The key question being debated is whether or not web applications can constitute end to end encryption. Nadim's opinion is that, as he writes, "no webmail-style application could". His viewpoint is that E2EE is not possible with web clients, period, end of discussion. This is a rather extreme position to take as it would also apply to the web versions of Whatsapp or Wire, for instance.
ProtonMail, like Whatsapp and Wire, offers apps on Linux, Windows, MacOS, iOS, and Android. Like Whatsapp and Wire, we also offer a web app. The major opinion Nadim is expressing here is that we should offer all the above, minus the web-app, because in his opinion, you can't do end-to-end encryption in a webapp. Obviously Whatspp and Wire do not share this opinion. Signal coincidentally does share this opinion.
We do understand Nadim's arguments, and agree that web-apps are less secure than say a native iOS app. Where we differ in opinion is that we don't believe the threat model of web-apps is so fundamentally different from an iOS app, that we need to take the step of not offering a web-app at all. When it comes to mobile apps for instance, the situation is really not so different, particularly since automatic updates are the norm and recommended for security.
There are definitely design decisions that we could have taken to make ProtonMail more secure (no passwords, only passphrases, sync keys between devices using QR codes, no web app etc), but this could compromise usability to a large degree, which runs contrary to our goals.
Disagreeing on design decisions however, does not indicate that the cryptography is unsound or improperly implemented, as this paper seems to imply. That's why this paper reminds us a bit of the now retracted story in the Guardian about Whatsapp's "security flaw", which was in fact a design decision. It is also a bit disingenuous to claim that ProtonMail doesn't meet it's "self-professed security goals", when we have fundamentally different interpretations of those security goals.