ProtonMail does not support Yubikeys. I would like to ask all of HN to think seriously about this and what this means. ProtonMail does many things exactly right. This 1 oversight suggests something very very scary going on at the organization. HN does not allow you to delete comments. I would ask that if you think that not having Yubikeys does not require a significant and immediate answer from the ProtonMail team, t…
Clarifying ProtonMail and Huawei
41–50 of 72 posts
Re: Clarifying ProtonMail and Huawei
#42At the risk of making myself a punching-bag for downvoting, here. Bloomberg is a source that investors and traders trust with getting them some level of access to the rumour mill (in the spirit of the saying that exists among traders that goes "buy the rumour, sell the news"). The problem here is that, fact or fiction, rumours affect the financial markets, and not knowing about them puts a market participant at a dis…
Re: Clarifying ProtonMail and Huawei
#43Earlier quoted context omitted.
I'd prefer WireGuard support. But I guess there just is not enough demand for that.
You'd prefer WireGuard support in an email service? What do you mean by that?
Given how simple WireGuard is to set up I don't understand why they don't support it. Their UI etc, sure. Then just make it alpha or beta or whatever. I'd happily test it. Give feedback, etc.
Meanwhile, I paid for a 2 year sub and barely use it because of this reason. Instead, I run a WireGuard VPN _to_ my home cable connection.
Re: Clarifying ProtonMail and Huawei
#44ProtonMail does not support Yubikeys. I would like to ask all of HN to think seriously about this and what this means. ProtonMail does many things exactly right. This 1 oversight suggests something very very scary going on at the organization. HN does not allow you to delete comments. I would ask that if you think that not having Yubikeys does not require a significant and immediate answer from the ProtonMail team, t…
Can you elaborate why not supporting Yubikeys (yet) "suggests something very very scary going on at the organization"?
It has been known for some time that TOTP 6 digit codes are easy to intercept. SMS Codes can also be intercepted, or gained via SSB7 vulns/ SIM jacking. This made things like Google Authenticator or Authy more resilient but certainly still quite vulnerable.
To intercept and exploit MFA in ProtonMail would absolutely trivial for a skilled single person to do. DNS poisoning + this github library would be all you needed: https://github.com/kgretzky/evilginx2
EDIT: replaced quotemark with asterisk
Re: Clarifying ProtonMail and Huawei
#45I wonder why ProtonMail is getting so much negative press. They are releasing articles like that to clarify "the truth" on a regular base. Even here on HackerNews, there are so many negative voices repeating the same things over and over again. Even and especially those that (seem to) have been rectified by ProtonMail. Usually, the people here seem to be neutral and fact-based, but as soon as ProtonMail is involved m…
For years companies used to provide all sorts of incentives to put apps in their store. It benefits them highly.
This is ridiculous: https://protonmail.com/blog/clarifying-protonmail-and-huawei...
Re: Clarifying ProtonMail and Huawei
#46Re: Clarifying ProtonMail and Huawei
#47Earlier quoted context omitted.
Can you elaborate why not supporting Yubikeys (yet) "suggests something very very scary going on at the organization"?
Yubikeys are one of the few forms of 2FA that are highly resilient to being phished. Google has not only an option to restrict SMS 2FA, but an additional one below to restrict “all 2FA options except security keys” in GSuite. It has been known for some time that TOTP 6 digit codes are easy to intercept. SMS Codes can also be intercepted, or gained via SSB7 vulns/ SIM jacking. This made things like Google Authenticato…
Re: Clarifying ProtonMail and Huawei
#48I wonder why ProtonMail is getting so much negative press. They are releasing articles like that to clarify "the truth" on a regular base. Even here on HackerNews, there are so many negative voices repeating the same things over and over again. Even and especially those that (seem to) have been rectified by ProtonMail. Usually, the people here seem to be neutral and fact-based, but as soon as ProtonMail is involved m…
That article does not clarify anything. I want to provide a link. It is nothing but thousands of words saying they aren’t partnering by putting an app in Huawei App Store. For years companies used to provide all sorts of incentives to put apps in their store. It benefits them highly. This is ridiculous: https://protonmail.com/blog/clarifying-protonmail-and-huawei...
Are you implying that Huawei is paying ProtonMail so that they put their app in the Huawei AppGallery? Can you provide any proof?
Re: Clarifying ProtonMail and Huawei
#49Earlier quoted context omitted.
Yubikeys are one of the few forms of 2FA that are highly resilient to being phished. Google has not only an option to restrict SMS 2FA, but an additional one below to restrict “all 2FA options except security keys” in GSuite. It has been known for some time that TOTP 6 digit codes are easy to intercept. SMS Codes can also be intercepted, or gained via SSB7 vulns/ SIM jacking. This made things like Google Authenticato…
That does not really answer my question. Why does missing support for Yubikeys "suggest [that] something very very scary going on at the organization"? Supporting Yubikeys is probably already in their list of planned features. But ProtonMail is a relatively small company and the user base requesting that feature might be relatively small. Yes, security is one of their top-most priorities but so is earning money. The…
Not doing this was a deliberate choice. The benefits of implementing it outweigh at maybe a dozen orders of magnitude not implementing it.
The very scary thing btw is simple. They were bribed the same way the WordPress Core Contributors have been for years. Let me discuss this quickly, and I’m happy to name names in a separate posting (Gary Pendergast out of Australia is going to jail though along with another America dev). That being said please review this discussion where several core contributors admit to not even reading an extremely important path from arguably one of the best PHP developers in the world (certainly in terms of security): https://core.trac.wordpress.org/ticket/39309
Re: Clarifying ProtonMail and Huawei
#50Earlier quoted context omitted.
You'd prefer WireGuard support in an email service? What do you mean by that?
For ProtonVPN. Same company. Statement made on the assumption that resources spend on ProtonMail can be spend on ProtonVPN (which I admit is a stretch). Given how simple WireGuard is to set up I don't understand why they don't support it. Their UI etc, sure. Then just make it alpha or beta or whatever. I'd happily test it. Give feedback, etc. Meanwhile, I paid for a 2 year sub and barely use it because of this reason…
Your WG tunnel to your home is nice for accessing home stuff from outside, and for protecting your use of the coffee shop wifi, but it isn't anonymizing your traffic to your home ISP or to websites you use, which is a big reason for using a VPN product.