Live data from Hacker News

ProtonMail includes Google Recaptcha for login

github.com

251–260 of 308 posts

Re: ProtonMail includes Google Recaptcha for login

#251

Earlier quoted context omitted.

A few clarifications. There is an export tool that is available. The reason we must count disabled addresses towards your quota is because if we did not do that, we would be susceptible to an attack where a paid user could run through our address space by creating and disabling addresses continuously, so some limits are required. You can remove disabled addresses, but only by contacting support.

This is a sort of weird reply. The person you're replying to isn't saying "you need to allow an attacker to create and disable millions of addresses to DOS you". They're saying "you need to allow medium to longer term clients that de-activate very small portions of their overall number of accounts to not have to pay for those". You already have a system to measure account numbers, so what makes it impossible to also…

Why would you not pay for deactivated accounts for which they’re still storing the data? I don’t think the delivery of email is what costs most money, it’s the storage of data.

Re: ProtonMail includes Google Recaptcha for login

#252

Earlier quoted context omitted.

> Obviously there could be a middle ground of allowing someone to deactivate 5 accounts per month or something. A improvement like this is indeed in our feature backlog, and something we hope to implement in the future.

Wow this response chain is so layed on thick with half answers and marketing speak. I guess you can now "hope" that I won't cancel my protonmail subscription.

I very much assume they wouldn’t care (or not more than you do anyway).

Re: ProtonMail includes Google Recaptcha for login

#253

A few comments about this. A very small fraction of logins get the CAPTCHA challenge. We, and other services, face unrelenting brute force attacks on our login endpoints. If you are seeing a CAPTCHA on login, chances are that something about your connection is suspicious to our system. It's far from perfect, and we continue to improve it, but at most a percent or two of users are seeing CAPTCHA at any time. The CAPTC…

I'm going to put you on a spot a bit, because this seems important to ProtonMail's viability, and I want you to keep succeeding...

> Obviously Google still gets some information, but we do all we can to limit this.

When you cause a request to be made for ReCaptcha, it seems that you're leaking enough information to (in many cases) link a possibly-pseudonymous Protonmail account to an identifiable individual.

(For example, even if you leak nothing else than times that individuals identifiable by Google logged into unidentified ProtonMail accounts, Google can already see various external activity of specific ProtonMail accounts, and you've given them temporal correlations between activity of pseudonymous accounts and logins by identifiable individuals. That's not the only example, but even that alone seems a significant risk.)

And it's seems to be a real risk: Google is in the business of doing things like that, has a track record of doing things like that, and presumably is more than capable enough of doing it some more.

> but at most a percent or two of users are seeing CAPTCHA at any time.

That sounds like a lot. And the "at any time" sounds like an even higher percentage of users are potentially being compromised by the use of ReCaptcha.

> we don't like it either

I'm not yet convinced that this is the least of all evils. And I don't know how much you have to dislike it before you decide not to do it.

For persuasive effect, is it helpful to imagine the reaction of your philosophical adversaries, when they heard that ProtonMail was using ReCaptcha? I just imagined some of them laughing derisively or incredulously. I don't say that to be mean, but I don't understand the rationale for using ReCaptcha, and I want to emphasize that it seems to be a problem that threatens ProtonMail's raison d'etre and/or brand image.

(BTW, I'm assuming this ReCaptcha choice isn't due to legally-compelled cooperation in unmasking specific accounts -- in which case I wouldn't say anything -- since, in that case, I expect you'd find a way to comply without misrepresenting the rationale to everyone else. I've seen ProtonMail thinking ahead to avoid related conflicting obligations and assurances.)

(BTW, I'm speaking here of Google as an adversary of your customers, and therefore of you, only because that seems to be how your product is positioned, and why you have customers at all, rather than everyone just using GMail. I'm not saying that Google is bad; only that I think it should be considered an adversary from your perspective.)

Re: ProtonMail includes Google Recaptcha for login

#254
post #97
post #47

When I started my company we chose to use Protonmail. My advice to anyone who wants secure email: don't use protonmail. The email search is completely useless. I don't understand how it can possibly be so difficult to do a substring search on a corpus and rank them in some kind of sane way. Searching for old emails based on content is an exercise in futility. After a few years of using an email service, search become…

It used to be the case that both ProtonMail and FastMail were frequently recommended on HN. So, how is FastMail doing in comparison?

Really happy with fastmail. It is above anything else, very fast.

Re: ProtonMail includes Google Recaptcha for login

#255

Earlier quoted context omitted.

I built a system that had all of a 100 or so users before some abuser came along. Limiting web abuse is a huge problem that requires solutions.

Would you be able to share what your solution looked like? Thanks in advance!

We just installed reCAPTCHA and blocked Tor IPs. Nothing that special.

