Follow

since ProtonMail is basically wrapping on OpenPGP, why don't they just allow IMAP login for MUA with native OpenPGP support?

@ghost I always thought there's another layer of encryption applied to the entire inbox, But no?

@niconiconi no, metadata aren't covered by their e2ee. I understand the usability issue though, webclient doesn't download the entire inbox to search something

@leo_song @ghost I meant, I thought the individual mails are public key E2EEed, but the mailbox itself is symmetrically encrypted as a whole, and this was what made it incompatible with IMAP. But apparently I was mistaken... Yeah, my mistake was obvious in hindsight. If it was the case, even dynamically appending data is a problem.

@niconiconi @leo_song it's already wildly nested, you enter a symmetric password to retrieve an asymmetric secret key to retrieve a symmetric session key to retrieve the content

@leo_song @niconiconi metadata fields only. client-side content search was added just last year.

Sign in to participate in the conversation
Fairground

The social network of the future: No ads, no corporate surveillance, ethical design, and decentralization! Own your data with Mastodon!