ProtonMail includes Google Recaptcha for login
github.com
github.com
A very small fraction of logins get the CAPTCHA challenge. We, and other services, face unrelenting brute force attacks on our login endpoints. If you are seeing a CAPTCHA on login, chances are that something about your connection is suspicious to our system. It's far from perfect, and we continue to improve it, but at most a percent or two of users are seeing CAPTCHA at any time.
The CAPTCHA is run in an iframe on a separate domain to sandbox it from the Proton login flow prevent it from compromising the webapp. Obviously Google still gets some information, but we do all we can to limit this.
CAPTCHAs are very hard to build, especially considering Google has a habit of clearing the field with it's own captcha-breaking code. Most companies do not have the resources to build their own. We had an alternative CAPTCHA we were going to use as a replacement a few years ago and then the company behind it went bankrupt. We are currently looking to replace ReCAPTCHA with hcaptcha, which should alleviate some of these problems.
We have other strategies which we are also exploring to try to reduce the need for CAPTCHAs entirely, but these are also not trivial to build and integrate into all clients.
TL;DR It's a small fraction of users who are affected, it's necessary to protect our users from brute force login attacks, we don't like it either and are working hard on replacements.
Off topic: please implement font size adjustment capability on iOS!
They are not what they were, what they stood against. They have been assimilated.
Sad times. But, hey they reply unlike the big G.
This may or may not be a problem for you.
The best mitigation as a user is to never reuse a password, however protonmail cannot enforce this. From their side the best option is to slow down the hackers as much as possible so it's less likely their more vulnerable users get compromised.
E.g. What was the ratio of failed logins to successful ones before implementing captcha? Now that you've implemented captcha, what is that ratio among the population of users not presented with captcha, compared to to population that is? How many attempts did adding the captcha stop?
dear god
That said, we can also understand the reaction. Back in 2014, there were no viable alternatives. Today, there is one alternative, and we started the transition to hCaptcha earlier this year, and will complete it in the coming weeks.
For security reasons, we can't say too much, but some truly massive residential IP botnets have appeared in recent years and can make millions of attempts per day. On really bad days, Captcha can appear for nearly 1% of legitimate users (some who are unwittingly part of the botnet), while blocking nearly all of the malicious attempts.
[1] https://www.reddit.com/r/ProtonMail/comments/5z70cd/when_sig...
That's reasonable. Thanks for responding.
Ah yes. All those insecure IoT and unpatched/unpatchable routers that are discoverable on shodan and ultimately end up joining giant botnets. They are a plague not just to ProtonMail.
TBH, I’ve never seen a Captcha. But then I’d tend to use your service via mutt/bridge or the iOS app. And I have MFA enabled.
Obscuring reasons due to security. Sounds like a security through obscurity type of thing.
> Obviously Google still gets some information, but we do all we can to limit this.
When you cause a request to be made for ReCaptcha, it seems that you're leaking enough information to (in many cases) link a possibly-pseudonymous Protonmail account to an identifiable individual.
(For example, even if you leak nothing else than times that individuals identifiable by Google logged into unidentified ProtonMail accounts, Google can already see various external activity of specific ProtonMail accounts, and you've given them temporal correlations between activity of pseudonymous accounts and logins by identifiable individuals. That's not the only example, but even that alone seems a significant risk.)
And it's seems to be a real risk: Google is in the business of doing things like that, has a track record of doing things like that, and presumably is more than capable enough of doing it some more.
> but at most a percent or two of users are seeing CAPTCHA at any time.
That sounds like a lot. And the "at any time" sounds like an even higher percentage of users are potentially being compromised by the use of ReCaptcha.
> we don't like it either
I'm not yet convinced that this is the least of all evils. And I don't know how much you have to dislike it before you decide not to do it.
For persuasive effect, is it helpful to imagine the reaction of your philosophical adversaries, when they heard that ProtonMail was using ReCaptcha? I just imagined some of them laughing derisively or incredulously. I don't say that to be mean, but I don't understand the rationale for using ReCaptcha, and I want to emphasize that it seems to be a problem that threatens ProtonMail's raison d'etre and/or brand image.