Re: ProtonMail includes Google Recaptcha for login

#256

A few comments about this. A very small fraction of logins get the CAPTCHA challenge. We, and other services, face unrelenting brute force attacks on our login endpoints. If you are seeing a CAPTCHA on login, chances are that something about your connection is suspicious to our system. It's far from perfect, and we continue to improve it, but at most a percent or two of users are seeing CAPTCHA at any time. The CAPTC…

Why / Who is DDOS'ing protonmail? Is it just a consequence of having a sass a certain size that you become a target?

It's not DDOSing, it's credential stuffing[0]. Hackers find leaked databases which contain username/password pairs. They then try username@protonmail with the password from that database (or they just try the top 1000 most common password). If they get in, they suddenly have control over someone's email. From there they can password reset any of the user's other accounts, some of which might allow them to buy real world items.

The best mitigation as a user is to never reuse a password, however protonmail cannot enforce this. From their side the best option is to slow down the hackers as much as possible so it's less likely their more vulnerable users get compromised.

[0]: https://en.wikipedia.org/wiki/Credential_stuffing

Re: ProtonMail includes Google Recaptcha for login

#257
post #250
post #227

Earlier quoted context omitted.

So the ultimate risk of using ReCAPTCHA on proton mail is that Google might find out I'm more tech savvy than the average? Fine by me.

No, no. Now Google knows you are using ProtonMail, and by extension the NSA knows you are protonmail, the FBI knows you are using ProtonMail, and so on. This may or may not be a problem for you.

meh, if FBI is truly trying to track you down, they have an easier time accessing your ISP and mobile carrier logs to see what IPs you've been talking to.

Re: ProtonMail includes Google Recaptcha for login

#258
post #216
post #199

Earlier quoted context omitted.

You can't use that sort of username on HN—see https://hn.algolia.com/?sort=byDate&dateRange=all&type=comme... . I've banned the account for now, but if you want to use it with a different name, you're welcome to email hn@ycombinator.com and we'll get you fixed up. (btw, the GP mentions hcaptcha)

Not questioning this dang, but would be useful to add something about trollish usernames in the guidelines, and perhaps clarify what qualifies as trollish.

That belongs to a category of subrules or heuristics which are too numerous to list. If we tried to make the guidelines comprehensive that way, they would just get so long (or worse, so bureaucratic) that people wouldn't read them.

There's a limit to how much information one can get across that way, so we err on the side of explaining the spirit of the site and leave the 'case law' to specific moderation comments. One of these years I want to compile those into an extended FAQ or something, which could provide a home for the kind of documentation you're talking about.

If anyone is so weird as to want to read an entire 'essay' about this, I wrote one a couple days ago: https://news.ycombinator.com/item?id=27307680. The relevant subthread starts at https://news.ycombinator.com/item?id=27303886.

Re: ProtonMail includes Google Recaptcha for login

#259
post #253

A few comments about this. A very small fraction of logins get the CAPTCHA challenge. We, and other services, face unrelenting brute force attacks on our login endpoints. If you are seeing a CAPTCHA on login, chances are that something about your connection is suspicious to our system. It's far from perfect, and we continue to improve it, but at most a percent or two of users are seeing CAPTCHA at any time. The CAPTC…

I'm going to put you on a spot a bit, because this seems important to ProtonMail's viability, and I want you to keep succeeding... > Obviously Google still gets some information, but we do all we can to limit this. When you cause a request to be made for ReCaptcha, it seems that you're leaking enough information to (in many cases) link a possibly-pseudonymous Protonmail account to an identifiable individual. (For exa…

The points made in this post mirror my own, and this incident has caused my trust of sound privacy focus design and implementation on the part of Proton to diminish somewhat.

Any small leakage of data/activity/identity is unacceptable to those of us who know how this information can be taken advantage of, and choice Proton specifically to avoid that happening.

Re: ProtonMail includes Google Recaptcha for login

#260
post #234
post #226

Earlier quoted context omitted.

I'm not sure what you mean -- it makes sense to me that if you are paying for an email service, they would continue to charge you as long as you store and access those emails in their server, and they would have to take steps to prevent abuse from people who might try to store too much data. Can you be more specific about what the behavior is? Maybe you could show a good way that another email provider has solved thi…

Can you name another corporate email provider that doesn't free up seats when users are deactivated? To my knowledge this is how all of Proton Mail's competitors charge for seats - at least all the ones I know of.

I haven't used many "corporate email providers", whatever that means, but I've used my fair share of "classic" email providers (standard mail stack + basic webmail) and most of them charge per inbox. If an address is deactivated, but the inbox is still present, it counts towards your quota (depending on your package, this might mean you're paying for it). If you want to reclaim it, the inbox with all its contents must be deleted. Since that is a highly destructive and usually non-reversible action, a few do require you to go through their support.

I personally don't like it and surely there's better ways of doing it, but it is definitely not unheard of.

Post reply on HN