Skip to content
This repository has been archived by the owner on Jun 24, 2022. It is now read-only.

protonmail github addition discussion #2278

Closed
zivian opened this issue May 3, 2021 · 8 comments
Closed

protonmail github addition discussion #2278

zivian opened this issue May 3, 2021 · 8 comments

Comments

@zivian
Copy link

zivian commented May 3, 2021

i am unable to find discussion about protonmail. where is it?
"Software Suggestion | ctemplar" which taugt a lot of things.

@zivian
Copy link
Author

zivian commented May 3, 2021

i am wondering why it is still supporting tls 1.0 & 1.1

@dngray
Copy link
Collaborator

dngray commented May 4, 2021

i am unable to find discussion about protonmail. where is it?

It was added a long time, ago. The discussion would have been in the re-vamp PR #1672

@dngray
Copy link
Collaborator

dngray commented May 4, 2021

i am wondering why it is still supporting tls 1.0 & 1.1

They do, but there is a server suite preference so, unless the remote email server talks nothing else, it will use newer: https://www.hardenize.com/report/protonmail.com/1620012644#email_tls

@dngray dngray closed this as completed May 4, 2021
@zivian
Copy link
Author

zivian commented May 4, 2021

@dngray unless the remote email server talks nothing else no comments (i have zero knowledge here)

but Content Security Policy Feature not implemented or disabled. Your server doesn't support this feature. this is worrying me.

@rusty-snake
Copy link

but Content Security Policy Feature not implemented or disabled. Your server doesn't support this feature. this is worrying me.

https://mail.protonmail.com/login has a CSP

@zivian
Copy link
Author

zivian commented May 5, 2021

@rusty-snake login is only important? all other things unimportant?

@rusty-snake
Copy link

Every page of https://mail.protonmail.com/ I tested (login, inbox, create/new) has a csp.
Every page of https://protonmail.com/ I tested (like blog) has no csp.

AV https://mail.protonmail.com/: High, untrusted (but sanitized) HTML/CSS of email
AV https://protonmail.com/: Low

Impact https://mail.protonmail.com/: High, emails, password, your personal data, ...
Impact https://protonmail.com/: Low

@zivian
Copy link
Author

zivian commented May 6, 2021

@rusty-snake thank you. i am still learning so stupid questions.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

3 participants