I keep hearing bad stuff about proton, but I don’t really get most of it. Could someone please explain all of the controversy to me. Lastly, what are the best alternatives to all of their services?

  • Ohh@lemmy.ml
    link
    fedilink
    arrow-up
    7
    ·
    7 hours ago

    Yes. There is controversy about the CEO. But mostly for me: is security theater. And in don’t trust them. Email will never work as a secure communication layer. Stop pretending it will. There a reasons which is tied to the protocol level, that make pgp non sufficient. There are also the pgp technology it self (no forward secrecy, no deniability, key management etc). Then there is the obvious fact about an email from proton to gmail, and 99% of other email providers, simply not being secure/encrypted. So you buy a privacy tool, which neglects to tell you: we actually don’t provide privacy at all - unless you treat proton emails as proton chat - strictly proton to proton… at which point youd be better of with e g signal.

    If you insist: mailfence.org allows you to upload and control you own pgp keys. That’s interoprational with proton. Simarly priced i think, also Schweiz, and a bit more honest and strict imap (no bridge). But honestly… stop treating email as secure.

      • M1k3y@discuss.tchncs.de
        link
        fedilink
        arrow-up
        6
        ·
        4 hours ago

        Its crypto from the 90s and email is not meant to be secure. Some examples:

        Only the mail body is protected, headers and metadata arent, so an attacker still knows with who you are talking about what.

        Replies contain the full thread, if one person messes up once, the entire chain is unencrypted.

        No ephemeral keys, no cleanly defined rotation mechanism. If someone gets your key, all past messages are also accessible.