Elektrine lite

← Feed

@dazo@infosec.exchange

Post #3897705

2026-07-17 23:18 UTC

@NetscapeNavigator@social.vivaldi.net To ease your mind a bit more. Almost everything in Proton is end-to-end encrypted. The exception is e-mail headers, which in most cases can't easily be encrypted to make the e-mail delivery work (SMTP protocol in practice). The Subject field does not have a formal standard for being encrypted, so that's the field to be cautious with. Everything else is encrypted in a way which makes it impossible for Proton to extract data from your account. Unencrypted Incoming e-mails has a risk to be captured before Proton encrypts it when storing it to disk. Similar with sending unencrypted emails to non-Proton accounts. All mails between Proton users (and external domains supporting WKD) gets encrypted on your client side before it hits the network. Similar for contacts where you have added the recipient's public PGP key to the contact in the Proton Contacts register. One risk factor is account recovery processes. If you use the passphrase and/or the file based recovery methods only, you're safe. If you have enabled e-mail or phone recovery, you have a potential break-in path this way. Proton claims there is no need for it, but you can also enable a "second password". Without this, Proton will derive a passphrase used to unlock the encryption keys from your login password. Enabling "second password" mode adds a disconnect between the login password and the encryption key. When logging in with this enabled, you will have username/password auth, twon-factor auth and then the second password. Enabling this will also require creating a new recovery passphrase and/or recovery file. But as always with these things, keep a good backup of these passwords, 2FA backup codes and recovery phrase/file. And don't store this inside Proton. If you can't access the Proton service storing it, you've locked yourself on the outside while keys being in the inside. So even if US government decides to want to look into your Proton account, your still well protected until you porovide them access. That's where threat modelling comes intok play to have a plan for various scenarios applicable for you. @frankps@mastodon.babb.no @jon@social.vivaldi.net

Replies (0)

No replies.