ProtonMail now offers elliptic curve cryptography
protonmail.com
protonmail.com
For example, they claim, "We have chosen a particular elliptic curve system known as X25519, which is fast, secure, and particularly resistant to timing attacks. It’s simple to implement".
However, previously they've said that they use Indutny's library [0]. This library is somewhat infamous because its leadership deciding to discard any pretense of defending against timing attacks on the grounds that would make the library "too slow." [1]
There are other options. They could have used something with good timing attack resistance from WebCrypto. Those options exist. Folks with more skill than I have recommended P-256 as an option.
[0]: https://protonmail.com/blog/openpgpjs-3-release/
[1]: https://github.com/indutny/elliptic/issues/128#issuecomment-...
Please tell me I'm reading that wrong, because I don't recall doing this for ProtonVPN on linux.
Using Ed25519 is by popular opinion the right choice.
However, the concern about their use of indutny's library and the comment you link to is entirely separate. Choosing to have timing attacks for performance in a cryptographic library seems absolutely absurd, and if this is still the case (the comment is from 2017), then that library should be avoided at all cost.
If the author wants to show up and say otherwise, I'm happy to take correction.
But, I'd rather have a robust implementation of a speculatively less secure scheme then have the undelivered promise of a more secure scheme papering over an insecure implementation.
Curve25519 avoids these problems. But then, if you're using a naive Javascript library, you've thrown out one of the main benefits of Curve25519 already, and are left essentially with invalid curve attacks, which are not especially hard to defend against and not always even relevant to a given protocol (who could be bothered to go look at what OpenPGP.js is doing with them, I don't know).
Ed25519 is the signing curve equivalent to Curve25519/X25519. It's what you'd use to generate and verify signature, but not what you'd use for ECDH.
There is general distrust in NIST, not any known issues with those curves. However, it is general consensus to prefer Ed25519 over NIST curves, specifically preferring it over P-256. The benefits of its implementation are a cherry on top. I have yet to see any suggestion or reason to pick P-256 when Ed25519 is available.
And yes, Ed25519 is the defacto standard. Hell, I don't even recall the last time I heard P-256 mentioned. It surprises me every time I stumble upon it. Picking anything other than Ed25519 means deviating from the norm, which would normally cause worry. Granted, P-256 is fine, but there is absolutely no argument for claiming Ed25519 was the wrong choice of algorithm.
And yes, I specifically refer to Ed25519 because it is the one relevant here. We're talking about signing, not key exchanges.
Ed25519 is not in fact the de facto standard for signing on curves; that's clearly P-256 ECDSA. You're saying that Ed25519 is better, and I agree, but P-256 is much more prevalent.
Again, people don't use Ed25519 because they distrust NIST (although many people do distrust NIST). They use it because:
1. It's easier to implement in constant time.
2. It's derived (if that's the word) from a curve that was selected to avoid invalid curve attacks.
3. They want a more modern, Schnorr-based signature construction, and Ed25519 gives you that and a better curve at the same time.
For signatures, as opposed to key exchange, I think the tradeoffs are pretty much the same: by using a goofy JS library, you're giving up the implementation and side-channel advantage. You're left with the superior signing construction, but you can just use Pornin's deterministic DSA and neutralize most of that problem as well.
Seems like they made a mistake. They're referring to your private key (which is used for signing) as "X25519", but X25519 is meant for key exchanges.
Nothing but Ed25519 makes sense in this particular context, unless they've gone out of their way to do something very non-standard.
> Ed25519 is not in fact the de facto standard for signing on curves; that's clearly P-256 ECDSA.
Having never been confronted with anyone having chosen P-256 ECDSA, I question the validity of this statement.
It is important to remember that this also requires use. I have a few times stumbled upon things where only NIST curves where supported, but in those cases, RSA remained the choice of the users.
> Again, people don't use Ed25519 because they distrust NIST (although many people do distrust NIST).
None of these arguments make sense to those not implementing the cryptographic libraries on their own (which, while fun, is not recommended).
For the integrator and the user, it's simply a case of reading the docs and picking.
You can use it for ECDH, and unless I've missed some non-obvious attack (which is of course, entirely possible) you probably should, since that allows you to use (mostly) the same elliptic curve math primitives for key agreement as for signature.
