Live data from Hacker News

Why ProtonMail is more secure than Gmail

protonmail.com

161–170 of 314 posts

Re: Why ProtonMail is more secure than Gmail

#161

I gave up on ProtonMail. The lack of a calendar means you often need to go back to using Google Calendar or Outlook.com Calendar, kind of negating the privacy benefits if you're a heavy calendar user. Secondly, its been years and you still can't store more than a single email address for a contact. This is so incredibly ridiculous that I have an extremely hard time understanding how they get away with charging what t…

Why would you expect an email provider to also provide a calendar?

There are many business, coordination, and communication tools that could be in my mail client (I do a lot of billing over email, is an email provider unusable if it doesn't integrate Quickbooks-like functionality too? What about shipping/receiving, project management, phone, SMS, mapping, etc, all things related to my use of email?), but I don't think they need to be there.

Calendar protocols are not federated like email. Choose between Exchange, Google, and iCloud. You'll have an easier time if you use the same one as most of your contacts.

Choose the best tool for the job. It's not likely that one provider will have the best tool for everything that, say, Outlook does.

Re: Why ProtonMail is more secure than Gmail

#162

Earlier quoted context omitted.

Uncle Sam can root your machine. If Uncle Sam is the threat vector you're better off using pen and paper.

This comment seems to conflate resistance to mass surveillance with resistance to targeted surveillance. It's almost as if the fact that I'll never be able to resist a targeted attack means that I shouldn't attempt to have any privacy at all, but surely that's not right. Encrypted messaging apps and services like ProtonMail have never been primarily to help people with Snowden's threat model. They're for people like…

> They're for people like you and me to reclaim a semblance of privacy, and they work even with "Uncle Sam" as the threat model in a limited, dragnet surveillance sense.

They don't work, because the US government's modus operandi is compromising machines or forcing users to provide access to their encrypted data. It's unclear to me why, if you take as premise a government capable of forcing one of the most valuable organizations in the world to hand over its data, you believe a company several orders of magnitude smaller is safe because it's "end to end encrypted" and has servers in Switzerland.

Put another way, I find the concept of a government willing to force Google to give up data but unwilling to use operational vulnerabilities to achieve the same thing to be contrived - how is this not just an arbitrary line in the sand?

Furthermore, the heuristic itself is a red herring, in my opinion. It is far more likely that Protonmail has a critical security vulnerability inherent to its software than Gmail does. And even if we assume that the government doesn't want to spend economic resources on actively compromising you as an individual, why would the government not spend resources on a system to compromise you passively as part of an en masse campaign? In other words, are you using a custom built computer with parts designed by a boutique firm from another country immune to the wiles of government backdoors?

How do you decide where you want to stop down the rabbit hole, and are you really doing so empirically?

Re: Why ProtonMail is more secure than Gmail

#163

Earlier quoted context omitted.

That sounds a bit formalistic and abstract to me. Perhaps you could educate us on which specific threats you think we should pay attention to when choosing between Gmail and Protonmail. What are some specific threats that Gmail defends us against more effectively than Protonmail?

Off the top of my head I think the number 1 "threat" that Google doesn't protect you from is privacy. They are actively watching your email with algorithms to use for advertising purposes. On the other hand, they have more resources than anyone else to protect against things like DDOS, nation-state hacking/phishing, and physical disasters. They also have a legion of lawyers to protect against improper legal requests,…

I think the right size of any security engineering team is largely determined by the diversity of threats it has to defend against. Same for the legal team.

So team size alone doesn't convince me one way or the other, even if I were to completely disregard all privacy issues.

I am a Gmail user as is my company, so I do trust them quite a bit. But I feel that Google has a much bigger problem on its hands than Protonmail. Both because of its business model and because Gmail does things like search and spam filtering, which Protonmail cannot do.

[Edit] Protonmail actually does spam filtering.

Re: Why ProtonMail is more secure than Gmail

#164
post #158

Earlier quoted context omitted.

ProtonMail has a publicly available threat model: https://protonmail.com/blog/protonmail-threat-model/ Without a threat model (that is, the set of threats that one is trying to secure a system against), you have no idea what someone means by "secure". It could mean unpickable doorlocks, it could mean unbreakable windows, it could mean angry-Hippopotamus-proofing. It could mean that you smelly farts can't escape your…

Any claim of security without a thread-model I'm not sure I understand what your counterpoint here is since we seem to be saying the same thing but I had to go back and fix 'thread model' twice myself. An underestimated threat model to commenting about threat models!

