Live data from Hacker News

ProtonMail takes aim at Google with an encrypted calendar

venturebeat.com

61–70 of 154 posts

Re: ProtonMail takes aim at Google with an encrypted calendar

#61
If one doesn't care about web access to their calendar is there any recommended encrypted calendar apps to use on an android device as the default calendar app? Does setting a default calendar app to something other than the calendar on ROM actually prevent calendar data from leaking to third parties?

Re: ProtonMail takes aim at Google with an encrypted calendar

#62
post #29

I recently left ProtonMail and went back to Fastmail. My reason was that they will never be able to fully support IMAP and now CalDAV because of the encryption they use. I grew to accept that email is not for secure messaging and my paranoia of "I'm being watched" just went away. If you need secure messaging, use something other than email.

I came to a similar conclusion. You should write every email as if it were public, because it's entirely likely that it will be. They can be forwarded, made public through legal discovery, or exposed in a data breach (eg. Sony/North Korea). Forget security for a second, imagining every email as public record will make you more considerate and less biased writer. And from a business perspective, email should be viewed…

I agree with most of what you have written, but this:

> doesn't mean I want Google getting a free pass to mine and sell my data.

AFAIK, they don't do that with gmail. Do you have any evidence to the contrary?

We need to hold Google's feet to fire on privacy, but it is also important that we do not exaggerate or distort the facts.

Re: ProtonMail takes aim at Google with an encrypted calendar

#63
post #57

Earlier quoted context omitted.

Don't integrate privacy-focused email service (hushmail/proton etc) into a non-private phone. Access it via the webmail interface. I've been asked several times to decrypt my phone at international boarders. If you leave things to webmail, unlocking your phone doesn't give them access to your email account, or even tell them where it is. All the TSA/Cops get is my "gmail-for-phone-2018@gmail.com" address that I haven…

My ProtonMail installation on Android supports PIN/fingerprint locking

They could definitely ask you to unlock it. It's why apps like 1password added a "Travel Mode" https://blog.1password.com/introducing-travel-mode-protect-y...

Re: ProtonMail takes aim at Google with an encrypted calendar

#64

I'm a bit confused it took Protonmail more than a year yo develop ProtonCalendar. Is it really that difficult to develop?

Google (but not Apple) is still charmingly unable to tell when I've switched time zones between scheduling an event and attending it. So, yeah, calendars are hard.

My Google Calendar now sends me two email notifications for every event that I set up notifications for, and I have no idea how to turn one of them off after scouring the settings. I can't remember how I managed to mess it up and I don't even know if it's something I did, but I can't for the life of me undo it.

Re: ProtonMail takes aim at Google with an encrypted calendar

#65
post #29

Earlier quoted context omitted.

I came to a similar conclusion. You should write every email as if it were public, because it's entirely likely that it will be. They can be forwarded, made public through legal discovery, or exposed in a data breach (eg. Sony/North Korea). Forget security for a second, imagining every email as public record will make you more considerate and less biased writer. And from a business perspective, email should be viewed…

> Forget security for a second, imagining every email as public record will make you more considerate and less biased writer. And from a business perspective, email should be viewed as a public legal record, because in some cases it will be used that way. > Just because I consider every email I write to be public Cool. Can I have the creds to your Fastmail account then? I'm curious what you're up to these days. If yo…

This is not a very strong argument. Here's a specific refutation: the credentials to their primary email account are likely equivalent to the credentials of many other services that they use, because of password reset. None of those emails are encrypted, or ever will be; further, they're of little value just a day or two after they're sent. That commenter could coherently expect both that their mail spool would eventually be "public" and that it was safe to use email for password resets.

More generally: it's reasonable both to expect that your mail spool could eventually be public, and still not to want people to read it. There are things I don't want people to read, and there are things I need to be as careful as I can to ensure everyone can't read. Email works for the former and not the latter, and the latter is what encrypted messaging was invented for. Comparatively: I don't know many people who trust Twitter DMs, and "let's move this off Twitter DMs" is a constant refrain. But my answer to "can I read all your Twitter DMs" is still "no".

Re: ProtonMail takes aim at Google with an encrypted calendar

#66
post #29

Earlier quoted context omitted.