(That is, you should use Edwards form points as shared-secret output. It's possible to implement Curve25519 using Ed25519 internally, but probably not a good idea.)
That might be the case, I only meant isomorphic in the programming sense of f(x) = h⁻¹(g(h(x))) for relatively trivial h.
> I thought Ed25519 was [...] slower for variable-base operations in ECDH.
My understanding is that Ed25519 requires replacing several of Curve25519's field squarings with general multiplications, but isn't actually any slower if you use a general multiply for everything. I'm not sure how much optimization you can get out of squaring though, so it might be a easy 10% bonus you're passing up there.
If WebCrypto supported X25519, their choice would be a no-brainer, as 25519 is a safer curve (https://safecurves.cr.yp.to/). But P-256 is definitely not considered untrustworthy — see tptacek's reply — and at least Chrome implementation (BoringSSL) is good. (Browsers use the same implementation for TLS and P-256 is the most popular curve for TLS right now. In fact, delivery of their JavaScript code to browsers already depends on P-256 due to TLS.)
Regardless of the choice, my main concern is that they advertise X25519 as timing safe, while not having a timing safe implementation. This is a red flag.
Disclaimer: I ported TweetNaCl (which uses 25519) to JavaScript. The port intends to be "algorithmically" constant-time, but doesn't guarantee real-life timing safety due to JS.
I still find the argument to be wrong, in the sense that picking Ed25519 is an entirely correct decision to make. Picking that library is not a correct decision, and that might lead to needing a different algo (I'd argue that WebCrypto needs to pick up its pace for common algorithms, rather than picking picking up whatever dropped fruit is available).
We shouldn't slander them for Ed25519 (although you are right that such claim about timing safety is borked—maybe that got lost in marketing). We should only target the library choice.
Plus, with WASM widely available, we should be able to port a constant-time of Ed25519 with good performance without much work. WebCrypto is just a cherry on top.
I do not use email for discussing sensitive topics. It is not the right tool for the job.
It is secure, except that metadata are open go Google. And metadata is the new data nowadays.
The biggest issue i've had so far is the search is terrible, and the spam filtering has many more false positives.
You made me panic when you mentioned Spam false positives, as I've never really bothered checking that folder!
Thankfully I don't appear to have any so far. Better than bloody GMail arbitrarily deciding that subscriptions and emails I've long-since received from various sources being suddenly spam... .
That's in fact my exact issue. The newsletter from the mayor of Seattle regularly gets tagged, for example.
PM pricing is €48-288/y while TN is €12-60/y[4,5]. Both have freemium options too; I'm paying €12/y for TN just to receive support (more to be able to message them with feedback, really).
My only complaints w/TN is that it's a bit slow; notifications will remain even seconds after I'd read the mail, and sometimes (especially in the beginning) I would hit "Del" twice or more for the same email because it would remain in my inbox, ultimately accidentally deleting the emails after it in my inbox (something I noticed only after refreshing the tab, which -- annoyingly but also securely -- would cause me to have to log in again).
I ultimately went with TN because of one thing, however: I can export emails. Yes, it's a hassle, and yes, I have to generally do it by hand, bundle by bundle, but I love being able to have all my emails archived offline. Plus, with their new (beta) desktop client, this should be even easier[6]. I'm staying with them for now because they're the only ones (that I know of) who encrypt both your emails and your contacts, as well as the subjects, contents, and attachments of all the emails you send[7]. This is HUGE for me. However, the moment a better service comes along who does all this and who is smoother, faster, I won't mind switching ship. Especially because the name is so annoying to tell people, especially over the phone ("Puta? Duda? T like Dom or like Tom?"). Yes, I get it means "secure message" in Latin, but come on now. Just use a simple word already. Or do what PM did and enable a neat shorthand domain (pm.me, how neat is that?[8]). Though they also do offer custom domain names so I suppose this isn't too much of an issue, I just haven't had time to properly look into this yet.
After reading this thread though I'm curious to find out more about FastMail. But Australia, uhhh... Five Eyes, no thank you.
[0]: https://tutanota.com/security
[1]: https://tutanota.com/blog/posts/innovative-encryption
[2]: https://nordvpn.com/blog/tutanota
[3]: https://reddit.com/r/ProtonMail/comments/85vgca/cambridge_an...
