Comment on Proton is transitioning towards a non-profit structure | Proton

<- View Parent
sudneo@lemm.ee ⁨4⁩ ⁨weeks⁩ ago

It’s not “insecure”, it’s simply a supply chain risk. You have the same exact problem with any client software that you might use. There are still jurisdictions, there are still supply chain attacks. The posture is different simply by a small tradeoff: business incentive and size for proton as pluses vs quicker updates (via JS code) and slower updates vs worse security and dependency on a handful of individuals in case of other tools.

Any software that makes the crypto operations can do stuff with the keys if compromised or coerced by law enforcement to do so.

In any case, if this tradeoff doesn’t suit you, the bridge allows you to use your preferred tool, so this is kinda of a moot point.

The main argument for me is that if you rely on mail and gpg not to get caught by those who can coerce proton, you are already failing.

source
Sort:hotnewtop