(BTW, I'm assuming this ReCaptcha choice isn't due to legally-compelled cooperation in unmasking specific accounts -- in which case I wouldn't say anything -- since, in that case, I expect you'd find a way to comply without misrepresenting the rationale to everyone else. I've seen ProtonMail thinking ahead to avoid related conflicting obligations and assurances.)
(BTW, I'm speaking here of Google as an adversary of your customers, and therefore of you, only because that seems to be how your product is positioned, and why you have customers at all, rather than everyone just using GMail. I'm not saying that Google is bad; only that I think it should be considered an adversary from your perspective.)
Any small leakage of data/activity/identity is unacceptable to those of us who know how this information can be taken advantage of, and choice Proton specifically to avoid that happening.
However, it's something our team cares about. That's why 6 months ago, we started preparing to migrate to hcaptcha, even though removing reCaptcha wasn't the most pressing community demand. This work is on track to be completed in the next few weeks. We are sure that after we switch to hcaptcha, on the community voting forum, there will be a "do not use hcaptcha" suggestion, which will then start to collect votes. When it collects enough votes, we will duly allocate resources towards building our own captcha, because that's what it means to be a community driven company.
[1] https://protonmail.uservoice.com/forums/284483-protonmail/su...
> In our setup, reCaptcha is served from a sandboxed iframe, which prevents it from being able to interfere with our java script, so it does not pose a privacy or security risk.
You might perceive low user demand for this change because your users assume that you handle the privacy/security risks, and assume that the only issue is annoyance.
Good luck with the fight.
> TL;DR It's a small fraction of users who are affected
Yes, though any of your users can be affected, randomly, without warning.
IME CAPTCHA will make your internet use unbearable if you a) are from a non-Western geo-location or b) you use a VPN. VPNs like the service you provide, which a fair number of your email users probably avail. It's fair to say a smaller number of "internet users" get CAPTCHA hell (which i also doubt), but I wonder if the ratio of Proton* users actually skews the other way.
The email search is completely useless. I don't understand how it can possibly be so difficult to do a substring search on a corpus and rank them in some kind of sane way. Searching for old emails based on content is an exercise in futility. After a few years of using an email service, search becomes really important.
It is exceedingly difficult to pull data out. You need dev ops skills to do it.
They charge for users that are disabled, and you can only stop paying for them if all of the associated data is deleted.
So they effectively hold your data hostage (yes, you can get it out but it time-consuming and requires technical skills).
I finally bit the bullet and paid a dev ops person (and gave him access to all my data) and switched to fastmail (at least it's not google) a few months ago. It's been an incredible relief.
I suggest you either stop responding, or actually respond to the issues people have, and don’t make excuses that are paper thin.
This is embarrassing at minimum, and show negative interaction with customers.
Is it that the developers 100% defer to a marketing rep without in-depth knowledge? Something else?
But yeah, they really need to control and focus their core message to a tech board. If you whiff that (which they did), there's a good chance in running off your core users. And that is generally considered a bad idea.
A improvement like this is indeed in our feature backlog, and something we hope to implement in the future.
I personally don't like it and surely there's better ways of doing it, but it is definitely not unheard of.
I would kindly suggest you stop wasting your time engaging them in their corp. troll techniques.
If you have additional questions hopefully other members can answer them here.
I can't even think of any? But also search isn't a core feature for the vast majority of sites. Something can be easy and still break if nobody cares very much.
Edit: Actually I can think of search breaking on one site that was notoriously badly run and had 0 to 1 part-time devs. That's not a flattering comparison.
Edit 2: So could the people that disagree name some notable sites with broken search? I feel like if I don't understand what "XYZ" stands for it's probably not something I should be blamed for...
Then there's MDN - a documentation site, whose 2nd most important function should be search. Yet, despite DuckDuckGo (a general-purpose search engine!) consistently finding the exact results I want, MDN's built-in search often misses even titles that are searched for verbatim.
If it weren't almost 2am and I weren't running almost entirely on caffeine, I'd probably be able to think of a few more.
