While I love ProtonMail as an effort to popularize security for end-users and trying to come up with smart technologies to achieve that, the whole risk model behind the writeup barely stands scrutiny. What's worrying, ProtonMail (who declare security a first-class feature) use "features" instead of systems to define security of their service. If you think of it for a second, web crypto (protection against intermediar…
PM team here, we just made an account to comment. We actually agree with some of the points made above, but we'd like to add the following commentary... Encrypting email while making it more usable than PGP is hard. There's no getting around that. Web crypto is always going to have some shortcomings, but web mail is on the rise, and at the end of the day, web crypto is better than no crypto. That said, we have been w…
I seriously disagree on this (our company is facing similar challenges, and I've asked these question myself numerous times). It's not better, it's much worse.
"Some crypto" creates illusion of security, where you don't really know has it failed or not - frequently, there is no functional failure in cryptographic failure. It doesn't stop working, it stops providing the very guarantees you're using it for.
> However, we think that not playing is taking the easy way out, so even though the game is 'rigged' against us, we have a great team of engineers who have decided to play anyways.
Truly so, but you need to play better then ;) Godspeed!