Hacker News new | ask | show | jobs
by e12e 4394 days ago
It's nice, but suffer from similar problems as all web apps: They have your encrypted keys, all they have to do is send you a different "client" (change the js/ui) the next time you log in, and they can snoop your encryption password. They can of course be forced to do this.

I also wonder about their claim to "expire" mails -- I assume they mean only for mails internal to protonmail -- as any other expiry would have to rely on the recipient using a cooperating pgp/gpg and/or cooperating pop/imap client.

1 comments

Yes, plenty of trust issues. I presume/would hope that they would leave a prominent warrant canary if compelled by Swiss agencies to make any amendments.

I understood 'expiring' mails to mean those accessed directly on their servers, following notification by email, subsequently deleted at the pre-agreed time. I could just have an active imagination.

Don't get me wrong, I'm not fully sold on the outfit, particularly for practical reasons, but am intrigued.