Proton Mail
Screenshot | |
Type of site | Webmail |
---|---|
Available in | English, French, Polish and Italian |
Owner | Proton Technologies AG |
Created by |
|
URL |
|
Commercial | Yes |
Registration | Required |
Launched | 16 May 2014 |
Current status | Online |
Content license | MIT License |
ProtonMail is a partly open-source end-to-end encrypted email service founded in 2013 at the CERN research facility by Andy Yen, Jason Stockman and Wei Sun.[2][3][4] ProtonMail uses client-side encryption to protect email contents and user data before they are sent to ProtonMail servers, in contrast to other common email providers such as Gmail and Hotmail. The service can be accessed through a webmail client or dedicated iOS and Android apps.[5]
ProtonMail is run by Proton Technologies AG, a company based in the Canton of Geneva, and its servers are located at two locations in Switzerland, outside of US and EU jurisdiction.[6] The service received initial funding through a crowdfunding campaign. The default account setup is free and the service is sustained by optional paid services. As of January 2017[update], ProtonMail has over 2 million users.[7] Initially invitation-only, ProtonMail opened up to the public in March 2016.
History
Development
On 16 May 2014, ProtonMail entered into public beta.[8] Within three days, ProtonMail was met with an overwhelming response and was forced to temporarily suspend beta signups while they worked to expand server capacity.[9]
On 31 July 2014, ProtonMail received US$550,377 from 10,576 donors through a crowdfunding campaign on Indiegogo, while aiming for US$100,000.[10] During the campaign, PayPal froze ProtonMail's PayPal account, thereby preventing the withdrawal of US$251,721 worth of donations. PayPal stated that the account was frozen due to doubts of the legality of encryption, statements that opponents said were unfounded.[11][12] The restrictions were lifted the following day.[13]
On 18 March 2015, ProtonMail received US$2 million from Charles River Ventures and the Fondation Genevoise pour l'Innovation Technologique (Fongit).[14]
On 13 August 2015, ProtonMail released version 2.0, which was the most significant update in ProtonMail's history and included a new codebase for its web interface and introduced significant performance enhancements. The ProtonMail team simultaneously released the source code for the web interface under an open-source license.[15]
On 17 March 2016, ProtonMail released version 3.0, which saw the official launch of ProtonMail out of beta. With a new interface for the web client, version 3.0 also included the public launch of ProtonMail's iOS and Android beta applications. These applications are built natively for each respective platform maintaining the gestures and actions familiar with each operating system.[16] The mobile apps proved to be a hit with reports of increased efficiency and the ability to leave other email providers such as Gmail due to the usability and feature set found in ProtonMail. After receiving hundreds of thousands of downloads in the first week and thousands of reviews, the ProtonMail mobile apps garnered the highest ranking score in the app and play store.[17]
On 19 January 2017, ProtonMail announced support through Tor.[18]
2015 DDoS attacks
From 3 to 7 November 2015, ProtonMail was under several DDoS attacks that made the service largely unavailable to users.[19] ProtonMail believed that it was affected by two separate attacks, the first led by a group of hackers known as the Armada Collective and the second by an unknown, more technically advanced group with abilities similar to a state-sponsored group. The first attack was tied to a ransom of 15 bitcoins (roughly US$6,000) which ProtonMail eventually paid due to pressure from ISPs and other companies affected by the attack. The DDoS attacks, however, did not stop and instead began to take on more sophistication, with rates exceeding 100 Gbit/s. The company received an email from the Armada Collective in which they denied responsibility for the ongoing attack.[20][21][22][23] During the attack, the company stated on Twitter that it was looking for a new data centre in Switzerland, saying that "many are afraid due to the magnitude of the attack against us". They have since posted that they "have a comprehensive long term solution which is already being implemented".[21][24]
Encryption
ProtonMail uses a combination of public-key cryptography and symmetric encryption protocols to offer end-to-end encryption. When a user creates a ProtonMail account their browser generates a pair of public and private RSA keys:
- The public key is used to encrypt the user's emails and other user data.
- The private key capable of decrypting the user's data is symmetrically encrypted with the user's mailbox password.
This symmetrical encryption happens in the user's web browser using AES-256. Upon the account registration, the user is asked to provide a login password for their account. ProtonMail also offers users to login with two password mode that require a login password and a mailbox password.
- The login password is used for authentication.
- The mailbox password encrypts the user's mailbox that contains received emails, contacts and user information as well as a private encryption key.
