Truth about ProtonMail
encryp.ch
encryp.ch
> Protonmail has an Onion domain that allows users to visit their site using the TOR browser. Protonmail even has an SSL cert for that onion address even though it’s completely unnecessary. When a user makes a new account with Protonmail on TOR they are re-directed from Protonmail’s “.onion” to “.com” address. This breaks your secure encrypted connection to their onion address, enabling your identification. There are absolutely no technical reasons for this feature. In fact, the only other websites that operate like this are suspected NSA/CIA Honeypots.
Why in the world are you trusting them to host your email if your threat model doesn't include connecting to them over HTTPS? Your endpoint is still a globally identifiable email address that you're going to use their webmail UI to view. What privacy, exactly, is TOR providing in this use pattern?
> Leaked documents at Wikileaks show that the CIA requires emails to be stored as an EML filetype. There are several ways to store emails, and Protonmail has selected the format that the CIA requires.
Everybody uses the EML format! It's a raw dump of the RFC 822 message[1] that the protocol itself uses!
[1]: https://www.loc.gov/preservation/digital/formats/fdd/fdd0003...
The author rails against Cloudflare originated SSH traffic assuming its immediately malicious, and decrying how carriers are ignoring his legitimate calls for their blacklist as well.
"Can you believe they're storing text files using ASCII? It's exactly what the CIA wants you to do!"
I would still use Proton over gmail, because I don't want google to have ALL of my data.
The article points 8 and 9 are ridiculous.
Take away message from the article: if the USA, or the EU, is your enemy, you shouldn't use proton, or gmail, or any 3rd party email provider. If you live in a Russian backed dictatorship, proton is OK; you should be more worried about your hardware and your meatspace.
That means a ProtonMail account can be created completely anonymously. I call that an advantage over some other options if you want to create secondary/throwaway accounts (for example, you want to register a small forum and you don't truth their admin).
I personally won't recommend ProtonMail as someones main email service. If I want to send anything secretive such as sharing a password, code etc, I'd rather send GPG encrypted email via Gmail.
How exactly is it ridiculous? I understand that email leaks metadata like a sieve, but the contents of emails can still be secured via encryption.
> (and ProtonMail's business model is effectively built on a marketing lie/false advertising),
No arguments here. They provide a web app to encrypt your emails, making the user trust the server for "end-to-end" encryption, this rendering it useless.
It is absolutely necessary, especially with the new, longer v3 onion domains[0].
Generating a v2 onion address that begins with "protonmail" takes a few hours of GPU. Given a link to one of these v2 addresses no user is ever going to authenticate it by memorizing the address:
protonmailrmez3lotccipshtklggee7olb73fu1rgj7r4o4vfu7ozyd.onion
The user knows and authenticates an onion because the endpoint is signed using the same certificate and CA as the .com address and the user can verify this in their browser.
> When a user makes a new account with Protonmail on TOR they are re-directed from Protonmail’s “.onion” to “.com” address. This breaks your secure encrypted connection to their onion address
This step won't deanonymize you or "break your secure encrypted connection". You are routed via a Tor exit node rather than via a guard node to a hidden service.
As to why they do it - offering a free service to anonymous users on Tor is a constant battle with spammers and bots.
You only have to look at the absurd lengths darkweb markets go to to authenticate "real" users (multiple CAPTCHA gateways with minute+ wait times) as to how difficult this challenge is with completely anonymous traffic that has absolutely nothing to session/fingerprint a user on to prevent abuse.
This entire post is speculative troll-bait, which unfortunately Protonmail fell for. Their response to this type of post only reinforces the views of those who are conspiracy-minded and see links where there are none.
It is very reminiscent of the FUD campaign Pando Daily ran against the Tor project itself (any second degree link to anybody even remotely US government means the software is obviously backdoored).
[0] The article links to the Protonmail v2 onion - a shorter format address and protocol that has been deprecated.
There is a huge difference in the anonymity afforded by a tor hidden service, vs. using tor to connect to a clearnet website. You should at least acknowledge that.
If they sent a cease and desist letter to somebody who is publicly, confidently, and repeatedly making untrue claims, that only makes sense
What do you mean?
They act like a honeypot. They redirect onion users to an exit node undermining the point of having an onion service, they require a phone number for onion users instead of actually offering privacy.
They rely in their fans to shield them from criticism while doing these privacy counterintuitive things.
The same thing happened at a swiss encryption company for 50 years. Employees kept finding flaws in the encryption and kept getting told to work on anything else and it turned out to be a CIA front intentionally selling backdoored encrypted communication devices worldwide [1]. When proton is doing the same thing and has an even more obvious ownership structure incentivized to keep a charade up, there is no reason to use proton for any of the reasons they advertise.
[1] https://www.bbc.com/news/world-europe-51487856 (BBC, find a source you happen to respect that corroborates the same thing)
> Leaked documents at Wikileaks show that the CIA requires emails to be stored as an EML filetype. There are several ways to store emails, and Protonmail has selected the format that the CIA requires.
Ummm, what now? It seems to be literally crazy to take that as evidence that ProtonMail is a CIA front. What next? The ProtonMail website is written in English and the CIA speaks English too, leading to the obvious conclusion that the CIA runs ProtonMail (also HN and Noam Chomsky).
https://www.loc.gov/preservation/digital/formats/fdd/fdd0003...:
> EML, short for electronic mail or email, is a file extension for an email message saved to a file in the Internet Message Format protocol for electronic mail messages. It is the standard format used by Microsoft Outlook Express as well as some other email programs. Since EML files are created to comply with industry standard RFC 5322, EML files can be used with most email clients, servers and applications. See IMF for a description of the message syntax.
