Live data from Hacker News

ProtonMail takes aim at Google with an encrypted calendar

venturebeat.com

81–90 of 154 posts

Re: ProtonMail takes aim at Google with an encrypted calendar

#81

Earlier quoted context omitted.

> Can I have the creds to your Fastmail account then? I'm curious what you're up to these days. This is just as specious of an argument as the retort of "ah so you claim you have nothing to hide but you have curtains on your windows, checkmate, I am very smart." The issue is not one of what specific measures are or are not taken, it's about having the informed choice to make decisions based on information use. I wage…

Did you misunderstand the meaning of the word 'public'? It's not really that nuanced.. I am part of the 'public', no?

No, I didn't, and I think you know that but you're trying to bolster a point you know isn't on the mark.

You showed your true motivations in your reply to someone else:

> If we're talking in hyperboles, then let's go all the way, right? Or 'public' means 'eventually public'? Or what?

We're not talking in hyperbole. At least, most of us aren't. We're trying to discuss reality as it is on the ground.

The person you replied to before said to imagine the contents of my e-mail box as though it is a public record. To imagine does not make it so. I imagine myself as James Bond whenever I put on a suit coat and tie; I am not James Bond. I can imagine my e-mails as ones that, through no intent of my own, are exposed and made as part of the public record but treating them as though that possibility might happen does not implicitly make them public. It also doesn't mean I don't want them to remain my own secure property.

Re: ProtonMail takes aim at Google with an encrypted calendar

#82
post #29

Earlier quoted context omitted.

I came to a similar conclusion. You should write every email as if it were public, because it's entirely likely that it will be. They can be forwarded, made public through legal discovery, or exposed in a data breach (eg. Sony/North Korea). Forget security for a second, imagining every email as public record will make you more considerate and less biased writer. And from a business perspective, email should be viewed…

I agree with most of what you have written, but this: > doesn't mean I want Google getting a free pass to mine and sell my data. AFAIK, they don't do that with gmail. Do you have any evidence to the contrary? We need to hold Google's feet to fire on privacy, but it is also important that we do not exaggerate or distort the facts.

> AFAIK, they don't do that with gmail. Do you have any evidence to the contrary?

What evidence do you need? They got close to 1 trillion dollars because of abusing mined data and you expect they don't do that with gmail?

Google is an evil company focused on profit. Only an idiot wouldn't sniff people's mails if they can. We know idiots don't get trillions.

Re: ProtonMail takes aim at Google with an encrypted calendar

#83

I recently left ProtonMail and went back to Fastmail. My reason was that they will never be able to fully support IMAP and now CalDAV because of the encryption they use. I grew to accept that email is not for secure messaging and my paranoia of "I'm being watched" just went away. If you need secure messaging, use something other than email.

> If you need secure messaging, use something other than email.

Many services I need do not give me an alternative. I only continue to use email because of those services.

Re: ProtonMail takes aim at Google with an encrypted calendar

#84

Earlier quoted context omitted.

I agree with most of what you have written, but this: > doesn't mean I want Google getting a free pass to mine and sell my data. AFAIK, they don't do that with gmail. Do you have any evidence to the contrary? We need to hold Google's feet to fire on privacy, but it is also important that we do not exaggerate or distort the facts.

> AFAIK, they don't do that with gmail. Do you have any evidence to the contrary? What evidence do you need? They got close to 1 trillion dollars because of abusing mined data and you expect they don't do that with gmail? Google is an evil company focused on profit. Only an idiot wouldn't sniff people's mails if they can. We know idiots don't get trillions.

> They got close to 1 trillion dollars

That's....not how that works...

Re: ProtonMail takes aim at Google with an encrypted calendar

#85
post #53

Earlier quoted context omitted.

Calendars are software so directly related to time, I'm not surprised. There are so many edge cases. Timezones, daylight savings time. The fact that so many regions don't use the same standards. We alter year length with leap years and doing things like adding leap seconds. Time is a nightmare to program around.

I somewhat believe our society would be easier if we had a better, simpler standard for time.

I've spent much more time than I care to admit researching calendars, the general counting of time from seconds to centuries — actually, ahem, from the Planck time unit to the age of the universe. I find that there would be elegance in having a metric system aligned with "natural" dimensionless units, orders of magnitudes.

Suffice it to say, not only are you 100% right, but there are many easier and better systems we could use; and a software-defined world makes that actually easier than ever to implement in real life.

But people don't like change, and the biggest obstacle historically has been religion — depending which culture/country, pick one or two who oppose any change whatsoever.

