Why ProtonMail is more secure than Gmail
protonmail.com
protonmail.com
Calling this fundamental difference in approach "more secure" manipulates the less-informed instead of educating and almost eliminates the chance of a worthwhile conversation about tradeoffs and values that could be very flattering to ProtonMail.
It's like comparing Android to Qubes OS. Not really fair. For what they are, Google products are surprisingly secure.
It's not a panacea. There are physical threats, there are threats from the very hardware you're using. But, like it says on the box, it is a reasonably secure operating system.
[1] https://blog.quarkslab.com/xen-exploitation-part-2-xsa-148-f...
Also, with their recent foray into enterprise support, they will hopefully be able to expand their auditing efforts in the next couple of years.
For one their products are not "secured" from Google seeing your private data...
In simple terms, end-to-end encryption means that messages are encrypted on the sender’s device (before it even leaves their computer or mobile phone), and can only be decrypted by the recipient on their device. This means that no third party which transmits or intercepts the email between the sender and recipient (i.e. internet service providers, the NSA, or even ProtonMail as the mail server operator) can decrypt and view the message.
This powerful protection is possible because ProtonMail has PGP email encryption built-in. End-to-end encryption is done automatically without user interaction whenever messages are exchanged between ProtonMail users. For an enterprise using ProtonMail for their email hosting, this means all communications between employees are automatically protected with end-to-end encryption. ProtonMail can also support sending/receiving end-to-end encrypted messages with recipients who are not using ProtonMail. The use of end-to-end encryption makes ProtonMail a better choice for security conscious individuals and organizations.
Which would correspond to a tiny fraction of all email a normal user exchanges and Even corporate users would be unprotected if they were to use protonmail to communicate with third parties such as service providers.
That said, even though the argument is a bit flawed here, I think most attracted by it would still prefer ProtonMail for other sound arguments.
I don't know about any security brochure, but I know I can setup 2FA to use push notifications (not an insecure SMS number), and can check where all of my logins are from, and have "suspicious" logins blocked automatically, etc, etc. I can also create single-use passwords for insecure devices (such as a youtube password just for my apple TV). Not to mention how amazing they are about spam detection.
I think their security posture is actually excellent.
Yes. Most definitely. I don't use Gmail and I recently had a discussion with my coworkers about Gmail. When I asked why they use it one person said, "because it's Google" and another said, "What else would I use? Yahoo or Hotmail? Hahahah". A third person responded by saying , "it's just easy because it's Google so it connects to everything else from them."
Absolutely. No doubt in my mind.
Plus, you could say they are describing a threat model. If ProtonMail were compromised in this one particular way the confidentiality of your mail would be 'stronger' or 'improved'. This should be as reassuring as 'Switzerland', which is, of course, also trotted out.
Without a threat model (that is, the set of threats that one is trying to secure a system against), you have no idea what someone means by "secure". It could mean unpickable doorlocks, it could mean unbreakable windows, it could mean angry-Hippopotamus-proofing. It could mean that you smelly farts can't escape your pants.
Any claim of security without a threat-model is in the most literal sense meaningless. And don't get me started on "Military Grade Encryption", which is a term that at this point should give you a sense of concern, rather than safety.
I'm not sure I understand what your counterpoint here is since we seem to be saying the same thing but I had to go back and fix 'thread model' twice myself. An underestimated threat model to commenting about threat models!
What are some specific threats that Gmail defends us against more effectively than Protonmail?
On the other hand, they have more resources than anyone else to protect against things like DDOS, nation-state hacking/phishing, and physical disasters. They also have a legion of lawyers to protect against improper legal requests, however they will roll right over for a government if it's legal.
Protonmail is on point with the privacy, but their security engineering team is probably less than 1/10th that of Google's.
So team size alone doesn't convince me one way or the other, even if I were to completely disregard all privacy issues.
I am a Gmail user as is my company, so I do trust them quite a bit. But I feel that Google has a much bigger problem on its hands than Protonmail. Both because of its business model and because Gmail does things like search and spam filtering, which Protonmail cannot do.
[Edit] Protonmail actually does spam filtering.
https://blog.google/products/gmail/g-suite-gains-traction-in...
They are definitely still reading your gmail. How else would the spam and other filters work? They can also use it under this policy for anything but "ads personalization". Machine learning, Google product integration, other recommendation not deemed to be ads, refining your google profile, etc. A very narrow scope of exclusion.
Spearphishing is a huge source of compromise at the moment; antiphishing filters might, in that view, be considered a security feature rather than a security fault.
On the other hand, I have, frankly, never understood these privacy arguments. Is it a privacy violation if someone checks a checksum of my incoming mail against a blacklist? What if they compute a hash of my mail to check the DKIM signature? And if those are OK, why is an ML model more of a problem?
No, the privacy concern is about the potential for abuse if there is a known place in the world where a very detailed account of all my online (and some offline) activities, contacts, communication and personal interests is stored.
It obviously arouses the interest and desires of criminals, governments, employers, politicians, landlords, insurance companies, creditors, marketers, ex partners, extremists and bigots, journalists, potential mates, researchers, etc.
Some of these groups are overlapping and some of the concerns might only arise in the distant future. Governments change. Ownership of companies changes. Personal circumstances and opinions change, but you can't take anything back once its out.
So even if someone hacks into the spam filters, they won't be able to reconstruct content from your account. They _might_ have insight into things like word usage, but they won't have reconstructed sentences or the like, a priori.
You can build systems like this without having long-term storage of the content, which protects against data issues for one-time leaks.
And, if it's being interpreted by a machine, does that really count as reading?