What really worries me is that Protonmail has asked their upstream domain provider to not only boot them from the Internet, but also reveal their personal information. Of course, they have no legal right to either - at least not until they obtain a court order - but it doesn't hurt to try, right? That doesn't look like a good guy behavior. I understand they may be pissed for being (likely unfairly) criticized, but we have way too many people that thing the only way to deal with criticism is to suppress the critic and try to ruin their life. We don't need more.
> Leaked documents at Wikileaks show that the CIA requires emails to be stored as an EML filetype
:D I know a lot of organizations that conspire with the CIA - probably including FSB, Iranian intelligence, and possibly my hair stylist .... The CIA also probably uses UTF-8, TCP/IP, various RFCs, Facebook, 120V power, and RJ-45 ports (actually, a large institution with loads of legacy tech might not be using UTF-8 in many circumstances, on the other hand they do handle a lot of international data ...). I can't tell you how I know that, though.
i'd like to emphasise, apart from claims made, ProtonMail actually sent abuse letter trying to get the personal details of the author
that's not something one would expect a privacy-focused company to be doing
more on that story here: https://news.ycombinator.com/item?id=29102776
> want to take it down so badly
> waste their lawyers time to send letters
idk, but i find it funny
> I expect to hear who (and why) generates that kind of traffic from cloudflare owned subnets.
Not that I use them.
I wouldn't depend on it however for E2EE of communication data. Or any third-party service where I'm not the one managing myself the key pair and locally en/decrypting data.
EDIT: as pointed out below, it seems that they do recycle your account under certain conditions (never happened with me) and they do require identification when registering via Tor (never done it through Tor). I don't think there are many scenarios left where choosing ProtonMail is the best option.
[0]https://yahoo.tumblr.com/post/52805929240/yournameyahoocom-c...
That said, I use proton mail with their bridge https://protonmail.com/blog/bridge-security-model/ which in theory is a lot easier to audit, and the end user is in charge of when it gets upgraded, so a warrant in theory doesn't just allow them to flip a flag somewhere and have the client forward the encryption keys. Whether or not that functionality is buried in the bridge is something that could be audited, although i've not done it and frankly probably no one else really serious has done it either since the effort to audit it is more than just setting up a custom GPG configuration.
Edit: And just as a note, frankly it hard to justify not having an encrypted email/dropbox/whatever these days. I use it fairly regularly to communicate with my bank/attorney/etc. Its easy for them to use, and throws up another barrier to the bad guys on the internet that don't need to know my social security number/bank account numbers/etc.
The lies are very harmful
Any "better" alternatives with some comparisons?
Thanks :)
GPG + RFC 1149
It doesnt matter then that the stored data is not encrypted. You can upgrade file sharing and communication elsewhere and also signup to services under an unlinked identity. The limits are much more clear.
A C&D letter is not itself evidence of anything. Most companies will send you one if you make egregious claims about their business.
I didn't mean to suggest it was. It is still surprisingly hostile/corporate behavior from a company that markets itself as an anti-authoritarian actor.
Instead, they are choosing to aggressively silence the author. That raises eyebrows.
Somewhere along the road, we've gone and conflated "someone sends you a scary letter" with "I'm being silenced." The author is clearly anonymous and apparently (correctly) scoffs at the letter, so it feels like a distortion to call this "aggressive silenc[ing]."
(Of course, this is all very abstract. The person who runs this site claims to live in Ukraine, so there is probably no meaningful legal recourse available to ProtonMail. Which brings us back to "aggressively silence" being a grand overstatement.)
Taking issue with the article in the first place.
One thing that I really appreciate is that I can reach ProtonMail support to asked why they flagged my email as spam.
I build an email forwarding service https://hanami.run and when we first rolled out I reached out to them, they explain to me my entire email looks good and problem is probably by the age of domains. A few weeks later our emails are no longer flagged as spam. I couldn't get that kind of support from gmail or outlook.
They also maintain https://github.com/openpgpjs/openpgpjs so I think ProtonMail still deserve some credits
>When a user makes a new account with Protonmail on TOR they are re-directed from Protonmail’s “.onion” to “.com” address. This breaks your secure encrypted connection to their onion address, enabling your identification.
Nope, whoever wrote this article has absolutely no idea what they are talking about. Onion routing works perfectly well on non onion addresses, and encryption doesn't mean butt for identifying where traffic is coming from.
The end node will have access to what’s being browsed.
If it’s an onion site, the last node is the node you’re visiting. No way things can be leaked/intercepted.
10 seconds of research tells me that going to protonmail.com without ssl immediately just redirects you to https://protonmail.com so again the things said in this article are utter bunk, nothing of interest is sent to protonmail without ssl.
It's called an 'exit node' not an 'end node'.
If the site is using SSL the exit node will not have access to what is browsed, and REGARDLESS of whether you use SSL neither they (nor anyone else) will be able to see your real IP.
But I agree that the article is badly misinformed.
Also, improvmx.com is a great product as well.
If you like open source, https://maddy.email/ is a single binary deployment that can handle everything even IMAP.
https://mailcow.github.io/mailcow-dockerized-docs/ is a dockerize solution with super detail document as well.
Suggest you hire an editor to fix up your content… or contact me and I’ll do it for free.
it is impossible to register a new PM account using an iCloud alias! I’ve always wondered, how?
Especially now with the ability to hide your email on ios, what would be the use of that if there is no distinction?
¯\_(ツ)_/¯