this post was submitted on 24 Mar 2024
75 points (100.0% liked)

Free and Open Source Software

17911 readers
53 users here now

If it's free and open source and it's also software, it can be discussed here. Subcommunity of Technology.


This community's icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

founded 2 years ago
MODERATORS
 

For some reason I have it in the back of my mind that they were at one point accused of being a honeypot for US intelligence because of their association with MIT. Probably complete BS, but maybe not. Are they as open source as they claim to be? Looks like they're on github. F-Droid seems to think they have some Google libraries or whatever that they use.

ProtonMail users, how do you like/dislike it?

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 12 points 7 months ago* (last edited 7 months ago) (1 children)

General rule of thumb:

  1. Web: can change at any moment, can serve a highly secure mail web app... except to those it might decide to target, giving them zero notice, leaving close to zero trace.
  2. Electron based "app": if it can run random JS from the web, see first point.
  3. Compiled app: to change its way of working, the user needs to update/download a different version. An explicit user action is required, people can notice malicious changes and warn others about them.
  4. Compiled open source app: same as a compiled app, except people can also notice malicious changes before running the code, fork it to remove them, compile it themselves, and warn others.

ProtoMail, touts itself as a "secure web app", which is a contradiction.

If you use an open source app to access ProtonMail's service, the security lies in whatever app you use. At that point, might as well send E2E encrypted mail via GMail.

TL;DR: the way most people use it, is just security theatre.

[–] [email protected] 7 points 7 months ago (1 children)

At that point, might as well send E2E encrypted mail via GMail.

From a security stand-point: Yes. From a privacy standpoint: Absolutely not.

[–] [email protected] 2 points 7 months ago* (last edited 7 months ago) (1 children)

Both privacy and security are the same in either case:

  • Both servers know who's connecting
  • Both servers see the connecting IP
  • Both servers know the source and target mail addresses
  • Neither server knows the message's content
  • Neither server controls the client's app

The moment you go off-VPN, or use a webapp, security goes out the window.

Privacy, as in social network/contacts, goes out the window the moment you use a fixed email address; more so if it's associated to your IRL identity.

[–] [email protected] 3 points 7 months ago (1 children)

There's a large difference between surrendering massive amounts of highly critical metadata aswell as some data* to a known abuser vs. an entity that prides itself in not abusing your data and which even takes specific technological measures to make it as hard for them as possible (zero access encryption at rest, automatic key discovery).

(* Partial social graph, interaction timestamps, political interests, health, hobby interests and much of that usually even in plain text data form when receiving email; stored in in plain text forever.)

[–] [email protected] 1 points 7 months ago* (last edited 7 months ago) (1 children)

known abuser vs. an entity that prides itself in not abusing your data

Right, "don't be evil" 🙄. Corporations are corporations.

zero access encryption at rest, automatic key discovery

Also called "encryption". Just so we're on the same page:

  • 1991: initial release of PGP
  • 2016: initial proposal and implementation of WKD

Enigmail for Thunderbird supports both since 2018. The mail service, be it ProtonMail, GMail, Outlook, etc., is irrelevant regarding security or privacy.

[–] [email protected] 2 points 7 months ago (1 children)

FYI Thunderbird now natively supports PGP (and possibly WKD?) without the need for Enigmail.