The ProtonMail Android app is now open source
protonmail.com
protonmail.com
Also not providing 20GB space as a default paid option in this day in age of $5/month/TB is also very disappointing.
[1]: https://github.com/ProtonMail/proton-mail-android/issues/1
Only downside I've seen is that there isn't a clear way to increase available data storage, independent of other billable line items (like number of users etc).
Other items on my wish list would be more customizable email filtering, I'd love to be able to create filters such as 'is this from [internet provider] and does it contain the word bill? -> inbox, else spam'
For data storage independent billing, go to Settings -> Dashboard. On Professional tier and above the data storage is a dropdown where you can increase the amount required.
For email filtering go to Settings -> Filters and create as many conditions as you want on a filter.
It’s a non-issue now, but yeah I’d prefer to interact with my plan the way that you describe and be able to scale storage independently (and ideally at a cheaper rate).
Regarding filters, that’s great! I didn’t see that before and will likely utilize it heavily now that I know it exists.
(And no, I don't want to clean up 20+ years of email. I want to pay someone else to handle archiving and indexing it and not think about it.)
2018 - Ask HN: How secure is Protonmail really? https://news.ycombinator.com/item?id=18101090
2019 - Ask HN: FastMail vs. ProtonMail? https://news.ycombinator.com/item?id=19372882
How secure would it be to use PM if the following conditions were met?
- you only used one of the open-source native PM apps
- you only emailed other PM users
- someone you trust audited the PM source code for the native apps
- you installed from F-Droid
So, it just like Telegram (or any other proprietary cloud/VPN/proxy service) - you really don't know what has happen on server side.
* Your e2e encryption key never gets sent to the server.
* Data is actually strongly encrypted using that key before leaving the client.
Then isn't that sufficient to prove that the server can't do anything nefarious, even if it wanted to?
Except "strongly encrypted message" you should send some extra info for server. And I'm not sure how those two types of info separated in Proton's communication protocol, so binary diff between those "parts" could be a key to select decrypt method.
Two password mode is technically more secure since even if the authentication exchange is cracked, the decryption key doesn't touch anything the server can see, it's locally decrypted.
There isn't any meaningful diff you could make.
However for F-droid this would allow them to sign their own APKs and provide some additional security guarantees in their supply chain.
Also a bit concerning that there is no tags yet in the repository.
https://support.google.com/googleplay/android-developer/answ...
>Note: Using app signing by Google Play is optional. You can still upload an APK and manage your own keys instead of using an app bundle
Tangentially, my needs are very minimal and I have a couple of ProtonMail accounts on the free tier that don't get much mail (the size of the mailboxes put together would be 5MB or so). I also aggressively delete unnecessary emails quickly and empty the trash. I'm waiting for multiple account support in the official mobile client for users on the free tier (this was promised quite sometime ago).
Really looking forward to when Proton has near parity with the GSuite basics.
I guess it can't be done as it's at the domain level, am I right?
the shorter name@pm.me email address is a nice feature to have as well
see https://en.wikipedia.org/wiki/Crypto_AG
Basically they were world's leading manufacturer of encrypted phones & fax machines for military use and it was revealed that they were controlled by German and US intelligence all along.
My suspicion for ProtonMail is only that it's too good to be true: A small amount per month to solve all my privacy/confidentiality needs w/o really inconveniencing me? I'm in!
Now, if it's run by the CIA/NSA/whatever, and they have found vulnerabilities in state-of-the-art encryption algorithms that we don't know about, you're hosed. But we're still hosed even if they aren't running the mail server (that just makes it easier for them to get hold of the data), so I'm not sure that's a threat model the average person could reasonably protect against anyway.
I use PM because fuck Google(Gmail), and fuck my ISP for profiting off my private data. I’ve always figured the 3 letter agencies can get access when they want. I’m not doing anything nefarious so I’m happy just to battle against corporate greed.
Stay suspicious though!
> the probability of the app to be opensourced is very unlikely
Can't see an option to enter my pop3/smtp server. Or I'm blind?
Either I'm misunderstanding what they mean by "outstanding" or this is a very bold claim. Shouldn't they be saying something like "Their audit found no vulnerabilities in our app."
Or maybe also getmail or fetchmail which will download your mail over IMAP and put it in the maildir format as files.
https://www.reddit.com/r/ProtonVPN/comments/8ww4h2/protonvpn...