Live data from Hacker News

Security experts declare all Proton apps secure after security audit

protonmail.com

21–30 of 49 posts

Re: Security experts declare all Proton apps secure after security audit

#21

Earlier quoted context omitted.

> when can you claim something as secure? here’s a maybe wild take, uh, never?

But you'd agree with me that some things are more secure than others right?

I’d be willing to say “there are things with known exploits, there are things which employ techniques that are known not to be safe making them less secure, and the rest is more akin to Schrödinger's cat as far as secureness goes.”

Re: Security experts declare all Proton apps secure after security audit

#22

Earlier quoted context omitted.

I agree with you that the title is a bit sensationalist. But if independent security audits with no major issues uncovered cannot make you claim something is secure, when can you claim something as secure? Or are you of the opinion that nothing ever can be claimed to be secure as there can always be holes that could be uncovered in the future? Using openssh as an example, would you say it's secure when you're using p…

> But if independent security audits with no major issues uncovered cannot make you claim something is secure, when can you claim something as secure? Nothing at all; it's a broken model. The server can at any time start serving malicious payloads [0]. The server hosts your mail but they also serve the webapp. The clientside decrypts the mail, but the server hosts the client code... It's a fundamentally flawed idea,…

This is why I'm excited for 9elements and Mullvad's System Transparency[0][1] project. The goal is to let the end users know that your server is indeed running the code it says it's running. Of course, open firmware and hardware also plays a role in this as a server running binary blobs still has the potential for malicious code to be unknowingly run.

[0] https://mullvad.net/en/blog/2019/6/3/system-transparency-fut...

[1] https://www.system-transparency.org/

Re: Security experts declare all Proton apps secure after security audit

#23
So many complaints about the headline, but for the purpose of getting their point across to the masses and encouraging the use of as-secure-as-can-be-known software, it’s perfectly fine.

If you cover your ass in a headline, which ultimately ends as legalese, the average person will completely ignore it due to wordiness or they will become suspicious and assume the worst.

The body and attachments do not mislead at all and that should be commended.

All this pedantry is counterproductive unless you truly know and trust your audience. Proton should be for the masses, not just for the technically adept.

Re: Security experts declare all Proton apps secure after security audit

#24

Earlier quoted context omitted.

I agree with you that the title is a bit sensationalist. But if independent security audits with no major issues uncovered cannot make you claim something is secure, when can you claim something as secure? Or are you of the opinion that nothing ever can be claimed to be secure as there can always be holes that could be uncovered in the future? Using openssh as an example, would you say it's secure when you're using p…

> But if independent security audits with no major issues uncovered cannot make you claim something is secure, when can you claim something as secure? Nothing at all; it's a broken model. The server can at any time start serving malicious payloads [0]. The server hosts your mail but they also serve the webapp. The clientside decrypts the mail, but the server hosts the client code... It's a fundamentally flawed idea,…

Secure email is snake oil; no amount of cruft can make it both reasonable secure and useful (as in federated). Other protocols better fill that space because they were designed for security needs.

Re: Security experts declare all Proton apps secure after security audit

#25

Earlier quoted context omitted.

> But if independent security audits with no major issues uncovered cannot make you claim something is secure, when can you claim something as secure? Nothing at all; it's a broken model. The server can at any time start serving malicious payloads [0]. The server hosts your mail but they also serve the webapp. The clientside decrypts the mail, but the server hosts the client code... It's a fundamentally flawed idea,…

It appears the audit was applied to the Android and iOS apps. So no comment is being made here about the security of the webapp.

I thought that was just a wrapper around the website, to be honest. But regardless, the app still loads JS from the website and executes it, so it's still a backdoor possibility.

Re: Security experts declare all Proton apps secure after security audit

#26
post #24

Earlier quoted context omitted.

> But if independent security audits with no major issues uncovered cannot make you claim something is secure, when can you claim something as secure? Nothing at all; it's a broken model. The server can at any time start serving malicious payloads [0]. The server hosts your mail but they also serve the webapp. The clientside decrypts the mail, but the server hosts the client code... It's a fundamentally flawed idea,…

Secure email is snake oil; no amount of cruft can make it both reasonable secure and useful (as in federated). Other protocols better fill that space because they were designed for security needs.

End to end secure email definitely is, I agree. No matter what you have to trust the server. (Maybe a Tor-based email system would be better, where each user is their own server? reminds me of `cables`).

If you do trust the server then it can be acceptably secure.

Re: Security experts declare all Proton apps secure after security audit

#27

Declaring it secure after an audit is like writing 100% coverage tests and saying it's bug-free. You can't prove absence, only presence. This title is the definition of sensationalism and only by reading the article do you find the truth: "Their tests uncovered no major issues or security vulnerabilities". This is a bad look for them and I'm wary of their company now...

I agree with you that the title is a bit sensationalist. But if independent security audits with no major issues uncovered cannot make you claim something is secure, when can you claim something as secure? Or are you of the opinion that nothing ever can be claimed to be secure as there can always be holes that could be uncovered in the future? Using openssh as an example, would you say it's secure when you're using p…

[deleted]

Re: Security experts declare all Proton apps secure after security audit

#28

Declaring it secure after an audit is like writing 100% coverage tests and saying it's bug-free. You can't prove absence, only presence. This title is the definition of sensationalism and only by reading the article do you find the truth: "Their tests uncovered no major issues or security vulnerabilities". This is a bad look for them and I'm wary of their company now...

I agree with you that the title is a bit sensationalist. But if independent security audits with no major issues uncovered cannot make you claim something is secure, when can you claim something as secure? Or are you of the opinion that nothing ever can be claimed to be secure as there can always be holes that could be uncovered in the future? Using openssh as an example, would you say it's secure when you're using p…

I think if it it more like having a fire Marshall inspect a building, doesn’t mean it can’t catch fire the next day, but at least you know that it’s not death trap (smoke alarms, fire doors, sprinklers etc all check out)

Re: Security experts declare all Proton apps secure after security audit

#29
So a company called Securitum did a security assessment limited to pentest according to the pdf.

More over "Tests have been carried out in September 2021 in accordance with generally accepted methodologies, including OWASP Top 10 and SANS Top Issues".

It's hard to believe that one can call apps being secured after pen testing especially when the two highlights are such low hang fruits that are OWASP top 10 and SANS top issues..

It doesn't really give any confidences into Proton, but then again, I am not an expert, and have seen such useless reports at different clients.

Re: Security experts declare all Proton apps secure after security audit

#30

ProtonMail has a bad history of irresponsible sensationalism. It’s like constantly marketing yourself as the most private e-mail service “built by CERN scientists” but who will give information about you to authorities: https://www.engadget.com/protonmail-climate-activist-ip-swis... I know that ProtonMail doesn’t claim to protect your IP address, but I don’t expect the average user to make that distinction. This is a…

If you want protection from bad laws, vote for people who don't make bad laws to start with.
Post reply on HN