There's nothing stopping them from sending your browser Javascript that completely compromises your keys.
They've admitted as much when I asked them about this years ago.
There's nothing stopping them from sending your browser Javascript that completely compromises your keys.
They've admitted as much when I asked them about this years ago.
All I know is, I would hear about it very quickly as soon as Proton Mail is discovered to violate my privacy, and that's all I can expect of email. To be honest, the fact that their API is not open sourced and I have to use their web client or mediocre IMAP bridge would make me seek alternatives if I were to reconsider email providers. It would have to be one that has as strong of a privacy-conscious brand, or self-hosting.
Forward secrecy only works up to the point your end point gets compromised and only for messages you have not kept. So for the vast majority of people it provides very little value.
It provides no protection against someone who breaks your encryption and something like the Signal Protocol's much greater complexity provides more opportunities to do that.
For someone from Belarus and opposing Lukashenko, ProtonMail is fairly secure service. For Edward Snowden, probably less so.
ProtonMail has been dragging their feet for so long in the interoperability department, it almost feels like they're aiming for vendor lock-in. If they truly were serious about interoperability, they've had plenty of time to create an open standard around their protocol (like FastMail and post-2017 Lavabit has done), or release patches to make their protocol available in widely used open-source email clients like Thunderbird. Instead they've got that mediocre IMAP bridge you mentioned. No thanks. When I choose an email service I want to retain the ability to export all my data and leave on short notice, without having to depend on non-standard tools.
There are no such guarantees. Social pressure on their brand did not stop Enron or Madoff from committing fraud. Nor did it stop millions of others from committing various crimes, atrocities, and other unethical acts throughout history.
In the realm of email providers, the case of Hushmail[1] serves as an instructive example.
Hushmail is an email provider that provides a service similar to ProtonMail, but:
"Developments in November 2007 led to doubts, amongst security-conscious users, about Hushmail's security, specifically, concern over a backdoor. The issue originated with the non-Java version of the Hush system. It performed the encrypt/decrypt steps on Hush's servers, and then used SSL to transmit the data to the user. The data is available as cleartext during this small window of time; the passphrase can be captured at this point, facilitating the decryption of all stored messages and future messages using this passphrase. Hushmail stated that the Java version is also vulnerable, in that they may be compelled to deliver a compromised java applet to a user."
and
"Hushmail supplied cleartext copies of private email messages associated with several addresses at the request of law enforcement agencies under a Mutual Legal Assistance Treaty with the United States.; e.g. in the case of United States v. Stumbo. In addition, the contents of emails between Hushmail addresses were analyzed, and 12 CDs were supplied to U.S. authorities."
Incidentally, despite all this, and what you'd expect to be "damage to their brand", Hushmail is still around, and I'd expect many of their users have never even heard of any of this.
[1] - https://en.wikipedia.org/wiki/Hushmail#Compromises_to_email_...
Let me also reemphasize that I don't consider email to be a secure or confidential medium of communication at all, even with PGP. I only want that my inbox is not sold to advertisers and the security practices of my provider aren't utter garbage. Maybe the fact that they're in Switzerland helps me in some ways, but if I had a state adversary I wouldn't bet on it.
Relying on hearing about compromises in the news only sort-of works when:
1 - such compromises are revealed
2 - they're big enough to make news in the first place
3 - your own data hasn't yet been stolen, so you have time to change services after you hear about the compromise
None of these is guaranteed to happen ever.
And even if you did hear about some compromise in the news, it could be far too late for you, as your data (the data ProtonMail is supposed to protect) could already be in somebody else's hands.
I think we don't agree on how proton mail works. As I understand it, they already have my keys. You can't even give them just a subkey, it only works if you upload a set of PGP keys including the master secret key. What is your understanding of how it works?
As for your other concerns, unless I am conversing only with myself, the attack vector for my data is the entire e-mail ecosystem. Even if I only talk to people who use encrypted email, they are also part of my threat model, even if I don't trust a provider with my keypair. e-mail is simply not secure. It wasn't meant to be secure; security cannot be bolted on top.
What is your threat model and how do other providers or self hosting achieve your desired level of security?
From: https://protonmail.com/security-details
"ProtonMail's zero access architecture means that your data is encrypted in a way that makes it inaccessible to us. Data is encrypted on the client side using an encryption key that we do not have access to."
Edit: Ok I see. They store the PGP keys encrypted with your password. Like you said, they could just as well inject javascript to phish your password from your session.
But this does seem to mean that if one uses their API directly it would be possible to securely use their service. Thanks for the heads up. There is a third party open source bridge that reverse engineers their API. I think I will look into it to see how authentication is done.
It’s good to use your own domain, it’s good to use a non ad-driven business model like fastmail (though even this is mostly for the user experience and not security)
Beyond that “secure” email when you’re largely communicating with other @gmail users, isn’t a thing.
Google has some of the best security researchers in the world, I’d trust their employees to do a better job than proton at securing the service itself.
Email should be treated as largely public (for personal use) and not used for sensitive communication. It’s a little different in a corporate setting, but then you’re not using proton mail anyway.