Live data from Hacker News

Protonmail Recommended Browsers

proton.me

131–140 of 154 posts

Re: Protonmail Recommended Browsers

#131
post #72

Earlier quoted context omitted.

Disclaimer: I do consulting work for Brave. Opinions my own. Maintaining a browser is a huge amount of work. The web evolves constantly and security fixes are extremely important. Being competitive in the space requires a very large amount of engineering resources. A commercial entity has a sustainable path to providing those resources. While nobody likes ads, I think they're opt-in in Brave and at the end of the day…

> Most of Brave is developed in the open. Where it isn't, there are good reasons why such as for example security. I don't think you can muster a good security reason for not developing something in the open.

[deleted]

Re: Protonmail Recommended Browsers

#132

Earlier quoted context omitted.

Disclaimer: I do consulting work for Brave. Opinions my own. Maintaining a browser is a huge amount of work. The web evolves constantly and security fixes are extremely important. Being competitive in the space requires a very large amount of engineering resources. A commercial entity has a sustainable path to providing those resources. While nobody likes ads, I think they're opt-in in Brave and at the end of the day…

> A commercial entity has a sustainable path to providing those resources.... [...] > ...having seen some of the internal discussions, I trust Brave a lot when it comes to privacy. I felt similarly about Google while I worked there. There were and still are a great many very skilled people focusing on security and privacy within Google, with good intentions. I personally had my own work vetted multiple times for secu…

One difference between Google and Brave is that Brave has privacy as its selling point to users. If they compromise on that, then they will become less attractive to users. As such, they are much better aligned with users when it comes to privacy. I would say that actually is a structural reason.

Re: Protonmail Recommended Browsers

#133
post #127

I was until recently using protonmail for throwaway email addresses for various web forums as it allowed a captcha verification during creation. Every other one I'd tried demands SMS verification these days, which is right out. But proton mail recently changed and requires SMS or another email now, I believe they say it is to combat bots. I tried tutanota but it refuses to create an account at all over a VPN, or at l…

Were you using Tor Browser ? From Switzerland, I can create free Proton accounts by solving a captcha, if I'm using Safari or Firefox. But if I use Tor on the same computer, the only option is to enter a phone number.

No, just VPN. Although my endpoint wasn't Switzerland. I still had email verification as an option in my case.

This was a very recent (within last week) change I noticed though.

Re: Protonmail Recommended Browsers

#134

Earlier quoted context omitted.

Apple collects your browsing history, something which I have yet to find a good explanation for. https://apps.apple.com/zm/app/safari/id1146562112

Safari history and tabs are end-to-end encrypted: https://support.apple.com/en-us/HT202303 And Apple provides iCloud+ members with a VPN which does not tie browsing history to users by separating ingress and egress traffic and using encrypted forwarding (similar to onion routing): https://www.apple.com/privacy/docs/iCloud_Private_Relay_Over...

>Safari history and tabs are end-to-end encrypted: https://support.apple.com/en-us/HT202303

They are for iCloud backup, which is not the same as the data collected by the App AFAIK.

Re: Protonmail Recommended Browsers

#135

What’s wrong with Safari privacy-wise?

Probably nothing; Apple talks a good privacy talk and I always recommend Apple products to my non-nerd friends and family because of it. HOWEVER, I can't really get past the fact that it's closed source. At the end of the day, that means that Apple can say they do XYZ practice, and it's very likely to be true (some is testable, and imagine the shit-storm if a whistle blower showed that they really do store your keys,…

> Apple talks a good privacy talk

but they don't walk the talk

Re: Protonmail Recommended Browsers

#136

Earlier quoted context omitted.

Safari history and tabs are end-to-end encrypted: https://support.apple.com/en-us/HT202303 And Apple provides iCloud+ members with a VPN which does not tie browsing history to users by separating ingress and egress traffic and using encrypted forwarding (similar to onion routing): https://www.apple.com/privacy/docs/iCloud_Private_Relay_Over...

>Safari history and tabs are end-to-end encrypted: https://support.apple.com/en-us/HT202303 They are for iCloud backup, which is not the same as the data collected by the App AFAIK.

iCloud backup is not end to end encrypted. iCloud sync of Safari History, Tab Groups, and iCloud Tabs is. The data collection the app page mentioned sounds like a 3rd thing. Or even E2EE is considered data collection for App Store purposes.

Re: Protonmail Recommended Browsers

#137

Earlier quoted context omitted.

Their iCloud security page says “Safari History, Tab Groups, and iCloud Tabs” is end-to-end encrypted. So they store history to sync across devices but the keys are only on your devices. https://support.apple.com/en-us/HT202303

Are the "keys" just your iCloud password (or a deterministic derivative thereof)? Otherwise, how could your tabs magically appear on a new device?

The keys are encrypted with your device pass codes. Setting up a new device requires the pass code from another device.

Re: Protonmail Recommended Browsers

#138

Earlier quoted context omitted.

Their iCloud security page says “Safari History, Tab Groups, and iCloud Tabs” is end-to-end encrypted. So they store history to sync across devices but the keys are only on your devices. https://support.apple.com/en-us/HT202303

Are the "keys" just your iCloud password (or a deterministic derivative thereof)? Otherwise, how could your tabs magically appear on a new device?

Nope, they are not your iCloud password. Keys for E2E items are kept on device and then there’s a process to join a signing circle for syncing. What this means in practice is to sync you need to allow your new device to be accepted into the circle from an existing device.

https://support.apple.com/en-gb/guide/security/sec0a319b35f/...

Re: Protonmail Recommended Browsers

#139
post #86
post #72

Earlier quoted context omitted.

> Most of Brave is developed in the open. Where it isn't, there are good reasons why such as for example security. I don't think you can muster a good security reason for not developing something in the open.

It's normal in any open source project to keep security mailing lists and things of that nature private. And for good reasons. One of the reasons is they are dealing with security related bug reports. Public disclosure before having a fix in place puts users at risk. Besides that 'security' is a process that all groups are responsible for. So it can't help being _developed_ in the open if the project is open. Which B…

I agree with the above. I guess I interpreted the comment as saying some code parts of Brave are not open for security reasons. I don't actually know whether this is true or not.

Re: Protonmail Recommended Browsers

#140
post #3

It's good to see Firefox on top of this list. Is Protonmail usually accessed through web clients? I only use native iOS client and MacOS Mail with the Bridge app. Somehow I would expect Protonmail users to not use the web client so much, maybe I am wrong.

Web client on desktop, native app on my phone. It's the easiest. I use Protonmail because it's not Google and pleasant enough to use.

same here, web client on desktop, app on phone.
Post reply on HN