Live data from Hacker News

ProtonMail takes aim at Google with an encrypted calendar

venturebeat.com

71–80 of 154 posts

Re: ProtonMail takes aim at Google with an encrypted calendar

#71
post #29

Earlier quoted context omitted.

I came to a similar conclusion. You should write every email as if it were public, because it's entirely likely that it will be. They can be forwarded, made public through legal discovery, or exposed in a data breach (eg. Sony/North Korea). Forget security for a second, imagining every email as public record will make you more considerate and less biased writer. And from a business perspective, email should be viewed…

I agree with most of what you have written, but this: > doesn't mean I want Google getting a free pass to mine and sell my data. AFAIK, they don't do that with gmail. Do you have any evidence to the contrary? We need to hold Google's feet to fire on privacy, but it is also important that we do not exaggerate or distort the facts.

IMO the burden should be on Google to prove that they don't. The flow of personal data through their systems is opaque and they have plenty of incentives to monetize the data.

Re: ProtonMail takes aim at Google with an encrypted calendar

#72

I lost a lot of faith in Proton when I learned how much funding they took from the EU. It just runs entirely counter to evidence we’ve seen of Snowden, 5eyes/14eyes, and other programs that the EU truly wants end to end encrypted comms for people. Am I wrong to be skeptical? Edit: oh apparently I’m wrong to even suggest something we have other examples of

They have a grand total of $4.8MM in funding, and €2MM came from an EU grant. Hardly even a modest sum considering the tech funding climate these days.

The EU is one of the most privacy-conscious government entities on Earth right now, and it needs to be noted that ProtonMail is located entirely within Switzerland, an even more privacy-conscious state that is not a member of the EU.

Re: ProtonMail takes aim at Google with an encrypted calendar

#73

I moved over to Fastmail from ProtonMail a few weeks ago. I think if you value the encryption and privacy and don’t mind the lack of basic stuff like threading in the mobile app or IMAP integration, ProtonMail is fully worth it. That said, for me I just want a well featured email/calendar service that can replace gmail once Gewgle fucked us over with Inbox. Fastmail does that for me and provides a lot less friction w…

I'm not even sure it's all that great of a trick, considering that no amount of encryption and security on Proton's own servers or in their app can protect the contents of emails that are sent to (edit: or received from) someone who doesn't use Proton. I am a current customer and think they've got a really well-done service and app, but lately I've been wondering if it's the privacy equivalent of the Maginot Line.

Makes me wonder if its possible or reasonable to consider an option with protonmails (and similar) - have a note in the footer of the email - explaining that encrypted is default in their system, but sending to your email provider has it converted to plain text where others can access it.. if you'd like to keep this mail message private click to login to protonReadPortal - where you can read, and if you'd like make a passphrase, to reply and keep messaging on secure servers.. get an optional app for replies to your contacts that have proton accounts.. then tap to checkbox so further emails to you from proton accounts send you a notice to check out the protonReadPortal instead of including the plain text..

I'd want my protonReaderApp to have default shred message after reading.. keep available on proton server for 48 hours after.. one click to save as pdf or zip or other safer password format, or save on protonServer longer.. with easy to change defaults..

would be nice option. I dunno maybe something like this exists?

There are several use cases for this..

a system like this could make for encrypted form storage and messaging with the right API maybe hippa compliant?

I'd expect my lawyers and accountants and such to use something like this.

Re: ProtonMail takes aim at Google with an encrypted calendar

#74
post #71

Earlier quoted context omitted.

I agree with most of what you have written, but this: > doesn't mean I want Google getting a free pass to mine and sell my data. AFAIK, they don't do that with gmail. Do you have any evidence to the contrary? We need to hold Google's feet to fire on privacy, but it is also important that we do not exaggerate or distort the facts.

IMO the burden should be on Google to prove that they don't. The flow of personal data through their systems is opaque and they have plenty of incentives to monetize the data.

You can't prove a negative.

Re: ProtonMail takes aim at Google with an encrypted calendar

#75

Earlier quoted context omitted.

> Forget security for a second, imagining every email as public record will make you more considerate and less biased writer. And from a business perspective, email should be viewed as a public legal record, because in some cases it will be used that way. > Just because I consider every email I write to be public Cool. Can I have the creds to your Fastmail account then? I'm curious what you're up to these days. If yo…

> Can I have the creds to your Fastmail account then? I'm curious what you're up to these days. This is just as specious of an argument as the retort of "ah so you claim you have nothing to hide but you have curtains on your windows, checkmate, I am very smart." The issue is not one of what specific measures are or are not taken, it's about having the informed choice to make decisions based on information use. I wage…

Did you misunderstand the meaning of the word 'public'? It's not really that nuanced.. I am part of the 'public', no?

