• sugar_in_your_tea@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    11 days ago

    I don’t think that’s true. They can always do PGP on the client after decrypting the email (so double-encrypt). It’s also not particularly interesting because almost nobody uses PGP. It’s a design decision that I’m not a big fan of, but if they’re legally obligated to maintain my privacy, maybe I’m okay with it. I’ll give it some time and see how that pans out.

    • AProfessional@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      11 days ago

      OpenPGP is actively supported by dozens of clients, they cannot and do not encrypt subjects, so Proton chose to be compatible with that. I think dismissing cross-compatibility because of a hand wave “nobody uses it” isn’t very productive either.

      • sugar_in_your_tea@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        1
        ·
        11 days ago

        AFAIK, PGP is only automatically used in emails to other Proton users, you need to do it manually if you want to communicate with someone else with PGP (or use the secure email thing, which does it on Proton’s servers). So the PGP is largely just an implementation detail in how they store it, unless you’re communicating with a lot of other Proton users.

        Then again, it’s been a couple years since I used Proton, so I don’t know if things have changed. But since nobody I contact uses Proton or Tuta, it’s irrelevant that Proton uses PGP. If I use PGP, I’d do it myself regardless.