You are viewing a single thread.
View all comments View context
0 points
*

You upload your private key to the cloud. Encrypted or not, this is a bad idea. No thanks. I can do the signing locally and then I’ll do the decryption with my own private key locally without them storing it as well.

Edit: mixed public keys with private keys

permalink
report
parent
reply
8 points

You upload your private key to the cloud. Encrypted or not, this is a bad idea.

An encrypted key is a useless blob. What matters is the decryption key for that key, which is your password (or a key derived from it, I assume), which is client side.

They can do the signing and encryption with my public key

They can’t sign with your public key. Signing is done using your private one, otherwise nobody can verify the signature.

Either way:

and then I’ll do the decryption with my own private key locally without them storing it.

You can do it using the bridge, exactly like you would with any client-side tooling.

permalink
report
parent
reply
3 points

It’s still insecure. They decryption process is still in the proton company hands and they could add some client specific code to log the password on the fly. Proton is obliged to follow the swiss law and I can imagine situation that police asks proton (+ gag order ) to log certain data for specific clients like passwords and ips. Still private keys are better to be stored separately. You can sync them easily if you with with either rsync or rclone

permalink
report
parent
reply
4 points

It’s not “insecure”, it’s simply a supply chain risk. You have the same exact problem with any client software that you might use. There are still jurisdictions, there are still supply chain attacks. The posture is different simply by a small tradeoff: business incentive and size for proton as pluses vs quicker updates (via JS code) and slower updates vs worse security and dependency on a handful of individuals in case of other tools.

Any software that makes the crypto operations can do stuff with the keys if compromised or coerced by law enforcement to do so.

In any case, if this tradeoff doesn’t suit you, the bridge allows you to use your preferred tool, so this is kinda of a moot point.

The main argument for me is that if you rely on mail and gpg not to get caught by those who can coerce proton, you are already failing.

permalink
report
parent
reply
3 points

Exactly. There’s no justification for them storing the private key online for “convenience”. And key generation happens in the browser with JS. Which means it is possible to send backdoored JS to easily copy the private key.

permalink
report
parent
reply
1 point

Yeah mb. Mixed private keys with public keys. Edited original comment.

permalink
report
parent
reply

Technology

!technology@lemmy.world

Create post

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


Community stats

  • 14K

    Monthly active users

  • 6.8K

    Posts

  • 156K

    Comments