Talk:Proton Mail: Difference between revisions
m Signing comment by SyntaxPolice - "→Encryption protocol needs citation: new section" |
→Proton VPN (proxy): new section |
||
Line 49: | Line 49: | ||
The section on encryption provides a moderately detailed description of how the crypto works, but it only sites a stack exchange article. The article has a brief description by someone claiming to be one of the developers, but even that doesn't support a number of the claims. I recommend replacing this section with something that indicates that ProtonMail has not provided an official explanation of how end-to-end encryption works. <!-- Template:Unsigned --><small class="autosigned">— Preceding [[Wikipedia:Signatures|unsigned]] comment added by [[User:SyntaxPolice|SyntaxPolice]] ([[User talk:SyntaxPolice#top|talk]] • [[Special:Contributions/SyntaxPolice|contribs]]) 19:40, 1 March 2017 (UTC)</small> <!--Autosigned by SineBot--> |
The section on encryption provides a moderately detailed description of how the crypto works, but it only sites a stack exchange article. The article has a brief description by someone claiming to be one of the developers, but even that doesn't support a number of the claims. I recommend replacing this section with something that indicates that ProtonMail has not provided an official explanation of how end-to-end encryption works. <!-- Template:Unsigned --><small class="autosigned">— Preceding [[Wikipedia:Signatures|unsigned]] comment added by [[User:SyntaxPolice|SyntaxPolice]] ([[User talk:SyntaxPolice#top|talk]] • [[Special:Contributions/SyntaxPolice|contribs]]) 19:40, 1 March 2017 (UTC)</small> <!--Autosigned by SineBot--> |
||
== Proton VPN (proxy) == |
|||
https://protonvpn.com/about it is a thing too [[Special:Contributions/88.159.71.224|88.159.71.224]] ([[User talk:88.159.71.224|talk]]) 00:24, 6 September 2017 (UTC) |
Revision as of 00:24, 6 September 2017
Websites: Computing C‑class | |||||||||||||
|
Software: Computing C‑class | |||||||||||||
|
Cryptography: Computer science C‑class | |||||||||||||
|
Image resize
Shouldn't [[File:Protonmail_system_architecture_2014.png|thumb|375px|Architecture of a ProtonMail datacenter.]]
be smaller? 71.34.137.244 (talk) 09:31, 27 April 2015 (UTC)
Zero Knowledge
Is protonmail really using a zero-knowledge protocol ? It is being said in the introduction, but nowhere else is anything specified (?) 95.91.240.213 (talk) 20:05, 4 November 2015 (UTC)
- I appended {{clarify}} to the sentence. Maybe someone has a good source for this. Otherwise we should remove it as advertising.–Totie (talk) 18:38, 5 November 2015 (UTC)
- ProtonMail is using client-side encryption. It is not using zero-knowledge proofs or zero-knowledge protocols actually fitting the cryptographic definition of zero knowledge. 85.76.73.223 (talk) 17:09, 24 July 2016 (UTC)
- I removed the phrases entirely. I did not like the formulation to begin with and believe that it puts as into a position that we have to justify the claims made by ProtonMail.–Totie (talk) 11:28, 25 September 2016 (UTC)
Not really "Open Source“
In contrary to what they say on their blog: "ProtonMail is Open Source”[1] ProtonMail seems to only release small parts of it's code as open source, and they release it slowly after using it in production, this kind of delay could speculatively be caused by the external audits — they speak of "Security Contributors" on their blog [2]</ref>. They have no intention of releasing their back end which — considering the audits — could be seen as some form of security through minority.
The security risks of open sourcing the back-end code is too high. It would let an attacker know how our infrastructure is set up or let spammers get insight into how to circumvent our anti-spam measures.
