Live data from Hacker News

ProtonMail takes aim at Google with an encrypted calendar

venturebeat.com

141–150 of 154 posts

Re: ProtonMail takes aim at Google with an encrypted calendar

#141
post #112

Earlier quoted context omitted.

Please note that Fastmail is an Australian service. I would not trust Fastmail with my email privacy. Not because of the company, but because of the encryption laws in Australia. Food for thought.

I don't understand. Email isn't encrypted is it? And what can the Australian government do that the US government can't these days?

Recent (2018) Australian data encryption laws are insane and archaic. It allows law enforcement to force individuals (including but not limited to developers) or companies to build a back door and requires them not to tell any one, including their employers. I'm not saying the US is better or worse, or that the UK (where I live) is better or worse. I'm raising awareness as not a lot of people know about their data encryption laws.

Personally I'd wanted to move to Australia but stopped chasing that due to their data encryption laws.

Re: ProtonMail takes aim at Google with an encrypted calendar

#142
post #112

Earlier quoted context omitted.

Please note that Fastmail is an Australian service. I would not trust Fastmail with my email privacy. Not because of the company, but because of the encryption laws in Australia. Food for thought.

Are you suggesting isp’s are more trustworthy in America? Because you’ve got to get your email over someone’s pipes eventually. Fastmail is excellent. If you want secure/private/not easily spoofable by a 5 year old and you’re using email.... then you’re doing it all wrong.

> Are you suggesting isp’s are more trustworthy in America?

Certainly not.

My comment is relating to their data encryption laws that was passed in 2018. If you care about your privacy in any way, shape or form, individuals should be very wary of using services that operate from, or are owned by individuals in Australia (and the rest of the 5 eyes for that matter) unless you have your encryption keys and all encryption happens on your client app.

Re: ProtonMail takes aim at Google with an encrypted calendar

#143
post #112

I recently left ProtonMail and went back to Fastmail. My reason was that they will never be able to fully support IMAP and now CalDAV because of the encryption they use. I grew to accept that email is not for secure messaging and my paranoia of "I'm being watched" just went away. If you need secure messaging, use something other than email.

Please note that Fastmail is an Australian service. I would not trust Fastmail with my email privacy. Not because of the company, but because of the encryption laws in Australia. Food for thought.

Reporting on Australia's encryption laws is wildly inaccurate. For one, it does not allow authorities to compel companies or individuals to introduce an encryption backdoor. The law very explicitly addresses this issue, see section 317ZG, which forbids any kind of "systematic weakness" or "systematic vulnerability" and very explicitly states that weakening encryption is included in those definitions.

What's permitted is to build something that targets a particular person in such a way that it cannot possibly affect another person's security.

The example I use (though IANAL) is that a request to backdoor WhatsApp's encryption would not be permitted under the law. However I think that pushing an update that checks for a particular person's hard-coded phone number and forwards messages to law enforcement would be permitted.

The law in question: http://www5.austlii.edu.au/au/legis/cth/consol_act/ta1997214...

Re: ProtonMail takes aim at Google with an encrypted calendar

#144
post #57

Earlier quoted context omitted.

My ProtonMail installation on Android supports PIN/fingerprint locking

They could definitely ask you to unlock it. It's why apps like 1password added a "Travel Mode" https://blog.1password.com/introducing-travel-mode-protect-y...

That's pretty cool! Similarly, couldn't you just uninstall the ProtonMail native app when traveling?

Re: ProtonMail takes aim at Google with an encrypted calendar

#145

Earlier quoted context omitted.

They already scan your purchases in your inbox: https://www.cnbc.com/2019/05/17/google-gmail-tracks-purchase... They say they won’t use it to sell ads: > “To help you easily view and keep track of your purchases, bookings and subscriptions in one place, we’ve created a private destination that can only be seen by you,” a Google spokesperson told CNBC. “You can delete this information at any time. We don’t use any inf…

> I have a hard time believing they would do it only for that. Why? Adding perceived values is how you get more users. More users == increased revenue. I think the important question is: if Google were doing something nefarious like that, why on earth would they tie it to a public feature instead of just keeping it totally secret?

