Live data from Hacker News

Protonmail can delete the wrong email and nobody cares

github.com

81–90 of 254 posts

Re: Protonmail can delete the wrong email and nobody cares

#81
post #76

Earlier quoted context omitted.

The bridge is just another client in the sense that any ProtonMail client would need to decrypt emails so you can view them. To be honest, their web client is probably less secure and trustworthy than other mail toolchains you could run locally. So if the bridge was reliable and trustworthy (which it may not be, hence this submission), using it is probably the most secure option.

“ To be honest, their web client is probably less secure and trustworthy than other mail toolchains you could run locally. ” To be honest, you’re guessing amirite? Be honest. Bizarre statement, it’s like in-browser security doesn’t exist? The password manager browser extension you may use, that’s Swiss cheese right?

You're not looking for a discussion, but rather a fight. I hope you find some peace. Understand that not everyone who responds with a counterpoint also downvoted you.

But I'll respond once in good faith - a browser, which is designed to load and run obfuscated remote scripts from quasi-trusted sources, and display complex untrusted HTML mail content, and which is subject to XSS vulnerabilities, will always be inherently less secure than, e.g., mutt. It exposes you to potentially malicious second parties (e.g. ProtonMail) and third parties. This is true regardless of any mitigations and security measures that are also built in to the browser. If you have enough distrust in your threat model to use ProtonMail, you also likely acknowledge the browser's weaknesses.

Re: Protonmail can delete the wrong email and nobody cares

#82
post #70

Earlier quoted context omitted.

If you’ve been using your mailbox (and deleting mail) for a while, have over 50K mails in it now, and see (what you think is) a UID of 51950 on the most recent email, the chances that it’s “U” are extremely low, meaning there’s a gap in understanding or in implementation.

Every time I see that, I’m floored by it. The fact that message IDs in IMAP change when you delete messages has got to be one of the worst design choices in any in-use protocol. I’m flabbergasted by it. The sooner everyone moves to jmap the better.

IDs change? Wtf indeed...

Re: Protonmail can delete the wrong email and nobody cares

#83
post #68

Earlier quoted context omitted.

If I understood correctly I run this bridge on my computer which connects to the protonmail API, downloads my mail, then decrypts it and starts a local IMAP server, so I can read it with my thunderbird. The email stays encrypted on the server, and this extension only decrypts it locally like it would happen in the web browser. > You use Proton Bridge to walk your secure email beyond that enclave into whatever YOU are…

Yes. Some people want to subscribe to a premium encrypted email provider so they can download that email locally so it can live perpetually in ever expanding sub folders on disk, in plaintext. These are the people who need Proton Bridge.

I mean, I have all my pcs encrypted with veracrypt and don’t have any issue with storing my emails in plain text on my disk.

Re: Protonmail can delete the wrong email and nobody cares

#84
post #8

They also don’t care about locking you permanently out of your own e-Mail with no warning, for no reason, with no recourse. Honestly - there are far better options out there. They’re not in anyway a responsible enough business to manage an e-mail service. It’s run more like a hobby project than critical infrastructure.

What are those better options that HN likes? I just switched all my accounts to protonmail, but stories like this make me want to reconsider. The fact that they won't allow me to set up a forwarding rule in case I want to switch again doesn't help.

I'm a happy customer of Zoho Mail

Re: Protonmail can delete the wrong email and nobody cares

#85
post #8

They also don’t care about locking you permanently out of your own e-Mail with no warning, for no reason, with no recourse. Honestly - there are far better options out there. They’re not in anyway a responsible enough business to manage an e-mail service. It’s run more like a hobby project than critical infrastructure.

What are those better options that HN likes? I just switched all my accounts to protonmail, but stories like this make me want to reconsider. The fact that they won't allow me to set up a forwarding rule in case I want to switch again doesn't help.

Anyone has experience with hey.com?

Re: Protonmail can delete the wrong email and nobody cares

#87
post #9

My own mail policy is simple: - a hosted service because host one myself is too much work CAUSED by anti-spam measure by some "self-appointed sheriffs" of the net; - mail fetched from remote via fetchmail, no messages left on the server, filtered on my homeserver via maildrop, indexed via notmuch, muchsync-ed over SSH to desktop(s)/laptop. That's is.

I think we have very different understandings of the word "simple".

Simple meaning: I'm not tied to anyone specifically (personal domain name) and I own my data. They are also on someone else iron, but also on mine and I use them locally. Composing a new mail is just hitting a key on my keyboard, searching my messages like GMail is another key for search&narrow results a modifier+the same key for notmuch-emacs UI. All mails can be linked on all my org-mode/org-roam managed docs equally.

It's FAR simpler and FAR more powerful than any modern crapware UI, BUT is hard to setup due to the little development compared to the mainstream UI.

Re: Protonmail can delete the wrong email and nobody cares

#88
post #8

They also don’t care about locking you permanently out of your own e-Mail with no warning, for no reason, with no recourse. Honestly - there are far better options out there. They’re not in anyway a responsible enough business to manage an e-mail service. It’s run more like a hobby project than critical infrastructure.

What are those better options that HN likes? I just switched all my accounts to protonmail, but stories like this make me want to reconsider. The fact that they won't allow me to set up a forwarding rule in case I want to switch again doesn't help.

Happy user of Migadu here, mostly because they let you bring as many domain names as you want and just charge usage.

Re: Protonmail can delete the wrong email and nobody cares

#89
post #3

The comments in the linked thread are shocking. One person says they lost a job because of email lost by ProtonMail.

I like Tutanota better anyway as it has better value and is truly FOSS (app without Google push is a must for me).

I had to move off tutanota when I discovered they don't offer offline access to email.

Protonmail claims to support offline access, but in every rare occasion I needed it, it wasnt working for me.

Re: Protonmail can delete the wrong email and nobody cares

#90

This sort of reaffirms my belief that UIDs are not sufficient for syncing mail. Emails should be hashed and synced by the hash which would solve other issues, like being able to redownload specific messages that may have got corrupted locally.

Can hashes not collide? Would that not cause problems?
Post reply on HN