An email with the order went to my @gmail. The next day in my Youtube videos the ads where for stop smoking patches.
They read email.
Sometimes hilariously. A few years ago a friend emailed me a barbershop quartet video, and I spent the next couple of weeks getting hairdresser ads ...
One could argue that Google's filtering of spam and potentially harmful mail is a point in favor of Google.
Email headers contain a lot of information. It has the various email addresses, servers involved, ip addresses, time stamps, subject, priority, and things like that.
The body of the email is the only part that gets encrypted when encryption is in use.
My entire family uses Gmail (our domain is hosted via Google Apps) and as far as I know, it's been very close to perfect for all of us.
Gmail + 0$ per month = zero privacy for you and anyone who emails you, plus Uncle Sam has full access to your life.
Protonmail + 4$ per month = you will never see ads for a <insert_item_name> like the one you just bought, plus you will be driving Uncle Sam crazy!
There’s a reason all my systems use other cards, and are behind a hardware firewall specifically configured for my use cases.
Let's assume a system where every piece of hardware has a closed device driver, or part of it, CPU included. We're there, or very close. It's not that hard to imagine a system within the system that can access data (hard drives have closed blobs), read passwords before they are encrypted through keylogging (USB sniffing), make screenshots of the desktop (video card closed blobs) and send them wherever they're instructed to (network card blobs), not to mention downloading and executing arbitrary code.
Now one could object that the traffic could be easily intercepted, but what if all network chipsets of all vendors, including those inside routers, had a small set of instructions to intercept any magic packet satisfying some rules and treat it differently. Let's say send it to some hardcoded addresses without counting them or reporting them to user applications; even leds on front panels would not report those packets passing through. The only way to realize something fishy is going on would be by tapping physically into the network cable using non-network dedicated chipsets, say very fast digital analyzers, decode all traffic and match it with what a normal sniffer would report.
I admit this is a crazy scenario, but if an entity with nearly infinite resources had the power to force any hardware vendor to put spying hardware/firmware into every machine, wouldn't it attempt to do something like that?
Encrypted messaging apps and services like ProtonMail have never been primarily to help people with Snowden's threat model. They're for people like you and me to reclaim a semblance of privacy, and they work even with "Uncle Sam" as the threat model in a limited, dragnet surveillance sense.
They don't work, because the US government's modus operandi is compromising machines or forcing users to provide access to their encrypted data. It's unclear to me why, if you take as premise a government capable of forcing one of the most valuable organizations in the world to hand over its data, you believe a company several orders of magnitude smaller is safe because it's "end to end encrypted" and has servers in Switzerland.
Put another way, I find the concept of a government willing to force Google to give up data but unwilling to use operational vulnerabilities to achieve the same thing to be contrived - how is this not just an arbitrary line in the sand?
Furthermore, the heuristic itself is a red herring, in my opinion. It is far more likely that Protonmail has a critical security vulnerability inherent to its software than Gmail does. And even if we assume that the government doesn't want to spend economic resources on actively compromising you as an individual, why would the government not spend resources on a system to compromise you passively as part of an en masse campaign? In other words, are you using a custom built computer with parts designed by a boutique firm from another country immune to the wiles of government backdoors?
How do you decide where you want to stop down the rabbit hole, and are you really doing so empirically?
In the US we have a constitution the prohibits searches of our papers without a warrant signed by a judge. It might be out of fashion is some circles, but the rule of law and not just rule of power is quite popular and I would say a superior system of governance. Many Chinese who are acquiring assets outside of China feel the same way.
"use operational vulnerabilities" am I the only one who strongly believes that Micro$oft is in bed with every 3-leter-agency in haning out backdoors/vulns for the last 20 years?
I'm not so sure - at least as recently as 2013, Lavabit showed that even top level US govt targets had some realistic reliance on properly encrypted 3rd party email providers...
The "dragnet" is the thing that's potentially useful - if it's difficult enough for them, they can't do warrantless "full take" surveillance - even for non US citizens, then choose to individually target you later based on a complete historical record being open to keyword/"selector" based searches.
(And for the appropriately paranoid - even Levison's comments back then suggested the thing he was prepared to fight and maybe go to jail for was handing over the SSL key that'd have exposes _all_ users. Reading it the right way suggests he may have sold Snowden out on his own - and I can't exactly say I wouldn't have done so myself in his position - but he was principled enough to not hand over the keys to the entire userbases's security. I sincerely hope _I_ never have the protection of privacy of a user like Snowden being my responsibility while the full pressure of the US government bears down on me. I strongly suspect my strongly-held personal principles would not stand up to that...)
ProtonMail doesn't meaningfully address the mass surveillance aspect, though. Most emails still hit its servers in plain-text form. Encrypting once it hits their server doesn't help the mass surveillance aspect, it only helps the targeted surveillance when a warrant comes in.
And if you're willing/able to get everyone that emails you to switch to PGP to get real end-to-end encryption then protonmail is worth even less, since none of their benefits matter anymore (google is obviously not able to decrypt your PGP emails, either).
For me - I think they're useful protecting against dragnet "full take" surveillance (especially since I'm a non-US citizen, so am considered "fair game" for warrantless surveillance), but I don't for a moment think they'll protect me from any sort of state actor level interest targeting me specifically (I'm still gonna get Mossad`ed upon...)
(In more paranoid moments, I suspect that the first "dragnet" protection quite probably makes the second "targeted interest in _me_" more likely...)
“The government can hack anyone, just give up” is a dumb objection if you view security from an economic perspective. Defenders have a huge advantage over attackers that we aren’t sufficiently taking advantage of yet.
