Live data from Hacker News

Clarifying ProtonMail and Huawei

protonmail.com

41–50 of 72 posts

Re: Clarifying ProtonMail and Huawei

#41

ProtonMail does not support Yubikeys. I would like to ask all of HN to think seriously about this and what this means. ProtonMail does many things exactly right. This 1 oversight suggests something very very scary going on at the organization. HN does not allow you to delete comments. I would ask that if you think that not having Yubikeys does not require a significant and immediate answer from the ProtonMail team, t…

Can you elaborate why not supporting Yubikeys (yet) "suggests something very very scary going on at the organization"?

Re: Clarifying ProtonMail and Huawei

#42

At the risk of making myself a punching-bag for downvoting, here. Bloomberg is a source that investors and traders trust with getting them some level of access to the rumour mill (in the spirit of the saying that exists among traders that goes "buy the rumour, sell the news"). The problem here is that, fact or fiction, rumours affect the financial markets, and not knowing about them puts a market participant at a dis…

It's inconceivable that a manufacturer would preload an app without some kind of discussion of the app's content, and I think it's reasonable to be afraid of even a non-explicit quid pro quo from Huawei. If ProtonMail-on-Huawei is using so much as a new logging library because Huawei said the old one is insecure, I want to know about that.

Re: Clarifying ProtonMail and Huawei

#43
post #31

Earlier quoted context omitted.

I'd prefer WireGuard support. But I guess there just is not enough demand for that.

You'd prefer WireGuard support in an email service? What do you mean by that?

For ProtonVPN. Same company. Statement made on the assumption that resources spend on ProtonMail can be spend on ProtonVPN (which I admit is a stretch).

Given how simple WireGuard is to set up I don't understand why they don't support it. Their UI etc, sure. Then just make it alpha or beta or whatever. I'd happily test it. Give feedback, etc.

Meanwhile, I paid for a 2 year sub and barely use it because of this reason. Instead, I run a WireGuard VPN _to_ my home cable connection.

Re: Clarifying ProtonMail and Huawei

#44
post #41

ProtonMail does not support Yubikeys. I would like to ask all of HN to think seriously about this and what this means. ProtonMail does many things exactly right. This 1 oversight suggests something very very scary going on at the organization. HN does not allow you to delete comments. I would ask that if you think that not having Yubikeys does not require a significant and immediate answer from the ProtonMail team, t…

Can you elaborate why not supporting Yubikeys (yet) "suggests something very very scary going on at the organization"?

Yubikeys are one of the few forms of 2FA that are highly resilient to being phished. Google has not only an option to restrict SMS 2FA, but an additional one below to restrict “all 2FA options except security keys” in GSuite.

It has been known for some time that TOTP 6 digit codes are easy to intercept. SMS Codes can also be intercepted, or gained via SSB7 vulns/ SIM jacking. This made things like Google Authenticator or Authy more resilient but certainly still quite vulnerable.

To intercept and exploit MFA in ProtonMail would absolutely trivial for a skilled single person to do. DNS poisoning + this github library would be all you needed: https://github.com/kgretzky/evilginx2

EDIT: replaced quotemark with asterisk

Re: Clarifying ProtonMail and Huawei

#45
post #32

I wonder why ProtonMail is getting so much negative press. They are releasing articles like that to clarify "the truth" on a regular base. Even here on HackerNews, there are so many negative voices repeating the same things over and over again. Even and especially those that (seem to) have been rectified by ProtonMail. Usually, the people here seem to be neutral and fact-based, but as soon as ProtonMail is involved m…

That article does not clarify anything. I want to provide a link. It is nothing but thousands of words saying they aren’t partnering by putting an app in Huawei App Store.

For years companies used to provide all sorts of incentives to put apps in their store. It benefits them highly.

This is ridiculous: https://protonmail.com/blog/clarifying-protonmail-and-huawei...

Re: Clarifying ProtonMail and Huawei

#46
I was a gmail user a few months ago and I switched my entire life over to protonmail because I didn't want to contribute to Google. I would have to say the most frustrating part of the switch is the somewhat perplexed look I get from people when they ask why I don't have gmail, they have to learn to spell proton, fascinating. I would imagine we will see quite a few hit pieces against protonmail in the coming years, and likely other email providers as more and more people make the switch to a service that markets privacy.

