Demand is high, so you'll have to wait in line a bit for the outfit to free up capacity, but all ProtonMail email accounts requested by June 17 (that's tomorrow), get an upgrade to 1GB of storage. The storage is nice, but it's the email accounts itself that matters. That's because ProtonMail is a free, browser-based, encrypted email service. It gives you security without having to master glitchy plugins or challenging tech (yes, you geeks—lots of people find this stuff challenging). It's pretty much like using Gmail, but minus the likelihood of being snooped on by marketing types, intelligence snoops, or asshole federal prosecutors.

ProtonMail got its start in the wake of Edward Snowden's revelations, when scientists at CERN decided that they didn't really want to provide browsing opportunities for the NSA. The service's technology is designed so that, unlike the late, lamented Lavabit, only users have access to their own email—there's no ability to comply with subpoenas. Servers are based in Switzerland, reducing the likelihood of backdoors being installed by the world's pushier intelligence services (among other things, they can use American court orders for toilet paper, so you don;t have to wait out the encryption wars).

Together with other encrypted and also-free communications offerings, like TextSecure, Signal, and RedPhone, ProtonMail makes relatively (let's emphasize that) secure communications accessible to pretty much everybody.

Keep it coming folks. These are the sort of developments we need.

  1. Unfortunately email still isn’t a secure protocol – the metadata/addresses are still public. That’s why these guys exist:
    Hope they finish soon…


      Too bad they’re so RACIST

      1. I understand there’s a recently unemployed lightly dark person who can buff up their image.

      2. I’ll set up a competitor… GenderOrientationAndToneofSkinEgalitarian-Mail; just for you…

        1. That’s might cis of you….

          1. My publicist says I might need to work on the acronym, but I think it’s fine…

            1. Gender Orientation And Tone of Skin Egalitarian Mail Encrypted against the NSA

              Or GOATSEMEN for short.

              1. The logo practically draws itself.

                1. Something like this?

                  1. ouch!

                  2. ouch!

              2. The God of All Texas will make you quack like a duck for taking their acronym.

                1. Is that you on the mic, Brett?

                  1. I don’t have the hip pop to swing like that. But he is one of my heroes.

                    1. If I had a dollar for every time I did something like that, I could buy a nice steak.

      3. Finally, progress in recognizing the transracials can be racist too. However, since race was proven to be a fiction as long ago as the 1950s, perhaps we can progress to transcultural. I, myself have declared myself transcultural. As a result, I can be deeply offended by absolutely anything anybody could possibly say or do.

        1. I find that offensive!

    2. Yeah, I threw them some bucks at Kickstarter.

      Got a sticker which I put on my work tablet. It has led to some interesting conversations.

      Looking at signing up for a VPN from the house. There’s wifi servers that will encrypt and direct all your internet traffic to VPN servers.

      Of course, you never know what the NSA has hacked/subverted, especially if its proprietary. The open source stuff (like DarkMail) I have more confidence in.

    3. ?

      You can use the STARTTLS verb to encrypt the transmission.

      1. Only helps if you also own the remote server… the record has to be interpreted at the remote and routed. At that point you’re at the mercy of what the mail server decides to do with the data, and the owner of the mail server can be subpoena’d

        1. Ahhh… so that’s what they’re trying to work around.

  2. The Swiss will eventually fold like a cheap tent. They all do.

    1. Hermes Conrad: We can’t compete with Mom! Her company is big and evil! Ours is small and neutral!

      That Guy: Switzerland is small and neutral! We are more like Germany, ambitious and misunderstood!

      Amy Wong: Look, everyone wants to be more like Germany, but do we really have the pure strength of will?

    2. Speaking of Swiss, I take it he’s been partying all day and all night?

      1. I think he’s had a lot of wood to chip…..if you know what I’m sayin’, and I think you do.

        1. *narrows gaze*


          1. HIYO! YES!


            /Ed McMahon

              1. Great review of Woodchipper Massacre by the Cinema Snob

            1. +1 You are correct sir!

