• 1 Post
  • 45 Comments
Joined 1 year ago
cake
Cake day: June 5th, 2023

help-circle









  • After reading that post and the linked github issues, with the latest updates and comments from the last 24 hours. Here’s the TL;DR:

    • This is only relevant if you want to use an email client with Proton Bridge.
    • If you’re just using Proton for encryption and signing (you can use the same PGP outside of proton too) then there is no issue at all.
    • If you want an external tool (like a hardware yubikey) to decrypt your messages that someone else has sent to you using the public key that corresponds to the external tool there will be signature validation shenanigans. This is because Proton expects to be the only entity doing any encryption.This is an important issue for those that need to send encrypted emails (and signatures) with specific keys.
    • It is not an issue for anyone using Proton email for a secure email service even if they want to use an external email client on desktop (like Thunderbird) with Proton Bridge.

    Please correct me if I missed something.

    CC: @[email protected]



  • Re: port-forwarding, I used traefik as a reverse proxy and that worked well (having a single domain cert instead of per service DNS is another layer but it’s just obfuscation), but it’s always a risk. I finally started using Tailscale after hearing about it for years and it is actually very good and deserves the hype. I had meant to setup wireguard myself but this is a lot easier. And if you don’t want to use tailscale server, you can run headscale (on a cheap VPS?) instead.