— ProtonMail Blog Admin, https://protonmail.com/blog/protonmail-open-source/#comment-8926
As of 22 february the only thing released as open source is the previous version (2.0) of the webmail front-end [3] which can still be accessed through v2.protonmail.com. Their server, iOS and Android code are closed. Though founder Andy Yen promised to the backers of the crowdfunding campaign to open source the native apps:
Hi Eric, this is why we are trying to hit our reach goal of $500,000 so we can also build native applications for ProtonMail which will be installed/loaded once, and also be open source.
So I would simplify the introduction by saying
- ProtonMail is a free
and open-source web-based encrypted email service ...
And in the infobox, the license could be:
- Freeware; some components MIT License
- I agree somewhat. They do seem to have a commitment to open source and said repeatedly that this happens once the product leaves beta. Nevertheless, Wikipedia is an encyclopedia and it would be wrong to suggest that ProtonMail is open source already. I am in favour of your suggestions and would be open to mentioning their open-source intentions elsewhere in the article.–Totie (talk) 17:03, 22 February 2016 (UTC)
Links to summary pages on email servers/services
Should the links at the bottom be retained? While they do link to nice summaries of email options, the Wikipedia pages they linked to does not include ProtonMail. I would suggest adding rows in the various tables which describe ProtonMail, or removing the links to the comparison pages. — Preceding unsigned comment added by 75.73.1.89 (talk) 00:26, 26 February 2016 (UTC)
- I see no problem there. The page is for further reading on a directly related topic.–Totie (talk) 13:40, 26 February 2016 (UTC)
Historical vulnerability
I am moving mention of the following historical vulnerability from the article to the Talk page. It does not seem notable at all, considering especially that it did not affect the then current version. --Hyperforin (talk) 01:26, 25 September 2016 (UTC)
- I disagree about the notability. Given the articles emphasis on security, I do believe that this kind of vulnerability should be mentioned.–Totie (talk) 11:26, 25 September 2016 (UTC)
- I don't feel strongly about it. You're welcome to add it back if you like. Typically I would mention it too, but there is no famous large software product that exists without a history of vulnerabilities. This one in particular was not even exploited as far as we know, making it less than notable. --Hyperforin (talk) 00:05, 26 September 2016 (UTC)
Vulnerabilities
A video demonstrating a cross-site scripting attack was shown in July 2014.[1] The ProtonMail developers reviewed the video and confirmed that the issue affected an early development version of ProtonMail that was released in May 2014. The attack did not affect the then-current version.[2]
User number
According to this source: https://protonmail.com/blog/protonmail-tor-censorship/ there are only "over 2 million" users. While technically 5 Million is "over 2 million", I think they would have wrote 5 million if it would be that much more than 2 million.Andylee Sato (talk) 08:46, 19 January 2017 (UTC)
Encryption protocol needs citation
The section on encryption provides a moderately detailed description of how the crypto works, but it only sites a stack exchange article. The article has a brief description by someone claiming to be one of the developers, but even that doesn't support a number of the claims. I recommend replacing this section with something that indicates that ProtonMail has not provided an official explanation of how end-to-end encryption works. — Preceding unsigned comment added by SyntaxPolice (talk • contribs) 19:40, 1 March 2017 (UTC)
Proton VPN (proxy)
https://protonvpn.com/about it is a thing too 88.159.71.224 (talk) 00:24, 6 September 2017 (UTC)
- ^ Hacking protonmail - with a browser. Vimeo. 30 June 2014. Retrieved 19 October 2015.
- ^ "Update about reported XSS issue". ProtonMail. 8 July 2014. Retrieved 19 October 2015.
- C-Class Websites articles
- Unknown-importance Websites articles
- C-Class Websites articles of Unknown-importance
- C-Class Computing articles
- Unknown-importance Computing articles
- All Computing articles
- All Websites articles
- C-Class software articles
- Unknown-importance software articles
- C-Class software articles of Unknown-importance
- All Software articles
- C-Class Cryptography articles
- Unknown-importance Cryptography articles
- C-Class Computer science articles
- Unknown-importance Computer science articles
- WikiProject Computer science articles
- WikiProject Cryptography articles