    3. This is all probably just a sting to find those people who are willing to make an extra effort to secure their communications. “TEH MUST BE UP TO SUMPIN’, I ZINK!” Seriously, who’d have imagined a world where the US Government is illegally spying on all of its citizens and, once discovered, every fucking branch of the government is complicit in its continuation……and nothing happens. So this is what it felt like to live in the Soviet Union? I mean minus the bread lines, of course.

      1. “I mean minus the bread lines, of course.”

        This is why nothing is happening. We haven’t gotten to the ‘let them eat cake’ stage. Yet.

        1. This is why nothing is happening. We haven’t gotten to the ‘let them eat cake’ stage. Yet.

          So 20 years of war and a military dictator?

          And you guys do know that the Bolsheviks took power when things got really bad?

      2. Seriously, who’d have imagined a world where the US Government is illegally spying on all of its citizens

        Well, Lincoln pretty much stuck to newspaper folk and legislatures that did not see things his way. Pretty sure Teddy Roosevelt thought of illegal spying plenty, then Wilson started the ball rolling in reality. FDR should win the medal for the first half of the 20th century.

    4. The Swiss will eventually fold like a cheap tent. They all do.

      They’ve already folded in some policies. As another recent example of folding in Europe, for the first time in its history, Andorra will impose an income tax an income tax

      In 2013, Andorra announced plans to impose an income tax in response to pressure from the European Union.[1] The tax was introduced in 2015, at a flat rate of 10%.[2]

      Actually they folded three times. The first was from the same negotiations with the EU, by implementing a VAT and small corporate levy in 2013 (again, first time ever). The second was the aforementioned income tax starting this year. The third comes from the US via the recent smackdown by FinCen of one of their primary banks over money laundering.

  3. “[…]asshole federal prosecutors.[…]”

    Hmmm. I can think of someone matching that description.

    1. I wooden know what you’re so chipper about.

  4. What’s the level of encryption in this? I’m no expert on encryption, but I think the best we can hope for is a service that the NSA can’t just crack and read everything in–that would take too much time and processing power–but if they decide they are really, really interested in certain specific emails, there’s pretty much nothing that can stop them from cracking them.

    1. Schenier’s takeaway from the Snowden leaks was that the math is still secure. If the NSA wants data, they try to find other, non-mathematical was to get it, like exploiting the implementation.

      Of course, if NSA did have a signification break in the math, they’d probably management it tightly. So who knows.

      1. Yeah, that’s the real question. What can they actually crack (within a reasonable time frame)?

        1. Not much. That’s why it’s all about the endpoints. And the zillion lb hammer of the National Security Letter, or just having a foreign government seize the whole server (if it’s hosted outside the U.S.)

        2. OTP’s are provably secure. You just have to hand carry a large enough pad to your destination in advance.

          1. If truly random. If the otp has patterns, it can be broken.

            And if someone screws up and uses it twice, its simple subtraction.

            1. But to your second problem, the compromised data is limited to those two (or n — but really ONE in the name should hold that down) messages.

            2. “If truly random. If the otp has patterns, it can be broken.”
              Roll that die, or shuffle those cards; presto!

              1. You’d be surprised how often people feel like a suit comes up too often/not often enough and cheat. Our brains don’t like random.

                1. Brett L|6.16.15 @ 9:32PM|#
                  “You’d be surprised how often people feel like a suit comes up too often/not often enough and cheat.”

                  No, I wouldn’t. I played poker on a fairly regular basis at one time and the number of people who believe cards have memory no longer surprises me.

        3. Targeted, they can crack whatever they want. The exact amount of computing power, as well as the number of targets, is highly classified. If you’re a high priority target, you have no privacy. None.
          Everyone else is back doored, which takes little to no computing power. If you’re a nobody, and you take precautions, you’re fine.

          1. Pl?ya Manhattan.|6.16.15 @ 11:59PM|#
            “Targeted, they can crack whatever they want.”

            Nope. Not random, they can’t.
            Any algorithm, agreed, but not random. That is not crackable.

            1. Sevo, I suspect that they get a lot of what they know through traffic analysis. Just knowing who communicates and when tells you a lot.

              1. “Sevo, I suspect that they get a lot of what they know through traffic analysis. Just knowing who communicates and when tells you a lot.”

                I don’t doubt that for a minute, but the fact remains that random is uncrackable.

