Climate activist arrested after ProtonMail provided his IP address
twitter.com
twitter.com
Their homepage says "By default, we do not keep any IP logs"
In 2021, any soft language like this should be a red flag for anyone who is against surveillance. Maybe in 2018 it was good enough. But in 2021 it's not. Come on, Protonmail, you're supposed to be leading the way -- don't make me figure it out myself.
Replace immediately with "By default we don't log IP, but may be required to by local law enforcement. We recommend everyone connect through Protonmail through Tor. This month, 60% of our users connected through Tor".
but...
I live in Australia - and they're totally fucked by our laws and government policy.
"The Australian Federal Police (AFP) and Australian Criminal Intelligence Commission (ACIC) will now be able to access the computers and networks of those suspected of conducting criminal activity online, and even take over their online accounts covertly, under the Identify and Disrupt bill, which was passed by the Senate on Wednesday." -- https://www.innovationaus.com/extraordinary-new-hacking-powe...
and:
"Amends: the Surveillance Devices Act 2004 and Telecommunications (Interception and Access) Act 1979 to: introduce data disruption warrants to enable the Australian Federal Police (AFP) and the Australian Criminal Intelligence Commission (ACIC) to disrupt data by modifying, adding, copying or deleting data in order to frustrate the commission of serious offences online; and make minor technical corrections; " -- https://www.aph.gov.au/Parliamentary_Business/Bills_Legislat...
Fastmail's privacy page says "Your data is for you and no one else".[1] So they do mislead about that. I didn't see anything about IP logs though. And Fastmail was just an example.
The privacy violation of creating a profile on me based on my mail to tailor ads is not the same thing as simply delivering mail.
I don't see how you could go "yeah, this is a privacy improvement" if your information is still visible to exactly the same entities, but one of them isn't really mentioning it.
Imagine you have a message written on a piece of paper. You intentionally show this message to two people, Alice and Bob, and are fully aware that they have both read and can perfectly remember the entire contents of the message.
Now imagine that Alice thought about the message independently (not recalling it, but actually thinking new thoughts), and that Bob did not do this.
Are you claiming that Alice violated your privacy by thinking about something you showed her and asked her to remember? Or perhaps would it only be a violation of privacy if she then subsequently told you one of those thoughts?
I was hoping to achieve a "yes" or "no", to at least one of the two questions. I don't know what GP thinks "scan" means when describing how a computer processes text, and was hoping that an analogy to a more natural concept would allow for that to be made clear. What's the actual action being taken that's the violation? It's clearly not simply being able to read the message, but is it "thinking" about it (for lack of a better word)? That's how I interpreted the initial comment, but it seems very reactionary, so I wanted to make sure I understood it.
> People want to be able to have a private email correspondence about, for instance, dildos, and then not have to be served dildo ads outside of that context.
Totally fair, but that's no longer about privacy (unless your concern is someone else watching your monitor over your shoulder, in which case that person is the one breaking your privacy).
I would entertain the idea that friend A is being a bit of a douchebag by painting stuff all over your house without you asking them to, but if you subscribe to that thought process you'd already be running an ad-blocker and this scenario wouldn't ever occur in the first place.
So to be 100% clear on this: if you tell someone information, and they think about that information, that's a violation of your privacy?
I've definitely always assumed that the right to think about information is intrinsically coupled with the right to know about that information. I wouldn't give someone data that I didn't want them to think about.
> for possible future use and abuse
This is a completely reasonable concern to hold, but surely "they could possibly do something bad later" applies to every email provider in existence.
If your phone began analyzing your local photos for child porn, you'd probably be upset, no?
>This is a completely reasonable concern to hold, but surely "they could possibly do something bad later" applies to every email provider in existence.
True, but google is CURRENTLY abusing it by selling ads to me based on it.
Yep. "local" here is the key word, though. If a service I uploaded photos to began doing that, I would not be upset. And indeed, just about every image-hosting website in existence already does this, because they're legally required to.
Gmail is markedly not a local service.
> True, but google is CURRENTLY abusing it by selling ads to me based on it.
This makes it seem like your concern is with the advertisement funding model, not with privacy.
I do not see any difference between these parts, no. If a human read my email I would expect them to be completely incapable of not working these things out, so I'm not really too concerned if a computer does it either.
> training a ML algorithm on it
Also not really. If it were a machine learning algorithm that was trying to write realistic emails there'd be a reasonable concern of it revealing things about the training data, but when it's just generating ad recommendations based on only your data that only you see, I'm not too sure there's a serious privacy concern there. I'm unaware of any allegations that you could uncover private details about someone else's life by looking at an advertisement you received on your own email inbox.
> and automatically propagating that to other google products?
I would definitely perceive this differently depending on the product, as Google products are usually distinct enough that you can functionally treat them as if they were different companies (and often they either used to be, or eventually become so). So in this case there are now four entities that know the contents of the email: the sender, the recipient, Gmail, and e.g., YouTube.
But again, I've not heard any claims that Google are using the contents of your emails to decide what YouTube videos to recommend you. It's certainly not outside the realms of plausibility, but that seems like the kind of thing people wouldn't ever shut up about, so I'm surprised that I haven't heard about it if it is in fact happening.
> you can sure as hell know that they build an extensive profile out of your private emails
Oh absolutely, but I don't see how that's a privacy violation when you gave them your private emails. How much thinking does someone have to do about a message you gave them before it becomes a privacy violation?
> and your ads are targeted based on that..
This is the main reason I'm okay with it. Google's entire business model relies on them preventing anyone else from seeing that data, so that they're the only ones who can target ads that effectively. If there was a significant risk of data leaks then I can absolutely see why people would be concerned, but Google has some absolutely gargantuan incentives to avoid that.
With Gmail/Hotmail/etc your communication are at the finger tips of governments for non-criminal domestic surveillance. For example it has been alleged that the NSA leaked private emails of a journalist in order to score political damage.
https://nypost.com/2021/08/11/tucker-carlson-unmasking-claim...
In fact, it turned 15 years old this past April[3].
[1] https://www.rsync.net/resources/notices/canary.txt
I was referring to Protonmail's canary specifically, in the event that wasn't clear.
In 2021 the most powerful canary statement should be "Don't trust us. Seriously, treat us as an adversary. We still want you to be our customer of course, but here's how we really recommend you use our service, Tor, semi-anonymous payments, etc. In God we trust, for everyone else use math."
Would love to sign up for some Tor-first services. So far the best we've got are Tor services that mirror public ones.
I admit that the marketing is bad, I do not agree with it, and I do not tolerate it in terms of my own OPSEC. But, there's just no way they would just admit they provide hardly any value besides, in a VPN's example, being a tube to another place, and just another tube with ends that can be stopped.
What is far less clear is if you can trust the continuation of a canary statement to indicate the absence of the action it denies, since it is both legally disputed whether continuation of the statement could be mandated by government and because anyone who has an interest in the PR value of providing a canary statement also potentially has the same interest in continuing it as long as it is impractical to falsify.
Is compelled speech seriously in jeopardy? I saw the github issue for signal saying that some (EFF?) lawyers said that canaries are not that helpful, but that just implies that the government CAN compel speech. That would be bigger news than mentioned as an aside on a Github issue, I'd like to believe that would be news...
For the non-Swiss customers working with a Swiss provider can be a good enough protection to avoid inconvenience of Tor. After all, even in the mentioned case it required review and approval of 3 agencies before request came to Proton - from French police, from Europol, and then from Swiss authorities. If this is not enough barriers to protect from politically motivated prosecutions and corruption, then we have much bigger problem in Europe.
In general, regardless of what their TOS say, never believe that a corporation can't be compelled by the law to do anything they could physically do. CEOs can be jailed; when's the last time we heard of one actually going to jail over user privacy?
Ladar Levison from Lavabit came close. But even he admits that was because the FBI wanted to subvert every single Lavabit user's account (attempting vast overreach on the brazen assumption that "we are after Snowden" was going to pull the wool over everybody's eyes). Levison admits though, to having "responded to" at least two dozen subpoenas and complied with at least one warrant before.
https://en.wikipedia.org/wiki/Lavabit#Suspension_and_gag_ord...
The „opt-in“ part for login logs is particularly interesting, because in fact Proton recommends this as a security best practice. Whether it’s in the best interest of the customer or not, it’s an open question. I would say, in a risk model, where threat of human rights violation by Swiss government is much lower than risks of unauthorized party accessing the account, it makes sense. Tough luck for the criminals that followed this advice.
https://en.wikipedia.org/wiki/Histiaeus#Ionian_revolt_(499-4...
Sure the bitrate is a bit slow and it's UDP only but our governments have proved over and over again that they can't learn from history.
Since this was a trusted slave, the tattoo seems unnecessary. The slave could just tell Aristagoras "Histiaeus says to revolt against the Persians".
There was enough trust that the slave did not desert and that they were taking the message to the destination.
