> They're for people like you and me to reclaim a semblance of privacy, and they work even with "Uncle Sam" as the threat model in a limited, dragnet surveillance sense.They don't work, because the US government's modus operandi is compromising machines or forcing users to provide access to their encrypted data. It's unclear to me why, if you take as premise a government capable of forcing one of the most valuable organizations in the world to hand over its data, you believe a company several orders of magnitude smaller is safe because it's "end to end encrypted" and has servers in Switzerland.
Put another way, I find the concept of a government willing to force Google to give up data but unwilling to use operational vulnerabilities to achieve the same thing to be contrived - how is this not just an arbitrary line in the sand?
Furthermore, the heuristic itself is a red herring, in my opinion. It is far more likely that Protonmail has a critical security vulnerability inherent to its software than Gmail does. And even if we assume that the government doesn't want to spend economic resources on actively compromising you as an individual, why would the government not spend resources on a system to compromise you passively as part of an en masse campaign? In other words, are you using a custom built computer with parts designed by a boutique firm from another country immune to the wiles of government backdoors?
How do you decide where you want to stop down the rabbit hole, and are you really doing so empirically?