protonmail github addition discussion #2278

Closed
opened 2021-05-03 05:30:47 +00:00 by zivian · 8 comments
zivian commented 2021-05-03 05:30:47 +00:00 (Migrated from github.com)

i am unable to find discussion about protonmail. where is it?
"Software Suggestion | ctemplar" which taugt a lot of things.

i am unable to find discussion about protonmail. where is it? "Software Suggestion | ctemplar" which taugt a lot of things.
zivian commented 2021-05-03 06:39:38 +00:00 (Migrated from github.com)

i am wondering why it is still supporting tls 1.0 & 1.1

i am wondering why it is still supporting [tls 1.0 & 1.1](https://internet.nl/mail/protonmail.com/523386/#control-panel-14)
dngray commented 2021-05-04 03:18:38 +00:00 (Migrated from github.com)

i am unable to find discussion about protonmail. where is it?

It was added a long time, ago. The discussion would have been in the re-vamp PR https://github.com/privacytools/privacytools.io/pull/1672

> i am unable to find discussion about protonmail. where is it? It was added a long time, ago. The discussion would have been in the re-vamp PR https://github.com/privacytools/privacytools.io/pull/1672
dngray commented 2021-05-04 03:20:11 +00:00 (Migrated from github.com)

i am wondering why it is still supporting tls 1.0 & 1.1

They do, but there is a server suite preference so, unless the remote email server talks nothing else, it will use newer: https://www.hardenize.com/report/protonmail.com/1620012644#email_tls

> i am wondering why it is still supporting [tls 1.0 & 1.1](https://internet.nl/mail/protonmail.com/523386/#control-panel-14) They do, but there is a server suite preference so, unless the remote email server talks nothing else, it will use newer: https://www.hardenize.com/report/protonmail.com/1620012644#email_tls
zivian commented 2021-05-04 10:47:45 +00:00 (Migrated from github.com)

@dngray unless the remote email server talks nothing else no comments (i have zero knowledge here)

but Content Security Policy Feature not implemented or disabled. Your server doesn't support this feature. this is worrying me.

@dngray `unless the remote email server talks nothing else` no comments (i have zero knowledge here) but **Content Security Policy** `Feature not implemented or disabled. Your server doesn't support this feature. ` this is worrying me.
rusty-snake commented 2021-05-04 11:00:11 +00:00 (Migrated from github.com)

but Content Security Policy Feature not implemented or disabled. Your server doesn't support this feature. this is worrying me.

https://mail.protonmail.com/login has a CSP

> but Content Security Policy Feature not implemented or disabled. Your server doesn't support this feature. this is worrying me. `https://mail.protonmail.com/login` has a CSP
zivian commented 2021-05-05 05:38:53 +00:00 (Migrated from github.com)

@rusty-snake login is only important? all other things unimportant?

@rusty-snake login is only important? all other things unimportant?
rusty-snake commented 2021-05-05 07:13:17 +00:00 (Migrated from github.com)

Every page of https://mail.protonmail.com/ I tested (login, inbox, create/new) has a csp.
Every page of https://protonmail.com/ I tested (like blog) has no csp.

AV https://mail.protonmail.com/: High, untrusted (but sanitized) HTML/CSS of email
AV https://protonmail.com/: Low

Impact https://mail.protonmail.com/: High, emails, password, your personal data, ...
Impact https://protonmail.com/: Low

Every page of `https://mail.protonmail.com/` I tested (login, inbox, create/new) has a csp. Every page of `https://protonmail.com/` I tested (like blog) has no csp. AV `https://mail.protonmail.com/`: High, untrusted (but sanitized) HTML/CSS of email AV `https://protonmail.com/`: Low Impact `https://mail.protonmail.com/`: High, emails, password, your personal data, ... Impact `https://protonmail.com/`: Low
zivian commented 2021-05-06 03:11:06 +00:00 (Migrated from github.com)

@rusty-snake thank you. i am still learning so stupid questions.

@rusty-snake thank you. i am still learning so stupid questions.
This repo is archived. You cannot comment on issues.
No Milestone
No Assignees
1 Participants
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: privacyguides/privacytools.io#2278
No description provided.