I am not sure I understand the “fear” of the US government. Do we have cases of “normal” people being harmed from NSA type activities? We’ve had a ton of cases of normal people being harmed from non-government “hackers,” so, from a risk management perspective it seems silly to prioritize surveillance avoidance over garden variety thieves. To think Proton has the same level of experience and technology that Google has is a bit naïve.
And server location doesn’t particularly mean much. Plenty of Swiss banks have been compelled to turn over US citizen information due to FATCA — it’s not a stretch that a legitimate request for information by the US government would be honored by the Swiss if it pertains to a US citizen. For non-US citizens, there might be some benefit to an offshore server, however email is generally not the weakest link in surveillance. Also, you’d need to ensure that all your recipients are also using non-US as well as non-British, or non-French systems as well.
US surveillance is in the spotlight, but France and the UK are equally aggressive, if not more so since the actual laws in the UK and France are much more liberal in terms of allowing government to intercept communications. The French law doesn’t even require a judge (secret or not.)
https://www.recode.net/2015/11/14/11620670/france-has-a-powe...
And then there is this law In Switzerland— backed by almost 70% of voters:
http://www.bbc.com/news/world-europe-37465853
I think Proton is a nice alternative, but other than effective marketing, there isn’t much differentiation from paid Google Apps/Gmail plans. Comparing “free” gmail with Proton isn’t exactly honest, comparing paid gmail to Proton is probably a more valuable comparison.
With Gmail, for example, it’s possible to get a Business’s Associates Agreement for HIPAA compliance.. which means that it’s possible to have email that’s more secure than “normal” free Gmail. Of course HIPAA isn’t relevant to government surveillance, but really, how many people are actually at risk from the NSA? If that concern is part of your risk profile, then perhaps you ought to be living in a Tora Bora cave with messages being delivered encoded with a one time pad. If you are worried about your Antifa or KKK meeting minutes being intercepted, it’s likely Proton isn’t going to be much help.
In other words, your comment is pointless.
Putting my tinfoil hat on, I'd say that they got a new-improved way to get in, and they patch the old one because now the 'others' got whiff of this (e.g. shadowbrokers) and are about to start abusing it themselves :)
https://www.usenix.org/system/files/1401_08-12_mickens.pdf
Threat: The Mossad doing Mossad things with your email account
Solution:
* Magical amulets?
* Fake your own death, move into a submarine?
* YOU’RE STILL GONNA BE MOSSAD’ED UPON
First and foremost, despite widespread fetishization of things like end-to-end encryption, real world software rarely differentiates its security based on superior cryptography. Most security vulnerabilities occur at the endpoint level and are not even technical vulnerabilities, they're just successful, targeted phishing campaigns. The next most common set of vulnerabilities are in mundane software, typically in the infrastructure and peripheral logic. These are due to developer ignorance, misconfiguration or sometimes both. From there we have crypto implementation flaws, which are typically due to software engineers' fascination with implementing their own cryptography libraries or taking strange liberties with existing libraries that deviate from the explicit or implicit intentions of the original author. Finally, on a peak so remote and small it's scarcely visible from the ground, we have actual cryptography design flaws, where someone literally rolls their own crypto at the conceptual level and deploys it.
Second, email is a fundamentally antagonistic medium when it comes to end-to-end encryption. If you are actually concerned about your privacy and you're discussing something that warrants extreme care, email is the least user-friendly and most error-prone method of going about it. You should consider a synchronous medium with forward security if possible, probably based on a well-known and well-audited messaging protocol (to avoid a flame war I'm not going to suggest any particular one - do your research).
Third, if your threat model is honestly the US government, you need to significantly revise your opsec entirely if you're realistically considering Protonmail. Regardless of its actual security, you're (implicitly) saying that you trust Protonmail to be capable of withstanding the resources of a motivated three letter agency with an armada of security compromising tools at its disposal. Why trust a third party at all then? What makes you think the servers being in Switzerland is going to help you if you distrust the government this much? By all means, don't use Gmail either, but then Protonmail isn't really a coherent security measure either - again, use a synchronous messaging platform, or develop the opsec needed to consistently use PGP correctly on your own.
Given the foregoing, if your adversary is actually the US government, neither Gmail or Protonmail are effective strategies, and if your adversary is not the US government, Google's security team is vastly more qualified and has overwhelmingly more resources at its disposal to secure its email infrastructure.
There are some people for whom "The government is literally after me, personally" is a valid threat model. There are some people for whom "Google employees with privileged access to Gmail are conspiring to be after me, personally" (one assumes there's a two-person rule for access to individual inboxes or deploying code that scans inboxes) is also a valid threat model.
However, those people should consider that the government will be willing to use either software 0-days or algorithmic 0-days to attack them (see e.g. Stuxnet taking out Iran's nuclear program using a previously unknown method of generating SHA-1 collisions, that looked kind of like how the academic community knew to generate collisions but with a different fingerprint), in the government case. Or that any interaction with anyone who uses Google must be avoided, in the Google case. See e.g. https://mako.cc/copyrighteous/google-has-most-of-my-email-be...
For normal people (which includes me and probably everyone else commenting here)? Google seems at least as likely, probably a tiny bit more, to protect me from threats like "A personal relationship has gone bad and someone who isn't a government and isn't Google is trying to impersonate be me" or "I don't want to lose access to my email" (remember that availability is a part of security!).
Really? You've heard just as many stories of unexpected Google account closures as I have.
I'm quite confident ProtonMail just don't do that. And if they did, you'd have a much more credible chance of talking to a human and rectifying the situation.
It's abused fairly regularly in fact.