There was not enough trust that the slave would actually know the CONTENT of the message. As such the slave wouldn't even know to where to desert to :)
that way the govt can demand from reddit that account ip but since the only ip available is from outside india, they cant do shit.
i was ready to dictate base64 image character by character but the internet blockade remained for only 2 days so yeah. there are plenty of ways
Oppressive government?
Right from a recent court filing, search warrant.
Really, it's a phrase that means 3 things: I can enable it, ProtonMail can enable it[0], or the authorities can compel ProtonMail to enable it.
Saying any of that, or at least linking to a page that does, would be a smart move.
[0] https://protonmail.com/privacy-policy - "IP logs may be kept temporarily to combat abuse and fraud, and your IP address may be retained permanently if you are engaged in activities that breach our terms and conditions"
https://twitter.com/OnEstLaTech/status/1434576598418796549?t...
The proposed statement above is intended to help people like that.
Do I have such activities? Nope. But I believe that those activities should be enabled, whether for me in the future or others around the world.
I advocate on behalf such "dumb" people by supporting simple services like Protonmail with my money. If Protonmail isn't supporting these users, why should I bother supporting Protonmail?
To use your example of emailing the police chief: let's say your threat profile is that you're being stalked by a criminal, and you want to email the police to give them information on this crime, but you don't want the criminal to know. If the criminal breaks into your email, or if your house is broken into and a hidden camera is placed behind your computer, it makes little difference whether you have end-to-end encryption or not, your privacy is still violated. Does that explain it better? Maybe Proton could have some better messaging around this, if their customers are getting privacy and security confused?
Security and privacy are intertwined, imagine your server getting hacked (security problem) leading to your private documents being exposed on the internet (privacy violation).
The former's safe because no one's going to deliver IPs to Afghanistan and the latter are doomed, because the US and China are following a policy of total surveillance. That ship has sailed decades ago.
At the same time, Tor is not the only, the required and the sufficient way to ensure privacy. There are different circumstances requiring different approaches. In many cases Tor will be redundant, in some cases it may be impossible to use, will offer insufficient protection or will actually put the person in an immediate danger, so giving this kind of advice is at least equally harmful as not having full disclosure on logs.
US military personell and from other nations is posting on TikTok. At least those probably don't work in reconnaissance.
They aren't stupid and this isn't a technical problem, it is a legislative problem. Real security has been undermined since the early 2000 and before. Western powers just ape China or Russia at this point.
That the Swiss people gave authorities these surveillance capabilities is pretty stupid though. Alpine air must have been pretty thin that day.
https://paris-luttes.info/communique-sur-l-affaire-de-la-145...
Looks like your run of the mill radical left occupation of housing (the stuff you see in big European cities like Berlin and Paris where they have that tradition).
Their bouts with law enforcement trying to evict them could be the reason for the arrests. If the google translate is not completely misleading then they refused to give their names or fingerprints when initially arrested.
https://twitter.com/MetPoliceEvents/status/14342276656791429...
These seem to have been climate activists engaging in sit-ins.
Surely these are the very sorts of people that secure accounts are intended to protect?
Well, in this case isn't it clear that these barriers were in fact not enough? Or do you think anti-squatting is a major enough problem that it warranted this level of international cooperation, without any politically motivated thinking?
From what I understand, connecting to an onion address 'just' involves 6 routers, not the typical 3. (Of course an oversimplification.)
Or am I misunderstanding your threat model here?
Even though they claim no identity is required to register.
I confirmed this today when I created a fresh Protonmal account over Tor: https://news.ycombinator.com/item?id=28428092
If they don't provide it, someone else will, and I'll pay them instead. This isn't the Hotmail age where everyone expects free email.
It totally is.
I was running my own mail server for a while. The thing that finally pushed me into not bothering any more was when I looked at my logs and realised 82% of my non-spam non-marketing email was captured by google (where at least one recipient was either @gmail.com or a gsuite custom domain).
Protonmail does offer a free tier, which is the problem. I'm sure they would be happy to take a payment instead, as the whole point of phone verification is to impose a cost on account creation. Perhaps they can rework their account registration flow to offer the ability to upgrade to a paid account at the verification step.
Anonymity toward state actors is compromised in either situation, whether phone verification or payment validation.
Doubt I'm the only one who thinks this, but the value proposition of their service is cancelled by their stated terms, which at least they make available. I have similar doubts about the veracity of claims by VPN providers (including mine) in terms of not keeping logs.
tor remains the only usable anonymising method with a decent track record. It's a shame Protonmail discriminates against it.
Are you human?
If you are having trouble creating your account, please request an invitation and we will respond within one business day. Request an inviteI have two - both on MVNOs, not in my name, and sitting in my office doing nothing but relaying sms to email:
But the mule only gives you some extra functionality, resilience, and is like having an email address just for spam or a home VPN endpoint. It gives you very little in terms of anonimity, which is why you'd go to Tor anyway. It's still in your proximity even if it's not in your name so anyone able to obtain your IPs from the services you use would also be able to get the location of your mule. And you forward to your own mail server which again does little to hide anything. That's a long traceable chain that can be compromised or at least broken (to force you out) at every link.
This is great to make sure companies don't sell your phone number or use it to create some social graph, and to access your accounts independent of your normal phone. But if you're looking to hide your identity or location from your service provider and the authorities then it's barely a speedbump.
My threat model is not state level actors or law enforcement. My threat model is simply individuals working at providers I use that get curious and go hunting for my traffic. So, for instance, someone that works at my ISP or for my cellular provider or (github/twilio/twitter).
I don't want these private actors to see my name or my phone number. However, VOIP numbers are typically blocked by providers for purposes of authentication and security because they need you to "burn" an actual SIM card number just to incur costs on you. This is their blunt response to a rather difficult spam/scam problem that would just explode if no costs were involved.
...
My use-case is that I don't want to carry around three phones everywhere I go and eSIMs don't work for these functions (again, their numbers are often discriminated against). I also don't want a single SIM card to correlate across multiple providers - that is why I have three (one personal SIM (not in my name) and two "mule" SIMs).
...
"It's still in your proximity even if it's not in your name so anyone able to obtain your IPs from the services you use would also be able to get the location of your mule."
No, they are rarely in my proximity. In fact, at this moment they are 12000 miles away from me. I keep them at my office and might move them to a datacenter ... but only if I can convert them from a phone form factor to a rpi-with-cellular-hat form factor ... or maybe ssh into the phone ?
Well, remember - their interactions with these 2FA Mules are SMS only - there is no IP/network connection made here. So the providers, at least, don't have an IP address to look up. Also, in case it is not obvious, I fully control my entire mail and dns infrastructure - as in, I own the machines and rent the racks.
They provide protection from your local network, but you they can do all the same things and more.
My VPN provider is not - but is obviously subject to their local laws. Which are almost certainly also not good for my privacy either.
Spreading the threat across two different jurisdictions is without doubt "somehow better" than just using my ISP, at least in the case of protection against snooping by non serious crime law enforcement.
(Where I am, organisations like local councils, the taxi commission, fishing inspectors, and dog catchers - can all access our "mandatory telecommunications metal data retention" stuff with very little oversight... While my VPN is still in five eyes, so there's no point pretending national security, intelligence, or serious crime like terrorism/drugtrafficing would have no trouble getting cross jurisdictional access, I'm pretty sure the fishing inspectors or dog catchers won't have that sort of access.)
I don't know where things stand with other browsers.
My ISP mines my data and sells it to the highest bidder despite costs not coming down.
My ISP determines what I can look at and can't (such as torrent sites).
My ISP is participating in anti-competitive behavior and I need the internet but I don't have a meaningful way to tell them to fuck off.
My VPN doesn't log. My VPN doesn't filter my traffic. My VPN reduces what my ISP can know about me and monetize me. My VPN allows me to access sites appearing in different countries or as a different user which changes what content websites serve to me, including price of products.
VPNs are a soft security practice, but one hell of a way to tell your ISP to fuck off. I think there's this group of people that say "oh, a security feature isn't bullet proof, therefore it is useless." But this is just dumb. All security features are probabilistic in nature and depend not only on how you use them, but your threat model and the will of your adversary. For people, like me, trying to escape dragnet operations VPNs do help. But alone they aren't enough and that's okay.
I just want to prevent my ISP from throttling my torrents.
You really can't talk about the "use" of any of these tools without a threat model.
Is the parent suggesting that no one should bother to read the Terms and Privacy Policy, linked to from the homepage. https://protonmail.com/privacy-policy
Despite the parent's claim, the Privacy Policy says the company may log IP address. Temporarily. Irrespective of any request from local authorities regarding a specific user. IOW, they may log anyone's IP address temporarily regardless of whether the particular user is casuing trouble; they can log IP address for everyone. The policy says they log this data for the purposes of preventing fraud and abuse. The problem for privacy-conscious users is that if they log the data, then that entices authorities to try to successfully request it.
