Sign in to follow this  
Followers 0
Lovely_Leigh

ProtonMail---secure email

14 posts in this topic

At the risk of sounding like I am wearing a tinfoil hat I figured I would share this with the community since I am not sure how many people know about it. Many of us are worried about prying eyes from SOs or LE or maybe even a No-Such-Agency sort of agency. There is a new-ish web based client-side encrypted email service that is zero-knowledge and seems to be the most secure product out there. It was developed by the folks at CERN (the same amazing people who found the Higgs boson) and was designed to correct current security flaws in how common webmails function. Also the servers are located in Switzerland which is out of the reach of the US and EU. They did a crowdfunding of some sort for more servers so you have to go on a mailing list but it is well worth the wait. I waited around two months. Just wanted to share with the community. If you like the service, please share it with others!!! Here's a link:

https://protonmail.ch/invite

Enjoy!

0

Share this post


Link to post
Share on other sites

Lol, good luck with that. These folks have no clue about data laws in Europe and Switzerland. Push comes to shove, the Swiss government is going to be more than happy to hand over all relevant data.

Edited to add: Americans need to stop peddling this bullshit about Europeans being a "safe haven" from data collection and snooping by the US.

0

Share this post


Link to post
Share on other sites
Push comes to shove, the Swiss government is going to be more than happy to hand over all relevant data.

Sure, that's why this is just one more layer of privacy. We know that the government is already snooping on Yahoo, Hotmail, etc. With this European guys you would really need to give the US government a reason to request or enforce snooping on your account.

I don't think that suspicion of a guy/girl having fun for $250 once in a while worth the effort to do that :P

0

Share this post


Link to post
Share on other sites
nothing wrong with wearing tin foil these days, how else do you prevent RFID credit card info from being stolen from your wallet?

A Faraday cage would do the trick nicely, but that's just a guess. ;)

And to purposely sound tinfoily... How do you know the CIA or NSA isnt behind this email site?

The beauty of this email service is that it doesn't store information. The key is the zero-knowledge protocol.

how about just encrypting your email?

http://www.howtogeek.com/135638/the-best-free-ways-to-send-encrypted-email-and-secure-messages/?PageSpeed=noscript

Sadly it isn't that simple. I wish it was. The Diffie-Hellman key exchange is not as secure as we once thought.

0

Share this post


Link to post
Share on other sites

Just look at how they rolled over because of the U.S. banking laws.

0

Share this post


Link to post
Share on other sites
Just look at how they rolled over because of the U.S. banking laws.

I can't stress this enough...zero-knowledge protocol! Anyone can "roll over" but if the one rolling over doesn't have anything of substance(due to encryption keys) then it doesn't matter. The reason "The Man" can put pressure on companies like Google, FaceBook, Yahoo, ect is that they themselves mine data. ProtonMail doesn't. I urge all to read into it before making grumpy comments like 2Big.

0

Share this post


Link to post
Share on other sites

Thanks Leigh; that is great information - I just signed up.

0

Share this post


Link to post
Share on other sites

Judging by the comments on their website, this seems to appeal mostly to the tinfoil crowd.:cool:

AES, RSA, OpenPGP have already been compromised, cracked, or will be in the future.

0

Share this post


Link to post
Share on other sites
Judging by the comments on their website, this seems to appeal mostly to the tinfoil crowd.:cool:

AES, RSA, OpenPGP have already been compromised, cracked, or will be in the future.

What? You're a fortune teller now?

While there have been some cases of PGP keys being acquired via phishing, OpenPGP has not been compromised.

You do not have to wear tinfoil to want private communications. And, unless you are involved with murder of anyone in LE, or someone high profile, TPTB are not going to go to all the work needed to capture your secure communications. Especially for the trivial crime of paying to peel tinfoil off of someone like lovely Leigh.

No. I signed up too. I like the idea of more secure communications.

0

Share this post


Link to post
Share on other sites
At the risk of sounding like I am wearing a tinfoil hat I figured I would share this with the community since I am not sure how many people know about it. Many of us are worried about prying eyes from SOs or LE or maybe even a No-Such-Agency sort of agency. There is a new-ish web based client-side encrypted email service that is zero-knowledge and seems to be the most secure product out there. It was developed by the folks at CERN (the same amazing people who found the Higgs boson) and was designed to correct current security flaws in how common webmails function. Also the servers are located in Switzerland which is out of the reach of the US and EU. They did a crowdfunding of some sort for more servers so you have to go on a mailing list but it is well worth the wait. I waited around two months. Just wanted to share with the community. If you like the service, please share it with others!!! Here's a link:

https://protonmail.ch/invite

Enjoy!

If you pair that hat with a silver corset it would look really hot. ;):D

0

Share this post


Link to post
Share on other sites

I just received an invite for family and friends for instant access to ProtonMail and figured I'd share with this "family". It is only open until June 17th. https://protonmail.ch/privacyforall

Since the technology is totally over 99.99% of people's head, here one of it's creators explains in simple terms (I included the Forbes article if you want to read the whole story):

We encrypt the data on the browser before it comes to the server, he explains. By the time the data comes to the server it's already encrypted, so if someone comes to us and says we'd like to read the emails of this person, all we can say is we have the encrypted data but we're sorry we don't have the encryption key and we can't give you the encryption key.

We've basically separated the message that's encrypted apart from the key all the encryption takes place on your computer instead of our servers, so there's no way for us to see the original message.

Happy Monday folks!

0

Share this post


Link to post
Share on other sites

"

Can I use this with my friends who use Gmail?

Yes! However, the messages they send to you will not be end-to-end encrypted. You can send messages to outside users as well. For outgoing messages to non-ProtonMail users, the default is unencrypted emails, which are sent just like any other email."

"When incoming emails from the outside first reach ProtonMail servers, the message bodies and attachments are automatically encrypted with your public key so that afterwards" so they are encrypted on the PronMail server if they are an outside party mail program?

hmmm ... Guess that means everyone would have to use ProtonMail before you got the added security you're really after. Sounds like too many loopholes to me.

Nevertheless, I appreciate the offer. I may give it a try for basic email stuff.

0

Share this post


Link to post
Share on other sites
out of the reach of the US and EU.

No such thing. Silk Road proved that. Ross Ulbricht had one server in France, and one in Iceland. They were hit simultaneously to preserve the data on them, then run by CI for a few months until they finished taking down Ulbricht. If they want the server and the info, they'll get it.

That email is safer, but I wouldn't call it safe. Nothing electronic is.

0

Share this post


Link to post
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
Sign in to follow this  
Followers 0