Daiski
My feedback
4 results found
-
2,102 votes
We have given this quite a bit of thought, but at the present moment, it is not clear the advantages would outweigh the disadvantages.
The biggest problem is search. Encrypting all metadata would break metadata search entirely on the web client as there is still no efficient way to handle search of encrypted data within a browser.
Secondly, metadata encryption’s value from a privacy standpoint is also somewhat dubious. Because we ultimately must deliver the message to the recipient, we must know who the recipient is. At the current time, there still isn’t any proven and viable way to work around this.
Metadata encryption is an area of continued research for us, and when the opportunity arises and the technology for doing this matures, we will definitely implement it in ProtonMail.
An error occurred while saving the comment
Daiski
supported this idea
·
-
341 votes
Daiski
shared this idea
·
-
2,555 votes
An error occurred while saving the comment
Daiski
commented
There is something called "Signal" and Threema" exactly for "secure end-to-end encrypted" chat and open source code.
-
2,034 votes
An error occurred while saving the comment
Daiski
commented
@Markus Jansson
Do you have a technical article that articulates what happened in the case of HushMail and how code was compromised to capture users' credentials and how a browser plug-in prevents this?
I know that browser plug-ins are a big major problems in many security incidents because they have too much power, too much visibility and, as with anything else, compromising a vulnerability or logic flaw in the plugin compromises mailboxes as well. It's a double-edge sword.
It is time that Proton adds an end-to-end encryption to the “Subject” field so that no one other than the intended party can view the subject. The subject reveal ample information about the nature of the email exchange and the topic discussed.
Completing services like ctemplar.com offer “Encrypted Subject” line and I see no reason why Proton cannot implement the same feature to enhance security.