There are a lot of cases but I'm at work and can't spend too much time collecting much. The gist however is that they are bound by Swiss speech laws, which are very ambiguous. "Inciting violence" is one such example, but of course, they can't see what you are supposedly inciting, so they suspend you.
But I think there are lots of other options besides ProtonMail that will do the same. (I pay $50/year for Pobox.com, personally, and vaguely feel like paying a bit of money for my email instead of relying on a free service is worthwhile.)
https://protonmail.com/blog/protonmail-threat-model/
Which says don't use it if you are up against state actors and: "Sensitive business communications – You have sensitive business information that you want to make sure is protected from competitors and other malicious parties. For example, you fear a competitor may want to sue you under false pretenses to get access to sensitive data. In this case, ProtonMail offers a great deal of protection. ProtonMail will not release ANY data unless provided with an enforceable Swiss court order. To get such an order, the case must first work its way through the Swiss courts where stricter privacy laws might result in a different ruling. Even if an adversary went through the expensive and time consuming procedure of obtaining such an order, ProtonMail’s zero access cryptography means we would only be able to release data that is encrypted since we do NOT hold the decryption keys."
Given that they have Javascript to handle the decryption keys, couldn't they demand ProtonMail change the code delivered to your browser session to give up the keys? This would make the only extra security provided by this scheme would be the multiple court jurisdictions and the less tested legality of a court order making their product less secure, ala the FBI and Apple.
Swiss authorities and security services cooperate closely with partners all over the world including the NSA. And there is a longstanding and working network of mutual legal assistance including the Convention on Cybercrime (CCC).
> "Nearly every country in the world has laws governing lawful interception of electronic communications. In Switzerland, these regulations are set out in the Swiss Federal Act on the Surveillance of Postal and Telecommunications Traffic (SPTT) last revised in 2012. In the SPTT, the obligation to provide the technical means for lawful interception is imposed only on Internet access providers, so ProtonMail, as a mere Internet application provider, is completely exempt from the SPTT’s scope of application. This means that under Swiss law, ProtonMail cannot be compelled to backdoor our secure email system."
[0]https://protonmail.com/support/knowledge-base/protonmails-ss...
Why bother?
If they can MITM ProtonMail, they might as well use letsencrypt which just requires you control the domain name (for some definition of control).
> I'm not sure what the state of certificate pinning is,
Public-Key-Pins-Report-Only: pin-sha256="Jh0ZSUYEc97HRYcwZIOkH2jKOUpmQhLO48MYd1s5pRM="; pin-sha256="2ZnCTNQBrKShr4c1olKfwNG53KiL6qoNcQi65YGRBn8="; pin-sha256="1D76xWwHug9p4iQWVBiDZF+e3UcxtPte/ig5pkYnmRU="; max-age=300; report-uri="https://protonmail.com/pkp-report"
Looks like they want to know about violations...This is often used as an argument by EV advocates, but it doesn't hold up under scrutiny. An attacker with access to a non-EV certificate can selectively intercept only connections for subresources of the targeted site (i.e. JavaScript). The "main" connection would still use the EV certificate and thus show the browser indicator. This attack was first made public in 2008[1] and has been further refined in later work[2].
HPKP and the Expect-CT header provide some viable mitigations for this. That said, it seems unlikely to me that a nation-state adversary would choose to attack at the Web PKI level in this scenario. Compromising ProtonMail or the user's device would probably cheaper and less likely to be detected.
[1]: http://w2spconf.com/2008/papers/s2p1.pdf
[2]: https://www.blackhat.com/presentations/bh-usa-09/SOTIROV/BHU...
Switzerland is not an island of privacy with regard to state surveillance – and with regard to private data privacy, it basically mirrors the European Union’s standard. According to Snowden documents, Swiss intelligence and security services are close partners with the NSA and other foreign services.
Do you think that's partly because, like most countries, the truth is... obfuscated.
In other words, the law does not say that ProtonMail is exempt for having to provide lawful interception. They might still have to do so, based on some other law.
Further, it's quite conceivable that unlawful means (such as blackmail, threats, or bribery) could be used to coerce ProtonMail. That's not to mention perfectly lawful means of enticing them -- like appealing to their patriotism, willingness to help in a critical investigation, or demonstrating some credible threat.
To my knowledge, it was Flame that did this not Stuxnet, and it was an attack on MD-5, not SHA-1 [1]
Arent there many (difficult to judge how many) cases of people losing access to their Google account, and therefore about everything they had online (photos, email, videos, etc...). That is also scary enough, especially when it happens randomly with no clear reason why and the support of Google seems to be limited to sending info via forms in the hope of a future human interaction.
People underestimate the power of a calm, deliberate letter sent by post with an elected representative or two copied.
It shows you're serious. Most people complain to blow off steam. This is what customer service handles. If you want something done at the corporate policy level, e.g. to have policy changed or have a decision made per policy reversed, you attack at higher levels.
The traditional form of leverage is legal. Have a lawyer pen a letter gets you out of customer service. It is as effective as it is expensive. Next best is a regulator (you can think of these as narrowly-scoped, publicly-funded lawyers). Unfortunately, nobody regulates Google.
So your final threat is getting a lawmaker pissed off with you. This is less about passing legislation (it's hard to pass legislation; everyone knows that) than creating an official, reliably-corroborated paper trail which could go public, causing PR damage, and/or damage relationships the company may want to lean on in the future.
More practically, I don't want to sit around writing and responding to letters. Having someone else do the back and forth with me Cc'd is more pleasant.
Disclaimer: I am not a lawyer. This is not legal advice. If you need legal advice, contact a lawyer.