          2. If you’re a nobody, and you take precautions, you’re fine.

              1. Point taken, but I’d say he’s the exception that proves the rule.

    2. You get more mileage cracking the implementation than by cracking the math. Oh, and for others, “open source” is not magic fairy dust.

      1. For those of you who are not aware, magic fairy dust is also known as white lotus, or yam-yam, or shanghai sally.

  5. Sign up link:

    1. I laughed

    2. Very funny.

  6. Servers are based in Switzerland, reducing the likelihood of backdoors being installed by the world’s pushier intelligence services

    That doesn’t reduce the likelihood of backdoors. NSA can probably just hack the servers, then subvert the software.

  7. RFC 2822 is an inherently unencrypted protocol. So either this service is not encrypted or it’s not e-mail.

      1. I can send encrypted data via RFC 5321 (smtp) quite easily. I just send the encrypted data as clear text via SMTP. What’s not encrypted via SMTP is metadata such as sender, receiver, location etc.

      2. It’s encrypted. The email protocol itself really only deals with routing of messages. As mentioned above the metadata is unencrypted but the payload–the email body–is encrypted. You can also “send” encrypted email to someone outside of protonmail. The recipient will be directed to their webpage and asked to enter a password you set (that presumably the recipient knows).

        1. No prob on the password. I’ll just include it in the email.

            1. This made me happy. Thanks.

  8. How long til an unfortunate and totally accidental drone strike on Proton Mail’s servers?

  21. Copied and pasted from the AM links:

    Together with other encrypted and also-free communications offerings, like TextSecure, Signal, and RedPhone, ProtonMail makes relatively (let’s emphasize that) secure communications accessible to pretty much everybody.

    From the scant details they give ProtonMail seems like it may be better than nothing.

    But TextSecure/Signal/RedPhone and ProtonMail shouldn’t really be mentioned together at this point. The former come from a well-known, accomplished security researcher (Moxie Marlinspike); the latter comes from, err, idk, some random nerds? I’m sure they’re very smart, but none of them mention any security background.

    And TextSecure in particular (and to an extent Signal, by extension, since it’s based on the same protocol) is not just open source but has been professionally audited; ProtonMail, err, uses some open source libraries and uh, has a bug bounty?

    Oh, and did I mention the “scant details” thing? Maybe they’re hidden somewhere hard-to-find, but ProtonMail’s website does a piss-poor job describing their architecture for users with technical/security knowledge… we’re just left to read between the lines and guess what they probably would do based on the mostly-non-technical descriptions they give.

  22. Signed up for an account about six months ago out of curiosity. They have since improved on one item – incoming messages are now stored encrypted, regardless of the source. In theory that is useful if their hard drive is snatched.

    There are potentially some issues of how the passowrds and keying are done but the bigger issue with ProtonMail, Tutanota and others is Javascript. You can read a bit more here but bottom line, anytime Javascript is involved security suffers.

  23. Excerpt from “Why isn’t StartMail free?”

    There are plenty of so-called “free” email services, but they aren’t really “free.”…

    There are also “free” email services that seek more ethical ways to raise needed capital. No matter how noble their intentions, someone has to subsidize the people who build the software programs, as well as the servers, the electricity and the security. These organizations may turn to volunteers and solicit needed funds through crowd sourcing and donations….

    Even if they do raise significant funds, you will always need to be concerned about the source of donations. Even nonprofit organizations answer to the people who pay their overhead and salaries, which could include large corporations and government agencies. Philanthropic organizations are no different, and you can likely look out onto the Internet landscape and identify a few of those companies that have either floundered or relinquished some control to corporate and government interests.

    When you purchase a StartMail account, you hire us to handle your email. We answer to YOU, not marketers, corporate donors, or government agencies. Our mission is to protect your privacy and deliver great email service at a fair market price….

  24. A tribute to a unique and famous flavour in combination with the respect to a serious technology: cohibaSIGNUMws has been designed by Wolfram Scharnhorst for conscious Protonmail clients. cohibaSIGNUMws is a child theme of the well-known whiteSands theme ( cohibaSIGNUMws aims to provide some useful features (e.g. print buttons, etc.) and facilitate relaxed mailing.

