Live data from Hacker News

Security experts declare all Proton apps secure after security audit

protonmail.com

31–40 of 49 posts

Re: Security experts declare all Proton apps secure after security audit

#31

Declaring it secure after an audit is like writing 100% coverage tests and saying it's bug-free. You can't prove absence, only presence. This title is the definition of sensationalism and only by reading the article do you find the truth: "Their tests uncovered no major issues or security vulnerabilities". This is a bad look for them and I'm wary of their company now...

I agree with you that the title is a bit sensationalist. But if independent security audits with no major issues uncovered cannot make you claim something is secure, when can you claim something as secure? Or are you of the opinion that nothing ever can be claimed to be secure as there can always be holes that could be uncovered in the future? Using openssh as an example, would you say it's secure when you're using p…

I think it's partly the phrase "Security experts declare" which is likely to be what's rubbing people up the wrong way.

The security auditors themselves would never actually word it like that in their reports, because the statement implies a degree of certainty that cannot really exist.

Here's an example of what the auditor's actually said:

"Auditors identified two low-severity vulnerabilities. Additionally, five general recommendations were reported. At the same time, we confirm that no important security issues were identified during the pentest."

There's a reason that audit reports will never say outright that something is "secure". They may say something like "strong and effective security measures are in place", but that's a very different kind of statement.

I think the article itself is great but the headline just falls on the wrong side of being a bit hyperbolic and seems to be optimised for marketing impact over accuracy.

Re: Security experts declare all Proton apps secure after security audit

#32
post #5
post #2

Unfortunately users declare Protonmail barely usable in terms of features and UX. After a decade of this, I’m shifting back to IMAP. My use case is better off with GPG than with Protonmail. I can’t usefully function without integration into the rest of my Mac or iOS. A secure walled garden with Apps that get worse over time? I’ll go with Apple’s version.

Protonmail user here, and I haven't declared any such thing. The complaints I see tend to center around the assumption that using the service is exactly the same as any other service, despite the lengths they go to tell you how it's different. The service and the app is very usable and there are more than enough features, without them getting in the way. I use the app and the bridge; both have served me well.

They just refactored their iOS app too, thankfully. It's not a stale product, by any means.

Re: Security experts declare all Proton apps secure after security audit

#33
post #24

Earlier quoted context omitted.

> But if independent security audits with no major issues uncovered cannot make you claim something is secure, when can you claim something as secure? Nothing at all; it's a broken model. The server can at any time start serving malicious payloads [0]. The server hosts your mail but they also serve the webapp. The clientside decrypts the mail, but the server hosts the client code... It's a fundamentally flawed idea,…

Secure email is snake oil; no amount of cruft can make it both reasonable secure and useful (as in federated). Other protocols better fill that space because they were designed for security needs.

I agree that I wouldn't use Protonmail if Signal was an option, but there are many situations where Signal isn't an option (eg. transactional email, people who don't use signal). In those contexts it's still better to use encrypted mail rather than ad-supported mail (eg. gmail, outlook), or even commercial mail (eg. fastmail), which are both unencrypted.

Re: Security experts declare all Proton apps secure after security audit

#34

ProtonMail has a bad history of irresponsible sensationalism. It’s like constantly marketing yourself as the most private e-mail service “built by CERN scientists” but who will give information about you to authorities: https://www.engadget.com/protonmail-climate-activist-ip-swis... I know that ProtonMail doesn’t claim to protect your IP address, but I don’t expect the average user to make that distinction. This is a…

If you want protection from bad laws, vote for people who don't make bad laws to start with.

I'm so tired of this argument. It doesn't work. Nobody volunteers to willingly and knowingly sacrifice their privacy. Politicians do this even after promising the opposite.

Re: Security experts declare all Proton apps secure after security audit

#35

Declaring it secure after an audit is like writing 100% coverage tests and saying it's bug-free. You can't prove absence, only presence. This title is the definition of sensationalism and only by reading the article do you find the truth: "Their tests uncovered no major issues or security vulnerabilities". This is a bad look for them and I'm wary of their company now...

I agree with you that the title is a bit sensationalist. But if independent security audits with no major issues uncovered cannot make you claim something is secure, when can you claim something as secure? Or are you of the opinion that nothing ever can be claimed to be secure as there can always be holes that could be uncovered in the future? Using openssh as an example, would you say it's secure when you're using p…

Here’s how I feel about this:

You can write all of the tests, you can get all of the audits, but there’s nothing that’s going to stop a 13-year old polish kid from mucking about in the guts of your tech. Security isn’t a promise you can make in absolutes, at some point you have to ship and you hope that you did everything well enough that there’s no low-hanging fruit.

There’s no such thing as a secure system, only systems which are more expensive to compromise.

Re: Security experts declare all Proton apps secure after security audit

#36

ProtonMail has a bad history of irresponsible sensationalism. It’s like constantly marketing yourself as the most private e-mail service “built by CERN scientists” but who will give information about you to authorities: https://www.engadget.com/protonmail-climate-activist-ip-swis... I know that ProtonMail doesn’t claim to protect your IP address, but I don’t expect the average user to make that distinction. This is a…

If you want protection from bad laws, vote for people who don't make bad laws to start with.

This is so smart, I wish someone would have thought about this a long time ago!

Joking aside - making good privacy laws is not an easy task. “privacy” is not even easy to define, much less create fair laws around what will likely be an imperfect definition.

Re: Security experts declare all Proton apps secure after security audit

#37

Declaring it secure after an audit is like writing 100% coverage tests and saying it's bug-free. You can't prove absence, only presence. This title is the definition of sensationalism and only by reading the article do you find the truth: "Their tests uncovered no major issues or security vulnerabilities". This is a bad look for them and I'm wary of their company now...

You beat me to it. I have sat with hundreds of software and network auditors. Never once have I heard them say something was secure. At best they might say they didn't find any high severity issues in this particular audit. I am curious who their statement was intended for.

Re: Security experts declare all Proton apps secure after security audit

#38
I have a hard time adding protonmail to my "generally regarded as safe" mail provider list when they haven't been able to implement Webauthn security key support (aka U2F security keys / FIDO security keys).

Yes, they support Multi-Factor authentication, but only via phishable methods (TOTP)[1]. They have been "trying" for years[2] to implement U2F but for some reason haven't been able to figure it out yet /shrug

[1] https://protonmail.com/support/knowledge-base/two-factor-aut...

[2] https://twitter.com/protonmail/status/1300758061255217153?la...

Re: Security experts declare all Proton apps secure after security audit

#39

Declaring it secure after an audit is like writing 100% coverage tests and saying it's bug-free. You can't prove absence, only presence. This title is the definition of sensationalism and only by reading the article do you find the truth: "Their tests uncovered no major issues or security vulnerabilities". This is a bad look for them and I'm wary of their company now...

I agree with you that the title is a bit sensationalist. But if independent security audits with no major issues uncovered cannot make you claim something is secure, when can you claim something as secure? Or are you of the opinion that nothing ever can be claimed to be secure as there can always be holes that could be uncovered in the future? Using openssh as an example, would you say it's secure when you're using p…

> when can you claim something as secure?

Typically: don't do that.

Nevertheless, if you insist: you can claim a certain abstraction of a system guarantees certain mathematically expressed requirements cannot be violated by a certain attacker model once you've formally proved that.

Of course, all implementations have implementation details which violate the abstraction, your mathematically expressed requirements may not fully capture your intentions, and in practice, an attacker may have additional options that your model doesn't consider. But hey, now you can truthfully claim that "the system" is "secure" - for some values of "system" and "secure".

Post reply on HN