There are, but that's not incorporated into a threat model because it's not a security issue (at least not a first-order security problem).
Unauthorised access, content modification or deletion, impersonation, and several other categories of security policy violations are also fairly typical.
Most of the cases of people losing access to their Google account that I've seen are not ones which would could feasibly be induced by a dedicated attacker unless they already had access to your account in the first place.
That may be a part of your personal threat model and also your decision-making, but from Google's perspective, that's not a security issue.
Yes, you could argue that only the loud ones making noise get their accounts back, which my be true, but considering that billions of people use GMail, the fact that so few stories even show up means that it's probably safer than even air travel.
If a service has thousands of times more users than another, you'll expect weird edge cases to show up thousands of times more often.
I thought employees do not have access to user data. Can anyone comment on this?
With months of effort researching tripwires and auditing systems, any of them could read your mail.
There's a pretty good chance they'd get caught by some auditing or alerting system they were unaware of though. Many of those systems are kept secret from employees for obvious reasons.
Any two employees collude to much more easily read your mail. There's probably ~1000 people in that position (not only the gmail team, but anyone who writes any kind of library code used by any of the databases, datastores, or application servers). They would leave audit records though, although they might go unnoticed.
A convenient way to put a target on your back. What benefit does this have to their security? Accountability?
I expect that any single Google employee does not have access, in the sense that they've locked themselves out of making changes to their systems without a computer seeing multiple human approvals. But there is a point at which someone can fix that computer.
But yes, my point was that the threat model here isn't "one Google employee goes rogue," it's "multiple Google employees with extremely privileged access to Gmail and/or their code deployment servers all decide that they want to read your email without telling you, and nobody blows any whistles," which seems much more far-fetched.
A lot of people in our industry and others have this same model. It is not that the NSA is after you. It's local law enforcement. In our case, SEC and FBI. For average users, local LE will not have 0 days or anything special. Protonmail is out of reach for a lot of LE and that is important.
The best choice for us when we're fully operational is to run a Protonmail-like setup, self-hosted. Deal with mail issues and spam. It is a pain!
Email is insecure, and most users don't even consider security when using it. I've seen my own social security numbers sent out via email. I've seen corporate card credit card numbers sent via emial. I've seen other confidential financial documents and a myriad of other things sent via email by people who didn't know or didn't care that the method of transmission isn't secure because frequently it's not their information at risk. In my experience, medical data is treated differently because there are laws around how it can be communicated and stored. Until there's regulation placed around other pieces of information, and those laws get enforced, I don't know that people will change how they use and abuse email.
"Switch to this other email provider" is not going to get much of a result from your gmail/outlook-using contacts (especially if money is involved), and wouldn't even solve this issue unless you convert absolutely everyone to, for example, Protonmail. "Hey man can you set up this thing called PGP?" is probably even worse unless your social circle is all technically minded already. Even in a group of "nerds that play video games", I'd be surprised if even half of the group even know what PGP is.
So long as we're stuck with email as we know it today, it really seems like there is just no bolt-on solution that can be used to "fix" it.
This is true of the marginal utility of the first and last element in a network effect. We might as well push for a paradigm where hosts have no access to data rather than, in 1950 say "Why should I join the internet, there are no other computers on it"
My money finally went to Fastmail. Excellent email service - just works and doesn't try to be super smart and take over the world.
https://www.nytimes.com/2017/06/23/technology/gmail-ads.html
US law interpretation of IMAP. Only with a POP3 service you are safe.
Retrieving email via the POP3 protocol typically deletes the email upon retrieval, making it impossible for the third party to comply with requests for already-retrieved emails.
What POP3 client are you using that does this? I've not seen it before. It gets marked as read but that's it.
It used to delete from the server after downloading locally. This was when most email mailboxes had a capacity of 10MB.
In general, if you aren't paying, then you're the product.
That is what I'd expect, since obviously they cannot build a search index over text they cannot read. Transferring the entire contents of your emails to your web browser to search locally would be slow and impractical on anything but a very fast connection.
ZKP[2] is real branch of cryptography and they do not use it AFAIK.
[1] https://spideroak.com/articles/why-we-will-no-longer-use-the...
That newsletter is not PGP-encrypted, so at some point the Proton Mail servers must be able to see a plaintext version of it. That means I have to trust that they never store that plaintext version.
In addition, even if they immediately encrypt it and store the encrypted version, how can they do so such that only I can read it? Is the key generated from my password? How come it's possible to reset my password with a recovery email address then? Surely they must be storing the key somewhere, in which case storing encrypted messages is pointless.
EDIT: apparently my second point is incorrect, forgetting your passphrase will indeed leave your emails permanently encrypted. The first point still stands though, it's not zero-knowledge at all if they receive the plaintext of my private emails in the first place and I have to trust that they don't store it.
I believe a copy of the key is sent to the recovery email. Not completely sure, I haven’t entered one.
You can encrypt your "master" key with another key derived from your password. When you change your password, you just decrypt and re-encrypt the master key so that it doesn't have to change.
The combination of these two techniques in one form or another is responsible for much of modern computer security, including the encryption used on this very website.
As it stands you don't send your password to proton -- they send you an encrypted private key that the password you type decrypts (at email creation time you generated that private key in your browser via openppg.js ) They most certainly could change their API to send the password to the server once it's typed in the UI. This isn't unheard of and there is large suspicion that law enforcement made hushmail modify their API for certain users of interest in order to decrypt their mail.
Attacks on build systems of native applications aren't unheard of (CCleaner, that Ukrainian tax software, etc.), but it's far more involved and more likely to be detected, whereas web app backdoors can easily be delivered exclusively to the target and only for as long as needed to pull off the attack.
