VehiclesFashionRecipesBlogsHuntTravelsSportFunHandmadeITEducation
Mini-Games
x

x
zakruti.com » IT - Software » IT, programs, coding
Is ProtonMail lying about their encryption? In response to Nadim Kobeissi and LiveOverflow - The Hated One

Is ProtonMail lying about their encryption? In response to Nadim Kobeissi and LiveOverflow - The Hated One

FBTwitterReddit

video description

Rating: 4.0; Vote: 1
Is ProtonMail lying about their encryption? In response to Nadim Kobeissi and LiveOverflow - The Hated One As the most popular encrypted email provider, ProtonMail has been criticized for false security promises and weak guarantees of its end-to-end encryption infrastructure. Can be ProtonMail's marketing of their Swiss-based email service justified? The results might SHOCK you! These are encrypted email providers that I would recommend Free and paid plans Only paid An Analysis of the ProtonMail Cryptographic Architecture by Nadim Kobeissi Liveoverflow End-to-End Encryption in the Browser Impossible? - ProtonMail The Reddit debate and Protonmail's response ProtonMail Threat Model Why is ProtonMail more secure than Gmail The problem with ProtonMail-s webmail service is that each time you go to sign in to their website, you have to completely trust ProtonMail that the javascript that your browser runs is correctly implementing PGP and is not trying to steal your private keys and read your messages. This problem is limited with smartphone apps, because each new version of an app has to be signed by the author and the platform - which in this case is ProtonMail and Google Play Store or Apple App Store. With these apps, users can verify whether they received the same binary for a particular version as everyone else. Because of the differences in the levels of trust, webmail services are objectively less secure than desktop and smartphone apps. That is if you expect ProtonMail to try to execute a malicious javascript that would let them read your emails without being detected. The fact that webmail is less secure than native apps is not new and ProtonMail has been saying that from day one. In their threat model article, ProtonMail explains this issue and even openly says that ProtonMail is for average people who want to protect themselves against mass surveillance, but it-s not for a next Edward Snowden. ProtonMail successfully accomplishes this mission because their servers can-t be tapped by the NSA to read plain-text emails as is the case with Gmail, Yahoo, Apple, or Microsoft. Where ProtonMail and Nadim differ, is that Nadim thinks that end-to-end encryption is not possible in webmail and ProtonMail should not be calling it that
Date: 2022-03-20

Comments and reviews: 10


I was using MailPapa, but it took forever to send an email, I suspected that mailpapa is allowing a third party to read my emails especially the politically charged ones, I switched to protonmail, it is still taking time but much less, I started to suspect Thunderbird is compromised and a copy of my email before the encryption is heading to a third party which defeat the purpose of having encrypted emails.
reply

Stop spreading disinformation. Anyone who has a clue about PGP knows that ProtonMail cannot guarantee security through the web browser. It is there for convenience.
Normal users sign on to ProtonMail because they do not scan your email like Outlook and GoogleMail. They have no clue about how to use PGP.
I guess it-s more important to shill for Google and Microsoft. :shrug:

reply

I know this is an old video but it would have been nice to see how doing it over the cell phone is better then the website. I know another person talked about this and said that the emails still go over SMTP which is not secure so if sending to others not on proton mail the messages would be in plain text and could be read by anyone.
reply

Makes Sense, but Rob Braxman, who invented his own Mailservice and did this for years, claimed that its only secure for Proton to Proton user, but not Intermail (like Proton to Tutanota. Also only the Message Body probably is encrypted. THe header is seeable. Also it may be a project of the cia. Thats at least his words.
reply

I use Protonmail and their VPN now for maybe 4 years. To be really secure I like the TOR network and I am just starting to play around with the darkweb. Nothing more secure than TOR over VPN. I am not a criminal but I like my privacy just BECAUSE it is a HUMAN RIGHT!
reply

My husband checks the settings tab security and check the IP address keys should not use Rsa 2048 but edcsa or RSS 4096 set connection on your linux box 802. 1 frame security do not use smart phones my husband has a pkcs12 browser 16384 bits certificate built
reply

I find it low that you didn't address the french government breaking into the messages, that was quite foundamental.
and this video is biased. you didn't present all the facts.
also multiflow brought a lot of good points as well.

reply

Dude is right. proton mail is amazing though not totally able to be encrypted for security sake when accessing via web, as web is defacto NSA property. only quantum based, passive analysis can use the data, whether encrypted or not.
reply

No email is secure, its impossible. All email protocols were created before security was an issue.
Proton and others can encrypt their files on server but it was NEVER END TO END ENCRYPTION. EVER.

reply

Omfg, lmao, I would put that Nadeem loser in my pocket at any given time, even when I'm drunk. Even colleagues in the 1st Level Support department are laughing at that loser.
reply
Add a review, comment






Other channel videos