Live data from Hacker News

ProtonMail takes aim at Google with an encrypted calendar

venturebeat.com

91–100 of 154 posts

Re: ProtonMail takes aim at Google with an encrypted calendar

#91

I recently left ProtonMail and went back to Fastmail. My reason was that they will never be able to fully support IMAP and now CalDAV because of the encryption they use. I grew to accept that email is not for secure messaging and my paranoia of "I'm being watched" just went away. If you need secure messaging, use something other than email.

For me it was their app just being so far behind Fastmail. If they had a better app I'd gladly pay. I just can't stomach gmail anymore and Fastmail was next best.

Amusingly enough, Fastmail is a web app wrapped in WKWebview and Protonmail is a truly native app.

Based on comments over in /r/protonmail there's some redesigns coming for the apps that should hopefully improve on the creature comforts.

Re: ProtonMail takes aim at Google with an encrypted calendar

#92
post #53

Earlier quoted context omitted.

I somewhat believe our society would be easier if we had a better, simpler standard for time.

My only agenda as Ruler of the World is to move the prime meridian to the longitude closest to the population center of the globe, and define one global time off that.

You have my full support! There is no reason why we couldn't introduce a better standard.

https://xkcd.com/927/

Re: ProtonMail takes aim at Google with an encrypted calendar

#93
post #29

I recently left ProtonMail and went back to Fastmail. My reason was that they will never be able to fully support IMAP and now CalDAV because of the encryption they use. I grew to accept that email is not for secure messaging and my paranoia of "I'm being watched" just went away. If you need secure messaging, use something other than email.

I came to a similar conclusion. You should write every email as if it were public, because it's entirely likely that it will be. They can be forwarded, made public through legal discovery, or exposed in a data breach (eg. Sony/North Korea). Forget security for a second, imagining every email as public record will make you more considerate and less biased writer. And from a business perspective, email should be viewed…

> You should write every email as if it were public, because it's entirely likely that it will be. They can be forwarded, made public through legal discovery, or exposed in a data breach (eg. Sony/North Korea).

None of these are unique to email.

This is the attitude one should take for any electronic form of communication. Even old-fashioned ink on paper letters of significance have made it into the public record for all to see.

Re: ProtonMail takes aim at Google with an encrypted calendar

#94

Earlier quoted context omitted.

I agree with most of what you have written, but this: > doesn't mean I want Google getting a free pass to mine and sell my data. AFAIK, they don't do that with gmail. Do you have any evidence to the contrary? We need to hold Google's feet to fire on privacy, but it is also important that we do not exaggerate or distort the facts.

They already scan your purchases in your inbox: https://www.cnbc.com/2019/05/17/google-gmail-tracks-purchase... They say they won’t use it to sell ads: > “To help you easily view and keep track of your purchases, bookings and subscriptions in one place, we’ve created a private destination that can only be seen by you,” a Google spokesperson told CNBC. “You can delete this information at any time. We don’t use any inf…

> I have a hard time believing they would do it only for that.

Why? Adding perceived values is how you get more users. More users == increased revenue.

I think the important question is: if Google were doing something nefarious like that, why on earth would they tie it to a public feature instead of just keeping it totally secret?

Re: ProtonMail takes aim at Google with an encrypted calendar

#95
post #29

Earlier quoted context omitted.

I came to a similar conclusion. You should write every email as if it were public, because it's entirely likely that it will be. They can be forwarded, made public through legal discovery, or exposed in a data breach (eg. Sony/North Korea). Forget security for a second, imagining every email as public record will make you more considerate and less biased writer. And from a business perspective, email should be viewed…

I agree with most of what you have written, but this: > doesn't mean I want Google getting a free pass to mine and sell my data. AFAIK, they don't do that with gmail. Do you have any evidence to the contrary? We need to hold Google's feet to fire on privacy, but it is also important that we do not exaggerate or distort the facts.

Unlike most other responders, I generally trust Google not to do this. Everything they say they don't do has been confirmed to me one way or another by people working there that I trust.

They may make money off ads but I don't think they have any real incentive to lie about what they're doing. Because most of their users don't actually care. I would be curious if anyone knows of any scenario where Google has outright lied about what they do and don't do with information, because I've never heard of it.

For me, I moved off gmail for other reasons: my email is too important to randomly lose access to because e.g. their youtube AI thinks I'm spamming a channel on Youtube. I look at all my data in Google as if I might lose access to it forever some day, because someday I might, with zero recourse.