[4]: https://protonmail.com/pricing
[5]: https://tutanota.com/pricing
[6]: https://tutanota.com/blog/posts/desktop-clients
[7]: https://tutanota.com/faq/#what-encrypted
[8]: https://pm.me
ProtonMail also encrypts emails, contacts, contents, attachments, of all emails you send and receive, with end-to-end encryption.
However, the most important differentiator is the trust model. ProtonMail has Address Verification, which means it is trust on first use, which is significantly more secure than the trust on every use model Tutanota uses for key distribution. Details here: https://www.reddit.com/r/ProtonMail/comments/b84kd3/why_is_p...
Indeed like still pushing the trope that since their datacenters are located in Switzerland they are able to provide more privacy protections. This is even mentioned on their homepage, and of course this hasn't been true in a few years now.[1]
In our mobile and desktop apps, where timing attack resistance is easier to achieve, the X25519 implementation is already constant-time.
Once they are generated, keys are controlled by our users and not easily updated, so we wanted to make our choice of default curve as future-proof as we could while balancing speed and interoperability.
[0]: https://github.com/indutny/elliptic/issues/128
[1]: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=861639#10
It inherits all of the flaws inherent in OpenPGP, including optional authenticators (which lead to EFAIL), kitchen sink bulk protocols complete with negotiation (did you know your public keys specify what algorithms you like?), lack of forward secrecy, repudiability, et cetera.
We should stop using RSA. But RSA isn’t what was keeping OpenPGP from being a great secure communications channel. That’s aside from the question if it’s meaningful to say you control your keys if you use OpenPGPjs served up every time by a third party. (I say that being extremely on the PGP apologia side of the scale compared to some of my peers!)
You could do all of this well if WebCrypto was good and you had a WebExtension, or an Electron app, or some other way where you weren’t just going to do whatever the website tells you to do.
(That is not a blanket security recommendation in favor of Electron. XSS does not normally get me RCE.)
tl;dr version is one pins all resources on the page with Subresource Integrity hashes and signs the page. The extension verifies the signature matches before rendering anything.
My email history: - gmail.com > US spying, escape. - lavabit.com > Shutdown due to US government legal attack. - Ran my own server > Too much bother, gave up. - openmailbox.org > Died for months, ran away with my money. - protonmail.com > Sketchy, cancelling it now. - Free mailbox.org with custom domain.
My only complaint with mailbox.org is that their 2FA system is really silly (you append your 2FA token to your passphrase, and there's no equivalent to Google's "app passwords").
I had a proton email created when it was announced & didn't use it. I found out that my mailbox decryption for that email id is not working (not sure how, I use password manager) & I haven't set a recovery email to recover my account.
I saw a HN comment earlier telling, the user had recovered their Proton mail account by answering few questions to customer service.
I attempted the same, the issue is that I used VPN to create the email id & didn't provide any personal details for the account.
They asked questions like,
-Do you remember the exact time and date when your account was created? -When was the last time you have accessed your account? -What is your display name? -Do you remember to which addresses you have sent your last messages? -Do you remember the email subjects of the last sent messages?
I tried to answer the account creation date by using the date of password creation in my password manager (the login password was working); but the support didn't seem to buy it.
They were insistent on,
-Can you please tell us if you remember from which addresses have you received your last few messages? -Could you tell us if you have used the ProtonMail account to sign up for some other web services?
I told them, I don't remember receiving email from anyone else & I didn't sign up for any service
-There is a service that the xxxxx@protonmail.com address has been used to sign up for. Can you please tell us what that service is?
I told them again that I didn't sign up for any service using that email id.
- Can you tell us the full address below?
no-xxxxx@drxxxxx.com
Even though I could obviously guess the username of that email id. I told them that I didn't sign up with such service, that it must be a spam mail sent by some service.
They said,
- If you have not signed up for this service, the account probably belongs to someone else.
Then I typed 'no-xxxxx@drxxxxx.com' on Google Search, the instant results gave 'no-reply@dropbox.com' as the first result.
I sent them,
Hey sorry, I remembered the service. I did signed up for Dropbox & used the account for a while.
The email id you asked was,
no-reply@dropbox.com
They reset the account & I got access to it.
Edit: Had to fix the xxxxx.
For most people the big risk is that their email can be leveraged to gain access to banks, social media etc through password resets.