I came to a similar conclusion. You should write every email as if it were public, because it's entirely likely that it will be. They can be forwarded, made public through legal discovery, or exposed in a data breach (eg. Sony/North Korea). Forget security for a second, imagining every email as public record will make you more considerate and less biased writer. And from a business perspective, email should be viewed…

> Forget security for a second, imagining every email as public record will make you more considerate and less biased writer. And from a business perspective, email should be viewed as a public legal record, because in some cases it will be used that way. > Just because I consider every email I write to be public Cool. Can I have the creds to your Fastmail account then? I'm curious what you're up to these days. If yo…

> Can I have the creds to your Fastmail account then? I'm curious what you're up to these days.

This is just as specious of an argument as the retort of "ah so you claim you have nothing to hide but you have curtains on your windows, checkmate, I am very smart."

The issue is not one of what specific measures are or are not taken, it's about having the informed choice to make decisions based on information use. I wager that a lot of people would make the choice to pay with actual cash when shown the actual cost in data of how their personal information is being used. But, conversely, a bunch of people probably don't truly care or mind, and the loss of information control is worth less to them than the loss of money to be paid.

That doesn't then imply that a person has zero care about the information under their control, nor that their refusal to give you control of that data makes them a hypocrite.

Re: ProtonMail takes aim at Google with an encrypted calendar

#67
post #3

Did anyone else notice ProtonMail being used in the movie "Knives Out" to send the ransom note? Cracked me up..

I noticed it as well and just that little touch (along with the line "What is this, CSI:KFC?!") pushed me from "I will probably stream this a few times in the background because it's funny" to "I am preordering the 4K disc as soon as it is listed."

Re: ProtonMail takes aim at Google with an encrypted calendar

#68
post #29

Earlier quoted context omitted.

I came to a similar conclusion. You should write every email as if it were public, because it's entirely likely that it will be. They can be forwarded, made public through legal discovery, or exposed in a data breach (eg. Sony/North Korea). Forget security for a second, imagining every email as public record will make you more considerate and less biased writer. And from a business perspective, email should be viewed…

I agree with most of what you have written, but this: > doesn't mean I want Google getting a free pass to mine and sell my data. AFAIK, they don't do that with gmail. Do you have any evidence to the contrary? We need to hold Google's feet to fire on privacy, but it is also important that we do not exaggerate or distort the facts.

You're right, "Sell my data" might have been too strong. But they are certainly mining it to train things like their "suggested responses". In my view, it's an ad company, and while they might not be doing it today, there's nothing stopping them from using my data in the future, hence the "free pass".

Re: ProtonMail takes aim at Google with an encrypted calendar

#69
post #60

Earlier quoted context omitted.

If that is so then "public" and "private" are insufficient categories to describe messaging options. I'm forced to send proof of identity as well as proof of address via email. I'm receiving bank statements and countless other sensitive documents via email. And I have absolutely no other choice. Whoever gets a hold of my email can impersonate me in almost every context. So no, I do not consider the contents of my ema…

In fairness, I don't think he meant the contents of your email account should be public, he said you should write and behave as if it could be because who knows what a webmail provider will do with your data. That's a very different thing than saying it should or will become public.

The question was whether or not it makes sense to make email services as secure as possible and prefer more secure email providers to less secure ones.

Some say we should give up making email more secure, because it can never be as secure as more modern messaging services.

That doesn't make sense to me, because we don't have a choice other than to use email in ways that require very high levels of security. I cannot behave as if my email could become public any moment.

I would love if the world were to move on to more secure messaging platforms. But it's simply not the world we live in right now.

Re: ProtonMail takes aim at Google with an encrypted calendar

#70

I moved over to Fastmail from ProtonMail a few weeks ago. I think if you value the encryption and privacy and don’t mind the lack of basic stuff like threading in the mobile app or IMAP integration, ProtonMail is fully worth it. That said, for me I just want a well featured email/calendar service that can replace gmail once Gewgle fucked us over with Inbox. Fastmail does that for me and provides a lot less friction w…

When I initially set out to change mail providers, I considered both Fastmail and ProtonMail.

Ultimately, my decision was based on the fact that ProtonMail is a Swiss company, a country whose privacy laws are stronger than Fastmail’s country of origin, Australia.

So far I’m really happy with ProtonMail as a replacement for Gmail, as a mobile-first user. The only issue is saying “ProtonMail” to people who have never heard of it (surprisingly prone to misspelling).

Post reply on HN