Post got deleted, posts removed…

    • _cryptagion@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      54
      ·
      4 days ago

      They gave meta information like IP to the government in Switzerland, where they are based, after the government forced them to with a court order. Not the encrypted mail, mind you, because they can’t do that, just the additional information they have on a user like email and IP.

      Because of that, a lot of redditers on r/privacy think they spy on their users for the US government. It’s a stretch, yes, but you have to remember they take turns using the one brain they collectively have.

      • AnAmericanPotato@programming.dev
        link
        fedilink
        English
        arrow-up
        22
        ·
        4 days ago

        Not the encrypted mail, mind you, because they can’t do that

        Just want to point out for anyone new that ProtonMail does not use E2EE for email headers. That means they CAN access your subject lines, to/from fields, and other email headers. That means they CAN be forced to hand it over to the government.

        Source: https://proton.me/support/proton-mail-encryption-explained

        Subject lines and recipient/sender email addresses are encrypted but not end-to-end encrypted.

        Personally I am disappointed in a lot of Proton’s wording about this. They frequently promise they can’t access “your data” and “your messages” when they do, in fact, store potentially sensitive data in a format they CAN access.

        • jherazob@beehaw.org
          link
          fedilink
          English
          arrow-up
          7
          ·
          3 days ago

          It’s email, that’s the best you can get with email, if you want to have more privacy, DON’T USE EMAIL

          • AnAmericanPotato@programming.dev
            link
            fedilink
            English
            arrow-up
            3
            ·
            3 days ago

            This is good advice, because email is very difficult to make reliably private. However, it’s not the best you can get. Tutanota, for example, stores headers with E2EE, and still has a search function.

            The goal should be to make it as private as it can realistically be. Ideally, any cloud service you use should only store end-to-end encrypted data.

            I’m not trying to shit on Proton — it’s a huge step up from the popular mainstream email services, and the inclusion of cloud storage makes it a much easier transition than going piecemeal with 2-5 different services.

        • _cryptagion@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          4
          ·
          edit-2
          3 days ago

          A bit more context is important here. They aren’t E2EE, but they are stored encrypted. In the case of the person whose meta information was turned over, ProtonMail wasn’t forced to hand over the information right away, they were forced to collect it the next time that person accessed and used their email. That tells us that they didn’t store the information beforehand and could not access it without preparing to intercept it the next time their service was used.

          Ultimately, though, if something like that’s a dealbreaker, it’s likely you’re doing something that would benefit from a more secure way of communicating than email.

      • Sundial@lemm.ee
        link
        fedilink
        arrow-up
        14
        ·
        4 days ago

        Yeah I agree, sounds a bit excessive. If that’s correct, it doesn’t sound like they’re reading your data and at the end of the day they have to comply with things like warrants. Thanks for the clarification.

        • underwire212@lemm.ee
          link
          fedilink
          arrow-up
          13
          ·
          4 days ago

          It is all also very clearly stated in the information they must collect in order to provide their service. There should’ve been no surprises here, as you must assume that scenarios like these will happen eventually.

      • SeekPie@lemm.ee
        link
        fedilink
        arrow-up
        7
        ·
        4 days ago

        If all they have on you is your optional backup email and your IP, I think they’re doing pretty well in the no data-collecting part?

        • _cryptagion@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          7
          ·
          4 days ago

          Well, you don’t even need to provide an email or phone number when you sign up, so if you access the site via their onion address every time, they would have no information on you at all.

      • bumpusoot [any]@hexbear.net
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        3 days ago

        But… basically every email provider or hosting service is legally obliged to give the information they collect to the government. It’s not like this is exclusive to Proton in any way whatsoever. If anything, subpoenas are evidence Proton tell the truth and do at least stop themselves from having most of the important data so they can’t give it away.

      • EngineerGaming@feddit.nl
        link
        fedilink
        arrow-up
        3
        ·
        4 days ago

        I guess the issue here is overselling the safety of the service. Wouldn’t rely on them encrypting the mail for you, for example. It’s probably fine if you treat it just like you would any other email service - assuming you’re fine with being unable to use a mail client at all on the free plan and using it in a weird roundabout way on the paid plans.

        • ReversalHatchery@beehaw.org
          link
          fedilink
          English
          arrow-up
          6
          ·
          4 days ago

          the issue is that they can’t defy the law without shutting down and going into jail. proton has given the tool the activist would have needed to protect themselves: the service has an official onion site, which would have made IP collection impossible, and they could have just said they can’t know it

          • EngineerGaming@feddit.nl
            link
            fedilink
            arrow-up
            2
            ·
            edit-2
            4 days ago

            Yes, that was exactly my point. You would not treat any mail service like they would cover you during your unprotected use, and Proton is not an exception. So I don’t understand why people are taking issue with them cooperating with LE - but I take issue with some other qualities.

            • ReversalHatchery@beehaw.org
              link
              fedilink
              English
              arrow-up
              2
              ·
              4 days ago

              So I don’t understand why people are taking issue with them cooperating with LE

              some believe they (proton) are invincible and can do whatever they want. maybe because they think that’s what swiss privacy and swiss laws mean

    • drkt@scribe.disroot.org
      link
      fedilink
      English
      arrow-up
      5
      arrow-down
      1
      ·
      4 days ago

      Privacy wise? Probably nothing. The company engages in shitty behavior, though, and will try to upsell you even if you’re a paying costumer. I switched to Tuta because of that, and then Tuta started doing all the same bs…

    • Batadon@lemm.ee
      link
      fedilink
      arrow-up
      4
      ·
      4 days ago

      I don’t think OP was trying to say Proton Mail is bad or insecure. Rather the opposite.