proton-bridge
ProtonMail Web Client
proton-bridge | ProtonMail Web Client | |
---|---|---|
83 | 181 | |
1,069 | 4,146 | |
2.2% | 2.1% | |
9.6 | 10.0 | |
18 days ago | about 1 month ago | |
Go | TypeScript | |
GNU General Public License v3.0 only | GNU General Public License v3.0 only |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
proton-bridge
-
ProtonMail Complied with 5,957 Data Requests in 2022 – Still Secure and Private?
That isn't really fair. If you read the article, protonmail essentially supplied the FBI the recovery email of the account. This is metadata that protonmail must have that isn't encrypted by the user for obvious reasons.
Regarding the "MITM" for every email sent, this is related to their "bridge" software which allows regular IMAP/SMTP software to use Proton Mail. This software must edit the emails to encrypt them in their scheme.
This software is open source and can be inspected and/or built locally. https://github.com/ProtonMail/proton-bridge
-
ProtonMail Rewrites Your Emails
> This appears to be related to a behaviour that ProtonMail has of dropping all plaintext email if any mime-encoded parts exist.
https://github.com/ProtonMail/proton-bridge/issues/26#issuec...
I'm actually more shocked knowing that they drop plain text if there is a mime-encoded part (e.g. HTML). Just verified that all mails imported from GMail and all newer mails I received in PM only have the HTML part now, while GMail shows both HTML and plain text parts in message source. Great, now if I want to use a text-only client to read those mails in the future, I won't be able to.
Now I honestly wonder, how did they think this is something okay to mess up? Is there just no usable email hosting service for someone that want their mails not touched and also stored securely? Like, this is not even going to save storage space for PM - I'm paying for my storage.
- Proton Mail (Bridge) for High Sierra Mac
-
Bridge V3 Cache
Repository here https://github.com/ProtonMail/proton-bridge
- People over-emphasize the slow pace of update rollout, and under-emphasize that once the updates roll out they rarely break or malfunction
- Moving emails from Proton Mail.
-
FYI, Protonmail Bridge tries to silently install a sketchy CA cert in your OS cert store
The privkey is never loaded out of the keychain. Rather, it acquires a handle to the privkey and relies on the keychain to carry out cryptographical operations. (https://github.com/ProtonMail/proton-bridge/blob/master/pkg/keychain/helper_darwin.go and https://github.com/ProtonMail/proton-bridge/blob/master/pkg/keychain/keychain_darwin.go)
- How's the linux bridge coming along; and also, how do I stay on the main website?!
-
Mails missing in MacOS Mail
Oh yes. The Bridge shouldn’t have been marketed as stable for the past years because of this issue (see issue #220 on Github, reported 2021-09-29). It’s fixed in Bridge 3.0.
ProtonMail Web Client
-
Proton Mail Discloses User Data Leading to Arrest in Spain
> Is this password-derived key the "account key" which I see in the Proton Mail settings interface?
No, the account key is an OpenPGP key which is encrypted with a key derived from your password. The "key encryption key" is not separately visible. The address keys are in turn encrypted using the account key.
> Please clarify what key derivation function is being used.
We use bcrypt, in addition to the OpenPGP S2K (i.e. the bcrypt output is fed as the "password" to OpenPGP's key encryption).
We are in the process of rolling out OpenPGP.js v6, which supports Argon2 for the OpenPGP S2K step, after which we'll start using that - but we aren't quite yet.
> Are there instructions for verifying that all this is happening? I think a lot of folks on HN won't be convinced otherwise.
Take a look at https://github.com/ProtonMail/WebClients/blob/main/packages/..., for example. Though to be honest, if you want to verify that we aren't sending the password to the server anywhere, in principle you'd have to check the code of the entire web app. It's all open source, but it's a lot of work, of course. But you can also check the latest audit report: https://proton.me/blog/security-audit. They also verified all of this stuff.
> It's just that I'm going to create an OpenPGP identity for things like signing code commits on git, signing packages I publish. (...) So I was really hoping to be able to use Proton Mail with this identity instead of the key pair that's generated for the account.
Yeah, I understand. Though, the typical advice from a cryptographer's perspective would be, it's better to use separate keys for separate purposes; and the simplest way to do that is to generate separate OpenPGP certificates, so that's what we'd generally recommend. But, if you want to generate separate subkeys and sign them all using a common primary key, that's also reasonable enough. And, we can improve the documentation on that, although it's a bit of a niche use case (not for HN of course, but for the general audience it is).
> Thanks for reaching out here on HN. I've been a really happy Proton Mail customer and now I'm even happier.
Thanks, glad to hear! :)
- Has anyone tried to run the Proton Mail UI locally?
-
ProtonDrive encryption key
The source code is here https://github.com/ProtonMail/WebClients
-
Proton Pass – Protecting your passwords and online identity
> Finally, in keeping with our long track record of transparency, Proton Pass is open source so anyone can review and verify our security architecture
They sure do enjoy writing that sentence without including any hyperlinks. This (https://github.com/ProtonMail/WebClients/tree/main/applicati...) appears to be the browser extension and https://github.com/ProtonMail/WebClients/tree/main/packages/... appears to look like the backend referenced in the extension's readme, but that directory's readme is zero bytes so (shrug)
- Where is the source code for Proton Drive?
-
Basic HTML Mode?
Fork the frontend and make your own lightweight option
- Where can I find the source code of the web app?
-
Announcement: SMTP Server in Rust with DMARC, DANE, MTA-STS, Sieve, OTEL support
PS: I hope that we selfhosters will have a modern, efficient, easy to use mail suite one day with modern features like JMAP, good self-learning spam integration, automated checks and validations for SPF/DMARC/DKIM or whether the IP/host suddenly appears in a blocklist and integrated encryption at rest for emails. Something that isn't 30 services in a container image, with 30 different configuration styles. Maybe even with an API integrated that's compatible to the ProtonMail frontend (like the neutron server once intended to be). Anyway, I'm sorry for dreaming. ;)
-
Why is the "Special offer" button still there after I purchased 1 year of Mail Plus through that very button?? Not happy.
And if you want to customize it further you can use Stylus to add custom CSS, Tampermonkey to add JS, or even modify the whole thing yourself from source (if you run it locally it syncs with your actual account).
- Is Proton Drive better than Sync.com?
What are some alternatives?
hydroxide - A third-party, open-source ProtonMail CardDAV, IMAP and SMTP bridge
SimpleLogin - The SimpleLogin back-end and web app
FreeCAD_assembly3 - Experimental attempt for the next generation assembly workbench for FreeCAD
Roundcube - The Roundcube Webmail suite
Contents - Community documentation, code, links to third-party resources, ... See the issues and pull requests for pending content. Contributions are welcome !
RainLoop - Simple, modern & fast web-based email client
proton-bridge - ProtonMail Bridge application
Tutanota makes encryption easy - Tuta is an email service with a strong focus on security and privacy that lets you encrypt emails, contacts and calendar entries on all your devices.
aws-lambda-ses-forwarder - Serverless email forwarding using AWS Lambda and SES
Mailpile - A free & open modern, fast email client with user-friendly encryption and privacy features
wildduck - Opinionated email server
proton-mail - React web application to manage ProtonMail