But is that actually nefarious, or meaningfully proscribed, or is it not understood that this kind of stuff is how Google makes money, and how it will continue to make money into the future? Is this unacceptable to most people? I am uncomfortable with it, but isn't this the way "business is done?"

Re: ProtonMail takes aim at Google with an encrypted calendar

#147
post #102

Earlier quoted context omitted.

I didn't write https://latacora.micro.blog/2019/07/16/the-pgp-problem.html (the writing is too good, a giveaway that it's a 'tptacek joint) but I did review it and helped shape its contents and generally subscribe to its message :) In particular you are correct, and specifically GPG's MDC thing is some weird nonsense that does not deserve to be in use in 2019, let alone being in a product that describes itself as hav…

Setting aside the technical issues for a moment, your last point is interesting to me. One of the things that bugs me about security/privacy discussions is the rampant paranoia and misinformation, and it tends to be the louder voice in the discussions lately. I have to wonder if Protonmail being such a visible figure means that it attracts people who're inclined to fall under the aforementioned. i.e, the people who u…

Maybe! Certainly other environments with an emphasis on anonymity, pseudonymity or privacy in general have turned out to be terrible cesspools. But on the other hand, Signal and Whatsapp aren't. It's also not necessarily a broadcast-vs-1on1 problem: while I'm often frustrated with HN, it takes care of the white supremacists pretty effectively.

Re: ProtonMail takes aim at Google with an encrypted calendar

#148

Earlier quoted context omitted.

I'm not even sure it's all that great of a trick, considering that no amount of encryption and security on Proton's own servers or in their app can protect the contents of emails that are sent to (edit: or received from) someone who doesn't use Proton. I am a current customer and think they've got a really well-done service and app, but lately I've been wondering if it's the privacy equivalent of the Maginot Line.

Makes me wonder if its possible or reasonable to consider an option with protonmails (and similar) - have a note in the footer of the email - explaining that encrypted is default in their system, but sending to your email provider has it converted to plain text where others can access it.. if you'd like to keep this mail message private click to login to protonReadPortal - where you can read, and if you'd like make a…

You can already do that with protonmail. There are three buttons available when writing an email, doing exactly that.

Re: ProtonMail takes aim at Google with an encrypted calendar

#149
post #98

Earlier quoted context omitted.

If you want to build something which can't be compatible with popular standards, what is the better choice? Build it anyway, or let those standards stop you? It's the same reason I can't read my PGP-encrypted email on my phone.

Do what Fastmail did, and work with the community (generally via the IETF) to make your new standard open and compatible: https://fastmail.blog/2019/08/16/jmap-new-email-open-standar...

Good point, perhaps Proton will do so.

Re: ProtonMail takes aim at Google with an encrypted calendar

#150

I lost a lot of faith in Proton when I learned how much funding they took from the EU. It just runs entirely counter to evidence we’ve seen of Snowden, 5eyes/14eyes, and other programs that the EU truly wants end to end encrypted comms for people. Am I wrong to be skeptical? Edit: oh apparently I’m wrong to even suggest something we have other examples of

you could say the same thing about tor, which was originally developed by the us military. it could be a long-term honeypot with backdoors, or it could be that giving it to the general public makes it more useful for state-sponsored clandestine operations. hard to say, really.

You could say that, but it would be fundamentally misunderstanding why the US Government needs TOR users.

There is no extra safe guards to encrypted email that lives on a server the more users you add. It doesn't matter. It was a point to point transfer once. All emails are SSL/TLS sent anyhow.

TOR is a different thing. It's active user browsing. If only US spies (example) used TOR, it would be pretty damn obvious what they were doing or at least show that this was vital traffic to inercept. But add in millions of normal users and it's much easier to keep your nefarious deeds hidden by just blending in with the crowd.

Post reply on HN