When you can download a freeware tool that will find any file in the system instantly after maybe a minute of indexing you know the file search is not the problem here.
Just a month ago the only reason I could start a recently installed MS Office package on Windows 10 was its tendency to list newly installed programs first in the start menu. It did not show up anywhere else, could not be found by the search and Word could not even be set as default program for a file because the OS didn't seem to know of its existence.
I know for a fact, Gmail on my phone doesn't have the ~15 years of email in my account downloaded. I bet that would take significantly longer to download than the actual search would would take to perform.
If the things to be searched aren't already on the client, a client side search doesn't seem too useful to me, regardless of how much compute power you have.
No real complaints besides the bridge sometimes pegging a cpu until I HUP it..
It’s way above my pay grade but I wonder if homomorphic encryption could be leveraged at scale without compromising security.
The mobile app has some way to go but more than adequate for daily use because I'm using it daily.
// Or something like that, I’m dumb for cryptography :)
You can imagine each user as a folder in the /var/mail directory, it depends on your implementation to encrypt the folder or not. Gmail encrypts all in-transit e-mails but I cannot find a reference for encrypting on their servers
I thought when they were referring to the server, it was email servers in general.
Took me a second to figure out that you weren't claiming accessibility was only supported at an extra cost.
Ikea mass marketing emails are ~5.5 for me, and essentially all of the “false positives” in my spambox. The real spam is all 20+.
It looks like fastmail defaults the threshold to 5. Try increasing it to slightly above the score your legitimate emails get.
TricepMail is designed specifically for privacy, and not only privacy for your data on TricepMail’s servers but for preventing others from tracking and selling your information as well. The privacy policy specifically states that there is no collection of your personal information. TricepMail is based out of Colorado, US, but considering moving to another country which might be better for privacy.
The UI is definitely very minimal, but that is on purpose by design. No need for a bunch of visual clutter when reading/sending email. Improvements can and will be made though, of course.
I could promise you I'll send you a legit authentic fancy gold Rolex worth $20,000 if you transfer me $15,000, so you can re-sell it and make $5,000 in an instant. Would you believe me?
I remember a while ago someone promoting a new email service that "focused on privacy", etc. A few knowledgeable HN users quickly pointed out they were running Mail-in-a-Box on a single Digital Ocean droplet.
Your open source link contains nothing, your blog has no posts, your Windows app is not found in the store, your privacy policy is from a free policy generator tool, there are no reviews due to the service being new and there is no documentation for how to use custom domains, etc. You may offer an excellent service, but there's not a lot to base trust on.
Thanks for your feedback!
Oh, also, the open source repos are coming soon. Only so much time in a day. :)
Their “bridge” lets you use a regular imap client, which makes it trivial.
Does anybody else find that weird?
“I completely misunderstood Swiss privacy laws and fell for a sales pitch from an email and VPN company that goes out of its way to track every user no matter how they sign up! Its to avoid email abuse, exclusively!”
And why is that again? I want to understand that argument.
In case of DDoS scenario: Well, too late, traffic already served and server already done the workload.
In case of password brute forcing: Well, then implement a latency, or cryptographical challenge to delay it more efficiently.
In case of "evil" human: Well, if a human can get past your security so easily, then your approach to security through obfuscation might be wrong.
So, again, what is the scenario where a captcha helps you to avoid being "attacked" by malicious actors?
My question is related to the specific /login page, not the registration page.
I understand the benefit for blocking spammer signups, but not for the current case of the login page where users have an account already, were verified that the account/password was correct (captcha appears in second step), and then have to enter a second decryption password manually.
In that scenario there's no argument on the "WHY" a captcha helps. It simply doesn't.
The only reason I can think of is because they want more unique identities. More unique people means a greater chance for a purchase. More mail accounts just cost more.
The entire business model of free accounts requires someone paying for something extra. By unique identifying people they can limit new accounts and increase their chances of an upsale.
What if they changed how they operated. Instead of looking for more unique identities why not accept multiple addresses and include an ad at the end of every free email letting the receiver know this came from protonmail. That would give a benefit for each email sent and provide more advertising and give users a reason to upsell?
