For some reason I have it in the back of my mind that they were at one point accused of being a honeypot for US intelligence because of their association with MIT. Probably complete BS, but maybe not. Are they as open source as they claim to be? Looks like they’re on github. F-Droid seems to think they have some Google libraries or whatever that they use.

ProtonMail users, how do you like/dislike it?

  • Atemu
    link
    fedilink
    73 months ago

    At that point, might as well send E2E encrypted mail via GMail.

    From a security stand-point: Yes. From a privacy standpoint: Absolutely not.

    • @jarfil@beehaw.org
      link
      fedilink
      2
      edit-2
      3 months ago

      Both privacy and security are the same in either case:

      • Both servers know who’s connecting
      • Both servers see the connecting IP
      • Both servers know the source and target mail addresses
      • Neither server knows the message’s content
      • Neither server controls the client’s app

      The moment you go off-VPN, or use a webapp, security goes out the window.

      Privacy, as in social network/contacts, goes out the window the moment you use a fixed email address; more so if it’s associated to your IRL identity.

      • Atemu
        link
        fedilink
        33 months ago

        There’s a large difference between surrendering massive amounts of highly critical metadata aswell as some data* to a known abuser vs. an entity that prides itself in not abusing your data and which even takes specific technological measures to make it as hard for them as possible (zero access encryption at rest, automatic key discovery).

        (* Partial social graph, interaction timestamps, political interests, health, hobby interests and much of that usually even in plain text data form when receiving email; stored in in plain text forever.)