Earlier quoted context omitted.
Yup, for proton open source means client code only
I tend to think this is a fair trade-off for services like this because: 1) for end-to-end encrypted services, I think what you most want to verify is: is my data actually being encrypted with my keys before being sent over the network, which open-source clients allow you to do 2) you can't personally verify what code is running on a company's servers anyway and to a lesser extent: 3) there could be legitimate securi…
Proton Pass: Open-Source and Encrypted Password Manager App
111–114 of 114 posts
Re: Proton Pass: Open-Source and Encrypted Password Manager App
#112Earlier quoted context omitted.
Yup, for proton open source means client code only
I tend to think this is a fair trade-off for services like this because: 1) for end-to-end encrypted services, I think what you most want to verify is: is my data actually being encrypted with my keys before being sent over the network, which open-source clients allow you to do 2) you can't personally verify what code is running on a company's servers anyway and to a lesser extent: 3) there could be legitimate securi…
Re: Proton Pass: Open-Source and Encrypted Password Manager App
#113Earlier quoted context omitted.
I think in general one might consider "the cloud" to be virtual resources on hardware shared with third parties. So of course AWS/GCP/Azure, but DigitalOcean would probably also qualify since to my knowledge droplets are virtual servers on shared hardware. Although renting virtual resources on shared hardware can be convenient (much easier to provision virtual resources than real servers), there are a couple of drawb…
Yes, this is indeed what we mean. Proton does not use third-party providers for hosting encrypted user data. So none of the providers that people typically consider to be "cloud" such as AWS. What we do instead is own and operate all of our physical server hardware and network equipment in datacenters in Switzerland and Germany.
Re: Proton Pass: Open-Source and Encrypted Password Manager App
#114Earlier quoted context omitted.
Yes, this is indeed what we mean. Proton does not use third-party providers for hosting encrypted user data. So none of the providers that people typically consider to be "cloud" such as AWS. What we do instead is own and operate all of our physical server hardware and network equipment in datacenters in Switzerland and Germany.
With properly managed encryption, it shouldn't matter to which cloud (yours or theirs) the data goes to.
Mistakes happen in the most secure systems. The more layers of defense you have, the less likely a mistake causes an incident.