Wait until they find out about other standard file formats; the possibilities for collusion are endless! The ACLU is colluding with the FBI, because both use PDF!
https://protonmail.com/support/knowledge-base/protonmail-isr...
Is is clear why they do the redirect?
https://old.reddit.com/r/ProtonMail/comments/62rfta/comment/...
Redirecting to the https site is a bit less secure than the hidden service, in that your traffic will only go over 3 hops (TOR client) rather than 6 (TOR client + hidden service circuit). But AFAIK they could also write a modified TOR client that served a hidden service without any additional hops. Those additional hops are best seen as security for the hidden service rather than the user. Also, a hidden service for a well known business is kind of a pointless marketing gimmick.
Same applies of course to chat apps that offer end to end encryption.
Maybe it's safe for messages to be intercepted, but can you trust the application decrypting messages and displaying to do just that?
Article is poorly written conspiracy hogwash.
And then it really quickly diverts into "it has ties to MIT which has ties to NSA" 6-degrees-of-Mossad drivel. Congrats, everybody who ever studied at or worked at/with MIT is a spy now.
Few people remember this today but downloading e-mails was the norm in the early 2000s and before. You would only keep a few weeks or months of e-mails on the server and then either delete or download them, as providers didn't offer very generous storage quotas. It was only with the introduction of GMail that this changed because Google offered "unlimited" storage (since they wanted people to store all their e-mails online so they could mine them).
BTW Protonmail doesn't need to inject extra JS into your client and wait for you to login in to decrypt your e-mails, they receive them all in cleartext and they send out e-mails for you in cleartext so they can simply log them without any modifications to the client code.
> encrypted backups of the e-mails which I store in the cloud, the encryption key never leaves my device.
Doesn't in mean that in (unlikely) case something happens to your device (like harddrive crash), you won't be able to access the backups?
https://news.ycombinator.com/item?id=26536019
Depending on your POV it is either a mild story or a non-story. It certainly doesn't meet my threshold for avoiding a service, but some people are more sensitive.
As a privacy step i see how this protects you from hackers and thieves (and legitimate search warrants), but not anything snowden warned us about
Even if you use a secure email service (whatever that means), the other party you're emailing with rarely does, so the NSA/CIA/MI6/whatever still has access to your 99.9% of your email traffic. If you don't want this, then don't email.
I truly don't get why we're having these discussions here on HN.
"Not recommended
If you are attempting to leak state secrets (as was the case of Edward Snowden) or going up against a powerful state adversary, email may not be the most secure medium for communications. The Internet is generally not anonymous, and if you are breaking Swiss law, a law-abiding company such as ProtonMail can be legally compelled to log your IP address. A powerful state adversary will also be better positioned to launch one of the attacks described above against you, which may negate the privacy protection provided by ProtonMail. While we can offer more protection and security, we cannot guarantee your safety against a powerful adversary."
If you're concerned about hiding your identity, you should be doing that by additional means (eg TOR browser). If you're concerned with security of your message archive, you shouldn't be using webmail. If you're concerned about metadata, you should be communicating with something other than SMTP.
https://userforum-en.mailbox.org/topic/oauthbearer-support-f...
When did the ability to send Monero payments (or perhaps payments in general) become a requirement for privacy email? Or are you specifically talking about a solution you would most prefer?
The idea being that if you want private email then you can’t pay for it with your Visa/MasterCard/AmEx/etc because if you pay for it that way then you tie your irl identity to the account.
For that reason, every server that claims to offer some end to end encrypted email service is bullshit, since somewhere the mail must be decrypted to be sent out to other servers (except if you exchange mails with users of the same service, that is extremely unlikely).
In my opinion, the best thing to do is to host your own mail server. For a person with a moderate knowledge of Linux it's not that difficult to install, the most difficult thing is to configure the server and the DNS correctly with all the record required to not be considered spam, and you have full control of your mail.
Yes, your mail of course are still going out in plain text when you send them to other servers (of course these days the communicatoin is TLS encrypted, but still they can be intercepted by controlling the destination server), but otherwise the messages are on your server, that can be a physical machine with encrypted disks if you want it to (I don't care that much and I have my server on AWS).
The article that justifies this claim is absurdly unreasonable in its approach, and its titular claim easily demonstrably false. Most of its method, such as it is, hinges on complaining that people haven’t chosen to make their email address public on their GitHub profile (which is something you have to opt into), and trivially falls apart; most of the rest comes of ignoring a separation of personal and work identities and is also nonsense; and the remainder is at least mildly dubious too.
Point six is also utterly clueless, as observed by others here already, and one or two of the other points where I do know a little have claims that are misleading or speculative at best.
Doesn’t incline me to trust this article on the parts that I don’t know about, even though I agree with some of its points (most significantly that first-party encryption is largely a crock—see Fastmail’s reasoning about that in parts of https://fastmail.blog/advanced/why-we-dont-offer-pgp/).
That said, the web-generated encryption keys in ProtonMail are an interesting exercise.
You have the choice of having a password for both logon and the mailbox or a unique password for both. You also have the ability to generate keys on your computer and upload them to the system. The combined web-generated password key is the default.