My guess is having that ad after every mail would bother you (the customer) more than having your identity uncovered.
Disclaimer: using protonmail until my current subscription runs out, then selfhosting
Self-hosting at least means that this should not apply, I think.
Sure. But I'm not worried about someone who has an actual warrant for ME getting at stuff.
What I want to stop is some random law enforcement idiot from Dipshitsville, Texas, from sending an electronic request to Google for "every email with the word "abortion" and "protest" in it" who promptly turns over all my email.
If you want my email, you're gonna have to get up off your chair, file a warrant with somebody's name on it in front of a judge, crossfile in some different legal jurisdictions, and have someone come seize my machines.
That will stop most everybody short of NSA.
If your threat is the NSA, you're screwed anyway. If they can't get at your email legitimately, they'll just fabricate the evidence they need against you.
The NSA doesn’t need evidence; you must have them confused with the FBI.
Right now only hotmail bounces mail. Am using DO/Singapore. Other centers fare better.
My server is a "Mail-in-a-Box" running on a DigitalOcean VPS.
That way no one reads the emails sent to you and the ones that you send get through (and outbound privacy is not expected if you are sending to gmail or another provider anyhow).
That also makes it harder to track conversations and would take manual work to recreate the conversation threads.
This is completely not true. Comes up every time there is a thread related to email. Every time many of us who host our own email servers will explain how it is not true. You can absolutely self-host your email server for your domains, configure it correctly and it will work fine.
gmail has a huge false positive spam identification problem, but it applies to all emails, even those from gmail to gmail.
Excision Mail which runs on OpenBSD hits the majority of what you need technically. https://github.com/Excision-Mail/Excision-Mail
The bigger problem is finding a hosting provider that hasn't had their entire space blacklisted.
For that, you're likely going to have to pick a "responsible" provider, have a couple of rounds of back and forth with them to prove you're neither an idiot nor a spammer, and ask them to manually open the port for you. And they're going to demand something that will tie to identity.
From talking to other people who tried the same, my theory is that the main reasons for my success were having everything configured well from the very beginning, running on a single static IP for multiple years, hosted at reputable mid-range server provider (not the cheapest, not the most popular) and not sending any "broadcast" email whatsoever for a very long time.
I don't think it means they're interested in tying accounts to a specific identity, just an identity, to prevent bots or bad actors from signing up for thousands of accounts. This is a necessary reality of being an email provider. If you do not police your outbound mail then other mail servers will block or auto-junk your users' messages.
There is no way to preserve privacy while also not becoming a festering ground for Viagra spam mail.
"The recaptcha, when it shows up (in rare situations), is sandboxed so that it doesn't send any data to Google. We are also in the process of replacing it with hcaptcha."
Not sure what possible sandboxing they could be referring to - if they load the captcha in an iframe from a different origin then it is true that Google's javascript can't access things on the Protonmail origin, but the concern seems to be that your data is sent to Google (which is still happening even with sandboxing, their tweet cannot be correct), not that Google's recaptcha javascript would have done something malicious on the Protonmail origin (which seems unlikely).
In any case, at least they're moving to hcaptcha.
[1]: https://twitter.com/ProtonMail/status/1398657423913668614
also, captcha in general shifts burden onto and penalizes legitimate users, especially privacy-conscious ones, in addition to malicious ones. that is, false positive rates are too high to achieve acceptable false negative rates.
it would be better not to use a centralized captcha service, if one must be used at all.
but more importantly, in the long term, it needs policy and legal progress. it needs to be costly and international (via treaties/sanctions).
Until they get broken by botnets and we are back to where we started by using Google ReCaptcha.
Looking only at the technical differences, hCaptcha lets enterprise users like Proton locally scrub any info like IPs prior to sending to hCaptcha. It can be set up so that the user makes no direct connection at all to the service, and the code runs inside of a sandboxed IFRAME.
As for false positive vs false negative rates, not sure what you consider too high. We've been able to demonstrate FP rates under 0.005% when measured against known-good/bad signals from customers, which is as good as it gets.
