this post was submitted on 29 Nov 2023
57 points (90.1% liked)
Technology
59174 readers
974 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related content.
- Be excellent to each another!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, to ask if your bot can be added please contact us.
- Check for duplicates before posting, duplicates may be removed
Approved Bots
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
What's the issue with proton? Just the UI being a bit shit?
The UI has improved a lot since their re-brand, so I doubt that's it.
Proton only uses E2EE for the message body (including attachments). The subject and headers are not end-to-end encrypted.
That's not entirely unreasonable, since they use that data for the search function on the server side. Nobody's really cracked the nut of E2EE search, though there's been some interesting research in the field recently.
they make a lot of promises about security, but email can truthfully only reach a certain level of security. the comment from @RTRedreovic@feddit.ch shows weaknesses in relying in protonmail to protect various aspects of your communications, but they sell themselves as TOTALLY SECURE.
the lady doth protest too much.
so they're no more secure than, say, google, when you implement your own e2ee on top of email with PGP or something. but the promises of enhanced security actually set people up to expect more than that. coupled with the fact that they don't even let you use imap or pop, it's not exactly a hacker's dream service.
Proton should be avoided.
https://www.theregister.com/2021/09/07/protonmail_hands_user_ip_address_police/
https://arstechnica.com/information-technology/2021/09/privacy-focused-protonmail-provided-a-users-ip-address-to-authorities/
https://cyberwarzone.com/protonmail-complies-with-a-record-6000-government-requests-for-user-data-in-2022/
https://encryp.ch/blog/disturbing-facts-about-protonmail/
I do agree that's a fair point about mail.