TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

ProtonMail now offers elliptic curve cryptography

201 pointsby _eigenfooabout 6 years ago

16 comments

KirinDaveabout 6 years ago
This announcement is an example of why I am not using ProtonMail anymore. There are a lot of things they do that sound very good on marketing materials, but upon examination are security theater.<p>For example, they claim, &quot;We have chosen a particular elliptic curve system known as X25519, which is fast, secure, and particularly resistant to timing attacks. It’s simple to implement&quot;.<p>However, previously they&#x27;ve said that they use Indutny&#x27;s library [0]. This library is somewhat infamous because its leadership deciding to discard any pretense of defending against timing attacks on the grounds that would make the library &quot;too slow.&quot; [1]<p>There are other options. They could have used something with good timing attack resistance from WebCrypto. Those options exist. Folks with more skill than I have recommended P-256 as an option.<p>[0]: <a href="https:&#x2F;&#x2F;protonmail.com&#x2F;blog&#x2F;openpgpjs-3-release&#x2F;" rel="nofollow">https:&#x2F;&#x2F;protonmail.com&#x2F;blog&#x2F;openpgpjs-3-release&#x2F;</a><p>[1]: <a href="https:&#x2F;&#x2F;github.com&#x2F;indutny&#x2F;elliptic&#x2F;issues&#x2F;128#issuecomment-302593662" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;indutny&#x2F;elliptic&#x2F;issues&#x2F;128#issuecomment-...</a>
评论 #19751322 未加载
评论 #19749019 未加载
评论 #19749847 未加载
评论 #19749153 未加载
评论 #19748464 未加载
评论 #19749460 未加载
lvhabout 6 years ago
X25519 is great, but it doesn’t make Protonmail (really, OpenPGPjs) a net safe communications mechanism.<p>It inherits all of the flaws inherent in OpenPGP, including optional authenticators (which lead to EFAIL), kitchen sink bulk protocols complete with negotiation (did you know your public keys specify what algorithms you like?), lack of forward secrecy, repudiability, et cetera.<p>We should stop using RSA. But RSA isn’t what was keeping OpenPGP from being a great secure communications channel. That’s aside from the question if it’s meaningful to say you control your keys if you use OpenPGPjs served up every time by a third party. (I say that being extremely on the PGP apologia side of the scale compared to some of my peers!)
评论 #19748278 未加载
brendynabout 6 years ago
I was silly enough to sign up without looking in to it because it was recommended on HN. Then I realised they need this bridge software to connect. I asked about it stating I&#x27;d like to build it my self and confirm it is libre software. They just sent back a generic link to a .deb beta file. I had a look and its got this eula.txt with the standard you-have-no-rights. Messaged them again asking what they intended to do license-wise and they ignored me. Someone else has written their own bridge and put it on github but it&#x27;s a bit of a joke to have to do that. Not sure what to move to now, mailbox.org was another I saw recommended.<p>My email history: - gmail.com &gt; US spying, escape. - lavabit.com &gt; Shutdown due to US government legal attack. - Ran my own server &gt; Too much bother, gave up. - openmailbox.org &gt; Died for months, ran away with my money. - protonmail.com &gt; Sketchy, cancelling it now. - Free mailbox.org with custom domain.
评论 #19752038 未加载
评论 #19754882 未加载
评论 #19749091 未加载
评论 #19749117 未加载
评论 #19748815 未加载
ahelwerabout 6 years ago
Love ProtonMail. Over the past few years I&#x27;ve slowly switched more and more of my usage onto it as my confidence in the service grows. Gmail now occupies a similar niche as Facebook in my life, where I keep a vestigial &amp; largely empty account for those few organizations which still insist on proprietary apps (Google groups&#x2F;docs, Facebook groups&#x2F;chats) for organization.