The policy, which imposes no obligations on the company BTW, reads as follows:
"IP Logging: By default, we do not keep permanent IP logs in relation with your use of the Services. However, IP logs may be kept temporarily to combat abuse and fraud, and your IP address may be retained permanently if you are engaged in activities that breach our terms and conditions (spamming, DDoS attacks against our infrastructure, brute force attacks, etc). The legal basis of this processing is our legitimate interest to protect our Services against nefarious activities."
There is nothing that says "By default we do not retain any logs". This clearly states they may be expected to retain IP logs. ("IP logs may be kept temporarily...")
But wait there's more.
"We will only disclose the limited user data we possess if we are instructed to do so by a fully binding request coming from the competent Swiss authorities (legal obligation)."
This clearly states the company may disclose the data they possess, e.g., IP logs collected to combat fraud and abuse, if in response to a request from competent local authorities.
Further down is a curious statement about decrypting messages.
"If a request is made for encrypted message content that we do not possess the ability to decrypt, the fully encrypted message content may be turned over."
Why include a statement such as this, specifically the part that says "that we do not possess the ability to decrypt". The company already specified it may disclose the data it possesses. This further statement suggests there could be some situation where they may have the ability to decrypt some messages. Besides their own communications with customers, why would they ever have encrypted messages that they can decrypt. They could state something like "If the request is made for encrypted communications addressed to us or sent by us, ...", but they do not. As such, their statement must include other messages, too.
Just how transient do logs need to be to fit this criteria?
Am guessing the 7 years or so we need for some of our specific logs might fit the temporary definition too.....
This is the way most tech company "Privacy Policies" are written.
There is a significant difference between a statement such as "We (Company) do not do X" versus a promise such as "Company shall not do X" or a statement such as "We do Y. We may do Z" versus a promise such as "Company shall do Y."
Why not have our own "Policies" as users that we publish for tech companies to read. In them, we could describe what we do and what we do not do, and what we may or may not do. Tech companies could rely on these statements. You can see how silly that sounds. Yet users are expected to read and rely on hundreds of different "privacy policies", collection of non-binding statements like "We take privacy seriously".
Edit: And amusingly it only gives protonmail.com a B.
I would look for websites that generally do not ask for data. Then send them the minimum data you can get away with. I would avoid "signing in" or "signing up" to any website. There is an immense amount of data and information available from free from the web, no "account" is necessary.
For example I dont send any extra HTTP headers like Cookies or User-Agent, I dont use Javascript. I dont request images, CSS. I dont automatically follow links in src tags. Yet I can still read and comment on HN and I can read every website posted to HN. Thats a lot of websites. I can read them just fine while not sending them any more data than is needed. Because I do not use a large, complex graphical browser sponsored by an online ad-supported vendor to make HTTP requests, I can easily control what I send. This is far better IMO than sending unknown amounts of data (letting the websites control what the browser sends via headers, Javascript and src tags) and then hoping the websites dont do things with the data that we dont like.
Privacy policies do not limit websites from collecting data nor do they limit how the data can be used. They are "policies" not agreements. If a website operator does things behind the scenes that violate privacy but that it does not disclose in a "privacy policy" what can a user do. How would the user even know. Or the website could clearly violate their own "privacy policy", but no one outside the website's operators would know. Even if users discover the violation, what would be the repurcussions. Its too late, because a violation means privacy has been blown.
Show me a case where a tech company got sued for violating a privacy policy. How can anyone prove a violation if the operations of the website are not open for public inspection.
For reading HTML I prefer links. It has the best rendering of HTML tables, IMO, and is for me the easiest source code to work with. I did use lynx back in the late 90's but would never go back to it. Its bloated. Its slow. Im not sure why anyone interested in text-only browsers would use it other than they are unaware of or have not tried alternatives.
Your observations are correct, the regulation is able to deal with the damage after it was done, and apply some form of punishment after the fact. It takes whistleblowers and activists to reveal some of the wrongdoings, otherwise the violations remain unknown to us.
Therefore there has to be a greater push towards proactive measures - letting people vote with their wallet by making informed choices; the prerequisite for that is for the relevant information to be available to them.
Have a look at some of the research I've been involved in, we're trying to solve this exact problem: http://privacy-facts.eu/
The idea is to express everything in unambiguous terms, so there's no way to weasel out of it with "yeah, but not by default" or, "well, it depends", etc.
For starters, I emailed Protonmail support.
Here's mine: Hi, Your homepage reads "By default, we do not keep any IP logs..."
This language is soft and misleading. Maybe in 2018 when I first began using ProtonMail it was good enough. But in 2021 it's not. I expect better from ProtonMail.
Replace immediately with something clearer. "By default we don't log IP, but may be required to by law enforcement. We recommend all customers connect through Protonmail through Tor. This month, 60% of our users connected through Tor".
If you can't come up with anything better for users, just fall back on your privacy statement verbatim and avoid any marketing language.
Think about a journalist in Afghanistan, a whistleblower in the USA, or a human rights activist in China. They're all engaging in potentially dangerous activities.
I advocate on behalf such people by supporting services like Protonmail with my money. If Protonmail isn't supporting these users, why should I bother supporting Protonmail?
I expect Protonmail to educate users like this about how Protonmail itself can be turned into an adversary. Educate users about how to use Tor. Do better. Improve the internet.
I look forward to your reply.
Also, registering a new account through Tor requires a phone number for verification, even though Proton says no unique identification is required to register. If this requirement isn't removed by the time I renew my account I will no longer renew.
https://protonmailrmez3lotccipshtkleegetolb73fuirgj7r4o4vfu7... is the URL that people should be using with Tor if they are concerned with being traced.
Using Tor to access a regular web site, ie: through an exit node, is (nearly) no different than using a proxy. Just assume all exit nodes are "naughty" and do your thing accordingly.
So Proton users who like to connect via Tor onion services have been faced with a choice of either staying on the old version of ProtonMail, or giving up on connecting via a Tor onion service. It definitely leaves the impression that they don't care much about Tor anymore, or that it's at best an afterthought for them.
It's plausible that Proton does not care about their Tor service, but there may be another reason: The new version relies more on Javascript code than their old version, and a Tor user is more likely to browse with scripts disabled than a regular user. Proton may be holding back the rollout of the newer version until they have tested it more without Javascript. This is only a hypothesis, and I came up with it just now; take it for what it is.
Perhaps there is a greater reliance on scripts in the new version, but this makes it seem more likely that they've abandoned the Tor version.
They are thinking about them. They want to make sure such people don't get them in trouble with the US or China, so they sell them out immediately.
Their page is full of what are now obviously lies. They admit that in the cases of "extreme crimes" they might be forced to give up information. _By no stretch of the imagination are these peaceful political protests "extreme crimes"._
I specifically advocate for the sorts of people that Protonmail ratted out and had arrested - climate change activists.
The eviction was legally sanctioned, and violence was used on the officers. Several officers had to stop work for a few days, one officer for two weeks.
I myself am a middle-aged "have" , but I do worry about climate and I do empathize with those that "have not".
However, violence during an eviction is not peaceful. People were hurt, and a legal response was due. Seems to me that arresting someone after the fact, and dealing with the matter in a court of law is the peaceful thing to do?
My point was just that 1) the arrest was related to squatting, not the climate 2) these people, idealist and well-intentioned as they were, were not "peaceful" (at least, not when faced with a brigade of police officers)
> The eviction was legally sanctioned, and violence was used on the officers. Several officers had to stop work for a few days, one officer for two weeks.
Usually they need to stop work for a few days because their hands/wrists are aching due to hitting too hard on protestors. Anti-riot are perfectly equipped and physically trained to be in fights, it's literally their job. And while there are generally at least a few "semi-pro" violent protestors on the other side, they are not so well equipped like the police.
Something their marketing material appears to disclaim. This is just excuse-making. ProtonMail did what ProtonMail has (for years!) led their customers to believe they would not do. And they did.
I think there's an argument to be made that any commercial email/messaging provider simply can't do what ProtonMail claimed to do. But that doesn't change the fact that ProtonMail did it.
My rule is to give any corporate statement about what they "will not do" exactly zero credence.
The only thing worth anything in that context is open source where independent programmers can verify that the code cannot support undesirable behaviors. And even then you're not safe, because code running on someone else's machine might actually be anything. So in the end, self-hosted open source software is the only way.
Right now that requires some degree of technical know-how, but I believe that's a solvable problem the same way operating systems have turned the technical practice of process management into something users don't even need to think about.
and
> Proton reached out to us to confirm that the only data provided to Swiss authorities was the date of account creation. [1]
[1] https://proprivacy.com/privacy-news/protonmail-authorities-u...
A week ago: "Proton reached out to us to confirm that the only data provided to Swiss authorities was the date of account creation." [1]
Today: Article published claiming Proton gave up user data. Did Proton officially now state they "allowed the account to be monitored"?
Am I getting this right?
[1] https://proprivacy.com/privacy-news/protonmail-authorities-u...
``` if user.isUnderInvestigation { log(request.sourceIP) } ```
> Each time you connect to our service, we log your IP address, your client identifier (browser or mail client information) and your username.