I noticed that there is likely an implied third password key when using combined web because you have the ability to change the combined logon/mailbox password key and with email addresses from more than 1 domain sharing the same inbox I observed that changing the combined key for all the domains sharing the inbox continued to allow previously sent email within the system to be readable instead of unreadable, which implies the system has its own non-visible key.
I didn't test this with separate keys for mailbox vs logon and didn't test with PC-generated keys, because to be honest, I didn't really care that much and it's a cloud-based system on the web and it's trivial to write code to label something unreadable when it actually isn't so my observation is an oversight. It's an unrealistic expectation to expect complete anonymity and privacy both. You have to trust that whatever it is, is good enough and that's all.
They're a great service for what they offer, a less hassle, more private email service.
For one, their iOS app sucks and has a ton of UI bugs.
For two, they offer an SMTP bridge app that you can host on your own machine to use their service with an SMTP client, but it randomly logs you out and forces you to re-enter your password (on the server side, not the client side) to keep using your email.
Will be finding a new host when it’s time for the next payment
IMHO, ProtonMail is still vastly better than Gmail, which is nothing but a ads delivery vehicle specifically targeted to you.
GPG is a slight improvement that you can use on top of any provider and it will encrypt the content of emails (and content only, metadata will still be there and even subject lines in certain implementations), but both you and the recipient will have to use it and good luck convincing non-IT people to deal with its absolutely atrocious user experience.
In other words, treat it like a physical mailbox. Good enough for various notifications, useless if you're trying to protect anything valuable in it.
For a closed group like a business you can simplify things by having a self hosted email server kept in a secure location. Less secure than end to end encrypted email, but then, few things are as secure as E2EE email. It's hard to beat a medium where the encryption can be done completely offline.
They only allow interaction via the web site or their apps. The apps are nice. But they act more like an IM client.
The biggest issue i had with it, is that they don't support subfolder. So you only habe one level of E-Mail directories.
I moved to mailbox.org now and it seems fine now.
They probably would be if you were targeted, though, but that's what Tor and VPNs are for.
"The former CIA director used a trick often used by terrorists and teenagers to make e-mails harder to trace, the Associated Press reports."
https://www.cnet.com/tech/services-and-software/petraeus-rep...
Use a password manager :)
I wish I were smart enough to self-host.
Haven't regretted the decision since. Spent a while building up email filters and that's about it.
[1]: https://techcrunch.com/2018/12/05/australia-rushes-its-dange...
We have read the article that you linked carefully and we have to say that what they claim is truth is based on bunch of assumptions and mis-interpretations.
We will try to comment on the accusations in the same order as they are presented on the web page.
1. ProtonMail offers the users to log into their account through our Onion site due to privacy reasons. Some users simply prefer to use TOR and we allow them to access their accounts through our Onion site. The fact that we have an onion site does not automatically mean that we are linked to CIA. We are not related to CIA in any way, nor we have any backdoors that would allow anyone to access anyone's messages. We also do not allow sign-ups from the Onion page as part of our anti-abuse measures.
2. The claim that we do not use end-to-end encryption is a lie, and in fact, the author of the article that you linked has also linked our explanation on this topic.
https://protonmail.com/blog/cryptographic-architecture-respo...
ProtonMail uses zero-access encryption to store the user's messages on our servers and we certainly use end-to-end encryption.
https://protonmail.com/support/knowledge-base/what-is-encryp...
https://protonmail.com/blog/zero-access-encryption/
3 and 4:
Proton Technologies is majority owned by employees of the company, and is solely under Swiss jurisdiction. Information about the company and our directors are in public record, and can be found in the Swiss commercial register: http://ge.ch/hrcintapp/externalCompanyReport.action?companyO...
Regarding VMS, VMS is not an investment fund or investor. It's part of MIT (http://vms.mit.edu), which is an university in Cambridge, Massachusetts. As a company heavily focused on cryptography research, we do share research with many of the world's top research institutions, including CERN, MIT, ETH Zurich, and several other research institutes. This is actually a benefit as it ensures that our technology is thoroughly checked by others to be certain it is secure.
5. The present employer of people that used to work for us in the past does not mean anything.
6. If someone uses EML files, that cannot mean that they are automatically related to CIA. EML is a file extension that is used for an e-mail message saved to a file. EML files are widely adopted.
7. This is not correct, because we do not have access to our user's messages, nor the means to decrypt them.
https://protonmail.com/blog/zero-access-encryption/
8. We have used Radware in the past for DDOS protection, but they never had any access to any data.
https://protonmail.com/blog/a-brief-update-regarding-ongoing...
https://protonmail.com/support/knowledge-base/email-ddos-pro...
9. This is not true and we don't see how this claim is a security concern of any kind.
10. We are unable to comment on this.
11. See points 3 and 4
Also, you are welcome to review our terms and conditions, privacy policy and transparency reports.
https://protonmail.com/terms-and-conditions
https://protonmail.com/blog/transparency-report/
https://protonmail.com/privacy-policy
Have a nice day
Was your account free? Did you end up not logging in for a while? Seems reasonable for them to delete inactive accounts.
Is proton mail less likely to deplatform you than gmail in the event you utter the wrong political statement? If so that might be something I guess.