Abishek_Muthianabout 6 years ago
Off topic<p>I had a proton email created when it was announced &amp; didn&#x27;t use it. I found out that my mailbox decryption for that email id is not working (not sure how, I use password manager) &amp; I haven&#x27;t set a recovery email to recover my account.<p>I saw a HN comment earlier telling, the user had recovered their Proton mail account by answering few questions to customer service.<p>I attempted the same, the issue is that I used VPN to create the email id &amp; didn&#x27;t provide any personal details for the account.<p>They asked questions like,<p>-Do you remember the exact time and date when your account was created? -When was the last time you have accessed your account? -What is your display name? -Do you remember to which addresses you have sent your last messages? -Do you remember the email subjects of the last sent messages?<p>I tried to answer the account creation date by using the date of password creation in my password manager (the login password was working); but the support didn&#x27;t seem to buy it.<p>They were insistent on,<p>-Can you please tell us if you remember from which addresses have you received your last few messages? -Could you tell us if you have used the ProtonMail account to sign up for some other web services?<p>I told them, I don&#x27;t remember receiving email from anyone else &amp; I didn&#x27;t sign up for any service<p>-There is a service that the xxxxx@protonmail.com address has been used to sign up for. Can you please tell us what that service is?<p>I told them again that I didn&#x27;t sign up for any service using that email id.<p>- Can you tell us the full address below?<p>no-xxxxx@drxxxxx.com<p>Even though I could obviously guess the username of that email id. I told them that I didn&#x27;t sign up with such service, that it must be a spam mail sent by some service.<p>They said,<p>- If you have not signed up for this service, the account probably belongs to someone else.<p>Then I typed &#x27;no-xxxxx@drxxxxx.com&#x27; on Google Search, the instant results gave &#x27;no-reply@dropbox.com&#x27; as the first result.<p>I sent them,<p>Hey sorry, I remembered the service. I did signed up for Dropbox &amp; used the account for a while.<p>The email id you asked was,<p>no-reply@dropbox.com<p>They reset the account &amp; I got access to it.<p>Edit: Had to fix the xxxxx.
评论 #19749084 未加载
评论 #19748049 未加载
评论 #19748051 未加载
评论 #19749418 未加载
评论 #19748829 未加载
wil421about 6 years ago
Anyone using ProtonMail regularly? I created an account but haven’t used it much.<p>How are your experiences? Any iOS users who can comment on their experience with proton mail and the default mail client?<p>I don’t went to switch to something that won’t be around in a decade or so.
评论 #19748409 未加载
评论 #19748805 未加载
评论 #19747731 未加载
评论 #19747820 未加载
评论 #19748059 未加载
评论 #19748208 未加载
评论 #19748169 未加载
评论 #19748134 未加载
评论 #19747772 未加载
评论 #19747928 未加载
评论 #19755421 未加载
评论 #19747757 未加载
评论 #19749414 未加载
评论 #19749835 未加载
评论 #19748144 未加载
评论 #19747760 未加载
评论 #19748601 未加载
评论 #19749844 未加载
评论 #19747727 未加载
评论 #19747912 未加载
评论 #19747839 未加载
__ralston3about 6 years ago
As a PM customer of almost a year, I&#x27;d definitely say they should focus more efforts on the UI&#x2F;UX as opposed to advancing the crypto for now. What&#x27;s the point of having the world&#x27;s most cryptologically advanced, unusable inbox. Specifically conversation threading&#x2F;nesting. I don&#x27;t expect everyone to be as streamlined as say a Gmail, but basic &quot;1 conversation - 1 email&quot; in the inbox would be nice for starters.
