Live data from Hacker News

ProtonVPN

protonvpn.com

191–200 of 205 posts

Re: ProtonVPN

#191
Anyone knows how to use Protonmail to send/receive attachments encrypted by a different PGP key than Protonmail uses for one's account? It never allows to download such an attachment and I surely won't upload my private key there...

Re: ProtonVPN

#192
post #9

I have mixed feelings about protonmail. On the one hand, they tend to be on the right side of political / legal issues, and this transparency report is nice: https://protonmail.com/blog/transparency-report/ On the other hand, they recently reduced the level of detail in the transparency report. There is also the fact that they are Swiss, and their privacy laws were severely weakened by a recent referendum. In particu…

They updated the blog post here: https://protonmail.com/blog/swiss-surveillance-law/ Doesn't apply to ProtonMail and ProtonVpn.

Re: ProtonVPN

#193
post #103

Earlier quoted context omitted.

What would be a good jurisdiction for them?

Germany has very strong privacy laws which is one of the reasons Amazon dropped an AWS region there. Customers are paying a premium for the jurisdiction.

Those laws protect against commercial exploitation, but not against endeavours of law enforcement or intelligence services. "Vorratsdatenspeicherung" (data retention) law just took effect. In fact the BND doesn't care about the law at all. Fear driven neo-con politics are en vogue as everywhere else. I think the main difference is the civil opposition which is probably a tad more vocal and active than in non-EU or soon to be non-EU countries.

Re: ProtonVPN

#194
post #9

I have mixed feelings about protonmail. On the one hand, they tend to be on the right side of political / legal issues, and this transparency report is nice: https://protonmail.com/blog/transparency-report/ On the other hand, they recently reduced the level of detail in the transparency report. There is also the fact that they are Swiss, and their privacy laws were severely weakened by a recent referendum. In particu…

ProtonMail has pretty much stagnated and flat out refuses to cooperate with the community to implement new features of the OpenPGP email standards. Their Reddit guy is also pretty terrible, he pretty much insulted me in a comment after I criticized them.

ProtonMail would be happy to implement more of the OpenPGP encryption standard. Specifically, it would be great if someone would contribute ECC support to the opensource OpenPGPjs project that ProtonMail currently maintains. There are just not cycles to do it internally, right now. ProtonMail is far from idle. A number of new features and offerings are being worked on. For example, take the bridge application (currently in beta testing) that will allow integration with IMAP based applications like Microsoft Outlook.

If there's something that is a high priority for you personally to see (such as OpenPGP ECC algorithm support), I would ask that you take the time to submit it to the ProtonMail UserVoice page [ https://protonmail.uservoice.com/forums/284483-feedback ]. That page is monitored and the feedback received through UserVoice is considered and strongly influential. UserVoice has a great end user application and clarification effect that is difficult to experience through interacting with users through e-mail or traditional forum comments.

I don't believe I've seen the Reddit exchange that you are referring to (I don't personally visit that site very often). If someone using an official company account was rude to you, I sincerely apologize.

Re: ProtonVPN

#195
post #191

Anyone knows how to use Protonmail to send/receive attachments encrypted by a different PGP key than Protonmail uses for one's account? It never allows to download such an attachment and I surely won't upload my private key there...

Please report your difficulties to the Support Team: https://protonmail.com/support-form You don't need to be a paid user to do this. They will respond to your ticket. I have done this before - some time ago. But, perhaps a bug was introduced somewhere in the code or there is some other issue that you are running into (perhaps some configuration with the local platform). It should be possible and work correctly.

Re: ProtonVPN

#196
post #147

Too bad they're focused on new and shiny at the expense of real (paying) email users. After a year of Visionary, I finally went back to Google. PM just isn't designed for large mailboxes, real search, or navigation. Plus they still have not provided any way for you to export your emails out. They're locked up forever, unless you want to forward each one, one at a time.

Search has been dramatically improved. Difficulties with large mailboxes are often a complex function of many variables with things like client side javascript decryption speeds often playing a large role. While testing is done with large mailboxes as part of the development process, the ultimate solution for people with extremely large boxes will likely be the use of the Bridge program with an IMAP mail client such as Microsoft Outlook. There are unofficial export programs available that call pull all mail out through Proton's API. An official, supported, export (and import) program is planned for the future.

Re: ProtonVPN

#197
post #185

Earlier quoted context omitted.

I wondered about creating something very like that a couple of months ago. Check out my vapourware! http://digitalsnorkel.net/ I think a key problem may be that there aren't a whole lot of people who (a) understand the tech well enough to know they need this, and (b) don't understand the tech well enough to spin up a VPS and run a Bash script.

Interesting! How many sign-ups have you received?

Well, I never mentioned it to anyone until now ...

Re: ProtonVPN

#198
post #123

Earlier quoted context omitted.

I work in the field and anybody that says that a piece of software is secure before it has even had a security evaluation by a third party does not know what they are talking about. I think what you have seen is security people saying that the design of Wireguard seems to be equal or better than other, current, options, that doesn't mean that the implementation is just yet.

I agree with you. It needs formal evaluation by pros with time to dig into it with review and tool-assisted analysis. That said, a person as experienced at pentesting as tptacek saying the crypto and code looked good puts its trustworthiness above most options in my eyes. I mean, you rarely here good things about both in such software. The quality of average development in crypto is just that bad. I also liked what I…

The Wireguard protocol has been symbolically verified for correctness using Tamarin.

Re: ProtonVPN

#199

Earlier quoted context omitted.

I agree with you. It needs formal evaluation by pros with time to dig into it with review and tool-assisted analysis. That said, a person as experienced at pentesting as tptacek saying the crypto and code looked good puts its trustworthiness above most options in my eyes. I mean, you rarely here good things about both in such software. The quality of average development in crypto is just that bad. I also liked what I…

The Wireguard protocol has been symbolically verified for correctness using Tamarin.

Didn't know that. Thanks for the tip!

Re: ProtonVPN

#200
post #74

Earlier quoted context omitted.

Check out Mullvad. I haven't yet found a service that I think is slicker, more convenient, and more serious about privacy. You can generate unlimited free trials until you're confident you want to spend the paltry $5 a month on them. https://mullvad.net

I second this. I can't make any claims about the security of the client, but the way they handle things is confidence-inspiring. I have been in touch with them over some issues I have had,and the support is fantastic. I had an issue with mosh over my local network (SSH worked,mosh did not) and got a very detailed reply about why they treated LAN UDP packets that way, and why I was probably not affected since I ran a…

They definitely aren't just running a VPN to make a quick buck. The amount of guides and such that they offer for integration, etc. is confidence-inspiring as well.

What sold me was their mention of using Qubes OS in-house. They clearly give 100% fucks about keeping their infrastructure safe.

Post reply on HN