I'm sorry dude, but that decision from switching to fastmail was not very productive to counteract the specific case mentioned on the OP.
If anything, it's even worse since fastmail apparently always logs your IP.
Moreover: > We process mail sent and received from your account to block spam and fraud. We receive information from third party services to assist us in identifying spam.
Looks like your emails aren't even encrypted. If any government body what's your email bodies, they'll have it. They even share it with 3rd parties for fraud detection. With protonmail and similar services, they'll just log your IP if they're asked to do so, which you can obfuscate using a decent enough VPN.
I can't understand what just happened. I truly believed it's all save and secure.
We cannot rely on what companies say about their privacy guarantees, or rely on vendors' technical analysis of their own black box systems, because a simple court order can essentially be a backdoor.
I agree PM should be more forthright in their messaging but realistically I don’t believe any company that takes payments and doesn’t track any info at all.
I'll call that a win for all customers who emailed Protonmail about this.
HN discussion: https://news.ycombinator.com/item?id=28443449
I have seen a ton of disturbing pieces about ProtonMail. Every time I've looked into them, they seem to be maliciously motivated and usually not true, or otherwise twisting of the truth. This has been a confusing thing for me because why is there a small subset of people so vehemently against them?
In this case, I'm not surprised. They say quite clearly they can be compelled to collect IP addresses - including in the linked tweet. This seems like a pretty clear cut case of them being compelled to provide an IP address. What the authorities can't do, is read that person's email. And that's what I and others pay for.
I'm not sure what there is to be upset about here? Other than perhaps France prosecuting this individual to begin with? If we had faith that ProtonMail wouldn't hand over anything to the government, why would anyone even care about having encrypted emails?
Tor solves this. Protonmail's Tor support is lukewarm. They have a Tor based login without captchas. It's mentioned on their homepage in the bottom menu under "Onion Site", (/tor). And there's one blog post from 2017 that still promotes their v2/shorter onion address.
I expect Protonmail to push its users to login through Tor. "Don't trust us, trust math". Embed Tor support in their apps as well. Rebuild their iOS app to offer to drive all connections through Tor.
And frankly, for $50 a year for email, I expect Protonmail to be thinking ahead about this, rather than me coming up with dumb ideas on a forum. Protonmail was neat in 2018 but 3 years later it's stagnant.
Tor is mentioned on their homepage in the bottom menu under "Onion Site". However, this menu link redirects to their Tor placeholder page, rather than directly to the Tor service: https://protonmail.com/tor
There's one blog post from 2017 that still promotes their old v2 onion address: https://protonmail.com/blog/tor-encrypted-email/
Protonmail's Tor service is located at: https://protonmailrmez3lotccipshtkleegetolb73fuirgj7r4o4vfu7...
Alright then, what more do you want them to do? Spend millions in court fighting every warrant issued for their users and go bankrupt defending criminal activity?
from https://pando.com/2014/12/09/clearing-the-air-around-tor/
1. whether or not your request stays within the tor network or not (if you use the .onion address, no need for an exit node)
2. given both entry and exit nodes can be literally all over the world: your threat opposition level. I doubt the NSA will be happy to help French authorities trying to catch a teenager who blockaded a government parking garage).
Is there any evidence this is what happened?
An alternate scenario is that they were not keeping logs, and were then compelled by the authorities to start keeping them on that user.
I, for one, will not renew my ProtonMail account if that's their status quo.
Sure, the law would (hopefully) be changed, but at the moment, this is the best they can legally do?
Put alert warning that account has logging enabled
Change the service so collecting logs is not possible
Stop adding captcha to tor users login because you want to identify users
Frequently not legal
>Put alert warning that account has logging enabled
See above. Gag orders a problem with government in general. They do have a warrant canary page though, as well as a transparency report.
https://protonmail.com/blog/transparency-report/
>Change the service so collecting logs is not possible
You mean stop serving HTTP and MX requests?
>Stop adding captcha to tor users login because you want to identify users
You mean let bots brute-force my password?
Unless you are naive enough to assume that ProtonMail is incapable of logging IP addresses (in which case they'd be incapable of serving HTTP requests...see the problem?) then they can log. And they most certainly aren't going to declare independence from Switzerland and refuse to turn on IP logging when required to by law.
Whereas with E2E-E, they actually are incapable of turning over readable emails.
This is also why I don't get protonmail in the first place. Unless you use pgp or equivalent, you'll always be subject to law enforcement. Just that protonmail cares more and caters more to activists and so might not give it out without checking that the asker is really legit and then give the minimal amount possible. But they'll always be able to turn over your emails and log IPs, it's not protonmail's fault the laws were voted into action like this.
They tout that off-by-default statement on their homepage, underneath the header of "Anonymous Email," with the closing sentence of "Your privacy comes first."
So why even market that? It provides no meaningful security.
There is a difference between "available to police, not retroactively, and only with a valid warrant" and "available to any government agency constantly and in bulk, as well as to data-collecting commercial entities, Russian and Chinese hackers, and their dogs". Don't you agree?
They're not being as transparent as possible in their marketing, which is at odds with their allure of security.
We are trusting they wouldn't comply or no one would make that request?
This is the benefit if being located in Switzerland, where banking is one of the main pillars of the economy and which historically has been much more supportive of personal privacy than most other countries.
They eventually caved under US pressure on some things, so it's not such a "haven" as it used to be, but I believe it is still the country that respects individuals' rights the most.
Not perfect by any means, just better than most others.
I'm not taking sides on privacy or the threat of govt (or other sourced) tyranny, I'm just explaining the logic to answer your question:
Let's say you engaged in a long history of using protonmail innocently, then one day you decided to start commiting crimes for the first time and attract police interest. You would know that your historical logs were not kept, and it was only after you started attracting police attention that you would be at risk of incriminating yourself through proton mail. Maybe, on the run from the law, it would be safe for you to hide at your old friends house because there was no log to link you to him.
Yes, it is also the case that you may not have realized that ordinary behavior had been criminalized by an evil govt all along blah blah blah... I'm just pointing out that there is a difference where you saw none.
in the case where they receive a court order, they first log your IP and then they give it.
but you know this from their terms of service.
if you stop using protonmail when you start your criminal career, they will not give your IP because they didn't save it.
it's different in the end, not the same.
I see that you want to protect Protonmail, but if they want to stop being misleading they can just remove the IP log sentence
I would much prefer this, as a Protonmail paying customer.
Tor is an improvement. It's still a limited tool.
I can't but help read your post in comic book guys voice.
Traffic analysis, at a cost, could establish that the suspect is using Tor.
TorMetrics shows slightly more than 1,250 currently-running Tor exit nodes. I'll presume this is typical, history shows it's pretty consisten over the past 3 months.
https://metrics.torproject.org/relayflags.html?start=2021-06...
I'm going to presume that a court could conceivably issue an order to log all Tor-based traffic. A state actor / APT might then be able to correlate a known IP and traffic at a given point in time with other data to identify a source IP. This might be combined with other measures to encourage circuit-jumping until the suspect is on a specific known or monitored Tor circuit.
Yes, costs increase. I don't see this as technically infeasible, however.
Might not be rolled out just for a house-squatter, however.
Frankly, I don't think anyone is safe from the tip of a nation state, even small ones. But I do think we should protect everyone else and Tor would have done that.
Because this was clearly civil disobedience and that is what we really should be protecting.
Just ... don't think it's a majykal bullet. It's not. Tradecraft matters, vulnerabilities exist. Examine and review your threat models.
Even if a nation state was targeting you, it would still take months for a timing/bandwidth attack to identify a user. Even then it would only provide your adversary a probability of certainty and requires consistent traffic from the victim through a compromised exit node.
No system is 100% perfect but tor will make most attacks prohibitively expensive.
Remember: all you need is 33 bits.
Here, data enter the Tor system, but don't leave it as the onion service itself has a Tor address.
Yes, traffic analysis and timing correlations may still be used to draw inferences, but again, costs are raised, and that's the critical factor.
I'm a privacy activist and certainly think that a company should be able to not keep logs. If the law in the country they are in (or area, see for example the data retention directive in the EU) we should of course (and I am) work to change those laws.
It should come as no surprise to anyone who is privacy minded and actively seek out privacy focused services that are located within the EU or Switzerland that your IP (or other information) can be requested with a warrant and that a company is required to hand that over.
I get that you think people should already know this, but do you feel they should be punished for not already knowing this, and not reminded by a company that markets itself on protecting its users? Protonmail was forced to get an IP address, but they're not forced to keep the fact that they respond to warrants a big secret.
Not everybody who is an activist is a big techie, or even computer-literate.
> We will only disclose the limited user data we possess if we are instructed to do so by a fully binding request coming from the competent Swiss authorities (legal obligation). While we may comply with electronically delivered notices (see exceptions below), the disclosed data can only be used in court after we have received an original copy of the court order by registered post or in person, and provide a formal response.
It would also be nice if they were allowed to notify the customer but I'm not familiar enough with Swiss laws to know if they can.
