It rephrases and generalizes his points rather than tackling them head-on.
Kobeissi's main point is that ProtonMail could serve up any javascript they want to the client, including javascript that compromises the encryption or which hands over the encryption keys to ProtonMail.
Nowhere in ProtonMail's response is this point ever directly addressed or even acknowledged.
"It seems Nadim (the author of this paper) took it really badly when we called him out for intentionally spreading fake news this weekend." [1]
That's really low. The beautiful thing about computers is that we can prove each others right or wrong with technical arguments. If ProtonMail thinks Nadim has a personal grudge against them, wouldn't it be beautiful for them to disprove him with another professionally written paper as Nadim did? They can't.
Also, I think Nadim knows more than anyone the dangers of pushing weak products and marketing them as secure. It happened to him with Cryptocat. It's a thing that can harm reputation and also harm users, Nadim went through that and I believe he has good intentions by presenting this paper.
---
[1] https://www.reddit.com/r/ProtonMail/comments/9yqxkh/an_analy...
The only way to address this point, with current technology and current standards, is to discontinue the webapp and force everybody to the native apps on desktop and mobile. It is the opinion of almost everybody in the industry that webapps are necessary, and that's why we, WhatsApp, etc, all provide webapps.
So the point is acknowledged (and has always been acknowledged), but the opinion being expressed (remove the webapp) is not something that we agree with.
It sounds like you just admitted you could.
Browser extensions.
But I don't think everybody are making webapps to service data of their E2EE product, isn't it?
The key point is, if the webapp can be compromised by anybody who are in control of the front-end assets, then what's the point of the entire ProtonMail E2EE thing? Especially when you have other solutions like GPG which also is an open protocol?