While I love ProtonMail as an effort to popularize security for end-users and trying to come up with smart technologies to achieve that, the whole risk model behind the writeup barely stands scrutiny. What's worrying, ProtonMail (who declare security a first-class feature) use "features" instead of systems to define security of their service.
If you think of it for a second, web crypto (protection against intermediaries and dishonest server) actually requires trusting the server, so no encryption-derived claims are sound if the server is dishonest. Any third party exploiting (or forcing legally) the server can make it dishonest and collect required keys in few simple steps. And, FWIW, if encryption is controlled by browser, adversary compromising the client itself can simply disable it.
So, while the effort is very important (and I bet they'd be around the first people who will suggest techniques for safe in-browser crypto execution), it isn't that they can be compared security-wise other than:
- ethics
- security policy
- competence of security teams.
Isn't a level playing field for ProtonMail.
And, my final problem is, 99% of people are still outside Protonmail anyway, hence the intolerant winner argument, which ruined PGP and will ruin many optional security systems on top of convenience protocols in the foreseeable future.
We actually agree with some of the points made above, but we'd like to add the following commentary...
Encrypting email while making it more usable than PGP is hard. There's no getting around that. Web crypto is always going to have some shortcomings, but web mail is on the rise, and at the end of the day, web crypto is better than no crypto.
That said, we have been working for some years towards moving ProtonMail encryption entirely to the local environment using our Bridge application, which will be released soon. There is also extensive R&D being done on end-to-end authentication and ensuring key validity.
You are correct in that it is not a level playing field. This is why the tech industry is fast becoming an oligarchy or even a monopoly, owned and controlled by a few big players. However, we think that not playing is taking the easy way out, so even though the game is 'rigged' against us, we have a great team of engineers who have decided to play anyways.
I seriously disagree on this (our company is facing similar challenges, and I've asked these question myself numerous times). It's not better, it's much worse.
"Some crypto" creates illusion of security, where you don't really know has it failed or not - frequently, there is no functional failure in cryptographic failure. It doesn't stop working, it stops providing the very guarantees you're using it for.
> However, we think that not playing is taking the easy way out, so even though the game is 'rigged' against us, we have a great team of engineers who have decided to play anyways.
Truly so, but you need to play better then ;) Godspeed!
+1 while it's nice that you're email at rest is secure most of your personal email is getting sent to someone with a gmail account anyway - perhaps defeating the whole exercise
If you think of it for a second, web crypto (protection against intermediaries and dishonest server) actually requires trusting the server, so no encryption-derived claims are sound if the server is dishonest. Any third party exploiting (or forcing legally) the server can make it dishonest and collect required keys in few simple steps. And, FWIW, if encryption is controlled by browser, adversary compromising the client itself can simply disable it.
So, while the effort is very important (and I bet they'd be around the first people who will suggest techniques for safe in-browser crypto execution), it isn't that they can be compared security-wise other than: - ethics - security policy - competence of security teams.
Isn't a level playing field for ProtonMail.
And, my final problem is, 99% of people are still outside Protonmail anyway, hence the intolerant winner argument, which ruined PGP and will ruin many optional security systems on top of convenience protocols in the foreseeable future.