I am sorry, I misread your comment slightly, which resulted in the polar opposite meaning. English is a fun language. :)

Re: Why ProtonMail is more secure than Gmail

#165
post #142

Earlier quoted context omitted.

The HN community has quite a wide variety of views and tends to value civil, considered, constructive discourse (as well as refraining from commenting on down votes). Tone as well as content go a long way: there have been plenty of comments over the years that are critical of Snowden. Choosing to use a pejorative nickname and phrases like "HN worships" don't do anything to promote your argument. You're choosing to pa…

You seem to have good writing skills. Can you now respond to my post whereby I’ve made the claim that Snowden has committed treason, weakened US national security, and possibly ticked off a decline in interest for working for US intelligence? If the public is aware of our intel capabilities as a direct result of Snowden’s action, it seems close to certain that my points are correct.

I think all of the points you raise are worth discussing. Of particularly interest to me is figuring out how to have discussions on contentious topics in a constructive manner, which is why I commented here. Whether or not I'm effective in this, I do know that I haven't done enough research to weigh in responsibly on Snowden or the other points you raise. (For example, to be effective, I would want to have some facts at hand with respect to education levels and curriculum of high school students in St. Petersburg, Russia, undergrads in the US, rates of entry into the intelligence services over time, etc. I don't have such and am not sufficiently motivated to look them up). I do believe that the points you make in this comment are much more likely to result in a better discussion. Thank you for that!

Re: Why ProtonMail is more secure than Gmail

#166

While I love ProtonMail as an effort to popularize security for end-users and trying to come up with smart technologies to achieve that, the whole risk model behind the writeup barely stands scrutiny. What's worrying, ProtonMail (who declare security a first-class feature) use "features" instead of systems to define security of their service. If you think of it for a second, web crypto (protection against intermediar…

PM team here, we just made an account to comment.

We actually agree with some of the points made above, but we'd like to add the following commentary...

Encrypting email while making it more usable than PGP is hard. There's no getting around that. Web crypto is always going to have some shortcomings, but web mail is on the rise, and at the end of the day, web crypto is better than no crypto.

That said, we have been working for some years towards moving ProtonMail encryption entirely to the local environment using our Bridge application, which will be released soon. There is also extensive R&D being done on end-to-end authentication and ensuring key validity.

You are correct in that it is not a level playing field. This is why the tech industry is fast becoming an oligarchy or even a monopoly, owned and controlled by a few big players. However, we think that not playing is taking the easy way out, so even though the game is 'rigged' against us, we have a great team of engineers who have decided to play anyways.

Re: Why ProtonMail is more secure than Gmail

#167

I gave up on ProtonMail. The lack of a calendar means you often need to go back to using Google Calendar or Outlook.com Calendar, kind of negating the privacy benefits if you're a heavy calendar user. Secondly, its been years and you still can't store more than a single email address for a contact. This is so incredibly ridiculous that I have an extremely hard time understanding how they get away with charging what t…

I'm optimistic about ProtonMail in the long run, but won't use it until it gets out of my browser and onto a native app on my desktop.

If UI problems bother you, and you need a calendar, you can use mailbox.org which (1) can encrypt incoming emails w/ your GPG key, (2) offers SMTP so you can use Thunderbird, (3) comes with a calendar you can use on thunderbird/your phone via network.

They're also based in Germany, which is nice.

Re: Why ProtonMail is more secure than Gmail

#168
"ProtonMail uses Zero Knowledge Encryption, which means it is technically impossible for us to decrypt user messages" is kind of false within the definition of "impossible". It is exactly as feasible for them to crack encryption as it is for any other party with an encryption and security background, so really this is "The only way for ProtonMail to read your email is by cracking it, which can be prohibitively time consuming" but really it won't be because the fact that "ProtonMail takes care of the security" means that if the service ever becomes mainstream popular, the proportion of people using easier-to-crack-than-should-reasonably-be-the-case password will skyrocket.

Re: Why ProtonMail is more secure than Gmail

#169

The meaningful differences come with costs too. “Zero knowledge” of email content means I can’t search my corpus of email without having all of that mail on a PC with a client that has a search feature. What’s a bigger risk to you? “End to end encryption” We’ve all had the PGP discussion. That adds a lot of complexity and a lot of cost and risk. Good luck searching it. “TLS transport” Welcome to 2017, this isn’t mean…

We are close to solving the search issue actually. With the ProtonMail Bridge, full body search can happen locally so the servers can remain "zero knowledge".
Post reply on HN