Re: ProtonMail takes aim at Google with an encrypted calendar

#76
post #65

Earlier quoted context omitted.

> Forget security for a second, imagining every email as public record will make you more considerate and less biased writer. And from a business perspective, email should be viewed as a public legal record, because in some cases it will be used that way. > Just because I consider every email I write to be public Cool. Can I have the creds to your Fastmail account then? I'm curious what you're up to these days. If yo…

This is not a very strong argument. Here's a specific refutation: the credentials to their primary email account are likely equivalent to the credentials of many other services that they use, because of password reset. None of those emails are encrypted, or ever will be; further, they're of little value just a day or two after they're sent. That commenter could coherently expect both that their mail spool would event…

No credentials is fine, I understand. As I specified, I would also settle with a dump of the emails. Public means public, right? If we're talking in hyperboles, then let's go all the way, right? Or 'public' means 'eventually public'? Or what?

The reason I'm asking is that the original comment is basically dismissing efforts to make personal productivity products more secure for the reason that they can become public at any time anyway, so why bother, right? Well fuck it, let's all pack it up and go home then, make email public and unencrypted and reallocate the development effort to something more lucrative like desktop apps in Javascript.

Re: ProtonMail takes aim at Google with an encrypted calendar

#77
post #74
post #71

Earlier quoted context omitted.

IMO the burden should be on Google to prove that they don't. The flow of personal data through their systems is opaque and they have plenty of incentives to monetize the data.

You can't prove a negative.

You definitely can [0], but this one would probably be hard for google without significantly modifying the architecture of gmail in ways that would remove its revenue model. For example, they could open source a client that had audit-able end-to-end encryption, but then they couldn't optimize ad revenue by aggregating and mining large email datasets.

[0]: https://en.wikipedia.org/wiki/Proof_of_impossibility

Re: ProtonMail takes aim at Google with an encrypted calendar

#78
post #29

Earlier quoted context omitted.

I came to a similar conclusion. You should write every email as if it were public, because it's entirely likely that it will be. They can be forwarded, made public through legal discovery, or exposed in a data breach (eg. Sony/North Korea). Forget security for a second, imagining every email as public record will make you more considerate and less biased writer. And from a business perspective, email should be viewed…

I agree with most of what you have written, but this: > doesn't mean I want Google getting a free pass to mine and sell my data. AFAIK, they don't do that with gmail. Do you have any evidence to the contrary? We need to hold Google's feet to fire on privacy, but it is also important that we do not exaggerate or distort the facts.

I don’t trust google products. I will never buy anything they want to sell to me. Burden is on them.

I tore off my nest thermostats and replaced them with dumb ones. I miss the ability to change my heat remotely, but at the end of the day. I don’t need that functionality.

Re: ProtonMail takes aim at Google with an encrypted calendar

#79

I moved over to Fastmail from ProtonMail a few weeks ago. I think if you value the encryption and privacy and don’t mind the lack of basic stuff like threading in the mobile app or IMAP integration, ProtonMail is fully worth it. That said, for me I just want a well featured email/calendar service that can replace gmail once Gewgle fucked us over with Inbox. Fastmail does that for me and provides a lot less friction w…

When I initially set out to change mail providers, I considered both Fastmail and ProtonMail. Ultimately, my decision was based on the fact that ProtonMail is a Swiss company, a country whose privacy laws are stronger than Fastmail’s country of origin, Australia. So far I’m really happy with ProtonMail as a replacement for Gmail, as a mobile-first user. The only issue is saying “ProtonMail” to people who have never h…

You could try out the short-hand version "yourname@pm.me". It is not enabled by default, but it is a simple radio button toggle away in your account settings. Certainly more convenient than the full '@protonmail.com'.

Re: ProtonMail takes aim at Google with an encrypted calendar

#80
post #74
post #71

Earlier quoted context omitted.

IMO the burden should be on Google to prove that they don't. The flow of personal data through their systems is opaque and they have plenty of incentives to monetize the data.

You can't prove a negative.

They said "prove" but really it's about trust. Google has lost many peoples' trust and it's on Google to restore that trust.
Post reply on HN