• @brochard
    link
    English
    15
    edit-2
    3 months ago

    I’m not sure what you’re talking about ? You’re not sending your private key to their server without first encrypting it first locally. Their servers are not doing the E2EE, your client is. The website front and apps are open source.

    Yes they could send you a compromised front if you use it via their website, that’s a compromise you accept, otherwhise you could only use their apps which are open source.

    • John Richard
      link
      English
      -103 months ago

      Tell me… when you visit a website that gets updated daily, if not hourly. If it served you a different version of JavaScript than what it served someone else… would you know?

      • @brochard
        link
        English
        53 months ago

        I already answered that. Yes you can’t trust a website’s content, that’s why they offer apps. It’s your choice to trust the website which is as secure as they can make it, or you simply use the apps…

        • John Richard
          link
          English
          03 months ago

          How does a WebView wrapped app offer much more security than a website? Why do they require a paid subscription to use the desktop apps?

        • John Richard
          link
          English
          -13 months ago

          Last I checked the apps are mostly just wrappers around WebView, so either way you’re getting served different content randomly without ever knowing. AND, Proton specifically prevents the desktop apps from functioning on unpaid accounts. That would be like Gmail disabling IMAP for unpaid users.

          • @brochard
            link
            English
            73 months ago

            That’s not how electron apps works. When you load a website with your web browser you get served the front and execute it. When you have an electron app, the front is in the source code of the app, and you decide when to update it so you don’t get served unexpected compromised updates. As for the paid service : They don’t sell your data and don’t show you ads so they need money, it’s that simple.

            • @nieminen
              link
              English
              13 months ago

              For real, if it’s a useful product, and it’s free, then YOU’RE the product.

      • sunzu
        link
        fedilink
        23 months ago

        Ain’t this a website issue? Or is somebody doing it better?

        No JavaScript?