When I created this account, I wanted to build upon the premise of privacy of proton mail & so I created using VPN, with no personal link whatsoever (hence no recovery email).
Unfortunately when my decryption password failed, I had no means of recovery until I attempted to talk through support successfully.
It ended up being that a trailing newline got added.
It's a long shot but worth looking into...
OTOH account hijacking is a well documented[1][2] threat.
I don't like the idea that if I set up a secure password and 2FA someone could call up Protonmail and go "Uh yeah, I use, uh... Hulu? Reset my password please!"
[1] https://www.ftc.gov/news-events/blogs/techftc/2016/06/your-m...
[2] https://www.engadget.com/2016/06/10/hacker-hijacks-deray-by-...
So you think it'd be stronger protected if you're paying due to probably having a CC etc tied?
AWS doesn't even consider you the account owner despite you holding the credit card that they bill for that account.
https://news.ycombinator.com/item?id=19574672
Our industry is such a shitshow in some massive ways.
It all depends upon how much trust, my initial answer to the question 'When you account was created'; I'm 90% sure I have correct year & 70 % on the month (I gave another month as well).
If that answer really did create some trust, then there's something; if not then I'm quite sure anyone can hijack an account without recovery email if they are able to guess few email ids correctly.
How are your experiences? Any iOS users who can comment on their experience with proton mail and the default mail client?
I don’t went to switch to something that won’t be around in a decade or so.
>Sometimes, when the ProtonMail app is updated to a new version and that update is bigger and more incremental, that could happen.
That's unsatisfactory. However it does not address the complaint I had at the time that every once in a while a notification appears that tells me I have been logged out, with no explanation. I don't know if that still happens, as I cannot be bothered to keep logging in on my phone. I'll give it a new try now.
Retrieving that quote for you meant I had to browse my Protonmail archive. I could log in via web, but for some reason your TOTP works differently from everywhere else: I have to enter it every time, and there is no way for me to "remember this browser". I could use the Bridge, but for some reason the Bridge, too, logs me out whenever it feels like it. Again, I have to enter both factors with no option to trust permanently.
Do you see how these paper cuts could demotivate me?
Not sure about whether it will be around in a decade or not.
The encryption is great and the anti-spam works well enough. No complaints.
I also use a ProtonMail "+" alias when signing up for a totally new service (with a filter to place emails from that alias directly in Spam; as all it does is handle account signup/verify). If I can't change my email after signing up for a service I don't continue using that service, as I define that to be user-hostile. If I can't use "+" in an address when signing up I default to GetNada.
The other use case for a PM address is for anonymity (e.g. throwaway/whistleblowing) with a requisite VPN and browser-only login, etc.
As an aside, I use a free Outlook address as my newsletter spam box (good storage size and Android interoperability for consuming content).
This guards you from spammers stripping the + label, which I’m sure they all do by now.
Aside from that, yes I use proton, it’s fine. The Mac bridge is a joke but the rest works ok.
I'm using the paid version of protonmail with a custom domain, giving me the ability to somewhat easily switch to a different provider in the future if they go out of business or end up losing my trust.
Also, understand that due to the encrypted nature, you can't just point an IMAP client at their servers. They offer separate software to serve as a bridge, but it's complicated. So, you are only using their web interface. They don't offer a native app for OS X, even. So again, no offline mail processing.
I recently put serious thought into moving my personal and business presences to PM to support the idea and normalize serious encryption, but ultimately felt like my need of the security it provides doesn't justify the complexity and UX compromises it forces. But ymmv.
[1]:https://protonmail.com/support/knowledge-base/combine-accoun...
Have you tried the Bridge? We are putting a lot of development effort into making that UX very seamless.
The idea is great, works well, and we support it as best we can. However they REALLY need to step up their game in terms of making it easy to manage as opposed to just "moar security!". I put in tickets for each of the aforementioned pain points 6 months ago, and heard nothing back really. I doubt the developers ever got to see them. If they want more money and more users, which i'm sure they do, they need to really step up their game in terms of group management and onboarding.
In case I don't hear from you, HTML Signatures are live.
Thanks!
Overall 8/10 would recommend.
I had problems with Bridge on MacOS, but after learning that Apple Mail is reporting all e-mail metadata to Apple I stopped using it altogether. Don't know if ProtonMail fixed Bridge since then.
