Are you all using proton stuff? Can we trust to register your entire private life to them?

I think the main contention here was this statement of yours. But let’s drop it now.

No, I read the whole thing. Anyway, refer to what @anon57862721 said.

I primarily use Proton for their email, VPN, and calendar. I don’t do a ton of cloud storage but I do have some important stuff saved on my drive. I have not used any of their other products. For my password manager I use Bitwarden for my password manager, and I use SimpleLogin (technically now a Proton product) for disposable email addresses. I also have an email address with Tutanota which I haven’t used too much yet, but I got my account name secured incase I decide to start using it.

If you didn’t know, you get all of Simplelogin and more if you used Proton Pass Plus instead. But you also get Proton Pass Plus if you pay for Simplelogin. So, perhaps check it out to see if PP meets your needs and save a little (even though $10 may not be much) if you move to Proton Pass for all your credential management needs.

You are misunderstanding. Quantum computing will not break the data at rest encryption at all. This is a big misconception. Quantum computing is only a real risk for encryption in transit for which many are already having or taking the right mitigations.

No. I use Proton only for email and VPN.

It looks like Proton Mail uses AES256 (symmetric key encryption a.k.a. cipher), ed25519 (public key signing) and cv25519 (public key encryption) algorithms by default.

The best known theoretical quantum attack of AES256 is Grover’s algorithm which can search an unsorted database of N entries in O(√N) operations. An attack on AES256 using Grover’s algorithm would be as successful as a brute-force attack on AES128. If AES128 is considered secure against conventional attack methods then AES256 should be considered quantum resistant. I would consider 2^128 operations (worst case) to attack AES256 is secure enough. AES256 is believed to be quantum resistant and GnuPG has a --require-pqc-encryption flag that enforces AES256 use.

Public key cryptography appears to be a different story, more prone to quantum attacks. There has been activity (Signal 1, Signal 2, Tuta) to transition to quantum-resistant public key algorithms. To my knowledge Proton Mail (based on OpenPGP) has not yet adopted a quantum-resistant public key encryption algorithm. AFAICT while Proton Mail stores emails using AES256 by default, if public key cryptography (let’s say it’s cv25519) is used to encrypt an email, it may be theoretically possible to use some kind of quantum attack to extract the symmetric key from the encrypted packet (cv25519) that protects the symmetric key, then use that key to decrypt the email (AES256).

… even for AES-128, the practical security impact of Grover with existing techniques
on plausible near-term quantum hardware is limited.

Also this is being sorted:

I’ve used Bitwarden longer than I have SimpleLogin so my flag was already staked there. I know its fairly easy to switch but I don’t want to put all my eggs in one basket with Proton, hence why I keep a few alternative products in my toolbox (Bitwarden, Tutanota)

Hopefully:

  • Proton can be used for a few of those
  • while other trustworthy companies full-fill the gap of features for the rest
  • and if you feel adventurous, self-hosting can go a long way too

With all those 3, I think we covered all the use cases in a healthy way. :hugs: