Skip to content

Comment on Proton is taking its privacy-first apps to a nonprofit foundation modelparent

Comments

The key has to be on their servers though? If I log into a proton account on a new computer I could see all my emails decrypted. I don't have to store the key somewhere and move it to my new computer.

Second, I am not talking about swiping the key, but the password. When you log in, you send your password to their server. They presumably hash the password and compare the hashes then send you the decryption key if the hash is correct.

The problem with that is they could keep the password you entered (pre hash). If hashes are good then use the password you entered themselves with the key to decrypt your email.

It sounds like the separate decryption password may work around this, but is not the default meaning a large chunk of the users are vulnerable to proton logging passwords.

You never send your password to their servers, they use the "secure remote password protocol" : https://en.wikipedia.org/wiki/Secure_Remote_Password_protoco...

They explain what they do here : https://proton.me/blog/encrypted-email-authentication

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.