That said, Proton's response to this issue is joke.
That said, Proton's response to this issue is joke.
If they cannot handle basic things like PGP correctly, how should I trust other part of their software. Especially they are a "Privacy-first" company.
"Privacy" becomes a marketing term nowadays.
It’s a user benefit. By definition that means it’s a marketing term. That is not mutually exclusive with being a general concept.
download free full mp3 album now
(no download just spam, not free, not mp3, not the album you wanted and not now)
You can genuinely support privacy and still have features or user cases that don't work. This feature does nothing to weaken privacy.
But for PGP? You should treat it seriously, considering your target customers.
> though we could of course add that in the future.
> It’s absurd that there’s no way to disable this, no option to tell Proton “if you see a multipart/signed or multipart/encrypted message, just leave it the hell alone.”
which, as I said in my response, I disagree with the first half of that. Our goal is to (automatically) encrypt messages whenever possible, and leaving multipart/signed messages alone doesn't reach that goal. So I proposed two different solutions to what OP wants, one of which is already built into Proton Bridge, and one which we could add in the future (but which would be more effort than the one OP proposes).
Bridge is a proxy which hosts a local IMAP and SMTP server, and takes "normal" unencrypted and unsigned messages from desktop MUAs like Thunderbird, signs and encrypts them, and then sends them out. Note that this requires changing the MIME message somehow.
OP writes:
> Everything was great until I decided the other day that I’d also like to do PGP signing on my outgoing messages.
The "intended" way to do this is enable the setting in Proton Mail that says "Sign external messages" :) That way, Bridge will sign them for you. (Internal messages are always signed.)
> Tough luck, bucko, we’re the SECURE email company, you’ll upload your private key to our servers and you’ll like it!
FWIW, private keys are stored encrypted on the server, we don't have access to them.
But yes, the entire goal of Proton is to handle PGP for you, without having to set up PGP encryption and signing manually on all of your devices. I know that the HN audience is fully capable of doing so, but our goal is to make it easier for everyone else :)
> It’s absurd that there’s no way to disable this, no option to tell Proton “if you see a multipart/signed or multipart/encrypted message, just leave it the hell alone.”
IMO, if we see a multipart/signed message, we should still encrypt it whenever possible, not leave it alone. But note that normally in OpenPGP, signing and encrypting is a single operation. It's possible in PGP/MIME to sign a message first and then encrypt it, but we don't support sending that way at the moment, though we could of course add that in the future. But in any case, that's the reason we currently recommend signing using Bridge rather than manually using gpg or similar.
PS: the lack of threading support in your mobile apps is embarrassing, it's been like this for years. No I will never use your web client. Stop trying.
PS: yes, this is being worked on
I don't know why you think this is some sort of gotcha. Other than you think having standards is too entitled.
I'm always bothered by statements like this because it appears to be skimming over if the provider can perform cryptography with the key. My understanding is that those keys are only decrypted in the users apps/web browser, not server-side. Is that right?
You need to trust that the provider doesn't perform additional operations along side legitimate user triggered actions, which I believe PM handles.
"Don't have access" is a little too strongly worded IMNHO.
(I understand the reasoning - and I don't necessarily think it's bad - I just think it overpromises a bit)
Although they are open-source and can be scrutinized by anybody, it does not means that's what is run on the server side.
(Just say they have the capability; no accusation)
So at the end of the day, the question is whether you trust Proton or not. Encryption might not help in that case.
On mobile, to do such an attack we'd have to collaborate with Apple or Google to do it, which IMHO seems infeasible - but nevertheless also there a "Binary Transparency" feature of sorts might be valuable.
Thank you for moving the web forward. Proton mail does a lot of things well, and there's more to do. I was auditing DANE support and PM was one of the few I found with support.
> FWIW, private keys are stored encrypted on the server, we don't have access to them.
This is frankly fucking ridiculous. Users (including me) have been requesting a change to this for years. It's thanks to this bullshit that ProtonMail's key feature for me is just 'isn't Google'.
Brilliant quote!