Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

AFIAK, Protonmail private keys are kept client-side. They are decrypted by the password inside the browser UI.


No. I just logged in to that very same account using different browser on a different computer. The email was displayed just fine.

Protonmail keeps generated public and private keys on their servers.


It keeps copies that your browser locally encrypted with a symmetric key derived from your password. When you log on your browser downloads them, and decrypts them with your password.

Protonmail do not see your password and without it cannot decrypt the pub/private key pair.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: