More people are searching for an inbox that protects their privacy
protonmail.com
protonmail.com
I recommend everyone BUY A DOMAIN. Then switch providers. you can always switch with your own domain.
The select a provider based on thier offering be it protonmail, fastmail (shameless plug), or others
Who is right? Is there a consensus in the security community?
[1] https://medium.com/@N/how-i-lost-my-50-000-twitter-username-...
> Who is right? Is there a consensus in the security community?
There might not be one best answer. There have been many other stories on HN of people loosing access to their Gmail accounts, and having no recourse with Google to regain access.
My gut feel is the best any of us can do is to set up our digital lives so that our accounts are "misaligned" to make it more difficult to use social engineering to pivot between them. For instance, in the story you linked, they key to an actual attack was a shared credit card number between Paypal and Godaddy that was used for verification. Ignoring the fact of how stupid it is to use just 4 digits for such a task, it would have made that path more difficult for the attacker if he'd used a dedicated card for Godaddy (given his domains were valuable enough to him that they could be used to extort a $50k twitter handle from him). Having different, secret, email addresses/domains attached to important accounts could also provide a stumbling block.
But it's also worth noting that much of the attacker's planned attack failed, and he only succeeded in the end through extortion.
you will end up having most of your conversations with gmail or outlook users so that would not change anything
E-mail in 2020 is not secure against a motivated attacker. It doesn't matter how secure and woke your provider is, when:
1. Everyone you talk on an e-mail thread gets a copy of the entire e-mail thread, to do whatever they want with.
2. You can't control the present and future security of other people's providers, or the present and future security of the computing devices they use to read the e-mail you send them.
Now, if you want to LARP, you can try setting up a mailing list for your friends who only use secure providers (For whatever definition of secure you want to use), and only limit your use of a single e-mail address to that mailing list. Great. Go for it. Write a blog post about it, even. But that's not going to solve the fundamental problems of #1 and #2 for the rest of the world.
Now, if you actually want security (as opposed to 'I want to LARP at security'), take a page from conspiracies in the financial sector, and don't use e-mail for any conversations that you'd like to remain secure.
Securing e-mail is a waste of time. It can't be secured, because of 50 years of social expectations about how e-mail should behave. (Other people retain copies of your e-mails, and other people can choose which provider services their address.) You can spend that effort on trying to secure a different communication protocol, which does not have those 50 years of social expectations, and that will probably lose to e-mail (Because those two security holes provide users with value, and when it comes to value versus security, security will lose every time.)
Things like '.family', '.wtf', etc. are less of a problem. At most people ask "what, no .com?", and that will be it.
EDIT-after-parent-edit: That, too, regarding "and that'd be @gmail.com?".
It does raise an eyebrow or two when I tell someone my email is theirname@myname.domain
Not everyone is even contactable from my own domain. The IP address used to belong to some spammers several years ago and some blacklists are still there.
Also, my newsletter, even though it uses double opt-in, triggered some automatic mechanisms of Spamhaus. I ended up on a blacklist several times. Fortunately, I was able to argue my way out and after the last incident, they must have updated their lists.
But those were bad times, no one could literally post a link to my blog onto Twitter etc.
My company name was too long, so we registered a domain for our email that was just our initials and it was nicer to type, and really easy to set up.
Post Cambridge Analytica I'm not sure which is worse.
That said: I'd love to run my own e-mail servers, but Yahoo does a pretty good job keeping spam away from me and offers enough convenience that I just stuck with it.
Happy to consider alternatives I can run on a cheap instance somewhere.
Partner is a die-hard webmail user who detests native desktop clients. I'd like them to be able to use Fastmail webmail with my self-hosted calendar and contacts.
For CalDAV, many people use the Fastmail web interface with other calendars by syncing them (https://www.fastmail.com/help/calendar/sync.html?).
https://support.google.com/mail/answer/7190?hl=en
I'll try ninemail. Thanks.
Everyone has this. It's called IMAP.
As for the gmail web client, various services are providing similar interfaces on their email service.
(A great thing about HN is that you don't need to have an account in order to read articles. So I can bookmark it on my phone without worry.)
Browser is a huge, unreviewable (well not true but there is not just simple to reverse java code but also arm dissasembly to be done and that part can take forever), black box that you have to trust and as you dont use it for one single task (as for instance mail client - there is exactly one ip address where it needs to connect to in my case - to my mail server - and my mail client is allowed to connect exactly there and nowhere else) you cant "jail" (pun, not as bsd jail) it. And I dont use any google spyware on my android phone, like GMS.
This might be of help to you, I have reviewed the code and if you pay a donation directly, it wont do anything fishy (and I am building my own version and diffing every version with my baseline - for 2.266 I can guarantee it is safe): https://github.com/M66B/NetGuard
That said, I still 100% support getting off of the free email providers in order to wave a middle finger at surveillance capitalism.
But that's false. They're encrypted with TLS. It's just not end to end encrypted.
There is clearly some merit to Proton Mail's privacy claims. Even Google goes out of their way to try to scrape data from ProtonMail: https://old.reddit.com/r/ProtonMail/comments/9yl94k/never_co...
I have my own domains, POP mailboxes hosted by my domain providers which also provide SMTP servers (I don't feel like self hosting) but I know Google know most of what I write.
Until some time ago there used to be a prompt indicating that the page was translated. But haven't used chrome in a long time.
https://duckduckgo.com/traffic
Maybe a desire for privacy is driving this. Or maybe Google's increasing bias, or ad saturation, or AMP, or something else...
Generally I'm pretty happy with DDG results and don't feel the need to switch back to Google. I have seen a lot of scam ads on DDG which I've reported but never received a response to. The new Apple map integration seems to work pretty well even though I'm on Android.
I'd love to move away from everything Google (further support a company who is pro-consumer) to a company in which i trust and whose business model/ethos is privacy.
There's nothing stopping them from sending your browser Javascript that completely compromises your keys.
They've admitted as much when I asked them about this years ago.
All I know is, I would hear about it very quickly as soon as Proton Mail is discovered to violate my privacy, and that's all I can expect of email. To be honest, the fact that their API is not open sourced and I have to use their web client or mediocre IMAP bridge would make me seek alternatives if I were to reconsider email providers. It would have to be one that has as strong of a privacy-conscious brand, or self-hosting.
ProtonMail has been dragging their feet for so long in the interoperability department, it almost feels like they're aiming for vendor lock-in. If they truly were serious about interoperability, they've had plenty of time to create an open standard around their protocol (like FastMail and post-2017 Lavabit has done), or release patches to make their protocol available in widely used open-source email clients like Thunderbird. Instead they've got that mediocre IMAP bridge you mentioned. No thanks. When I choose an email service I want to retain the ability to export all my data and leave on short notice, without having to depend on non-standard tools.
There are no such guarantees. Social pressure on their brand did not stop Enron or Madoff from committing fraud. Nor did it stop millions of others from committing various crimes, atrocities, and other unethical acts throughout history.
In the realm of email providers, the case of Hushmail[1] serves as an instructive example.
Hushmail is an email provider that provides a service similar to ProtonMail, but:
"Developments in November 2007 led to doubts, amongst security-conscious users, about Hushmail's security, specifically, concern over a backdoor. The issue originated with the non-Java version of the Hush system. It performed the encrypt/decrypt steps on Hush's servers, and then used SSL to transmit the data to the user. The data is available as cleartext during this small window of time; the passphrase can be captured at this point, facilitating the decryption of all stored messages and future messages using this passphrase. Hushmail stated that the Java version is also vulnerable, in that they may be compelled to deliver a compromised java applet to a user."
and
"Hushmail supplied cleartext copies of private email messages associated with several addresses at the request of law enforcement agencies under a Mutual Legal Assistance Treaty with the United States.; e.g. in the case of United States v. Stumbo. In addition, the contents of emails between Hushmail addresses were analyzed, and 12 CDs were supplied to U.S. authorities."
Incidentally, despite all this, and what you'd expect to be "damage to their brand", Hushmail is still around, and I'd expect many of their users have never even heard of any of this.
[1] - https://en.wikipedia.org/wiki/Hushmail#Compromises_to_email_...
Let me also reemphasize that I don't consider email to be a secure or confidential medium of communication at all, even with PGP. I only want that my inbox is not sold to advertisers and the security practices of my provider aren't utter garbage. Maybe the fact that they're in Switzerland helps me in some ways, but if I had a state adversary I wouldn't bet on it.
Relying on hearing about compromises in the news only sort-of works when:
1 - such compromises are revealed
2 - they're big enough to make news in the first place
3 - your own data hasn't yet been stolen, so you have time to change services after you hear about the compromise
None of these is guaranteed to happen ever.
And even if you did hear about some compromise in the news, it could be far too late for you, as your data (the data ProtonMail is supposed to protect) could already be in somebody else's hands.
I think we don't agree on how proton mail works. As I understand it, they already have my keys. You can't even give them just a subkey, it only works if you upload a set of PGP keys including the master secret key. What is your understanding of how it works?
As for your other concerns, unless I am conversing only with myself, the attack vector for my data is the entire e-mail ecosystem. Even if I only talk to people who use encrypted email, they are also part of my threat model, even if I don't trust a provider with my keypair. e-mail is simply not secure. It wasn't meant to be secure; security cannot be bolted on top.
What is your threat model and how do other providers or self hosting achieve your desired level of security?
From: https://protonmail.com/security-details
"ProtonMail's zero access architecture means that your data is encrypted in a way that makes it inaccessible to us. Data is encrypted on the client side using an encryption key that we do not have access to."
Edit: Ok I see. They store the PGP keys encrypted with your password. Like you said, they could just as well inject javascript to phish your password from your session.
But this does seem to mean that if one uses their API directly it would be possible to securely use their service. Thanks for the heads up. There is a third party open source bridge that reverse engineers their API. I think I will look into it to see how authentication is done.