(disclosure: work there)
so in effect google can tie you to this visit later if you interact with anything that has a captcha. now these two thinks are liked in the borg’s memory.
so if you use google (anything while logged in, even once) now google knows everything else you do
Every popular online service today is being continuously attacked. Bad actors get a lot of economic value from credential stuffing, account takeovers, and fake registrations, especially on email services.
This is why CAPTCHAs exist. They are one of the better tools in the defender's arsenal to increase the cost of attacks.
Building and maintaining a good CAPTCHA service is both hard and requires a high level of continuous development, since every day people are waking up and trying to figure out how to break it.
This means almost every company that tried building their own in the past has switched to either hCaptcha or Google, since it is not practical for even large companies to maintain their own solution these days.
Why was ProtonMail originally using Google? Probably because for many years it was the only plausible option until hCaptcha came around, and they needed to protect their users.
We're working with them now to switch over to the enterprise version of hCaptcha, which:
1) includes privacy-preserving features that let them decide exactly what user data hCaptcha sees and when, and 2) guarantees what happens to any data received via a data processing agreement, and 3) isn't run by an ad network.
hCaptcha doesn't care who you are and ensures all data is ephemeral, since unlike Google we're not trying to sell ads targeting you.
(disclosure: work there)
I’m under the impression that the bottleneck isn’t “high level of continuous development” so much as it is just having a large enough data set of Internet activity to conduct statistical analyses on. Cloudflare and Google are obviously in a good position for this, since a significant amount of Internet traffic goes through them. But I can’t create a startup to invent the next Captcha unless I magically discover a flash drive containing a giant corpus of HTTP requests made by billions of modern devices around the planet.
Even HN requires a recaptcha if you fail too many times (and it's also based on IP).
If you want to blame anyone blame:
1: The bad actors spamming logins
2: Google for essentially monopolizing captcha
hcaptcha proves there's a market/demand for alternatives, this is HN, if you dislike it, go build a better alternative than Google's and I am sure PM will be only too pleased to switch.
Complaining is easy, actually changing something is more difficult.
(P.S I challenge anyone to deploy a system used by tens of thousands and not have any abuse/rate limiting systems, you'll soon be turning to captcha's at some point)
Personally, I hate hCaptcha more than recaptcha, Craigslist uses it for their contact forms and I hate. hCaptcha is much more difficult and tedious than recaptcha.
[1] https://www.trendmicro.com/vinfo/hk-en/security/news/cybercr...
What was described above is correct though. One popular app (which had legal troubles recently) made money with Luminati:
https://torrentfreak.com/mobdro-luminati-proxy-service-suspe...
I'm in Poland, using one of most popular landline ISP
Usually you wouldn't want to make it easy for botnet owners to find out they've been caught, but since displaying the captcha already reveals that, having an explanation might help regular users who got a low-reputation IP assigned.
Edit: also it says there are 0 items blocked
What in tarnation are we paying you for?
Thank you for posting this.
Fastmail's side of the story: https://fastmail.blog/legal-policy/aabill-and-fastmail/
The vast majority of mail services will hand your data to the government on court order. Though if your mail is hosted in a different country than you live in, it's arguably more frustrating for them to do so, since they must use international agreements to get it.
If state ordered surveillance is in your threat model, you need a very different type of mail service than almost everyone else.
Caution, abject speculation:
I thought spooks like this kind of thing because they can do illegal things in other jurisdictions that they're restrained from doing in their own - or get foreign agents to spy on you to avoid getting a warrant. Like they can route traffic to another country, then have affects there hack you to avoid laws that curtail actions against your own citizens.
I don't know, just seemed like one point of groups like Five-eyes.
This is absurd indeed. hCaptcha[0] is a better alternative though, and I wouldn't mind if they used that instead of reCaptcha. I never liked the carpal tunnel that reCaptcha introduces.
In the end, the services that are using captchas are the services that become the least liked, and users will start migrating to other services that don't use captchas, so there's a business penalty for using them.
On the other hand, if you want to filter out bad actors, then captchas are the way to go. The reason I recommended hCaptcha is because they're easier to solve, and sometimes Google's reCaptcha offering is so complex and hard-to-solve that it starts inducing carpal tunnel / RSI symptoms (at least for me). I don't get so easily fatigued & inflamed with hCaptcha though.