(also a paying Protonmail customer)
Of course Protonmail is accessible via Tor. Not that you should need to do that to remain private.
Gmail does all of this for free though, right?
Gmail Pro (paid G Suite) has never done that, and Gmail Perso (Free) hasn't done that since 2017.
Because I am aware of no reason to think that Google stores my gmail with zero access. I don't know for a fact that ProtonMail discards this information at the earliest opportunity nor do I know for a fact that they don't try to aggregate it to learn about you (or even people in general), but that is what I interpreted the pitch as.
But, look, of course if they get a subpoena they will have to start scanning your email if they are technically able to collect it. That's just a wiretap, and little would prevent the author and operator of the server software from doing whatever they want... and they're clear that if you aren't sending email between two compatible accounts that there is no E2EE.
We can talk about how they should have been clearer about the need to use Tor to avoid IP logging (even if they don't do it, someone between you and ProtonMail certainly could). That's a good idea. But they are actually very clear that E2EE with your email is not what you should expect in general. And I don't think they have much incentive to scan my email from unencrypted sources to do anything nefarious, but I don't think anyone has any ability to prove they do or don't at present.
But that is not a proton issue that is an issue with our current governments.
"Hey, we respect your needs. However, we have to tell you that you should treat us as a bit of an adversary. We will do what we can as a private company, but ultimately we can be compelled by the government, rogue employee, or if somehow we get hacked. This is the case for any company no matter what they promise or avoid telling you. We do tell you. As our customer, here's what we recommend you do: Use Tor, fund open source, vote, etc."
You’re telling us that you never considered that an incorporated company, bound by democratic laws, would be required to respond to criminal activity warrants?
What fantasy land do HNers on this thread live in?
No service is capable of completely hiding IPs and still getting you the data. If you "threat model" includes hiding from Western governments, I'd recommend not using the internet.
Interestingly, ProtonMail's privacy policy lists a number of cases in which they may log your IP address permanently (including if you breach their Terms and Conditions). But a request from law enforcement is not one them.
Moreover, I would like to point out that ProtonMail is about encryption of email *content*. It is foolish to expect more from them. They won't protect your identity: law enforcement can know who you are and who you communicate with, but they cannot know the content of your emails (if you recipient uses encryption services as well).
I think trusting your security or privacy to website-based email is a bad idea. If the email is being displayed in your browser, then the authorities can coerce the company that owns the website to include JavaScript in that page that sends the plaintext content to them too -- or demand the website's TLS key and start intercepting the traffic that you see.
The only encryption-based security that you can reliably trust is encryption that happens locally on a device you control, and that doesn't involve a web page or website loaded from a 3rd party.
If you want privacy protection with real end-to-end encryption that the government can't get past trivially with court orders, use services where the decryption happens on devices that you own, such as WhatsApp or Signal or iMessage. If you must use email, do the encryption yourself on a hardened Linux distribution like Tails using PGP for email encryption; but this is much harder to set up than the above secure messengers.
I wouldn't say ProtonMail is a scam, but a trivial software change on their server-side would let the authorities see your email every time you do. If they can be compelled to make that change then the "encryption" you're paying for is worth nothing. The next time you sign in, a court-required modified version of their server software can capture your password, and then use whatever key derivation function gives them your encryption key.
This might not even require the company to actively participate. In the case of Snowden and LavaBit email, the US Government demanded LavaBit's TLS certificate so as to intercept the communications themselves at the ISP layer when LavaBit refused to comply with narrower court orders to provide information about his account.
What could police do with ProtonMail's TLS certificate and court authority to intercept and MITM traffic for your account? They can probably capture your password, use that to read all of your old email, and at minimum read your email as you read it. Even if decryption is happening in the browser somehow with JavaScript, that JavaScript is coming from the origin server that the government now controls by virtue of MITMing the traffic with the site's TLS cert, and so they can insert JavaScript that logs a plaintext copy of either the emails or the encryption key needed to decrypt them.
There is no security with web-based communications if the companies involved can be coerced with a court order. US based firms would be required to hand over their TLS cert if they weren't willing to help track someone, and at that point the government could do anything to your traffic.
The only secure encryption happens on your device with no browser involved.
By comparison, if you're using an iPhone, in theory the US Government could try to force Apple to modify WhatsApp/Signal on your phone, or force the App developers to do so. These companies would all fight tooth-and-nail in court against doing so. Plus, you can configure your iPhone to disable automatically updating apps, so once you have a working version of WhatsApp installed, unless Apple has some backdoor-ability to push an update of it to your phone anyway, you could turn off app update and be cautious & picky about when you choose to update WhatsApp or Signal. What I don't know how to do is verify the integrity of their binaries: to confirm that what you're getting is the same app distributed to everyone. Facebook would appeal to SCOTUS before allowing a government to install a backdoor into WhatsApp; so would Apple, based on their response to the government's request to unlock the San Bernadino shooter's phone.
All that being said, if the government's goal is simply to discover your identity, which was the case here, then Signal and WhatsApp won't help you. Their accounts are based on a phone number. If the govt has your phone number then unless it's a burner acquired with no name registration then they'll know who you are, and regardless will be able to find out approximately where you are, if you continue to use that phone number. They can triangulate where you are fairly rapidly with modern technology, and this is assuming that the cell company can't simply send a signal asking the phone for its GPS-based location; but even if the govt only knows your nearest cell towers, narrowing that down to a building is a matter of minutes once they're in the area.
If you need to communicate in a way that keeps your identity a secret then you're probably best off using a free email service over Tor from a machine running Tails Linux, accessed from various locations that provide public wifi.
If they were forced to log the IP address, they can be forced to log user password. This makes entire encrypted mailbox useless.
What if authorities ask, serve this user this malicious JacaScript code to obtain their encryption key?
PM has to obey and the result is the same.
How is that any different from them being compelled to disable or weaken clientside encryption?
In both cases they're being compelled to make changes to their service.
The camel's nose is clearly already under the tent. Everybody needs to start diffing javascript served by them.
The GP says that it's possible under German law. Is it "FUD" to say that it could end up being possible under Swiss law?
Shouldn't there be fear, uncertainty, and doubt about any channel that activists use to communicate with each other?
It would be nice if there were something like Perspectives[0] or Binary Transparency / Sigstore[1] to raise the alarm when something like this happened, but the threat would also be avoided if ProtonMail was available as a SecureBookmark[2].
[0] https://www.techrepublic.com/blog/data-center/ssl-tls-certif...
[1] https://security.googleblog.com/2021/03/introducing-sigstore...
They come off as a very dodgy company willing to twist the truth themselves. They claim that they can provide E2EE for email, being careful not to give away the fact that this is impossible for regular emails to non-PM customers.
Frankly I only use them because they're the biggest "private" email service and that provides a kind of safety in numbers.
While I concur that it's a bit misleading nothing is stopping you from using your own key and mail client (albeit with their "bridge" solution) to send E2EE e-mails.
If you rely on the keys they generate you can export them and use them accordingly but one should be weary of the handling of said keys if they were compelled to make a backdoor as others have noted.
That being said this does leave a bad taste in my mouth.
From where I stand, the only difference here is that ProtonMail has to receive the warrant before they give up all the info they have on you, and others may do it voluntarily even without that, just to keep on the good side of the police, but since it's not exactly hard to achieve such warrants (and in the US, as we learned, it's ok for the police to lie on such warrants and they know no punishment will come to them even if the lie is discovered later) the difference is minimal. If you have something the police really wants to see, and they can reveal it, they will.
this seems to be the reply from protonmail on reddit[0]
>Hi everyone, Proton team here. We are also deeply concerned about this case. In the interest of transparency, here's some more context.
In this case, Proton received a legally binding order from the Swiss Federal Department of Justice which we are obligated to comply with. Details about how we handle Swiss law enforcement requests can found in our transparency report:
https://protonmail.com/blog/transparency-report/
Transparency with the user community is extremely important to us and we have been publishing a transparency report since 2015.
As detailed in our transparency report, our published threat model, and also our privacy policy, under Swiss law, Proton can be forced to collect info on accounts belonging to users under Swiss criminal investigation. This is obviously not done by default, but only if Proton gets a legal order for a specific account. Under no circumstances however, can our encryption be bypassed.
Our legal team does in fact screen all requests that we receive but in this case, it appears that an act contrary to Swiss law did in fact take place (and this was also the determination of the Federal Department of Justice which does a legal review of each case). This means we did not have grounds to refuse the request. Thus Swiss law gives us no possibility to appeal this particular request.
The prosecution in this case seems quite aggressive. Unfortunately, this is a pattern we have increasingly seen in recent years around the world (for example in France where terror laws are inappropriately used). We will continue to campaign against such laws and abuses.
to me this seems like they did all the could in regards to handling this request.
[0]https://www.reddit.com/r/ProtonMail/comments/pil6xi/climate_...
Maybe not having the IP address in the first place like they advertise was that was needed.