For someone from Belarus and opposing Lukashenko, ProtonMail is fairly secure service. For Edward Snowden, probably less so.
Forward secrecy only works up to the point your end point gets compromised and only for messages you have not kept. So for the vast majority of people it provides very little value.
It provides no protection against someone who breaks your encryption and something like the Signal Protocol's much greater complexity provides more opportunities to do that.
It’s good to use your own domain, it’s good to use a non ad-driven business model like fastmail (though even this is mostly for the user experience and not security)
Beyond that “secure” email when you’re largely communicating with other @gmail users, isn’t a thing.
Google has some of the best security researchers in the world, I’d trust their employees to do a better job than proton at securing the service itself.
Email should be treated as largely public (for personal use) and not used for sensitive communication. It’s a little different in a corporate setting, but then you’re not using proton mail anyway.
And seriously, this is an email period it was invented how many decades ago? It should be easy to have something that works very well with offerings from multiple providers.
As you dig deeper, there are a lot of little details that give Google the advantage. I'm not expert enough to describe all of them in detail, but certainly part of it is we have big players who are dominant on Android and Apple making it difficult for small players to catch up. We also have, as one person pointed out, blacklists and not being easy to get around that with other providers because Google is so dominant in this space too.
The spam fighting services. First of all, I'm not sure whether they are being run locally on the mail servers or maybe the mail servers forward our emails body to a third party anti-spam service to get a "spam score".
And secondly, after being assigned a "spam score" a part of your email may end up in the headers as "X-something" where the anti-spam service describes why it didn't like your email. And we know that many 3-letter agencies collect as much email metadata (e.g. headers) as they can sniff out. So, you should know that the first X bytes of your unencrypted emails are less private than the remaining part, because they can be part of the metadata.
Should you forward the email with these header fields intact, then all it does is reveal a bit about your mail providers' infrastructure, which is already entirely public information.
I don't see why any of this would lead to any amount of concern, but feel free to present the header field you refer to.
https://en.wikipedia.org/wiki/Lavabit#Connection_to_Edward_S...
It's right there in the link you're replying to.
The irony here. I wonder if the number of people searching for Google search alternatives on Google is up as well?
FBI cant issue an NSL to read every email you sent or received to construct your patterns of life to more easily parellel construct you or blackmail/coerce you into compliance.
even NSA has to tread lightly, and cant just casually feed your emails into XKEYSCORE, because if they get caught, then Yandex with the assistance of FSB will kick out NSA and/or hack back or retaliate with active measures. so NSA would only risk blowing their Yandex collection for very high National Priority targets. not you.
in a sense, the smartest surveillance evasion tactic is to hide in the fog of cyber war between the Nation States. if you're not Baghdadi or Carter Page, you wont have to worry as much.
plus, Yandex mail is better than gmail. Yandex is what gmail was 10 years ago--simple UI, no bloat, no ads, no spam, no BS. Yandex has a mobile email app too. better, you can host your private DNS on Yandex, then use Yandex for your private domain's emails.
and unlike Google, who is probably selling your info about you from your emails to an ecosystems of ad spammers and "database of ruin" analytics spy companies, Yandex is not. thanks to US sanctions on Russia, your data is effectively siloed off from the US market.
finally, consider the Shadowbroker hacker used Yandex to leak the stolen NSA EQGRP files. has the Shadowbroker been caught? nope. Yandex security looks better than anyone else's.
we live in interesting times, when Russia is now a safer place to store your data than the US. the world has gone mad.
Also, I see that they have their own browser?? https://browser.yandex.com/ I assume it's just a rebrand.
and yes, Yandex has an API for everything. You don't need language bindings as long as your language speaks HTTPS.
I get the limitation because of the encryption, but I wish I can just turn off the encryption for specific apps. I don’t need my mail encrypted in flight, I just don’t want it sitting on Google servers. For that ProtonMail is overkill.
That's optional.
purpose of what? being fully anonymous? If all you want is a mail provider that doesn't scan your emails for marketing purposes, it shouldn't make a difference. If you really want to be anonymous, you can always use a burner email (no, not the disposable kind) to sign up.
Metadata can reveal a great deal.
You can reduce what an adversary sees by not including anything useful in the subject line and the only thing you can't protect is who you're speaking to and when.
Not being able to access the email body already makes full text search impossible, among other things. It is one tradeoff for using Protonmail instead of, say, Gmail.
Encrypting header data would make most operations impossible unless you download your entire inbox first.
So the providers can work to get that to 100% and mandatory to foil active attacks.
I think about moving off Gmail, but 99% of my emails are from retailers I shop with.
Newsletters are now RSS, email with humans.. doesn't happen much, etc etc.
Business emails are not very interesting -- we use secure methods to share info when needed.
Email is.. to me personally, not very important anymore.
(I show up to my accountant's office to sign things.. I keep looking for something that I need to secure.)
Its not a new idea, but I wanted to build something mostly for myself. So it is rudimental, but works.