Skip to content
TopicTracker
From HackerNewsView original
TranslationTranslation

Proton's crypto is not Transparent and not OPAQUE

The article argues Proton's authentication uses SRP, not truly transparent or OPAQUE cryptography, despite marketing claims. It explains that SRP reveals a password verifier to the server, unlike OPAQUE which fully hides the password from the server.

Background

- Proton is a Swiss company best known for Proton Mail, an encrypted email service. It also offers VPN, cloud storage, and other privacy-focused tools. - This post is part of a continuing debate between Proton and its critics about the trustworthiness of its encryption. The author, Marc Schärli, is a Swiss security engineer who has been publicly critical of Proton’s cryptographic choices. - The author argues that Proton’s new cryptographic protocol, which it calls “Transparent” (for password management) and “OPAQUE” (a related protocol), misleads users. OPAQUE is a real academic protocol, but the author claims Proton’s implementation is neither truly transparent nor OPAQUE-compliant, weakening the privacy guarantees users expect. - This matters because Proton markets itself as a privacy-first company; if its cryptography has flaws or deceptive naming, users may trust it with sensitive data under false assumptions. The debate reflects wider tensions between usable security, marketing, and cryptographic rigor.