And before anyone suggests that PM should have been more "open/honest" about this, I disagree, the fact that a criminal investigation will do this is well known and mentioning it would be akin to asking your bank to plaster "if the world economy implodes, we might not be able to pay out your account" all over their frontpages.
For a user the result is the same.
I wonder what this “activist” did to earn himself Europol attention. At least before the world went insane, that would only happen for serious crimes.
If so, on which basis do you ironically call squatting a "terrible crime"?
Squatters in your house in France means that you you have zero rights on this place until a lengthy process gives it back to you, ruined. You are then expected to be grateful and can forget about any reimbursement from the poor people who stole your property.
Sure, it's a crime, but it's a relatively minor one. I suppose if you were the victim you'd have a different point of view.
This can happen to the slumlord (who will then send someone to beat up the squatters), to the big capitalist (who will go through the courts and win) and to smalltime owners where that is maybe their family home or future retirement apartment (who will suffer the most).
Homelessness/lack of housing is a problem, but squatting is in most cases not the right solution.
Then starts a possibly very long process to have them evicted/ If they have a child you are basically screwed and won't be able to get your property back. Or you will wait months/years and get a ruin back.
Please give your opinion about squatting primary and secondary homes of people. Who worked to buy them and have zero rights afterwards, when a colony of parasites come and destroy their belongings.
This is what happens in France.
But the law allowed him, as a good landlord, to work on the outside of the house, for the good of his tenants. So he did.
He installed security cameras, and reported every minor infraction of the squatters to the police. The police loved it, and duly did everything. Oh look, a cm of your wheel is parked outside the allowed boundary. That's a ticket. Of course he duly tested the very loud alarm every evening, to make sure it works.
He did a paint job, first removing the old paint with the noisiest dustiest old tools he could find, then painting it in an old ugly pink he found on a flea market somewhere. Then decided the quality wasn't good and removed the paint again. One day, the squatters had enough and actually went to a court to demand he let their poor baby sleep. Judge just laughed, and told them all work happened before 22:00 so he was in his right.
Squatters ran away after a few months, which supposedly is a happy outcome, at least compared to what the law could do for him.
Vandalising banks is stupid and also an efficient way to make powerful people dislike you.
Unfortunately this sort of extremist group is harmful to people and organisations genuinely trying to do something for the environment.
https://www.oxfam.org/sites/www.oxfam.org/files/file_attachm...
https://ourworldindata.org/co2-by-income-region#emissions-by...
Sure, ProtonMail and its current operators could opt to stop operating in such jurisdictions, but usually it's too late for that when you get the [secret] court order, because if you refuse the operators personally are quickly found in contempt of court (or whatever other bad legal circumstance), and eventually that can lead to similar InterPol/EuroPol (other MLAT) warrants.
[1] https://theconversation.com/explainer-what-is-an-interpol-re...
[2] https://www.journalofdemocracy.org/articles/weaponizing-inte...
I wanted to test how Protonmail is doing for new users I created an account from scratch just now over Tor.
1. Am asked to verify new account by entering a cell phone (edit: this is horrible. They lie and say account creation is anonymous, as pointed out by the poster below)
2. Upon login, "Basic" logs are selected which do not display IP. You can enable "Advanced" logs to log IP. I would suggest Protonmail make it crystal clear that these "Basic" logs do not store IP. In 2021, lies by omission are not good enough. Get rid of the soft language.
3. Their help page [1] says that "Advanced" (IP stored) logs are enabled by default. However, I created the account and it's just the Basic (no IP) logs. https://protonmail.com/support/knowledge-base/authentication...
Interestingly the sentence on their front page, right before the most commonly quoted snippet in this thread, is:
> No personal information is required to create your secure email account.
A phone number is quite a personal, unique identifier.
For those concerned about using a temp mail site, it's only used to verify the account; it can never be used to recover it.
But the account is made and I can log into it just fine, perfectly accessible.
I just did it yesterday. The text from them says "Your Proton verification code is: ######"
Welp.......Now, please excuse me, I need to go check my Protonmail settings pronto....
Vendors really need to figure out how to thread the needle of "No don't trust us" but still encourage customers to buy. Protonmail failed here. Apple's still very much in the "trust no one but us!" vibe, and it's just not sustainable.
I'll be switching my Protonmail use to default to Tor now. Open to Tor-first vendors...are there any?
I like how Brave has "open in Tor" displayed on Tor-mirrored sites. There's even an option for "Automatically redirect .onion" sites too. Makes it easy to switch over.
What if Protonmail pushed their Tor services more? "Guide to using Protonmail as privately as possible", have a switch for "Private Mode" that kicks you over to Tor/download Tor.
Tor is a powerful tool for increasing the privacy of its users, though it is worth noting that it prioritizes performance over privacy. Tor's threat model does not include global adversaries, particularly those who can access traffic metadata for large numbers of ISPs- though, hidden services do fare significantly better than your usual clearnet services, usually requiring DoS attacks to deanonymize their hosts, and protecting their users especially. But note that Tor is not a mix network- it does not provide mathematically provable anonymity against a global passive adversary, unlike systems such as Loopix. See from this paper describing Tor in 2004, and consider reading the whole thing for a better understanding of Tor: https://www.usenix.org/legacy/publications/library/proceedin...
Tor's Threat Model "A global passive adversary is the most commonly assumed threat when analyzing theoretical anonymity designs. But like all practical low-latency systems, Tor does not protect against such a strong adversary. Instead, we assume an adversary who can observe some fraction of network traffic; who can generate, modify, delete, or delay traffic; who can operate onion routers of his own; and who can compromise some fraction of the onion routers. In low-latency anonymity systems that use layered encryption, the adversary’s typical goal is to observe both the initiator and the responder. By observing both ends, passive attackers can confirm a suspicion that Alice is talking to Bob if the timing and volume patterns of the traffic on the connection are distinct enough; active attackers can induce timing signatures on the traffic to force distinct patterns. Rather than focusing on these traffic confirmation attacks, we aim to prevent traffic analysis attacks, where the adversary uses traffic patterns to learn which points in the network he should attack. Our adversary might try to link an initiator Alice with her communication partners, or try to build a profile of Alice’s behavior. He might mount passive attacks by observing the network edges and correlating traffic entering and leaving the network by relationships in packet timing, volume, or externally visible user-selected options. The adversary can also mount active attacks by compromising routers or keys; by replaying traffic; by selectively denying service to trustworthy routers to move users to compromised routers, or denying service to users to see if traffic elsewhere in the network stops; or by introducing patterns into traffic that can later be detected. The adversary might subvert the directory servers to give users differing views of network state. Additionally, he can try to decrease the network’s reliability by attacking nodes or by performing antisocial activities from reliable nodes and trying to get them taken down—making the network unreliable flushes users to other less anonymous systems, where they may be easier to attack."
Tor increases the costs to uncover your identity, especially so in the context of a hidden service, which the entity in question (Protonmail) actually does offer to users. Perfection is the enemy of the good- Tor is not built to deal with global adversaries unlike a mix network, but surely any increase in privacy is a good thing, no? You do not complain that your wrench does not serve the purpose of a hammer quite as well as a hammer might- you either put some more energy into it, or you buy a hammer.
Again, provide evidence or stop spreading FUD.
The USG persecutes and imprisons journalists for exposing its war crimes, anyways I'm going to download this Tor binary from them because it says 'totally legit' on the packaging and there's no "hard evidence" to the contrary...
Downloading Tor from a particular IP in Iran? We'll add a little something extra...
Or maybe you're a US citizen with a set of known IPs on a "watchlist".
If you were relying on Protonmail to conceal evidence of criminal activity for you, you may not have thought that all the way through.
Everyone realizes that, by default, literally just connecting to another service over the web, will expose your IP address?
It’s trivial to monitor and report your IP to the authorities, as soon as you login to ProtonMail, despite lack of “logging”.
Logs only matter for historical data. This legal request is impossible to /not comply/ with.
Does anyone here have a feasible way to solve this? Or is it just a bunch of ProtonMail hating FUD?
Current solutions like TOR, I2P, VPNs and/or mobile proxy services are just a matter of time and legality until they come obsolete due to their publicly known nature.
I am convinced that the only way to solve this is by simply not downloading the website from its origin. The origin tracks you, so don't talk to them. Talk to your peers and receive a ledged copy of it instead.
The only problem is that this contradicts all that came after Web 2.0, because every website _wants_ unique identities for every person visiting them; including ETag-based tracking mechanisms of CDNs.
I think it's not possible with supporting Web Browser APIs the same way in JavaScript (as of now, due to fetch and XHR and how WebSockets are abused for HDCP/DRM to prevent caching), but I think that a static website delivering network with a trustless cryptography based peer-to-peer end-to-end encrypted statistically-correct cache is certainly feasible. I believe that because that's exactly what I'm building for the last two years [1].
I’m asking if there’s any feasible way for ProtonMail to not have the ability to know which IP addresses connect to their services.
Maybe ProtonMail could offer an alternative .onion service? This way they couldn't legally be forced to give a way the IPs, because on the other end it's a TOR exit node anyways. And by design they cannot see the real IP from their point of view, so a legal enforcement would be useless.