The main blocker is https://github.com/w3c/ServiceWorker/issues/1208 (which would fix the non-critical but less-than-ideal issue described under "Service Worker lifecycle" in the blog post).
Outgoing mail similar, but there it can be encrypted, so the TAP would be directly at the server, before it is encrypted.
In contrast to gmail TAP's are installed by a warrant ordered by a judge and per customer only. With gmail warrants are not needed, data is just handed over, and search interfaces are available to any agency which wants it.
Gmail could be as secure as Protonmail by using PGP yourself [1]. And then you can keep your desktop mail client.
Also Google won't need to pay criminals if they're DDOS attacked like Protonmail in the past: https://www.forbes.com/sites/thomasbrewster/2015/11/05/proto... (this is when I gave up on Protonmail)
[0]: https://protonmail.com/support/knowledge-base/encrypt-for-ou...
https://protonmail.com/support/knowledge-base/email-ddos-pro...
People whose lives are dependent on secure communication still need to manage their own PGP keys. Once protonmail makes it possible to use your own email client with your own keys, then I'd say it's worth trusting.
> "Nearly every country in the world has laws governing lawful interception of electronic communications. In Switzerland, these regulations are set out in the Swiss Federal Act on the Surveillance of Postal and Telecommunications Traffic (SPTT) last revised in 2012. In the SPTT, the obligation to provide the technical means for lawful interception is imposed only on Internet access providers, so ProtonMail, as a mere Internet application provider, is completely exempt from the SPTT’s scope of application. This means that under Swiss law, ProtonMail cannot be compelled to backdoor our secure email system."
Not all actions of the US government have survived legal review and some may argue the latest administration is more prone to such accidents.
Heck, the EU and US are already not on good terms on the subject of privacy/intelligence gathering, so i doubt this would be done so easily. Especially with the current US administration.
In other words, the law does not say that ProtonMail is exempt for having to provide lawful interception. They might still have to do so, based on some other law.
Further, it's quite conceivable that unlawful means (such as blackmail, threats, or bribery) could be used to coerce ProtonMail. That's not to mention perfectly lawful means of enticing them -- like appealing to their patriotism, willingness to help in a critical investigation, or demonstrating some credible threat.
Unfortunately in this case it sounds like there might be a tradeoff between securing my internet postcards[1] and training spam filters.
[1] and that's all they are really, postcards. We've known that for decades, you can't patch envelopes over emails at this point.
That's fair for you to demand. I run my own personal email server with SpamAssassin and I definitely got a lot of spam in the first week. Then I told SA to learn what spam and ham looks like based on what I received and it's been excellent ever since. I have retrained it about once every 2 years but it's really not that bad. Personally, I'm happy to manually filter a handful of spams and then have top-notch filtering plus added privacy.
In a previous life/job I set up, administered, and maintained mail servers. I don't have an exact count but high tens to low hundreds over multiple clients.
I think that's one skill I'm completely burned out on for personal use. Capable, but not willing.
If you trust them with all that why even encrypt the mail client side?
https://www.mozilla.org/en-GB/thunderbird/
Also, the V1.0 release of Mailpile is meant to be coming soon:
https://github.com/mailpile/Mailpile
For setting up your own email server...
https://www.reddit.com/r/ProtonMail/comments/77ifdx/protonma...
I work for them (oath now). and at some point all employers were forced to dogfood it. the UI took a while to get used, but now I miss in app tabs witg several emails (in Gmail I need browser tabs).
...Long story short: after yahoo was acquired we moved to gmail. you cannot belive how much more spam shows up on my imbox that I had never seens before.
not to mention yahoo took the high road on properly fighting spam for everyone, even if made them loose some users using misconfigured email lists.
my guess, you probably had the y email much longer than the g one (yahoo mail is a decade older) and you posted that email in too many geocities guestboards. do the same with your g address and report back in 10 years :)
If you think of it for a second, web crypto (protection against intermediaries and dishonest server) actually requires trusting the server, so no encryption-derived claims are sound if the server is dishonest. Any third party exploiting (or forcing legally) the server can make it dishonest and collect required keys in few simple steps. And, FWIW, if encryption is controlled by browser, adversary compromising the client itself can simply disable it.
So, while the effort is very important (and I bet they'd be around the first people who will suggest techniques for safe in-browser crypto execution), it isn't that they can be compared security-wise other than: - ethics - security policy - competence of security teams.
Isn't a level playing field for ProtonMail.
And, my final problem is, 99% of people are still outside Protonmail anyway, hence the intolerant winner argument, which ruined PGP and will ruin many optional security systems on top of convenience protocols in the foreseeable future.
We actually agree with some of the points made above, but we'd like to add the following commentary...
Encrypting email while making it more usable than PGP is hard. There's no getting around that. Web crypto is always going to have some shortcomings, but web mail is on the rise, and at the end of the day, web crypto is better than no crypto.
That said, we have been working for some years towards moving ProtonMail encryption entirely to the local environment using our Bridge application, which will be released soon. There is also extensive R&D being done on end-to-end authentication and ensuring key validity.
You are correct in that it is not a level playing field. This is why the tech industry is fast becoming an oligarchy or even a monopoly, owned and controlled by a few big players. However, we think that not playing is taking the easy way out, so even though the game is 'rigged' against us, we have a great team of engineers who have decided to play anyways.
Shoot me a message if you're interested in implementing something like that in ProtonMail.
I've also been a happy customer of your VPN product, but I'd be happy to retire the OpenVPN app on my iPhone. Any word on an iOS app soon?
