|
|
|
|
|
by 8organicbits
1079 days ago
|
|
> FWIW, private keys are stored encrypted on the server, we don't have access to them. I'm always bothered by statements like this because it appears to be skimming over if the provider can perform cryptography with the key. My understanding is that those keys are only decrypted in the users apps/web browser, not server-side. Is that right? You need to trust that the provider doesn't perform additional operations along side legitimate user triggered actions, which I believe PM handles. https://proton.me/blog/encrypted-email |
|
Although they are open-source and can be scrutinized by anybody, it does not means that's what is run on the server side.
(Just say they have the capability; no accusation)
So at the end of the day, the question is whether you trust Proton or not. Encryption might not help in that case.