Upon logging in the user has to provide both passwords. This is to access the account and the encrypted mailbox and its private encryption key. The decryption takes place client-side either in a web browser or in one of the apps. The public key and the encrypted private key are both stored on ProtonMail servers. Thus ProtonMail stores decryption keys only in their encrypted form so ProtonMail developers are unable to retrieve user emails nor reset user mailbox passwords.[25] This system absolves ProtonMail from:
- Storing either the unencrypted data or the mailbox password.
- Divulging the contents of past emails but not future emails.
- Decrypting the mailbox if requested or compelled by a court order.[26]
ProtonMail exclusively supports HTTPS and uses TLS with ephemeral key exchange to encrypt all Internet traffic between users and ProtonMail servers. Their 4096-bit RSA SSL certificate is signed by QuoVadis Trustlink Schweiz AG and supports Extended Validation, Certificate Transparency,[27] Public Key Pinning, and Strict Transport Security. Protonmail.com holds an "A+" rating from Qualys SSL Labs.[28]
In September 2015, ProtonMail added native support to their web interface and mobile app for Pretty Good Privacy (PGP). This allows a user to export their ProtonMail PGP-encoded public key to others outside of ProtonMail, enabling them to use the key for email encryption. The ProtonMail team plans to support PGP encryption from ProtonMail to outside users.[29]
Email sending
An email sent from one ProtonMail account to another is automatically encrypted with the public key of the recipient. Once encrypted only the private key of the recipient can decrypt the email. When the recipient logs in their mailbox password decrypts their private key and unlocks their inbox.
Emails sent from ProtonMail to non-ProtonMail email addresses may optionally be sent in plain text or with end-to-end encryption. With encryption the email is encrypted with AES under a user-supplied password. The recipient receives a link to the ProtonMail website on which they can enter the password and read the decrypted email. ProtonMail assumes that the sender and the recipient have exchanged this password through a back channel.[25] Such emails can be set to self-destruct after a period of time.[30]
Two-factor authentication
ProtonMail currently supports two-factor authentication for its login process.[31]
Interface
Users can deploy a third-party theme if desired. ProtonMail provides a web interface for accessing user emails, contacts, and user settings. The default layout of the interface places:
- Mailbox folders along the left side of the screen.
- A search bar and controls across the top.
- Email messages in the remaining space.
The user also has the ability to choose between two different styles for each of the:
The source code for the web interface, including all client-side encryption methods, is available on GitHub under the MIT License.[34]
Data centres
ProtonMail maintains and owns their server hardware and network in order to avoid trusting a third party. They maintain two redundant data centres in Lausanne and Attinghausen (in the former K7 military bunker under 1,000 meters of granite rock).[30][35][36] Since the data centres are located in Switzerland they are legally outside of US and EU jurisdiction. Under Swiss law all surveillance requests from foreign countries must go through a Swiss court and are subject to international treaties. Prospective surveillance targets are notified and can appeal the request in court.
ProtonMail is outside the scope of the Swiss Federal Act on the Surveillance of Postal and Telecommunications Traffic. This act governs lawful Swiss interception of electronic communications.[37]
Each datacenter uses load balancing across web, mail, and SQL servers, redundant power supply, hard drives with full disk encryption, and exclusive use of Linux and other open-source software.[38] In December 2014, ProtonMail has joined the RIPE NCC in an effort to have more direct control over the surrounding Internet infrastructure.[39]
Account types
Protonmail is offered with free and paid accounts:[40]
Free | Paid for (4 euros per month) |
---|---|
150 messages per day, 500 MB storage, limited support | 1000 messages per day, 5 GB storage, labels and custom filters, encrypted messages to external recipients, own domain, up to 5 email aliases, priority customer support |
See also
References
- ^ "protonmail.com Site Info". Alexa Internet. Retrieved 5 February 2017.
- ^ "ProtonMail is Open Source!". ProtonMail. 13 August 2015. Retrieved 19 October 2015.
- ^ Biggs, John (23 June 2014). "ProtonMail Is a Swiss Secure Mail Provider That Won't Give You up to the NSA". TechCrunch. Retrieved 19 October 2015.
- ^ Suberg, William (30 June 2014). "ProtonMail collects over US$10,000 in BTC donations in 6 weeks". The Cointelegraph. Retrieved 19 October 2015.
- ^ http://motherboard.vice.com/en_ca/read/protonmail-the-easy-to-use-encrypted-email-service-opens-up-to-the-public
- ^ "Why Switzerland?". ProtonMail. 19 May 2014. Retrieved 19 October 2015.
- ^ "Fighting Censorship with ProtonMail Encrypted Email Over Tor". Protonmail. 19 January 2017. Retrieved 20 January 2017.