Though I guess you could also access via Tor regardless, if not for the account creation stage.
You can come up with an excuse, depending on the service it might be laborious to get an IP on a running live system that doesn't otherwise care about connection information.
Depending on the truthfulness of that you might make yourself guilty of impeding investigations though.
Your contempt for web devs seems to correlate with your lack of understanding of how the web works. Responses like yours make me cringe, in how uninformed they are, despite trying to sound smart.
IP addresses can and will be exposed in any situation that a user connects to a service - it’s a fundamental property of the web. You cannot tell Government agencies, esp. when they have a 3-country-approved warrant, that “we don’t know how to”.
If you terminate a connection at the load balancer, they will make you monitor it. If that’s not owned by you, they will send the warrant onto your cloud provider or whoever.
I could setup a service that masks any clients IP address towards my service with no problem. If a client connects through TOR or similar network I would not be the wiser either. So apart from just not logging connection attempts, there are other tricks.
Of course that doesn't work if law enforcement is knocking on your door and forcing you to do that. But there are still mechanisms that would allow IPs to be hidden. The state cannot know the intricacies of the mechanisms your service employs. protonmail.com could point to a server in Timbuktu that makes any request in delegation for a client to hide IPs.
This privacy arms race is pure idiocy though and the problem is legislation and lacking control and supervision of police forces within European countries that decided they should be so afraid to call one emergency legislation after another for more than two decades.
You also don’t seem to understand the gravity of an international criminal warrant, and counter with ideas of “paying a provider in Timbuktu to mask IPs”.
I don’t like feeding trolls, so I’ll stop replying now.
Still, just for technicalities:
Any proxy server hides your IP. VPN, Tor, McDonalds Wifi...
https://nitter.eu/OnEstLaTech/status/1434575322465382404
Translation: "The company @ProtonMail delivered IPs of climate activists to the police, after which the activists were arrested and searched. ProtonMail claims on its website, however, that it does not store the IP addresses of its users."
Source (in French): https://secoursrouge.org/france-suisse-securite-it-protonmai...
Translation (via Google Translate):
The year 2020 and 2021 was marked by the establishment and repression of a series of occupations in the district of Place Sainte Marthe, in Paris, in order to fight against its gentrification. Some 20 people were arrested, three searches were carried out and several people were sentenced to suspended prison sentences or to fines of several thousand euros (more info here and here). In addition, seven people are on trial in early 2022 for “theft and degradation in assembly and home invasion” following the occupation of a with a file of more than 1000 pages. During the investigation, the police focused on the collective “Youth For Climate”. In particular, they were able to use photos published on Instagram, even if they were blurred because of the clothes.
The police also noticed that the collective communicated via a protonmail email address. They therefore sent a requisition (via EUROPOL) to the Swiss company managing the messaging system in order to find out the identity of the creator of the address. Protonmail responded to this request by providing the IP address and the fingerprint of the browser used by the collective. It is therefore imperative to go through the tor network (or at least a VPN) when using a Protonmail mailbox (or another secure mailbox) if you want to guarantee sufficient security.
(Disclaimer, Protonmail user.)
https://protonmail.com/privacy-policy
They also provide a report of all warrants received https://protonmail.com/blog/transparency-report/
And even on their English website, the marketing is misleading. They say that the service is "anonymous" and also: "By default, we do not keep any IP logs which can be linked to your anonymous email account".
https://protonmail.com/blog/protonmail-mr-robot-secure-email...
Scroll down to comment:
> Liam, October 14, 2015 at 10:30 PM
> But https://protonmail.com/security-details page says “No tracking or logging of personally identifiable information. Unlike competing services, we do not save any tracking information. We do not record metadata such as the IP addresses used to log into accounts.” So, now it turns to be that you introduced tracking and logging? Is this data encrypted as well?
> Admin, October 17, 2015 at 9:14 PM
> We don’t save any of this data by default, the user must explicitly turn it on for us to save it.
There should be a reasonable assumption that given they have end-to-end encryption for the service, they just encrypt the logging for the user and store it encrypted without the key themselves like they do the emails.
Also to note, they at least have an onion link to use their email service.
https://twitter.com/andyyen/status/1434600373059297284
"As described in the link above, under Swiss law, we can be forced to collect info on accounts belonging to users under criminal investigation. This is obviously not done by default, but only if we get a legal order."
Activists beware.
Weird definition of privacy we've got going these days
If it's illegal to provide a completely anonymous email service, then you should not claim to provide a completely anonymous email service.
Except maybe Lavabit, that guy apparently shut everything down to avoid doing something along these lines. So maybe he wasn't actually lying.
Also: One more reason NAT was a good thing over IPv6. The closer we get to the platonic ideal of "UUID per person" the more likely justice systems will use it that way.
The day everyone learns how to self-host mail on ephemeral compute instances is the day law enforcement starts requiring MX domain logs to be maintained in a historical manner. Work around that magically, and some law'll go on the books to try to tame the super spooky criminal communicators hiding from law enforcement.
This is why we can't have nice things.
This still doesn’t protect your privacy because your ISP knows what prefix they gave you and will likely provide that to the authorities if you broke the law while using that address. Just like they would even if you used NAT and ipv4 so I don’t get where the parent comment thinks that is protecting their privacy at all.
IP's address Internet endpoints, not people using them, yet States, prosecutors, and law enforcement regularly try to create the illusion that an IP has anything to do with who uses something.
IPv6 makes that temptation worse. IPv4 forces you to realize IP's can be ambiguous. IPv6, through having more addresses than people on Earth, checks off the Institutional checkbox for "raw material to contribute to a UUID identity scheme". Just look at China's proposals for a more governable international Telecom network, and the intention to use device persistent addressing as a control mechanism becomes obvious.
Where IPv4 creates enough decentralization and localized namespace unscrambling to provide enough friction via statefulness to thwart these types of efforts, I'm not at all confident IPv6 will do the same. I believe it is just what the Doctor ordered for laying the foundation of coupling IP's and net addresses in the minds of the masses to personal identifiers.
Which is not by any stretch the way we want things to go.
My iPhone spoofs the MAC address each time it connects to WiFi, so support for changing your /64 is not going to be a challenge even with consumer devices. Whether we lose this ability or not is another question (but they could easily make the same requirements of “hard device uuid” on IPv4 if they wanted. These are laws and regulations after all, not technical limitations).
If anything IPv6 gives you an even greater amount of plausible deniability because like you said you could be running a vpn with a billion different devices connecting to it.
IPv6 just means your laptop could have an internet routable IP associated with it. You can easily change to one of the billions upon billions of possible addresses that your assigned prefix will give you (just like you could have something like 10.0.0.0/8 with millions and millions of addresses behind your internet routable IPv4 address. Your ISP will turn you over all the same if the authorities ask who that address belongs to.
> No personal information is required to create your secure email account. By default, we do not keep any IP logs which can be linked to your anonymous email account. Your privacy comes first.
Except your phone number? That's highly personal. https://news.ycombinator.com/item?id=28428092
(I recall encountering this too when creating an account a few months ago.)
If you need trust, theres no way around rolling your own service.
I'm not sure how your tech-stack has to look like for you to claim that you can't log IP addresses and user-agents etc...
That's a cute idea, but it won't get them out of complying with a warrant.
This does not mean you need to log everything all the time. (usually that is actually quite illegal too) but you need to have infrastructure in place to allow for police investigations.
I don't get how people don't understand this. companies need to operate according to the law of the land, this being one of them.
However, better than most (both by jurisdiction and their own rules) than other email providers - and I'd have thought any of their users who were serious about anonymity would have used Tor/Tails etc to connect anyway and used pgp for their messages.
Details of connections to the account (IP and connection fingerprint) shouldn't matter if you were taking your privacy seriously.
Basically just signing up for protonmail doesn't make you secure and there's nothing they could do to help if you just rely on that.
So tutanota would be a good alternative to protonmail. And mailbox.org is a good alternative to fastmail. Both are based in Germany.
> Storage only takes place for IP addresses made anonymous which are therefore not personal data any more.
What the heck does "IP addresses made anonymous" mean?
I don't thinks that dedicated server provider (like Hetzner) or cloud provider (like Digital Ocean or Vultr) stores traffic logs with enough details to be useful in such case.
But payment will be a problem...
Even if they don’t, as long as they have the email address then they can probably find the mail server even if the payment is anonymous.
Anonymous/protected enough payment is the problem.
One expensive but possible option would be to build a server yourself with sufficient traps to shut off when it's tapered with. Then set it up with full disk encryption and put it in a shared rack.
What would be the benefit of being in a shared rack? Wouldn't the service provider still know which physical system is yours if you only rented a 1/2/3U space? (Or is there an advantage at a network layer?)
Going for a rack has the advantage that you own the hardware and can install the anti-tamper measures so that the server can't be turned against you. Anonymity wise, renting a server makes things a lot easier.
