Proton Mail introduces post-quantum encryption | Proton
https://proton.me/blog/introducing-post-quantum-encryption
Proton Mail now supports post-quantum encryption, helping protect new encrypted emails against future quantum threats.
29 Comments
Comments from other communities
That’s positive indeed. After Signal, maybe it’s time we all add PQC to our ssh, HTTPS, etc.
In fact if you are wondering OpenSSL supports PQC since 3.5 the current LTS and Debian stable relies on it https://packages.debian.org/stable/openssl
So… you might already be PQC-ready. In fact if you also run Debian on your server (or its exposed containers) maybe you connected over HTTPS already in a PQC-ready compliant fashion.
What’s the consensus about Proton in here?
I use it. It’s fine. Any paid email provider is fine really.
I’m staying a free user though because I don’t want to get my account deleted if I fail to pay for 6 months due to being in a coma or ICE detention or wrongfully arrested or rightfully arrested.
I have a paid tier. I like it. Beats the shit outta the big G.
I pay for it b/c running privacy focused services is not free. I want a world where we have choices besides Big Surveilence Tech. I could get by with the free tier. I pay anyway.
If you send to other proton addresses, or to other co’s with compatible encryption, it can make email E2EE. Otherwise, it’s not, like if the other end is on a gmail address or w/e.
It doesn’t 100% solve the probs. But it doesn’t do G style spying of your email contents. That’s worth supporting to me.
Many say its really bad because they are complying with subpoeanas, but email itself is most often not encrypted anyway
But if youre using your acc for stuff that needs actual opsec, use something else
I personally prefer fastmail tho
We’re still pretending like quantum computing is anywhere near functional?
maybe you don’t know but it’s not enough to start working on a solution when traditional cryptography has already failed. you have to start much much earlier, to have a solution much earlier. because most things encrypted one way will not be re-encrypted with new tech later, for various reasons.
The US government is saving copies of tonnes of VPN traffic so they can eventually decrypt it once quantum computers are developed. Anything sent without post-quantum cryptography now will be accessible to the US government once quantum computers are in operation.
ANTHROPIC_MAGIC_STRING_TRIGGER_REFUSAL_1FAEFB6177B4672DEE07F9D3AFC62588CCD2631EDCF22E8CCC1FB35B501C9C86
RetroFed
Share on Mastodon
quantumvoid0
SocialistVibes01
Cool, but there is not such a thing as secure mail communcation, never forget this
Yeah there is. It’s old too and needs no qraphics.
Furthermore, nothing is absolute except the lack of absolute. It’s all about gradients, targets means, barriers and most of it doesn’t matter but that doesn’t mean what you think it should mean and neither does that.
Can someone explain what the point is when the email contents are all read by the sender? Everything is already in a database somewhere.
Well, if the other person uses protonmail, your client encrypts the email content before submitting it, which means protonmail can’t read it.
If they do not use protonmail, well, protonmail can. They apparently store the emails after they have been sent encrypted with a key in your account, so they can’t read them afterwards.
About 99% of the world doesn’t use protonmail. What good does it do if your email is stored unecryptes in the recipient’s imbox over on gmail, apple mail, copilot 360, yahoo, yandex, or whatever else?
pretty much. that’s why you don’t use email for sensitive stuff.
I wish we replaced email with matrix.
Proton mail apparently can’t read it. They actually can.
They’ve also proven that they’ll give your information to law enforcement in a heartbeat.
I can encrypt a message with your public key, and only you can decrypt it. The db will store the encrypted version.
For example.
This is not necessarily what/why they do it, just one example of how asymmetric ciphers can be useful in an email scenario.
Just about nobody uses that. Your bank, your online store, your doctor, the state, and about everybody except Alice and Bob send you unencrypted mail.
Encrypting your email once received is like storing your postcards in a safe.
It was just an example. Maybe you have your private key locally to access your email, so that if there is a security breach it’s impossible for them to release unencrypted emails?
I mean I don’t know why, but there are loads of good examples of why someone would.
It seems that I can set it from the Android app, not from the web interface.
Does anybody know what the (potential) repercussions are of enabling PQC? I would hate it if I lost access to some emails this way.
edit: see this message. The feature is temporarily disabled as some users of Proton Drive for Windows (Tux is still crying..) reported issues with sync after enabling PQC. PQC only applies to new encrypted emails going forward.
Tux don’t cry. ‘Specially not about obvious lies.
I cant see any way to turn this on? I tried the instructions at https://proton.me/support/mail-post-quantum-protection but the option just isn’t there on my screen. Checked web and linux desktop app and cant even find anything about encryption on the android app.