Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bartbutler
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
bartbutler
8mo ago
That's not a bad idea, I'll see what people think. Note that clicking on the unsubscribe link will unsubscribe you to whatever comms preference was specified in the sending and tell you what it was.
2.
▲
by
bartbutler
8mo ago
Hey, Proton CTO here. There was a bug, and we fucked up. Support should have reported it up the chain and acknowledged this. Things happen, especially at scale, but we take comms consent seriously and will fix it.
3.
▲
by
bartbutler
2y ago
We (Proton) have had our own CAPTCHA for a year or more now.
4.
▲
by
bartbutler
2y ago
We aren't physically located in the US.
5.
▲
by
bartbutler
2y ago
We do support automatic forwarding, have since last fall.
6.
▲
by
bartbutler
2y ago
The author mentioned WKD but was mistaken. The culprit was keys.openpgp.org, not WKD.
7.
▲
by
bartbutler
2y ago
Proton does this.
8.
▲
by
bartbutler
3y ago
There aren't any links between Proton and Crypto AG, none at all.
9.
▲
by
bartbutler
4y ago
This is Bart, Proton CTO here. For clarity, the issue mentioned here only impacts Proton Mail Bridge, our desktop IMAP/SMTP gateway to Proton Mail encrypted email. The fact that Bridge and its client can become desynchronized sporadica
10.
▲
by
bartbutler
4y ago
As of a month or two ago, it does not redirect to the cleartext site and stays on .onion.
11.
▲
by
bartbutler
5y ago
UI refresh, SSO/persistent sessions, and because this crowd might care, the whole app was rewritten from scratch to transition from Angular v1 to React, which simply had to be done and retired an enormous amount of technical debt.
12.
▲
by
bartbutler
7y ago
We are aware of the the issues brought up in [0] and [1]. As suggested in [2], we are already considering to switch to an implementation in WebAssembly to mitigate the possibility of timing attacks on the web platform. In our mobile and des
13.
▲
by
bartbutler
8y ago
Hi there, I'll ask someone to reach out. In the future, please file a support ticket at: protonmail.com/support-form
14.
▲
by
bartbutler
8y ago
It's not a small use case for corporate users where the internal mail is all encrypted. We also have full PGP support and the bridge is fully integrated with this, so we hope the garden aspect will decrease with time, though we expect
15.
▲
by
bartbutler
8y ago
We (ProtonMail) don't provide a server-side IMAP/SMTP interface because we don't want to see your cleartext mail. And if you are doing the encryption and key management yourself locally, then you can literally use any email p
16.
▲
by
bartbutler
8y ago
We sent out an update about security features.
17.
▲
by
bartbutler
8y ago
It is something we'd like to do, but it's still a little experimental and it hasn't gotten to the top of our priority list yet.
18.
▲
by
bartbutler
8y ago
1. ProtonMail implements the OpenPGP standard and is fully interoperable with other OpenPGP email systems. 2. The web app is a single page application so it does not reload on every request. That said, you are correct that the web app is no
19.
▲
by
bartbutler
8y ago
I also think exploiting it would be extremely difficult. IIRC, it was NIST ECC curves which are hard to make constant time and do not have WebCrypto primitives. We are still going to see what we can do to address this.
20.
▲
by
bartbutler
8y ago
You are confusing crypto primitives with a high-level spec like OpenPGP. OpenPGPjs used WebCrypto and node crypto libraries when available for primitives. You still need a library for the OpenPGP stuff.
21.
▲
by
bartbutler
8y ago
You are confusing crypto primitives with a high-level spec like OpenPGP. OpenPGPjs used WebCrypto and node crypto libraries when available for primitives. You still need a library for the OpenPGP stuff.
22.
▲
by
bartbutler
8y ago
Import/export tool is in beta now and will be available for all users on launch. Export is available now via the web interface but it's a little clunky. The reason this stuff is complex and taking a while is not nefarious, it'
23.
▲
by
bartbutler
8y ago
These are good points, though at this point I think it does make sense to wait a bit to clean up the deprecated stuff, given that a lot was waiting on this release and we'll probably drop the old stuff in a month or so. Re: API access
24.
▲
by
bartbutler
8y ago
1. Mobile apps are native, not web views 2. That's not what the TLS key was subpoenaed for--it was a very different system with a set of vulnerabilities we don't have, including a server-side encrypt mode and non-PFS TLS ciphers.
25.
▲
by
bartbutler
8y ago
> You're expecting us to believe nobody on your team would take a payout from or be coerced by US LEO's or spooks. That's crazy. No, we're saying that we don't store the data partly so that such a scenario isn&#
26.
▲
by
bartbutler
8y ago
The API docs are available on request mostly because we are phasing out some old APIs we don't want people to use and don't have bandwidth to provide support for them. The bridge and the import/export tool are not yet open so
27.
▲
by
bartbutler
8y ago
Because running PGP software and handling key management locally is way easier than double-clicking on an installer? I don't concede that for a second. Remember that the alternative you want is ciphertext directly via IMAP, which is no
28.
▲
by
bartbutler
8y ago
I'm not exactly sure where that is in the copy but it is referring to emails between ProtonMail users, not unencrypted mails from outside. It should probably be clarified, but it's tough to tell without context.
29.
▲
by
bartbutler
8y ago
We actually have this and have provided it on request. Also, we plan to open-source the bridge, which should alleviate your other concerns.
30.
▲
by
bartbutler
8y ago
A bit of both, though the API restriction will be relaxed soon. We'd much prefer to open-source the bridge and have the community contribute there though. Hopefully we can get there soon.
More ›