I seriously disagree on this (our company is facing similar challenges, and I've asked these question myself numerous times). It's not better, it's much worse.
"Some crypto" creates illusion of security, where you don't really know has it failed or not - frequently, there is no functional failure in cryptographic failure. It doesn't stop working, it stops providing the very guarantees you're using it for.
> However, we think that not playing is taking the easy way out, so even though the game is 'rigged' against us, we have a great team of engineers who have decided to play anyways.
Truly so, but you need to play better then ;) Godspeed!
> The final nail in the coffin for me is this page right here: https://protonmail.com/blog/transparency-report/ Can I draw your attention to this sentence: "After reviewing the relevant evidence forwarded by US authorities, criminal intent was apparent, so Proton Technologies AG decided to comply with the data request"
https://www.healthit.gov/providers-professionals/faqs/what-d...
It uses trust bundles that hold the public key. Identity is vetted so there is no spam and it helps guarantee you are communicating with the right person.
https://www.directmdemail.com/info/how-it-works/Direct-excha...
edit: I would also like to add that the direct trust model is starting to get used for things outside of email.
This thing is in production very wide usage by health industry. And the applications for it continue to grow. For example FHIR via Direct promises to empower patients.
But yes, this particular implementation especially is PKI with identity vetting. There are other trust bundles with different logos and requirements.
But the direct project defines more than just the PKI. It defines edge protocols such as XDR and IMAP. It also defines methods for message delivery and processed notifications.
And of course you can create your own trust bundle with whatever requirements you want.
This particular accredited portion means that these organizations have particular identity vetting processes for users, have on site visits to inspect servers, and adhere to a long list of privacy and security practices.
Here is the most popular one. https://services.directtrust.org/about_accredited_bundle/
So what happens if, say a hacker breaches the systems and makes an interception at the SMTP level... before they encrypt? They then can read your mail before ProtonMail encrypts it...
There is a lot of marketing bumpf on this page without any link to detail.
- Encrypted emails sent to non-Tutanota users are permanent (they expire at a maximum of 28 days with ProtonMail).
- Tutanota has an email export feature.
- Tutanota is WAY cheaper.
> Protected by ... European privacy laws
So is GSuite (https://gsuite.google.com/)
> No conflict of interest
There is no conflict of interest with G Suite either, which is governed by a different Terms of Use than normal Gmail. If that wouldn't be the case, being the "business" version, G Suite would be banned in most European companies.
“Zero knowledge” of email content means I can’t search my corpus of email without having all of that mail on a PC with a client that has a search feature.
What’s a bigger risk to you?
“End to end encryption” We’ve all had the PGP discussion. That adds a lot of complexity and a lot of cost and risk. Good luck searching it.
“TLS transport” Welcome to 2017, this isn’t meaningful.
It sounds like Proton Mail is a cool service. But that security comes at a capability cost and comes with other complexity that users may not understand.
The utility is not in magically making every email sent to or from you unreadable to 3rd parties. The utility is purely on the side or privacy intrusion: be it via court order or hacker. Nobody can compel them to decrypt any messages that have been sent to or from you and stored on their servers.
Protonmail will NOT: Prevent interception of your messages by 3rd-party MITM attacks.
Protonmail WILL: Protect your privacy versus legal authorities. Safeguard your stored communications against hacker breach. Provide a high-quality, ad-free email experience and multiple email addresses.
It seems most people care more about spam filters and search functionality than security. Which is kind of a downfall of protonmail because it probably will never have high adoption because if you want good search and spam filters then it means your emails need to be scanned by the servers.
Most people have multiple email accounts anyway, so why not use protonmail for the important emails and another service for junk account signups and everything else?
Potential improvements: Searching the inbox isn't great, and I'd like to reduce my attack surface by moving my transactional email from sendgrid to protonmail (not yet supported). Also, it might make sense for protonmail to become an OAuth provider-I'd be willing to support it on bandgap.io
In practice, yea, no search.
[1] https://blog.fastmail.com/2017/05/13/nyi-datacentre-move/
I think almost every desktop mail client support S/MIME. Many support PGP/MIME, using plugin/extension or natively. Unfortunately, the situation is much worse on mobile.
Anyway, if the client software is capable - which is rarely true but sometimes is the case - any classic mail server can store everything encrypted.
If you self-host - just make your MDA pipe the unencrypted emails to GnuPG or OpenSSL (and encrypted emails are already okay) and that's it. You'll be as good as ProtonMail (note: https://protonmail.com/support/knowledge-base/does-protonmai...). IIRC, there also was some hosted email service that works this way, although I forgot where I saw it and how it was called.
At this time Protonmail does not support IMAP/SMTP or POP3 due to the technology ProtonMail utilizes within web browsers to encrypt and decrypt your messages. We apologize for the inconvenience and are working on creative solutions to allow IMAP/SMTP use.
https://protonmail.com/support/knowledge-base/imap-smtp-and-...
If it uses IMAP4 variant under the hood and not completely different/proprietary API - are there any plans of possibly releasing this as a standalone tool someday?
I don't use Protonmail, because I already have self-hosted own-premises mail system for a long while, but I don't have encryption at rest. Given that you use OpenPGP, this bridge app looks very interesting. If it only could talk to a local gpg-agent as an option (rather than an PM account), it would be probably just perfect.
"ProtonMail can also support sending/receiving end-to-end encrypted messages with recipients who are not using ProtonMail."
Protonmail doesn't afaict encrypt to external keys (PGP, GPG, SMIME), so you're limited to the remote provider's capabilities and practices.
(I'm a Protonmail user.)