Re: Clarifying ProtonMail and Huawei

#47
post #41

Earlier quoted context omitted.

Can you elaborate why not supporting Yubikeys (yet) "suggests something very very scary going on at the organization"?

Yubikeys are one of the few forms of 2FA that are highly resilient to being phished. Google has not only an option to restrict SMS 2FA, but an additional one below to restrict “all 2FA options except security keys” in GSuite. It has been known for some time that TOTP 6 digit codes are easy to intercept. SMS Codes can also be intercepted, or gained via SSB7 vulns/ SIM jacking. This made things like Google Authenticato…

That does not really answer my question. Why does missing support for Yubikeys "suggest [that] something very very scary going on at the organization"? Supporting Yubikeys is probably already in their list of planned features. But ProtonMail is a relatively small company and the user base requesting that feature might be relatively small. Yes, security is one of their top-most priorities but so is earning money. The latter requires a large paying audience where other features might be more important.

Re: Clarifying ProtonMail and Huawei

#48
post #32

I wonder why ProtonMail is getting so much negative press. They are releasing articles like that to clarify "the truth" on a regular base. Even here on HackerNews, there are so many negative voices repeating the same things over and over again. Even and especially those that (seem to) have been rectified by ProtonMail. Usually, the people here seem to be neutral and fact-based, but as soon as ProtonMail is involved m…

That article does not clarify anything. I want to provide a link. It is nothing but thousands of words saying they aren’t partnering by putting an app in Huawei App Store. For years companies used to provide all sorts of incentives to put apps in their store. It benefits them highly. This is ridiculous: https://protonmail.com/blog/clarifying-protonmail-and-huawei...

> For years companies used to provide all sorts of incentives to put apps in their store. It benefits them highly.

Are you implying that Huawei is paying ProtonMail so that they put their app in the Huawei AppGallery? Can you provide any proof?

Re: Clarifying ProtonMail and Huawei

#49
post #47

Earlier quoted context omitted.

Yubikeys are one of the few forms of 2FA that are highly resilient to being phished. Google has not only an option to restrict SMS 2FA, but an additional one below to restrict “all 2FA options except security keys” in GSuite. It has been known for some time that TOTP 6 digit codes are easy to intercept. SMS Codes can also be intercepted, or gained via SSB7 vulns/ SIM jacking. This made things like Google Authenticato…

That does not really answer my question. Why does missing support for Yubikeys "suggest [that] something very very scary going on at the organization"? Supporting Yubikeys is probably already in their list of planned features. But ProtonMail is a relatively small company and the user base requesting that feature might be relatively small. Yes, security is one of their top-most priorities but so is earning money. The…

It’s such an oversight that to quote someone from early 20th century ... “is this stupidity or is this treason”.

Not doing this was a deliberate choice. The benefits of implementing it outweigh at maybe a dozen orders of magnitude not implementing it.

The very scary thing btw is simple. They were bribed the same way the WordPress Core Contributors have been for years. Let me discuss this quickly, and I’m happy to name names in a separate posting (Gary Pendergast out of Australia is going to jail though along with another America dev). That being said please review this discussion where several core contributors admit to not even reading an extremely important path from arguably one of the best PHP developers in the world (certainly in terms of security): https://core.trac.wordpress.org/ticket/39309

Re: Clarifying ProtonMail and Huawei

#50
post #43

Earlier quoted context omitted.

You'd prefer WireGuard support in an email service? What do you mean by that?

For ProtonVPN. Same company. Statement made on the assumption that resources spend on ProtonMail can be spend on ProtonVPN (which I admit is a stretch). Given how simple WireGuard is to set up I don't understand why they don't support it. Their UI etc, sure. Then just make it alpha or beta or whatever. I'd happily test it. Give feedback, etc. Meanwhile, I paid for a 2 year sub and barely use it because of this reason…

OK for ProtonVPN I am less confused about where your request is coming from. But I still don't see why your ProtonVPN subscription is totally useless to you because of no WG.

Your WG tunnel to your home is nice for accessing home stuff from outside, and for protecting your use of the coffee shop wifi, but it isn't anonymizing your traffic to your home ISP or to websites you use, which is a big reason for using a VPN product.

Post reply on HN