Oddbean new post about | logout
 You need to use an email client with pgp support such as thunderbird (with the enigma extension) or if you're comfortable with a terminal app you can use aerc, mutt or neomutt.

There are probably more but I don't know them. 
 Interesting. I thought proton didnt allow sign in to other clients. Must be new? 
 You asked from gmail.
With proton all that is done automatically no matter which client you use (app, web or thirdparty using Proton Bridge). 
 I said to gmail from my proton

@nostr:nevent1qqsy6svs7elgwt4yu3jts4uzmfppj7evpecnm6svhgcnawg4ugrcs4spz3mhxue69uhhyetvv9ujuerpd46hxtnfdupzq5t2m5v6scdz7s5uejyrleejgvte655cyjxgyltgltlgytnf0sq5qvzqqqqqqydpyfry 
 Sorry misunderstood.
Gmail user needs to setup pgp on another client before they can receive pgp email from a proton user.
Tuta users cannot do that as their encryption scheme is not pgp compliant.
. 
 If you and your recipient are capable to use pgp then don't use protonmail. Just use regular e-mail provider even Gmail.

Bear in mind that Protonmail officially scans all unencrypted e-mails.

 
 The difference is protonmail encrypts it at rest with private keys under your exclusive control.

They can only scan unencrypted emails while they are in-transit (same as any other provider) which they obviously use for spam detection.

The value of protonmail is precisely encryption-at-rest combined with automatic open pgp encryption. 
 What's the difference? They scan all encrypted e-mails before they "encrypt" them with private keys without password which they keep.

 
 The private key you import/generate is encrypted clientside with your password (which is also only known clientside, since serverside only sees the salted hash).

Email is inherently insecure and non-private. I don't know exactly what your point is. Protonmail takes steps to improve the situation as much as possible but you still claim that it's better to just use gmail. 
 First of all what is the purpose of importing the key?

I can generate my key and export it to Protonmail. 
 That's what I meant by "importing". You can import your local gpg key into PM, or if you change your reference frame, you are exporting it from your OS to PM. 
 I agree with you. E-mail is a history.

The point is that Protonmail and Tutanota have nothing in common with privacy and security. They use those words to fool people. It's marketing.

If you are capable to use pgp, it's better to use it in yahoo, gmail or other email provider with pop3 imap access. 
 Disagree. At least with those providers you have encryption at rest and with PM you can also use pgp.

You can claim that is "privacy theatre" since they can clone and archive unencrypted emails in-transit. True.

But doing that severely goes against their business model, specially when you are a paying customer. It is a trusted relationship in that respect, but at least the incentives are on your side.

Using gmail or other mainstream providers is strictly worse in every way. And you know that they are actively scanning your unencrypted emails not just for spam prevention, but to sell your data and to give your up to Law Enforcement.

 
 I know the rest about proton. That was my point. Its encrypted.