- ^ "ProtonMail now in Public Beta!!". ProtonMail. 16 May 2014. Retrieved 31 January 2016.
- ^ "Über-Secure ProtonMail Beta Maxes Out Servers in Just 60 Hours". Infosecurity Magazine. 22 May 2014. Retrieved 19 October 2015.
- ^ "ProtonMail". Indiegogo. 31 July 2014. Retrieved 19 October 2014.
- ^ Halfacree, Gareth (1 July 2014). "ProtonMail hit by PayPal account freeze". bit-tech. Retrieved 19 October 2015.
- ^ Howell O'Neill, Patrick (1 July 2014). "PayPal freezes account of email encryption startup ProtonMail [Update]". The Daily Dot. Retrieved 19 October 2015.
- ^ Yen, Andy (30 June 2014). "Paypal Freezes ProtonMail Campaign Funds". ProtonMail. Retrieved 19 October 2015.
- ^ Yen, Andy (18 March 2015). "ProtonMail has raised $2M USD to protect online privacy". ProtonMail. Retrieved 19 October 2015.
- ^ Yen, Andy (16 May 2014). "ProtonMail goes Open Source with version 2.0". ProtonMail. Retrieved 31 January 2016.
- ^ "Announcement: ProtonMail has launched worldwide! - ProtonMail Blog". 17 March 2016. Retrieved 21 July 2016.
- ^ "The ProtonMail Mobile Apps are about to get even better! - ProtonMail Blog". 22 April 2016. Retrieved 21 July 2016.
- ^ "Fighting Censorship with ProtonMail Encrypted Email Over Tor". 19 January 2017. Retrieved 27 January 2017.
- ^ Leyden, John (5 November 2015). "ProtonMail still under attack by DDoS bombardment". The Register. Retrieved 5 November 2015.
- ^ "DDOS Update". ProtonMail. 5 November 2015. Retrieved 5 November 2015.
- ^ a b "ProtonMail Statement about the DDOS Attack". ProtonMail. 5 November 2015. Retrieved 5 November 2015.
- ^ "Armada Collective Blackmails Swiss Hosting Providers". Swiss Governmental Computer Emergency Response Team. 22 September 2015. Retrieved 6 November 2015.
- ^ Fox-Brewster, Thomas (5 November 2015). "ProtonMail Pays Crooks $6,000 in Bitcoin to Cease DDoS Bombardment". Forbes. Retrieved 5 November 2015.
- ^ @ProtonMail (5 November 2015). "We are seeking a datacenter in Switzerland brave enough to host ProtonMail, many are afraid due to the magnitude of the attack against us" (Tweet) – via Twitter.
- ^ a b "How are ProtonMail keys distributed?". Stackexchange. 22 May 2014. Retrieved 19 October 2015.
- ^ Khandelwal, Swati (26 May 2014). "ProtonMail: 'NSA-Proof' End-to-End Encrypted Email Service". The Hacker News. Retrieved 19 October 2015.
- ^ "SSL Certificate Update". Qualys SSL Labs. 19 January 2016. Retrieved 31 January 2016.
- ^ "SSL Report: protonmail.com". Qualys SSL Labs. 7 March 2016. Retrieved 7 March 2016.
- ^ "ProtonMail adds Facebook PGP integration". ProtonMail. 22 September 2015. Retrieved 19 October 2015.
- ^ a b "ProtonMail Security Details". ProtonMail. 31 January 2016. Retrieved 31 January 2016.
- ^ "Two Factor Authentication".
Setting up Two Factor Authentication in ProtonMail
- ^ "ProtonMail Composer". Retrieved 31 January 2016.
- ^ "How to change the layout of the inbox". Retrieved 31 January 2016.
- ^ "Official AngularJS Web Client for ProtonMail". Github. 31 January 2016. Retrieved 31 January 2016.
- ^ Patterson, Dan (13 November 2015). "Exclusive: Inside the ProtonMail siege: how two small companies fought off one of Europe's largest DDoS attacks". TechRepublic. Retrieved 31 January 2016.
- ^ "Datacenter Attinhausen". SRF. 5 September 2012. Retrieved 19 February 2016.
- ^ "Why Switzerland?". 19 May 2014. Retrieved 31 January 2016.
- ^ Yen, Andy (17 December 2014). "Infrastructure Upgrades". ProtonMail. Retrieved 19 October 2015.
- ^ Yen, Andy (17 December 2014). "ProtonMail joins Réseaux IP Européens (RIPE NCC)". ProtonMail. Retrieved 19 October 2015.
- ^ https://protonmail.com/signup