|
|
|
|
|
by lvh
2362 days ago
|
|
I didn't write https://latacora.micro.blog/2019/07/16/the-pgp-problem.html (the writing is too good, a giveaway that it's a 'tptacek joint) but I did review it and helped shape its contents and generally subscribe to its message :) In particular you are correct, and specifically GPG's MDC thing is some weird nonsense that does not deserve to be in use in 2019, let alone being in a product that describes itself as having top-notch security. (Mostly I think I get why Protonmail does what it does, but GPG+email is a losing horse. It also doesn't help that protonmail addresses are a mild predictor for content not worth reading. I haven't quite had Popehat's experience of protonmail being a proxy for overt, virulent white supremacy, but... certainly have seen it be a proxy for poorly informed opinions on security :-)) |
|
One of the things that bugs me about security/privacy discussions is the rampant paranoia and misinformation, and it tends to be the louder voice in the discussions lately. I have to wonder if Protonmail being such a visible figure means that it attracts people who're inclined to fall under the aforementioned.
i.e, the people who use Protonmail for mostly innocuous reasons just don't say anything, so the poorly informed bits float to the top.
It's like apartment ratings, I guess - nobody writes a rating for a good one.
Disclaimer: I interviewed with PM last year and was offered a role, but for various life reasons didn't take it. They're pretty smart people though so I'm inclined to give the team the benefit of the doubt - I don't think any of this influences my comment above, but worth noting.