Honestly I wish other providers would give me this sort of 'transactional email' conversation tie up because it's convienent. I can see in the last 12 months for example, I have always paid my gas bill on time, at a glance too!
But I agree with you that the UI lacks several things, like searching in the body of the messages...
The mobile experience is fine, but desktop is brutal unless you happen to prefer one of the few clients they support.
If I wanted to grow protonmail, I would emphasize users moving domains to it because while the brand has exceptional trustworthiness, anything security and privacy themed runs into the "tacti-cool," problem, where even if it's the best available and used by real operators, it triggers peoples sense of illegitimacy, and depends with users who identify with a "rebel," e.g. "losing" team who are not attractive to other users.
IMO, the same problem killed Silent Circle, and the rest of the cryptophone market.
When you look at who overcame the tacti-cool problem in security and privacy, the way a brand like arcteryx did it in clothing, Apple's iPhone has done it in hardware, WhatsApp did it for messengers, and protonmail is just on the cusp of it.
There is an opportunity to build a new privacy brand that would be as big as a FAANG, and if I were running it, I'd fold protonmail into it.
What is the motivating threat model of ProtonMail?
If I just want to access my email securely, that's done by HTTPS. If I want an end-to-end encrypted solution, ProtonMail can provide that, though only for emails between ProtonMail users. For e2e outside of ProtonMail, I can use PGP.
From what I understand, ProtonMail makes all the PGP stuff easier by baking it into their UI. Is there anything else it offers other than this convenience? Are they encrypting incoming mail with recipient keys and throwing away the original? If so, who is that protecting, and against whom? Presumably the plaintext was stored by the sender and possibly seen by intermediary servers. Can I get similar security properties by periodically downloading my email and deleting it off the server (assuming the deletion is actually happening)?
These are honest questions. I admit I'm skeptical of PM's utility, but I'd this fits someone's usecase and threat model, I can't argue with that.
Are they encrypting incoming mail with recipient keys and throwing away the original?
Yes we do. This mainly protects against service level requests for data in the future.
Can I get similar security properties by periodically downloading my email and deleting it off the server (assuming the deletion is actually happening)?
Yup, assuming you want to deal with that. ProtonMail is designed to give you a privacy focused option for email.
I ended up using StartMail from the StartPage people. It's not perfect, but I was actually able to migrate to it and use it effectively.
I'll probably soon subscribe to PM for two reasons: to use the @pm.me domain for outgoing (currently only incoming), and for custom domain support. Also subscribing gets IMAP support (I think).
Proton mail has more advanced cryptographic features and my understanding is that your email is encrypted so they can't offer it up to third parties without your consent (or at least stealing your password.) The usability is not as good: search often does not work very well (I believe this is due to the encrypted nature of it) and there are only a handful of local clients you can use via their bridge. The mobile app is pretty good, the web app is acceptable but clunky.
I use fastmail for day to day stuff I don't care too much about and protonmail for my more important/personal stuff. Both support custom domains so you can move your email to another provider if you get sick of one.
(Ex: I could search by the [Mailing-List-Tag] + date range, from address etc)
This is why I hope they fix the bridge: I'd like to index my email fully and locally, but I'm not going to use thunderbird to do it.
Fastmail does one thing and does it well, email. There is no PGP support. Protonmail does PGP in the browser via a library that they serve you themselves which I find less than ideal. If you want to do it outside the browser you need to have a subscription and download a bridge software that needs to be running on your machine. With Fastmail if I need PGP in my email I do it via the GPGTools plugin for the Mail app which uses the system gpg installation.
FastMail:
+ simple, lean, paid email.
+ fast web interface
++ working full text search( not just subject line)
+ No ads.
+ iOS App. Fast and simple.
+ Integrated calendar
- No encryption.
- group calendar has been a pain or non intuitive.
Protonmail:
+ Encrypted
+ Lean, safe web interface
+ IOS App that works.
+ or - Free as in cost.
- - - No Full text search.
- can't really configure your chosen email client to it...
- last time I tried, dragged and dropped images disappeared. May have improved UI now.
I only use protonmail for automated alerts and system originated communication.
Do you have any experience with using the IMAP Bridge? It is a daemon you run locally that translates between Protonmail's internal protocol and IMAP, to let you use your email client of choice. I'm using it and it seems to be working OK in my experience, but I don't use my Protonmail account heavily.