Hacker News new | ask | show | jobs
by uoaei 1269 days ago
Sending decrypted information over an encrypted line makes it relatively much easier to reverse-engineer the private key. If Google has, say, the contents of an email via GMail, and surveillance over the transmission line that carries the encrypted version of that, they would have not much trouble cracking your Protonmail key. It's unlikely that they would gain access to Protonmail's secure servers, but if they can surveil traffic going into and out of Protonmail's servers, they can decrypt the messages they know the keys for. They own more than a few installations and high-throughput (e.g. undersea) cables and it doesn't seem far-fetched to assume they have built systems for extracting information from the massive bitstreams, especially considering all we know about NSA surveillance programs.