TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

ProtonMail: End-to-end encrypted email

52 pointsby icotalmost 11 years ago
A secure mail startup founded by CERN and MIT scientists in 2013.

17 comments

thecoffmanalmost 11 years ago
&gt; <a href="https://protonmail.ch/blog/protonmail-threat-model/" rel="nofollow">https:&#x2F;&#x2F;protonmail.ch&#x2F;blog&#x2F;protonmail-threat-model&#x2F;</a><p>I&#x27;m always skeptical of browser&#x2F;JS based crypto, but it is nice to see that they&#x27;re at least upfront with the risks involved in doing such a thing.<p>They probably downplay the risk of a MITM attack a little much, but otherwise I&#x27;m glad to see they&#x27;re realistic about possible weaknesses of the platform.
评论 #7846082 未加载
评论 #7846618 未加载
jfaucettalmost 11 years ago
This sounds really good. The only disappointment is that it seems there is no business model that allows email providers and services like this to provide Unlimited encrypted email (no limitations i.e. Gmail-esque) absolutely free to all users. I&#x27;d be willing to gamble that if anyone could sustain this for a couple years, people would leave Gmail in droves, no one I know likes having to use the USA&#x2F;NSA&#x2F;google&#x2F;big brother tagteam, but they still don&#x27;t value the invasion of privacy enough to pay for it.
评论 #7846171 未加载
评论 #7852742 未加载
Xylakantalmost 11 years ago
From reading the service description, this is an encrypted messaging service that happens to have email notifications.<p>I can&#x27;t write messages with my preferred mail client, can&#x27;t read messages with my preferred mail client and I can&#x27;t access my (old) messages while offline. non-protonmail-users will receive a notification with a link that they received a message, not the actual message that they can keep for archiving purposes, offline use etc. I wonder if and how they handle searching mailboxes.<p>Neat, but not mail.<p>edit: typo. darn.
评论 #7846250 未加载
sudonimalmost 11 years ago
And none of the employees are US citizens that can be compelled by the US government in a way that they&#x27;re not allowed to talk about it (even to other employees) to compromise the security of the service?<p>I&#x27;m not sure that having a Swiss company makes any difference in a case where people have ties to the US. Does anyone else know better than me on this topic?<p>edit: It looks like the goal is that you don&#x27;t even have to trust protonmail: &quot;For this reason, we are also unable to do password recovery. If you forget your decryption password, we cannot recover your data.&quot; <a href="https://protonmail.ch/pages/security_details.php" rel="nofollow">https:&#x2F;&#x2F;protonmail.ch&#x2F;pages&#x2F;security_details.php</a>
评论 #7846204 未加载
评论 #7846358 未加载
评论 #7846226 未加载
flym4nalmost 11 years ago
It appears they silently closed a critical vulnerability recently [0]<p>[0] <a href="https://twitter.com/StackSmashing/status/474214532114812928" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;StackSmashing&#x2F;status&#x2F;474214532114812928</a>
评论 #7850953 未加载
luxpiralmost 11 years ago
The security details page[1] makes for interesting reading. Hopefully the new norm is &#x27;E2E&#x27; encryption. It&#x27;s actually starting to feel inevitable, and the hopelessness that followed in the wake of the &#x27;Summer of Security&#x27; is perhaps evaporating bit by bit, through universal encryption, bit by bit.<p>-<p>[1] <a href="https://protonmail.ch/pages/security_details.php" rel="nofollow">https:&#x2F;&#x2F;protonmail.ch&#x2F;pages&#x2F;security_details.php</a>
评论 #7845963 未加载
评论 #7846197 未加载
danesparzaalmost 11 years ago
This made me chuckle...<p>From the threat model article here: <a href="https://protonmail.ch/blog/protonmail-threat-model/" rel="nofollow">https:&#x2F;&#x2F;protonmail.ch&#x2F;blog&#x2F;protonmail-threat-model&#x2F;</a><p>&quot;NOT RECOMMENDED:<p>Edward Snowden – If you are Edward Snowden, or the next Edward Snowden, we would not recommend that you use ProtonMail. And in case Mr. Snowden was foolish enough to try, we have already blocked the username snowden@protonmail.ch&quot;
pandemicsynalmost 11 years ago
Wonder what the cost is going to be when it goes live.<p>Running infrastructure in those DC&#x27;s can&#x27;t be cheap (compared to regular co-lo facilities). Thats on top of probably having to deploy more gear (or higher perf gear than a regular email provider) since the work load is probably CPU heavy.
Fede_Valmost 11 years ago
Looks interesting, but I think if you trust non-open source encryption, you are basically a knave. Even with really smart people behind it, unless it&#x27;s completely open, they could be compelled to put backdoors into it.
programminggeekalmost 11 years ago
So, if I send an ecrypted protonmail to someone else&#x27;s yahoo mail, what happens? Is it only encrypted in the protonmail ecosystem?<p>True end to end encryption would mean everything is transferred as an encypted thing, and only people with a key can open it. If any email you send out ultimately is unencrypted so that the other side can read it, we aren&#x27;t much closer than where we started are we?<p>If an email ends up in an unencrypted IMAP mailbox on a server somewhere, how is that more secure than what happens now?
评论 #7846125 未加载
mikegioiaalmost 11 years ago
What a great project with what looks like 3 really talented guys. My one gripe is the @protonmail.ch domain requirement.
spacefightalmost 11 years ago
I wonder how they will stand up against requests from the swiss government regarding lawful intercept access. Which, for larger providers is mandatory to participate in.
评论 #7846328 未加载
dangalmost 11 years ago
This is a dupe of <a href="https://news.ycombinator.com/item?id=7757420" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=7757420</a>.
BillFranklinalmost 11 years ago
Lavaboom.com has similar goals but is based in Germany. It&#x27;s also webmail. I&#x27;m one of the co-founders if you have any queries.
galapagoalmost 11 years ago
&gt; &quot;we plan to open-source key parts of our code as well later on.&quot;<p>Great!
评论 #7845945 未加载
评论 #7845974 未加载
dailenalmost 11 years ago
Anybody know when this is finally opening up for more sign ups??
trvzalmost 11 years ago
The site uses Google Analytics. Easy to deduce the service&#x27;s usefulness in a critical situation from there…
评论 #7845842 未加载
评论 #7845844 未加载