Live data from Hacker News

Security experts declare all Proton apps secure after security audit

protonmail.com

41–49 of 49 posts

Re: Security experts declare all Proton apps secure after security audit

#41
post #24

Earlier quoted context omitted.

> But if independent security audits with no major issues uncovered cannot make you claim something is secure, when can you claim something as secure? Nothing at all; it's a broken model. The server can at any time start serving malicious payloads [0]. The server hosts your mail but they also serve the webapp. The clientside decrypts the mail, but the server hosts the client code... It's a fundamentally flawed idea,…

Secure email is snake oil; no amount of cruft can make it both reasonable secure and useful (as in federated). Other protocols better fill that space because they were designed for security needs.

I wouldn’t call secure email snake oil: it meets some of the characteristics, but not all. “Snake oil” implies at least in part inefficacy and deceptive marketing; yet secure email is possible, though there are typically rather severe caveats (mostly around the question of which parts are being encrypted, and usability).

What is actually snake oil, and distressingly rarely realised as such, is first-party end-to-end encryption. That’s what sodality2 is actually talking about. And when you stop and consider it in this light, you realise that the significant majority of stuff that’s advertised as having E2EE is first-party and thus, to put it mildly, not robust.

In the context of email, here’s Fastmail’s take on it: https://fastmail.blog/advanced/why-we-dont-offer-pgp/.

Re: Security experts declare all Proton apps secure after security audit

#42
I always think twice when a company offers me an "app" for an application that is already available as a web app or that is already inbuilt in the system or doesn't use existing standards. Like, I perfectly understand the need for a Proton Mail client as some would like offline access to their mail and a backup of their mail in their system. But I resent the need of a custom and locked-in app, instead of the service being available over existing POP3 / IMAP protocol. (Yes, I understand how email encryption creates hurdles of using it over POP3 / IMAP, usage, but it would be a lot easier to trust a company if they actually built an extension over existing protocol or create a new standard that makes it easy to access their service. E.g. https://fastmail.blog/open-technologies/jmap-new-email-open-... ). ProtonVPN app also seems a bit redundant when most OSes already have built in support for VPN. Though I understand that it does make configuring, changing / choosing VPN servers a lot simpler, and probably helps ProtonVPN in load balancing, it provides more avenues for data collection and data leak.

Re: Security experts declare all Proton apps secure after security audit

#43
post #34

Earlier quoted context omitted.

If you want protection from bad laws, vote for people who don't make bad laws to start with.

I'm so tired of this argument. It doesn't work. Nobody volunteers to willingly and knowingly sacrifice their privacy. Politicians do this even after promising the opposite.

And I'm so tired of people just voting straight down the party line. That's why nothing works.

Re: Security experts declare all Proton apps secure after security audit

#44
I was totally confused by the title thinking what does that mean or how can they say such a thing without proving a secure sandbox environment, which I didn't even know was possible. Then I realized it's for ProtonMail etc, not Proton from Valve.

Re: Security experts declare all Proton apps secure after security audit

#45

Declaring it secure after an audit is like writing 100% coverage tests and saying it's bug-free. You can't prove absence, only presence. This title is the definition of sensationalism and only by reading the article do you find the truth: "Their tests uncovered no major issues or security vulnerabilities". This is a bad look for them and I'm wary of their company now...

I agree with you that the title is a bit sensationalist. But if independent security audits with no major issues uncovered cannot make you claim something is secure, when can you claim something as secure? Or are you of the opinion that nothing ever can be claimed to be secure as there can always be holes that could be uncovered in the future? Using openssh as an example, would you say it's secure when you're using p…

You can't claim anything is secure just because problems haven't been found.

It does build confidence in the security to perform security audits.

Re: Security experts declare all Proton apps secure after security audit

#46
post #2

Unfortunately users declare Protonmail barely usable in terms of features and UX. After a decade of this, I’m shifting back to IMAP. My use case is better off with GPG than with Protonmail. I can’t usefully function without integration into the rest of my Mac or iOS. A secure walled garden with Apps that get worse over time? I’ll go with Apple’s version.

Not my experience at all. It works really well.

Re: Security experts declare all Proton apps secure after security audit

#47

Earlier quoted context omitted.

I agree with you that the title is a bit sensationalist. But if independent security audits with no major issues uncovered cannot make you claim something is secure, when can you claim something as secure? Or are you of the opinion that nothing ever can be claimed to be secure as there can always be holes that could be uncovered in the future? Using openssh as an example, would you say it's secure when you're using p…

> But if independent security audits with no major issues uncovered cannot make you claim something is secure, when can you claim something as secure? Nothing at all; it's a broken model. The server can at any time start serving malicious payloads [0]. The server hosts your mail but they also serve the webapp. The clientside decrypts the mail, but the server hosts the client code... It's a fundamentally flawed idea,…

> The server can at any time start serving malicious payloads

True, and I call this threat model "Beware Each and Every Fetch" (BEEF) in contrast to the more common TOFU model (although if you trust a desktop app to auto-update itself then these two models might not be all that different).

In any case, I think you're being a little quick to dismiss the idea of server-hosted applications. It's true that browsers don't natively have a nice way of pinning specific versions of a web app, but there is the clever hack of SecureBookmarks[0] (if you're prepared to sacrifice the UX), or, more realistically, you can pin the web app version using some sort of browser extension.

Examples of the latter include the Signed Pages extension[1], and Code Verify[2], which is the result of a collaboration between Meta and Cloudflare (for securing the WhatsApp Web code, currently, but should eventually support other sites like Proton's too). Of course, it would be much better if this capability was natively included in browsers themselves, but hopefully adoption of this technology will pressure browsers and standards bodies to take ownership of this.

[0] https://coins.github.io/secure-bookmark/

[1] https://github.com/tasn/webext-signed-pages

[2] https://github.com/facebookincubator/meta-code-verify

Re: Security experts declare all Proton apps secure after security audit

#48
post #34

Earlier quoted context omitted.

I'm so tired of this argument. It doesn't work. Nobody volunteers to willingly and knowingly sacrifice their privacy. Politicians do this even after promising the opposite.

And I'm so tired of people just voting straight down the party line. That's why nothing works.

That's not the point I'm arguing, that's something else entirely. The two are not binary opposites.

Re: Security experts declare all Proton apps secure after security audit

#49

Declaring it secure after an audit is like writing 100% coverage tests and saying it's bug-free. You can't prove absence, only presence. This title is the definition of sensationalism and only by reading the article do you find the truth: "Their tests uncovered no major issues or security vulnerabilities". This is a bad look for them and I'm wary of their company now...

Considering we live in world where Google and Facebook publicly state "We care about your privacy", I think this title pretty close to reality.

Have they proved the non-existence of bugs? Nope. But the title is also not the complete opposite of reality, which is what their competition seems to doing.

Post reply on HN