealt in the model.

For instance date formats are a complete mess only because people value different informations. Even in a countey with a single official representation, people will write checks with shorthands and mixing of different norms.

It’s also interesting to look at China would try to simplify pretty hard, and still ended up with a tangled mess (https://en.wikipedia.org/wiki/Time_in_China)

Re: ProtonMail takes aim at Google with an encrypted calendar

#114
post #112

I recently left ProtonMail and went back to Fastmail. My reason was that they will never be able to fully support IMAP and now CalDAV because of the encryption they use. I grew to accept that email is not for secure messaging and my paranoia of "I'm being watched" just went away. If you need secure messaging, use something other than email.

Please note that Fastmail is an Australian service. I would not trust Fastmail with my email privacy. Not because of the company, but because of the encryption laws in Australia. Food for thought.

[deleted]

Re: ProtonMail takes aim at Google with an encrypted calendar

#115
post #74
post #71

Earlier quoted context omitted.

IMO the burden should be on Google to prove that they don't. The flow of personal data through their systems is opaque and they have plenty of incentives to monetize the data.

You can't prove a negative.

We're not talking about mathematical or scientific levels of proof, but assurance and trust.

The usual methods for achieving this are government regulation and oversight (free of capture), and independent third-party audits (likewise).

The good news is that there seems to be ... some, slight ... progress in this direction.

Re: ProtonMail takes aim at Google with an encrypted calendar

#116

Earlier quoted context omitted.

I agree with most of what you have written, but this: > doesn't mean I want Google getting a free pass to mine and sell my data. AFAIK, they don't do that with gmail. Do you have any evidence to the contrary? We need to hold Google's feet to fire on privacy, but it is also important that we do not exaggerate or distort the facts.

Unlike most other responders, I generally trust Google not to do this. Everything they say they don't do has been confirmed to me one way or another by people working there that I trust. They may make money off ads but I don't think they have any real incentive to lie about what they're doing. Because most of their users don't actually care. I would be curious if anyone knows of any scenario where Google has outright…

What exact behavior of Google are we talking about here? I'm pretty sure they do mine emails for their own ad targeting. On the other hand, I'm equally sure they handle the information securely and don't pass it on to anyone else.

Re: ProtonMail takes aim at Google with an encrypted calendar

#118

Earlier quoted context omitted.

Unlike most other responders, I generally trust Google not to do this. Everything they say they don't do has been confirmed to me one way or another by people working there that I trust. They may make money off ads but I don't think they have any real incentive to lie about what they're doing. Because most of their users don't actually care. I would be curious if anyone knows of any scenario where Google has outright…

What exact behavior of Google are we talking about here? I'm pretty sure they do mine emails for their own ad targeting. On the other hand, I'm equally sure they handle the information securely and don't pass it on to anyone else.

> I'm pretty sure they do mine emails for their own ad targeting.

They do not. See https://support.google.com/mail/answer/6603?hl=en

"We will not scan or read your Gmail messages to show you ads."

Re: ProtonMail takes aim at Google with an encrypted calendar

#119
post #74
post #71

Earlier quoted context omitted.

IMO the burden should be on Google to prove that they don't. The flow of personal data through their systems is opaque and they have plenty of incentives to monetize the data.

You can't prove a negative.

Sure you can. Apple does not run its image classification on your images using its cloud servers. You can test this by stepping inside a microwave or other cage and seeing that image classification and search still works on the iPhone.

---

On the other hand, what Apple does with your photos that you allow to be exfiltrated through iCloud... that's your own stupid fault.

Re: ProtonMail takes aim at Google with an encrypted calendar

#120

Earlier quoted context omitted.

What exact behavior of Google are we talking about here? I'm pretty sure they do mine emails for their own ad targeting. On the other hand, I'm equally sure they handle the information securely and don't pass it on to anyone else.

> I'm pretty sure they do mine emails for their own ad targeting. They do not. See https://support.google.com/mail/answer/6603?hl=en "We will not scan or read your Gmail messages to show you ads."

Interesting, looks like they stopped in 2017.
Post reply on HN