Governments just don't see much incentive in doing anything either, because it's a losing proposition — you'd spend a lot of "political capital" and probably earn a lot of resentment in return, except for a few nerds who'd love it.

I've thought long and hard about how to overcome all these historical roadblocks, but I honestly have no idea in this case. Calendars are... loaded topics for way too many people, and useless concerns for most everyone else.

It's like the dozenal society. They're right, about everything, but it just won't happen.

Re: ProtonMail takes aim at Google with an encrypted calendar

#86
post #77
post #74

Earlier quoted context omitted.

You can't prove a negative.

You definitely can [0], but this one would probably be hard for google without significantly modifying the architecture of gmail in ways that would remove its revenue model. For example, they could open source a client that had audit-able end-to-end encryption, but then they couldn't optimize ad revenue by aggregating and mining large email datasets. [0]: https://en.wikipedia.org/wiki/Proof_of_impossibility

> a proof demonstrating that a particular problem cannot be solved as described in the claim, or that a particular set of problems cannot be solved in general

did you even read the article you linked

Re: ProtonMail takes aim at Google with an encrypted calendar

#87

I recently left ProtonMail and went back to Fastmail. My reason was that they will never be able to fully support IMAP and now CalDAV because of the encryption they use. I grew to accept that email is not for secure messaging and my paranoia of "I'm being watched" just went away. If you need secure messaging, use something other than email.

> I grew to accept that email is not for secure messaging and my paranoia of "I'm being watched" just went away. Agreed. Even if you use protonmail, google still has most of your email because they have the most of everyone else's.

> Even if you use protonmail, google still has most of your email because they have the most of everyone else's.

I have far more incoming emails than outgoing and most of them are automated - probably not using GMail. That includes most of the most sensitive content like invoices and account management.

Re: ProtonMail takes aim at Google with an encrypted calendar

#88
post #29

Earlier quoted context omitted.

I came to a similar conclusion. You should write every email as if it were public, because it's entirely likely that it will be. They can be forwarded, made public through legal discovery, or exposed in a data breach (eg. Sony/North Korea). Forget security for a second, imagining every email as public record will make you more considerate and less biased writer. And from a business perspective, email should be viewed…

I agree with most of what you have written, but this: > doesn't mean I want Google getting a free pass to mine and sell my data. AFAIK, they don't do that with gmail. Do you have any evidence to the contrary? We need to hold Google's feet to fire on privacy, but it is also important that we do not exaggerate or distort the facts.

They already scan your purchases in your inbox: https://www.cnbc.com/2019/05/17/google-gmail-tracks-purchase...

They say they won’t use it to sell ads:

> “To help you easily view and keep track of your purchases, bookings and subscriptions in one place, we’ve created a private destination that can only be seen by you,” a Google spokesperson told CNBC. “You can delete this information at any time. We don’t use any information from your Gmail messages to serve you ads, and that includes the email receipts and confirmations shown on the Purchase page.”

What guarantee is there that this is not being used for other purposes? To train other kinds of models? To, say, monitor other people’s AWS bills, in order to optimize their own offerings? How likely is it that such a project was approved with no gain except adding perceived value to the Gmail product? I have a hard time believing they would do it only for that.

Re: ProtonMail takes aim at Google with an encrypted calendar

#89
post #61

If one doesn't care about web access to their calendar is there any recommended encrypted calendar apps to use on an android device as the default calendar app? Does setting a default calendar app to something other than the calendar on ROM actually prevent calendar data from leaking to third parties?

EteSync[1] has been around for a few years now. It's fully open source and offers secure, end-to-end encrypted, and privacy respecting sync for your contacts, calendars and tasks. Sounds like what you're looking for...

[1]: https://www.etesync.com/

Disclaimer: I created it.

Re: ProtonMail takes aim at Google with an encrypted calendar

#90
post #9

Article is light on the details, but ProtonMail has published some here: https://protonmail.com/blog/protoncalendar-security-model/ > This calendar key will then be symmetrically encrypted (PGP standard) using a 32-byte passphrase that is randomly generated on your device. Once it is encrypted, your calendar key will be stored on the ProtonCalendar backend server. 32-byte passphrase: might be fine, depending on what…

What are your thoughts on Protonmail's security in general?

Specifically this part from their whitepaper https://pbs.twimg.com/media/EKpHwB-WwAE4YN0?format=png&name=...

This is a bad idea right? We aren't supposed to decrypt then verify usually, correct? I'm told this is standard for implementations of OpenPGP, but it just seems like a horrible design (of course OpenPGP itself is probably bad).

https://protonmail.com/docs/business-whitepaper.pdf

Post reply on HN