评论 #19748240 未加载
评论 #19748269 未加载
throwaway_x13zdabout 6 years ago
While I appreciate advances in cryptography, I would rather protonmail work on things like getting their bridge returning properly formatted IMAP responses[1] so we can use whatever clients we want with it.<p>The mobile experience is fine, but desktop is brutal unless you happen to prefer one of the few clients they support.<p>[1] <a href="https:&#x2F;&#x2F;github.com&#x2F;Foundry376&#x2F;Mailspring&#x2F;issues&#x2F;429" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;Foundry376&#x2F;Mailspring&#x2F;issues&#x2F;429</a>
motohagiographyabout 6 years ago
I like protonmail and will likely move my domains to it. I don&#x27;t use it for regular social, dating, or sales emails because it is a privacy brand that creates cognitive friction with people who don&#x27;t get privacy and security.<p>If I wanted to grow protonmail, I would emphasize users moving domains to it because while the brand has exceptional trustworthiness, anything security and privacy themed runs into the &quot;tacti-cool,&quot; problem, where even if it&#x27;s the best available and used by real operators, it triggers peoples sense of illegitimacy, and depends with users who identify with a &quot;rebel,&quot; e.g. &quot;losing&quot; team who are not attractive to other users.<p>IMO, the same problem killed Silent Circle, and the rest of the cryptophone market.<p>When you look at who overcame the tacti-cool problem in security and privacy, the way a brand like arcteryx did it in clothing, Apple&#x27;s iPhone has done it in hardware, WhatsApp did it for messengers, and protonmail is <i>just</i> on the cusp of it.<p>There is an opportunity to build a new privacy brand that would be as big as a FAANG, and if I were running it, I&#x27;d fold protonmail into it.
elliotecabout 6 years ago
To answer everyone here, I&#x27;ve been using ProtonMail for 6 months now (and protonvpn) and I love it. The iOS app is great, the web view could be improved but isn&#x27;t bad.
doomroboabout 6 years ago
Slightly OT, but I didn&#x27;t see an important question being asked:<p>What is the motivating threat model of ProtonMail?<p>If I just want to access my email securely, that&#x27;s done by HTTPS. If I want an end-to-end encrypted solution, ProtonMail can provide that, though only for emails between ProtonMail users. For e2e outside of ProtonMail, I can use PGP.<p>From what I understand, ProtonMail makes all the PGP stuff easier by baking it into their UI. Is there anything else it offers other than this convenience? Are they encrypting incoming mail with recipient keys and throwing away the original? If so, who is that protecting, and against whom? Presumably the plaintext was stored by the sender and possibly seen by intermediary servers. Can I get similar security properties by periodically downloading my email and deleting it off the server (assuming the deletion is actually happening)?<p>These are honest questions. I admit I&#x27;m skeptical of PM&#x27;s utility, but I&#x27;d this fits someone&#x27;s usecase and threat model, I can&#x27;t argue with that.
评论 #19750174 未加载
评论 #19751422 未加载
jgowdyabout 6 years ago
I quit ProtonMail &#x2F; ProtonVPN after trying over and over and over again to import mail through their IMAP bridge. They won&#x27;t provide an open API for interacting with their mail services so someone can write a better bridge, and their bridge is very slow, disconnects repeatedly, and basically makes any migrations impossible. If you&#x27;re willing to start over with an empty mailbox, maybe ProtonMail is for you. I eventually gave up trying to move my mail account in (many tries, with Thunderbird in chunks, with Lamiral&#x27;s awesome imapsync tool, you name it), and let them keep the money I paid for a year of ProtonMail Visionary.<p>I ended up using StartMail from the StartPage people. It&#x27;s not perfect, but I was actually able to migrate to it and use it effectively.
philshemabout 6 years ago
Unsolicited opinion on ProtonMail: I&#x27;m a big fan. It&#x27;s not as flashy as gmail, but so far my mails haven&#x27;t been marked as spam, which was happening with zoho. Unfortunately, zoho doesn&#x27;t provide free email forwarding, so the migration to PM is taking longer than hoped for.<p>I&#x27;ll probably soon subscribe to PM for two reasons: to use the @pm.me domain for outgoing (currently only incoming), and for custom domain support. Also subscribing gets IMAP support (I think).
评论 #19755472 未加载
keiferskiabout 6 years ago
This gets asked often, but as someone wanting to get away from Gmail, any thoughts on Fastmail vs. ProtonMail?
评论 #19747761 未加载
评论 #19747901 未加载
评论 #19747817 未加载
评论 #19747802 未加载
评论 #19747832 未加载
评论 #19747746 未加载
评论 #19751290 未加载
usr1987about 6 years ago
I tried proton with my own domain... its a hasle, and how about address book sync and calendar?
dlphn___xyzabout 6 years ago
does it matter if its traffic is routed through counties with a history of breaching privacy?