Hacker News new | ask | show | jobs
by x1798DE 4398 days ago
I think it sends them a note that says, "Someone at ProtonMail sent you a message - click this link and enter the password they gave you to open it!"

Presumably they'll have some way to distribute the password in some ephemeral or slightly out-of-band way. It's probably less secure than messages within their environment, but it shouldn't ever hit another mailserver in plaintext (ideally ProtonMail wouldn't even have the plaintext anyway).