Re: ProtonMail takes aim at Google with an encrypted calendar

#96

Earlier quoted context omitted.

They already scan your purchases in your inbox: https://www.cnbc.com/2019/05/17/google-gmail-tracks-purchase... They say they won’t use it to sell ads: > “To help you easily view and keep track of your purchases, bookings and subscriptions in one place, we’ve created a private destination that can only be seen by you,” a Google spokesperson told CNBC. “You can delete this information at any time. We don’t use any inf…

> I have a hard time believing they would do it only for that. Why? Adding perceived values is how you get more users. More users == increased revenue. I think the important question is: if Google were doing something nefarious like that, why on earth would they tie it to a public feature instead of just keeping it totally secret?

I think you're right in the simple case, and they're not _currently_ doing something nefarious, but I also think it takes one creative product manager one day to decide they will directly sell that data, and most people will be too invested by that point

Re: ProtonMail takes aim at Google with an encrypted calendar

#97

I recently left ProtonMail and went back to Fastmail. My reason was that they will never be able to fully support IMAP and now CalDAV because of the encryption they use. I grew to accept that email is not for secure messaging and my paranoia of "I'm being watched" just went away. If you need secure messaging, use something other than email.

Same deal, I loved the service but I don’t love living in my browser. I wanted IMAP and eventually that meant installing an app that ran a local IMAP sever that your client needed to connect to.

I suppose it’s a limitation of the protocol, and it’s good that protonmail doesn’t store your emails plaintext. However, they know the encryption keys...and so will any attacker.

I went to the Office 365 email package because I get more value out of the exchange server. Any emails I want to encrypt, I will do so myself. 99.99999% of my inbox is spam and automated mailing list crap and notifications and TOS updates, with maybe one or two emails every couple of months that are actually from a human being.

Re: ProtonMail takes aim at Google with an encrypted calendar

#98
post #33

Correct me if I'm wrong, but this doesn't appear to be CalDAV-compatible. If so, xkcd-927 strikes again :-(

If you want to build something which can't be compatible with popular standards, what is the better choice? Build it anyway, or let those standards stop you? It's the same reason I can't read my PGP-encrypted email on my phone.

Do what Fastmail did, and work with the community (generally via the IETF) to make your new standard open and compatible:

https://fastmail.blog/2019/08/16/jmap-new-email-open-standar...

Re: ProtonMail takes aim at Google with an encrypted calendar

#99
post #31

I lost a lot of faith in Proton when I learned how much funding they took from the EU. It just runs entirely counter to evidence we’ve seen of Snowden, 5eyes/14eyes, and other programs that the EU truly wants end to end encrypted comms for people. Am I wrong to be skeptical? Edit: oh apparently I’m wrong to even suggest something we have other examples of

I disagree with much of your comment: > I lost a lot of faith in Proton when I learned how much funding they took from the EU. Unless the origins of the money are unethical (e.g. blood money), it's not where it comes from that matters, it's what's done with it. I haven't seen any misconduct from ProtonMail and the EU's motivations for giving the money seem to be economic, which makes a lot of sense. They want competi…

> Unless the origins of the money are unethical (e.g. blood money), it's not where it comes from that matters...

Well, if it's government money it's hard to justify that it's ethical. Government money is blood money: don't pay your taxes and you'll get your property taken away from you, go to prison or even get murdered by the state.

I understand that the idea the government is "benevolent" is somehow indoctrinated into people's heads from a young age, but objectively that's very far from being the case.

Now, in regards to this "investment" in Proton, if it's government money, it's necessarily a "malinvestment". If people didn't get their money taken away from them through taxation and would spend it according to their needs, Proton might or might not exist. If it does exist solely because of that specific "investment" though, most likely it's not sustainable, and that "investment" created economic signals that are distorted.

Re: ProtonMail takes aim at Google with an encrypted calendar

#100
post #86
post #77

Earlier quoted context omitted.

You definitely can [0], but this one would probably be hard for google without significantly modifying the architecture of gmail in ways that would remove its revenue model. For example, they could open source a client that had audit-able end-to-end encryption, but then they couldn't optimize ad revenue by aggregating and mining large email datasets. [0]: https://en.wikipedia.org/wiki/Proof_of_impossibility

> a proof demonstrating that a particular problem cannot be solved as described in the claim, or that a particular set of problems cannot be solved in general did you even read the article you linked

Apologies, I thought you were saying that you can't prove a negative... that negative proofs (like the examples linked) do not exist.
Post reply on HN