Avatar
JP
af9fa70cd13b02b3712106aa271cb42c7075d7c489de5da353093e759745ef73

Protonmail breaks user-applied PGP signatures,

They only allow Proton PGP. And NOT you applying it on your own.

"you’ll upload your private key to our servers and you’ll like it!"

I'm reposting this from John Floren's Blog, I'm not the author.

(he's using Proton Bridge in a VM, with his own PGP via FairEmail and Claws)

"

When I sent a test message to myself, though, Claws and FairEmail didn’t have any clue that it was signed. If I switched to PGP inline, it worked. I sent an email to one of the Claws maintainers, who reported that my MIME structure was all messed up. He sent me a signed message back, and Claws was able to verify the signature just fine.

It turns out that Proton has been breaking outgoing PGP signatures from the beginning: https://github.com/ProtonMail/proton-bridge/issues/26, https://github.com/ProtonMail/proton-bridge/issues/320. It seems that their argument is this:

-When you send a regular email via Proton to another Proton client, they automatically PGP sign+encrypt the message. (I think this is great!)

-Their automatic signing+encryption cannot coexist with a user-applied signature.

-Therefore, all user-applied signatures will be broken. Tough luck, bucko, we’re the SECURE email company, you’ll upload your private key to our servers and you’ll like it!

It’s absurd that there’s no way to disable this, no option to tell Proton “if you see a multipart/signed or multipart/encrypted message, just leave it the hell alone.”

I’m looking at other potential email hosts. I know PGP isn’t widely used, but I have a hard time swallowing Proton’s silent mangling of my email, and I especially dislike their smarmy we-know-better attitude when people complain about it."

Original Source:

https://jfloren.net/b/2023/7/7/0

Alternative?

https://simplifiedprivacy.com/email-cloud-combo/

Replying to Avatar Murdawk

Dang. It looks like it is. Alternately - one that for sure is on Apple would be Bitwarden.

https://bitwarden.com/ - with the first paid tier you get access to their authenticator. Which is $10 / year. You can also use it with Start9 if you use that as a node.

Oh! I already use this on start9… seems like Proton Pass also has something for TOTP, but I haven’t figured how to use it yet!

Thanks for the tip!

Seems like Proton pass has something but no import feature from Google Auth…

GM 🌻

Remember to pet a random cat today 🫂

Replying to Avatar Murdawk

Aegis

I don’t see this in the App Store, android only?

I wasn’t that much privacy focused, but following a few people here I realized a needed better guards against leaking my data left and right.

I subscribed to nostr:npub1mea2vwcu06qf7e4x00wd902vj54qnn2jacq76ldntrgfhtvhlpqqrvqane and setup my custom domain.

Feels great.

Next step is getting my own lightning address.

Onward 🫡

google authenticator alternatives? iOS

I ordered one over the weekend and it’s shipped already. Amazing cx so far!

Replying to Avatar Ian

I want to #zap you 2,100 Sats!

Good morning #nostr! It has been about a month since I joined and I'm loving "Self-Soverign Social".

My challenge has been connecting with like minded folks, which is surprising because if we are both here on nostr we likley share at least an interest in decentralization and #bitcoin.

So I want to try a little experiment this morning. I have just under 500,000 sats or about $350 in my nostr:npub1flm9yc3vhc3dj036pn3ysl5xwd4f5gyhyjnn9rzehs5mqe9y9ynq6qrg9q account, I want you to help me empty it!

Please follow me (if you are not already) and share this post and I'll zap you 2,100 sats until I run out or have to leave the office. It's about 8:45AM EDT, and I'll be zappin' until at least 3PM (or until I'm broke).

In theory this should yield about 235 paid engaugements, which will hopefully amplify my presance here and help me connect with some like minded folks.

Lets see how it works out, I'll share my results!

Thank you sir! ONWARD 🫡

Replying to Avatar jack

I auctioned for a Toyota Sienna yesterday and I lost it. I cried all night.

Always when you need to transact.