TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Security experts declare all Proton apps secure after security audit

121 点作者 chmars大约 3 年前

10 条评论

sodality2大约 3 年前
Declaring it secure after an audit is like writing 100% coverage tests and saying it&#x27;s bug-free. You can&#x27;t prove absence, only presence.<p>This title is the definition of sensationalism and only by reading the article do you find the truth: &quot;Their tests uncovered no major issues or security vulnerabilities&quot;. This is a bad look for them and I&#x27;m wary of their company now...
评论 #31069523 未加载
评论 #31072190 未加载
评论 #31098666 未加载
justinpowers大约 3 年前
So many complaints about the headline, but for the purpose of getting their point across to the masses and encouraging the use of as-secure-as-can-be-known software, it’s perfectly fine.<p>If you cover your ass in a headline, which ultimately ends as legalese, the average person will completely ignore it due to wordiness or they will become suspicious and assume the worst.<p>The body and attachments do not mislead at all and that should be commended.<p>All this pedantry is counterproductive unless you truly know and trust your audience. Proton should be for the masses, not just for the technically adept.
ctime大约 3 年前
I have a hard time adding protonmail to my &quot;generally regarded as safe&quot; mail provider list when they haven&#x27;t been able to implement Webauthn security key support (aka U2F security keys &#x2F; FIDO security keys).<p>Yes, they support Multi-Factor authentication, but only via phishable methods (TOTP)[1]. They have been &quot;trying&quot; for years[2] to implement U2F but for some reason haven&#x27;t been able to figure it out yet &#x2F;shrug<p>[1] <a href="https:&#x2F;&#x2F;protonmail.com&#x2F;support&#x2F;knowledge-base&#x2F;two-factor-authentication&#x2F;" rel="nofollow">https:&#x2F;&#x2F;protonmail.com&#x2F;support&#x2F;knowledge-base&#x2F;two-factor-aut...</a><p>[2] <a href="https:&#x2F;&#x2F;twitter.com&#x2F;protonmail&#x2F;status&#x2F;1300758061255217153?lang=en" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;protonmail&#x2F;status&#x2F;1300758061255217153?la...</a>
orlp大约 3 年前
Technical nitpick purely on the wording of the title: the pentesters declared that &quot;no important security issues were found during the pentest&quot;. Unfortunately in our current world that&#x27;s about as good as you&#x27;re going to get for a large software system, but that does not necessarily mean that Proton is secure. There could still be undiscovered vulnerabilities.
评论 #31069613 未加载
coffeeandbooks大约 3 年前
ProtonMail has a bad history of irresponsible sensationalism. It’s like constantly marketing yourself as the most private e-mail service “built by CERN scientists” but who will give information about you to authorities:<p><a href="https:&#x2F;&#x2F;www.engadget.com&#x2F;protonmail-climate-activist-ip-swiss-french-authorities-233004304.html?guccounter=1" rel="nofollow">https:&#x2F;&#x2F;www.engadget.com&#x2F;protonmail-climate-activist-ip-swis...</a><p>I know that ProtonMail doesn’t claim to protect your IP address, but I don’t expect the average user to make that distinction.<p>This is another dumb article. Getting your service tested for vulnerabilities is good hygiene but it shouldn’t be used as marketing material to make users think your service is Fort Knox.
评论 #31069492 未加载
评论 #31070853 未加载
评论 #31069737 未加载
etiam大约 3 年前
For a moment there I thought the title referred to the Valve-associated Wine enhancements... Now <i>that</i> would have been a feat.
Foobar8568大约 3 年前
So a company called Securitum did a security assessment limited to pentest according to the pdf.<p>More over &quot;Tests have been carried out in September 2021 in accordance with generally accepted methodologies, including OWASP Top 10 and SANS Top Issues&quot;.<p>It&#x27;s hard to believe that one can call apps being secured after pen testing especially when the two highlights are such low hang fruits that are OWASP top 10 and SANS top issues..<p>It doesn&#x27;t really give any confidences into Proton, but then again, I am not an expert, and have seen such useless reports at different clients.
webmobdev大约 3 年前
I always think twice when a company offers me an &quot;app&quot; for an application that is already available as a web app or that is already inbuilt in the system or doesn&#x27;t use existing standards. Like, I perfectly understand the need for a Proton Mail client as some would like offline access to their mail and a backup of their mail in their system. But I resent the need of a custom and locked-in app, instead of the service being available over existing POP3 &#x2F; IMAP protocol. (Yes, I understand how email encryption creates hurdles of using it over POP3 &#x2F; IMAP, usage, but it would be a lot easier to trust a company if they actually built an extension over existing protocol or create a new standard that makes it easy to access their service. E.g. <a href="https:&#x2F;&#x2F;fastmail.blog&#x2F;open-technologies&#x2F;jmap-new-email-open-standard&#x2F;" rel="nofollow">https:&#x2F;&#x2F;fastmail.blog&#x2F;open-technologies&#x2F;jmap-new-email-open-...</a> ). ProtonVPN app also seems a bit redundant when most OSes already have built in support for VPN. Though I understand that it does make configuring, changing &#x2F; choosing VPN servers a lot simpler, and probably helps ProtonVPN in load balancing, it provides more avenues for data collection and data leak.
karmakaze大约 3 年前
I was totally confused by the title thinking what does that mean or how can they say such a thing without proving a secure sandbox environment, which I didn&#x27;t even know was possible. Then I realized it&#x27;s for ProtonMail etc, not Proton from Valve.
vr46大约 3 年前
Unfortunately users declare Protonmail barely usable in terms of features and UX. After a decade of this, I’m shifting back to IMAP. My use case is better off with GPG than with Protonmail. I can’t usefully function without integration into the rest of my Mac or iOS. A secure walled garden with Apps that get worse over time? I’ll go with Apple’s version.
评论 #31069406 未加载
评论 #31078267 未加载
评论 #31069386 未加载