The biggest obstacle in becoming secure with email is all of the other people you correspond with over email.
Also, would it be possible that if I open an email on an Android device, that Google still could read the email?
I have a Proton Mail account since 2014, but i never really used it. I might give it a try again today.
Protonmail is a website which can read contents of your email, did I miss something?
Why would you compare a free service with a paid one?
If I give you some blueberries and you buy some from the store, you're still able to compare and contrast the two and the paid blueberries may actually be inferior to the free berries.
My favorite 'feature' of protonmail is that you can't access your messages via imap or pop, and their suggestion regarding exporting messages is: "At this time, you are able to save individual emails by using the "Print" function found inside each email in your account."
Protonmail had a very weird role in campaigning against the new sigint-law in switzerland, they used it for marketing for their service... now they say it's not that bad because protonmail advises the government on it.
I am very dubious of protonmail's claims. They don't release their server-side code, so nobody can audit it. There is no way to make sure a PGP encrypted message sent to a friend is actually encrypted with their public key only, you have to trust them.
You are also just one XSS away from losing your private key...
The reason not to open source the backend code is... terrifying: https://protonmail.com/blog/protonmail-open-source/#comment-...
What about the other things that are important, like does protonmail do full disk encryption? do they log ip addresses? They require you to sign up with a phone number if you use tor, but "promise" not store that. How can we trust them?
Their ToS states: "you agree to not use this Service for any unlawful or prohibited activities". But hey, if Mr. Robot uses it, it must be good!
They also have a very shifty claim of e2e encryption and a weird de-facto disabling the use of pgp. They do use openpgp.js, but for encrypting your mailbox, not for actually using pgp to mail other people.
They do actually support incoming pgp just fine, but I like to think of e-mail is bidirectional. To be fair, that is something they've had on their roadmap, but for almost three years now. Giving up the ability to send pgp-encrypted e-email is not a great trade-off (and let's not even get started on their notion that you're somehow better off with gmail as long as you use pgp).
So, trust the server, trust the HTTPS connection, trust the browser to not have any backdoors or security flaws in all extensions, and trust other apps that can access the browser's files and syscalls. Trust us, we are in switzerland. Why do people think that switzerland makes them somehow better position to deal with legal issues? Anyone from switzerland will tell you that they are not immune from evil laws and different parts of switzerland are significantly more draconian than others. Tell me how switzerland is some safe-haven that you should use as a criteria to determine your opsec. This selling point is pure snake-oil.
Secondly, its been years and you still can't store more than a single email address for a contact. This is so incredibly ridiculous that I have an extremely hard time understanding how they get away with charging what they do.
Lastly, the mobile app drives me nuts. I just can't get used to using it. You delete a message and a notification pop down drops from the top covering the next email so that you can't select it until the pop down notification goes away. This is deal breaking for me as if I have to go through 20 emails I have to sit and wait over and over and over again for this notification to go away. Yes, a message was deleted, I'm the one that deleted it, I don't need a notification telling me I did so. Infuriating to use.
There are many business, coordination, and communication tools that could be in my mail client (I do a lot of billing over email, is an email provider unusable if it doesn't integrate Quickbooks-like functionality too? What about shipping/receiving, project management, phone, SMS, mapping, etc, all things related to my use of email?), but I don't think they need to be there.
Calendar protocols are not federated like email. Choose between Exchange, Google, and iCloud. You'll have an easier time if you use the same one as most of your contacts.
Choose the best tool for the job. It's not likely that one provider will have the best tool for everything that, say, Outlook does.
Because calendar has become a key part of a productivity suite and Email is the keystone. We use Protonmail right now to avoid Google or Fastmail or someone serving up all our emails in a warrant. We keep sensitive stuff off Protonmail of course but every bit helps LE build their case against us.
Protonmail should have calendaring, wiki, and on and on. An encrypted replacement for Exchange eventually. We disable all audiovideo hardware for core members but I can see even secure voice being useful for our contractors to use.
If UI problems bother you, and you need a calendar, you can use mailbox.org which (1) can encrypt incoming emails w/ your GPG key, (2) offers SMTP so you can use Thunderbird, (3) comes with a calendar you can use on thunderbird/your phone via network.
They're also based in Germany, which is nice.
They're based in Switzerland which is no longer a safe haven, although ProtonMail seems to still trade on the idea that it is.
See:
https://www.theguardian.com/world/2016/sep/25/switzerland-vo...
Hrm, where's the pricing? Oh, it's based on "Messages per day" and "Folders / Labels"...
This doesn't detract from the meat of the article, but when user activity is involved in the pricing, you clearly can't claim 'no activity monitoring'.
https://www.theverge.com/2014/12/28/7458159/encryption-stand...
* If you are not comfortable giving Google unlimited access to all of your intimate communications*
Who would? But this is a sleight-of-hand where we somehow got from "google targets advertisement based on email content" all the way to "everyone working at google reads your email, and they all make fun of what you did last night".
By those standards, Google also reads everything on protonmail. At least if you use Chrome.
Besides, there are other factors than just encryption standards that impact security. The largest of all is the organisation you're trusting.
Google is obviously far ahead in terms of expertise and resources. They also have far more to lose, are probably better set up to protect against rogue insiders, and are impossible to compromise with money. OTOH, they're subject to FISA courts and whatnot.
ProtonMail has being known to shutdown accounts related to right wing, anti-semantic groups. Granted that those are extreme group. However, it will become a very slippery slop. http://govtslaves.com/2017-08-29-eff-warns-that-banning-extr...
"I do not agree with what you have to say, but I'll defend to the death your right to say it."
Evelyn Beatrice Hall