Earlier quoted context omitted.
> when can you claim something as secure? here’s a maybe wild take, uh, never?
But you'd agree with me that some things are more secure than others right?
Security experts declare all Proton apps secure after security audit
21–30 of 49 posts
Re: Security experts declare all Proton apps secure after security audit
#22Earlier quoted context omitted.
I agree with you that the title is a bit sensationalist. But if independent security audits with no major issues uncovered cannot make you claim something is secure, when can you claim something as secure? Or are you of the opinion that nothing ever can be claimed to be secure as there can always be holes that could be uncovered in the future? Using openssh as an example, would you say it's secure when you're using p…
> But if independent security audits with no major issues uncovered cannot make you claim something is secure, when can you claim something as secure? Nothing at all; it's a broken model. The server can at any time start serving malicious payloads [0]. The server hosts your mail but they also serve the webapp. The clientside decrypts the mail, but the server hosts the client code... It's a fundamentally flawed idea,…
[0] https://mullvad.net/en/blog/2019/6/3/system-transparency-fut...
Re: Security experts declare all Proton apps secure after security audit
#23If you cover your ass in a headline, which ultimately ends as legalese, the average person will completely ignore it due to wordiness or they will become suspicious and assume the worst.
The body and attachments do not mislead at all and that should be commended.
All this pedantry is counterproductive unless you truly know and trust your audience. Proton should be for the masses, not just for the technically adept.
Re: Security experts declare all Proton apps secure after security audit
#24Earlier quoted context omitted.
I agree with you that the title is a bit sensationalist. But if independent security audits with no major issues uncovered cannot make you claim something is secure, when can you claim something as secure? Or are you of the opinion that nothing ever can be claimed to be secure as there can always be holes that could be uncovered in the future? Using openssh as an example, would you say it's secure when you're using p…
> But if independent security audits with no major issues uncovered cannot make you claim something is secure, when can you claim something as secure? Nothing at all; it's a broken model. The server can at any time start serving malicious payloads [0]. The server hosts your mail but they also serve the webapp. The clientside decrypts the mail, but the server hosts the client code... It's a fundamentally flawed idea,…
Re: Security experts declare all Proton apps secure after security audit
#25Earlier quoted context omitted.
> But if independent security audits with no major issues uncovered cannot make you claim something is secure, when can you claim something as secure? Nothing at all; it's a broken model. The server can at any time start serving malicious payloads [0]. The server hosts your mail but they also serve the webapp. The clientside decrypts the mail, but the server hosts the client code... It's a fundamentally flawed idea,…
It appears the audit was applied to the Android and iOS apps. So no comment is being made here about the security of the webapp.
Re: Security experts declare all Proton apps secure after security audit
#26Earlier quoted context omitted.
> But if independent security audits with no major issues uncovered cannot make you claim something is secure, when can you claim something as secure? Nothing at all; it's a broken model. The server can at any time start serving malicious payloads [0]. The server hosts your mail but they also serve the webapp. The clientside decrypts the mail, but the server hosts the client code... It's a fundamentally flawed idea,…
Secure email is snake oil; no amount of cruft can make it both reasonable secure and useful (as in federated). Other protocols better fill that space because they were designed for security needs.
If you do trust the server then it can be acceptably secure.
Re: Security experts declare all Proton apps secure after security audit
#27Declaring it secure after an audit is like writing 100% coverage tests and saying it's bug-free. You can't prove absence, only presence. This title is the definition of sensationalism and only by reading the article do you find the truth: "Their tests uncovered no major issues or security vulnerabilities". This is a bad look for them and I'm wary of their company now...
I agree with you that the title is a bit sensationalist. But if independent security audits with no major issues uncovered cannot make you claim something is secure, when can you claim something as secure? Or are you of the opinion that nothing ever can be claimed to be secure as there can always be holes that could be uncovered in the future? Using openssh as an example, would you say it's secure when you're using p…
Re: Security experts declare all Proton apps secure after security audit
#28Declaring it secure after an audit is like writing 100% coverage tests and saying it's bug-free. You can't prove absence, only presence. This title is the definition of sensationalism and only by reading the article do you find the truth: "Their tests uncovered no major issues or security vulnerabilities". This is a bad look for them and I'm wary of their company now...
I agree with you that the title is a bit sensationalist. But if independent security audits with no major issues uncovered cannot make you claim something is secure, when can you claim something as secure? Or are you of the opinion that nothing ever can be claimed to be secure as there can always be holes that could be uncovered in the future? Using openssh as an example, would you say it's secure when you're using p…
Re: Security experts declare all Proton apps secure after security audit
#29More over "Tests have been carried out in September 2021 in accordance with generally accepted methodologies, including OWASP Top 10 and SANS Top Issues".
It's hard to believe that one can call apps being secured after pen testing especially when the two highlights are such low hang fruits that are OWASP top 10 and SANS top issues..
It doesn't really give any confidences into Proton, but then again, I am not an expert, and have seen such useless reports at different clients.
Re: Security experts declare all Proton apps secure after security audit
#30ProtonMail has a bad history of irresponsible sensationalism. It’s like constantly marketing yourself as the most private e-mail service “built by CERN scientists” but who will give information about you to authorities: https://www.engadget.com/protonmail-climate-activist-ip-swis... I know that ProtonMail doesn’t claim to protect your IP address, but I don’t expect the average user to make that distinction. This is a…