Web site source code verification to mitigate compromised code
I want to propose having web site source code verification. This would mitigate malicious code being service by the user web interface at proton[.]me. There are several tools, most famous being Meta's open source 'Code Verify' that uses published hashes.
It's no secret that Proton's web interface is a weak point for password compromise - such as via a court order. My proposal would require Proton, or a trusted entity, posting the hashes of known good Proton.me interface web site code. By allowing Proton users to verify the web site code they are being served, this reduces the risk of their password being at risk.
-
John commented
From another perspective, how a platform balances depth and simplicity can shape the overall experience. Some sites lean too heavily in one direction. While exploring various sources, I found https://www.ghanawebnews.org/ , where both aspects feel more balanced. You can go deeper when needed or stay at a surface level. This adds flexibility. In the end, it makes the platform more versatile.