I keep hearing bad stuff about proton, but I don’t really get most of it. Could someone please explain all of the controversy to me. Lastly, what are the best alternatives to all of their services?

  • M1k3y@discuss.tchncs.de
    link
    fedilink
    arrow-up
    9
    arrow-down
    1
    ·
    19 hours ago

    Its crypto from the 90s and email is not meant to be secure. Some examples:

    Only the mail body is protected, headers and metadata arent, so an attacker still knows with who you are talking about what.

    Replies contain the full thread, if one person messes up once, the entire chain is unencrypted.

    No ephemeral keys, no cleanly defined rotation mechanism. If someone gets your key, all past messages are also accessible.

    • jabberwock@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      5
      ·
      17 hours ago

      It depends on your threat model. The actual crypto portion of it holds up, at least until we have crypto-relevant quantum computers.

      If you want anonymization and PFS for basic messaging, yeah PGP + email isn’t going to cut it. But if you’re sending documents, for example, with financial or health data tied to my identity anyway, I’d take PGP with my own email provider over TLS to some tech company servers where it sits unencrypted any day.

    • manuallybreathing@lemmy.ml
      link
      fedilink
      arrow-up
      3
      arrow-down
      1
      ·
      18 hours ago

      so an attacker still knows with who you are talking about what.

      >implying i fill out the subject box with anything meaningful 🤪

    • bleustenns@lemmy.ml
      link
      fedilink
      arrow-up
      1
      ·
      19 hours ago

      TY for informing me. Is there a better alternative to PGP even with the other downsides of email you listed?