I don't think those sites show you a captcha before you enter your login and password, but rather on submit. So for that username you don't show them a captcha at all, if they don't have a proper cookie you ask for 2FA.
I find hCaptchas easier to solve though. My carpal tunnel in my wrist doesn't flare up and I don't get RSI[0].
reCaptcha is notoriously complex & difficult to solve if you suffer from RSI or joint inflammation.
Maybe I'm just a robot as far as hCaptcha and reCaptcha are concerned.
Sending mail to gmail requires setting up extra processes that most times won't work anyways. Sending mail from an unknown ip is like sending it from a blacklisted address. To avoid this I use my isp to send the mail.
Setup time including thunderbird settings is under an 2 hours for many.
It does not.
I set up my latest/current email hosting in about 2011. Very minimal work on it since then. There's really nothing to do once it's working.
Only work I can think of I've spent on it since 2011 is: regular OS updates (which take basically no time), added SPF and later DKIM support, added Let's Encrypt cert. That's it in ten years.
it takes 10 minutes to setup. it does not have a flashy web ui - but if you do imap it doesn’t matter.
cost: 12$/year for the domain, 4$/month for the user, 0.5$/month for the route53 zone
so 5.5$/month to kick gmail to the curb. the gov is still gonna get your emails if they want them.
Did I mention that Amazon has datacenters in places with stronger privacy laws (Germany cough cough)?
https://www.reuters.com/world/europe/email-bomb-threat-sent-...
It seemed rather fine-grained knowledge of specific communications that doesn't serve the narrative of privacy first. The articles I read made it sound like ProtonMail had just decided to share details on it rather than a more formal, court-ordered process.
I know in this situation there aren't too many people who would raise questions, but it did strike me as strange given how they market their service.
Any message that interface with the standard email network is better off regarded as public communication. I can only imagine the legal implications that would compel Protonmail to assist law enforcement after their Service was misused and complicit in an alleged bomb threat.
Their Terms of Service surely outline that illegal activity will void their protection as far as possible. Keeping communications inside their in-house, zero-knowledge email service on the other hand, would make it very hard for Protonmail to produce any of this information. That is their actual privacy offer, as far as I understand.
To Protonmails defense, I haven't heard that this email has successfully been linked to any real identity past the phony Sulanov alias.
Not saying it may not appear for others but I didn't see it.
If you know this, then I guarantee that the people making spam bots know this too. this is a very naïve argument
Even though I only saw it on creation, and not on login, the possibility of associating a strong identifying fingerprint with a presumably anonymous throwaway user account was concerning.
It’s just flies so flabbergastingly in the face of the entire point of the thing that I might as well stop using them.
As a project that advocates Privacy and Security, and was an immediate response to the Snowden Leaks, I find this kinda ironic that they now set the Google PREFs cookie for all of their users - while they still maintain the same marketing on their website.
And well, I am looking for new options now, I guess.
I hope you don’t assume the worst without investigating further.
But I agree with you, I think I should give them a chance to respond to this. Personally, I think this is a serious issue.
I opened up a GitHub issue for their frontend (as they do not have any security disclosure contact possibility as it seems): https://github.com/ProtonMail/WebClient/issues/242
Protonmail might have issues, but the threat of some leaked information through javascript and/or cookies (hello google fonts!) can be attributed to literally every site that uses recaptcha whereas the article is talking about a much, much worse practice of tracking physical location constantly and making it difficult or impossible to use your phone without giving that information to Google.
I hope protonmail finds a better way, and agree that it's not in keeping with their stance on privacy, but it is distracting from what Google is actually doing with phones by talking about an entirely unrelated issue.
No offense intended to the parent, the comment is interesting, it's just not about the article at all and yet is the top comment at the time I write this.
Don't let the perfect be the enemy of the good.
Google made it nearly impossible for users to keep their location private - https://news.ycombinator.com/item?id=27324755
Since it's more on-topic here, I've moved it hither.