Live data from Hacker News

Why ProtonMail is more secure than Gmail

protonmail.com

181–190 of 314 posts

Re: Why ProtonMail is more secure than Gmail

#181

Earlier quoted context omitted.

Right, Snowden weakened US national security. He clued in the public to important secrets related to our intel operations, and ticked off public backlash against our intelligence agencies. Now, Snowden sits comfortably in a country who is actively hacking us. I’d bet my life that high school students from St. Petersburg have more reverse engineering skills than all US undergrads, at least those who are now interested…

Just watch how I get down voted here. Tells you a lot about the culture here.

A new account introducing a very loaded topic that has been discussed over and over again as a tangent doesn't stand much chance. Going after other commenters because of their presumed nationality really doesn't help.

Re: Why ProtonMail is more secure than Gmail

#182
post #83
post #57

Earlier quoted context omitted.

I think what's telling here is that the blog post does not point to Protonmail's own threat model. https://protonmail.com/blog/protonmail-threat-model/ Which says don't use it if you are up against state actors and: "Sensitive business communications – You have sensitive business information that you want to make sure is protected from competitors and other malicious parties. For example, you fear a competitor may wa…

I'm not sure there is a legal mechanism to force ProtonMail to add a backdoor... > "Nearly every country in the world has laws governing lawful interception of electronic communications. In Switzerland, these regulations are set out in the Swiss Federal Act on the Surveillance of Postal and Telecommunications Traffic (SPTT) last revised in 2012. In the SPTT, the obligation to provide the technical means for lawful in…

ProtonMail has never painted an accurate picture of the surveillance requirements in Switzerland – and laws have been and are changing too.

Switzerland is not an island of privacy with regard to state surveillance – and with regard to private data privacy, it basically mirrors the European Union’s standard. According to Snowden documents, Swiss intelligence and security services are close partners with the NSA and other foreign services.

Re: Why ProtonMail is more secure than Gmail

#183
post #92
post #74

Anyone remember HushMail? The end-to-end encrypted email service that didn't have the ability to decrypt your emails? They were eventually coerced to change their code and record passwords in order to gain access to an encrypted email account. ProtonMail is the same thing, give or take, just in Switzerland. They can be coerced just like anyone else. People whose lives are dependent on secure communication still need…

I'm not sure there is a legal mechanism to force ProtonMail to add a backdoor... > "Nearly every country in the world has laws governing lawful interception of electronic communications. In Switzerland, these regulations are set out in the Swiss Federal Act on the Surveillance of Postal and Telecommunications Traffic (SPTT) last revised in 2012. In the SPTT, the obligation to provide the technical means for lawful in…

Not all governments restrict themselves to legal means. Turkey for example has recently started abusing Interpol search warrants to go after people outside their jurisdiction. The country of citizenship is usually clued in and is resisting but dare to go on vacation in a another country.

Not all actions of the US government have survived legal review and some may argue the latest administration is more prone to such accidents.

Re: Why ProtonMail is more secure than Gmail

#184
post #51

Web based encryption. Pointless. If you trust them enough not to send you bad Javascript, you trust them not to read your emails. You trust them with your private keys. If you trust them with all that why even encrypt the mail client side?

It's not about whether you trust them not to read your emails, its about whether they would be able to turn them over to anyone with a valid request. The decryption is local, they could send modified code specifically to you that returns whatever password you type in, but there's no legal mechanism for forcing that in switzerland and I imagine that practice wouldn't go unnoticed if they did it to comply with every request they got.

Re: Why ProtonMail is more secure than Gmail

#185
post #106
post #71

Earlier quoted context omitted.

This attack actually happened years ago at a company called Hushmail. Law enforcement had the encrypted email provider serve malicious code to the target which leaked the secret key.

Hushmail operates out of Canada, though. Jurisdiction matters a lot here since Switzerland has a reputation for making it difficult for foreign governments.

There is no such reputation.

Swiss authorities and security services cooperate closely with partners all over the world including the NSA. And there is a longstanding and working network of mutual legal assistance including the Convention on Cybercrime (CCC).

Re: Why ProtonMail is more secure than Gmail

#186
post #2

This post would be improved by discussing that their [threat model]( https://en.wikipedia.org/wiki/Threat_model ) is so different than Google's that it regards some of Google's business practices as threats. And that, in turn, there are threats that Google treats as much bigger threats, bringing their own world-class security team to. Calling this fundamental difference in approach "more secure" manipulates the less-…

That sounds a bit formalistic and abstract to me. Perhaps you could educate us on which specific threats you think we should pay attention to when choosing between Gmail and Protonmail. What are some specific threats that Gmail defends us against more effectively than Protonmail?

If Protonmail servers are hacked, it's game over (that could be mitigated by having verified client code, but at this time there's the web client that is served dynamically, and the mobile clients are closed source...). That is where Protonmail are at a huge disadvantage unless they have a really really good security team. Server hacking is done a dime a dozen nowadays.

Re: Why ProtonMail is more secure than Gmail

#187
post #51

Web based encryption. Pointless. If you trust them enough not to send you bad Javascript, you trust them not to read your emails. You trust them with your private keys. If you trust them with all that why even encrypt the mail client side?

Yep. And the same argument applies to their apps. We need an open standard with an app built by a trusted third party.

Re: Why ProtonMail is more secure than Gmail

#188

Earlier quoted context omitted.

Off the top of my head I think the number 1 "threat" that Google doesn't protect you from is privacy. They are actively watching your email with algorithms to use for advertising purposes. On the other hand, they have more resources than anyone else to protect against things like DDOS, nation-state hacking/phishing, and physical disasters. They also have a legion of lawyers to protect against improper legal requests,…

Except this is no longer true. Google does not read your gmail anymore. https://blog.google/products/gmail/g-suite-gains-traction-in...

From the link: "G Suite’s Gmail is already not used as input for ads personalization, and Google has decided to follow suit later this year in our free consumer Gmail service."

They are definitely still reading your gmail. How else would the spam and other filters work? They can also use it under this policy for anything but "ads personalization". Machine learning, Google product integration, other recommendation not deemed to be ads, refining your google profile, etc. A very narrow scope of exclusion.

Re: Why ProtonMail is more secure than Gmail

#189

Earlier quoted context omitted.

Denial of service (or access) is one of several possible security threats. Unauthorised access, content modification or deletion, impersonation, and several other categories of security policy violations are also fairly typical.

> Denial of service (or access) is one of several possible security threats. Unauthorised access, content modification or deletion, impersonation, and several other categories of security policy violations are also fairly typical. Most of the cases of people losing access to their Google account that I've seen are not ones which would could feasibly be induced by a dedicated attacker unless they already had access to…

Unusual access patterns or attempts may provoke lockouts.

Re: Why ProtonMail is more secure than Gmail

#190
post #185
post #106

Earlier quoted context omitted.

Hushmail operates out of Canada, though. Jurisdiction matters a lot here since Switzerland has a reputation for making it difficult for foreign governments.

There is no such reputation. Swiss authorities and security services cooperate closely with partners all over the world including the NSA. And there is a longstanding and working network of mutual legal assistance including the Convention on Cybercrime (CCC).

Cooperation isn't quite the same as cooperation. There's a world of difference between sharing intelligence on other countries and working together when conducting espionage elsewhere, vs actively attacking domestic targets. Rule of law is taken seriously, and government hacking is a thing - but the scope is very very narrow.
Post reply on HN