But as sibling comment mention, it can be seen as destroying of evidences in many jurisdictions :-(
Things like hiding or destroying evidence of a crime generally are separate crimes of which you can be convicted even if you're acquitted of the original crime (e.g. burying a corpse in the woods or throwing a gun in the river).
Destruction of evidence with the intent to hide it from prosecution also may enable so called 'adverse inference' where essentially the jury/judge can assume that the destroyed evidence actually showed what the prosecution intended to find there. For example, if you're being prosecuted for possession of child sexual abuse material, there's a warrant for your hard drive, but it gets fully destroyed because you have rigged some device to destroy it (and the prosecution proves that you did that with the intent to destroy evidence) then the court may take it as a fact that the hard drive did indeed contain CSAM and treat it as sufficient evidence to convict you.
In short, self-hosted service on a rented service does not provide much protection.
But, as far as I understand, case law is not in my favor in this case :-(
I basically decided to just give up. Email is an insecure protocol and there's not much that can be done about it. Choosing a "secure" email provider feels like choosing a "secure" VPN provider: it's impossible to verify the provider's claims so it's a kind of security theatre.
Email can't guarantee E2EE without a block cipher tool like GPG. Even if your provider stores and transmits only encrypted email data, once sent it does not maintain that guarantee while being passed by another entity's MTA.
If you email google, google gets to do whatever googly stuff it would like to do with its algorithm. If you email exchange, roundcube, ISP, hotmail, it could wind up being archived to tape, or simply be sitting for a long time in some unencrypted mail spool, maybe in a public cloud. If you selfhost, you would be forgiven if you find you have made a mistake or simply got pwned.
I've never selfhosted email, but I understand it is a lot of work to set up if you aren't familiar, and while maintenance is okay once you get rolling, there are occasional emergencies or hiccups that require intervention.
Aside from being much slower, regular mail is quite better since you can easily inspect the envelope for evidence of tampering, while email will be imperceptibly copied.
What? If Alice encrypts an email to Bob, using Bob's PGP key on her laptop, then it doesn't matter how many MTAs that email passes through, the email stays encrypted at every hop.
> it could wind up being archived to tape
I guess you're saying that an encrypted email could travel through a provider that keeps a copy of it in the hopes that quantum computers will one day be cheaply available enough that they can crack the private key and read the email.
That seems expensive (and illegal) for a company to do just on a whim (assuming the sender and recipient are periodically deleting old emails), and I'd like to think that a judge would turn down a request for a warrant that covers data that won't be readable for a decade or more.
>I guess you're saying that an encrypted email could travel through a provider that keeps a copy of it in the hopes that quantum computers will one day be cheaply available enough that they can crack
No, I'm saying when you send the email, the next MTA might not use encrypted transport and any mailbox/mail spool/cache might not store the data encrypted in any way.
You can of course get E2EE if you use GPG (you always could), but if somebody doesn't know how to use GPG or uses it wrong, that is problematic.
You can also just broadcast your gpg block message via public/ham radio or even hire a skywriter to spend his day tracing out your GPG cyphertext as a huge QR code in the sky :-)
Except that's not true. Often envelopes can be opened and resealed without any trace, meaning contents can be read or changed.
Notionally, I would imagine something that looks like "email" and acts like "e-mail" (to the end user) could eventually exist that provides the same (conceptual) security that the Signal protocol provides (and perhaps a hosting provider option that's the same level of user confidentiality that we get the Signal foundation), although you're correct that foundationally it would be a different protocol. Backwards-compatibility would be required, at least for seamless transition (perhaps represented as "secure" and "plaintext")
Wasn't Ladar Levison (the individual behind Lavabit) working on something like this? https://darkmail.info/
- The ability to login from multiple devices (using both dedicated clients and webmail) and subsequently being able to immediately access all my old messages, too.
- Global filtering, tagging, folders, read/unread tracking etc.
- Full-text search that doesn't require downloading all messages to your local device beforehand.
But if you want truly private and secure communication, you'll have to forget about email. Even with encryption there's still way too much metadata floating around that can identify you.
This also applies to ISP's and wiretaps. They need to provide NAT mappings when doing a wiretap if i remember correctly.
It gives no worse privacy guarantees than protonmail and possibly way better - because if you use protonmail through a web client and they get a court order to serve you a "special" client that forwards your certificate you won't notice it.
ProtonMail went under fire several months back about opting to use Google's reCaptcha for login in a time crunch, rather than setting up hCaptcha even if it took a little extra time.
The tradeoff was cost vs. user privacy and they chose cost, which is NOT why a lot of us pay PM to begin with.
This is unacceptable, but unfortunately there are no alternatives that hit all the check marks PM has in terms of features.
The response of "use Tor to connect" doesn't really help. If you so much as accidentally connect once with a normal IP, that's enough to nab you.
People likening this to exposing the hiding places of Jews to the Nazis is probably the saddest and most infuriating comparison I've seen in recent times.
Let's be rational here, folks.
The submission title doesn't reflect the details.
(Quote from the Twitter thread, by same author.)
Yeah, that is the problem. We don't know who, we don't know why, we don't know shit. All we know is that the request took place. We don't know if the request was or is justified. Those who trust police or dislike climate activism might say 'of course' and those who distrust police or like climate activism might say 'of course it wasn't justified'. Meanwhile, police (Europol in this case) are not releasing details for the neutral readers to make up their mind, because they're still fully in the investigation.
I'm very much pro-privacy, and actually I find the environment very important, but I also want to give Europol the benefit of the doubt. So I suspect a climate activist, using Protonmail, might've gone a step or two too far. And if Protonmail just runs some VPS in some other countries, they'll have to abide by the law in these, on top of Swiss law. That a Swiss company has to cooperate with Europol because Europol has mandate in Switzerland is also a no-brainer.
This is patently false. The first thing they could have done is not hosted their service in a jurisdiction susceptible to these kinds of logging requests, at least not openly. In other words, they could have concealed the location of their services.
Instead, ProtonMail is attempting to have their cake and eat it too: on the one hand, they repeatedly publicize the fact that they have 'Swiss privacy laws' as a selling point, but yet on the other hand when a privacy violation such as this occurs, they claim that their hands are tied because of....Swiss laws.
It's this two-faced behavior that is deplorable.
Where is that ? Which country doesn't have a law that allows authorities to request such information ? I'm not aware of any, at least not among any sufficiently developed countries with useful infrastructures.
> at least not openly. In other words, they could have concealed the location of their services.
> Instead, ProtonMail is attempting to have their cake and eat it too: on the one hand, they repeatedly publicize the fact that they have 'Swiss privacy laws' as a selling point, but yet on the other hand when a privacy violation such as this occurs, they claim that their hands are tied because of....Swiss laws.
You can't provide a paid commercial service while hiding your business entity. And, on top of that, DNS and SMTP make this basically impossible technically as well. So what you're looking for is, at least when it comes to email, something that doesn't and can't exist.
You absolutely can. This is how many entities on the dark web function. And in fact, so do many entities on the clear web (see the RBN and its successors as an example).
If you use gmail, It is my understanding that google ai will routinely read all your messages and add anything interesting to your profile so they can target you for ads. Law enforcement also has open access to everything in your mailbox all of the time.
ProtonMail don't read your email but will supply metadata to authorities in response to a lawful warrant.
That still feels like a difference between gmail and ProtonMail. I pay for that difference, your money your choice.
You're on Gmail or outlook ?
Well, now governments can have your IP, email contents and anything else you can imagine.
If anyone has specific recommendations for which open source encrypted platforms to set up, I am all ears
Why setting up a server vs simply using a vpn?
Hard to incorporate what threat vectors their users should be mindful of and recommend steps to mitigate in their marketing without scaring people off who want to do nothing but outsource their privacy™ to someone else and not think twice about it, even if some of those people are hn users…
ProtonMail lost it's essence to be honest. As soon as my subscription runs out I'm gonna host my own mailserver instead. There are no advantages in using ProtonMail snymore.
I might end up doing the same. I think I'm stubborn enough to pull it off. Personally I got my eye on https://gitlab.com/simple-nixos-mailserver/nixos-mailserver
I've been in the market for a service like protonmail because I'm trying to degoogle. Reading news like this and looking at the price of these services for two accounts has me thinking twice.
1) Malware scanning services. I noticed that links in my email are sent to a third party to be scanned for malicious content. I never signed up for this service.
2) Mobile phone analytics. Using a third party for mobile analytics known to track users.
3) CDN: using a content delivery network in countries that do not have the same privacy requirements as ProtonMail’s corporate domicile.
Privacy is a gimmick for the company at the very least, a front at the worst. I still use them because I trust other companies even less.
I know that every IT company eventually turns into a bunch of creepy and greedy jerks that end up contradicting all of their initial "don't be evil" statements. But please, Proton, don't do this so early in the process. I'm tired of migrating from one jerk company to a we-are-not-jerks-yet company all the time. If it turns out that Proton really leaked the IP and device info of an activist to the authorities I'll just go back to setting up my own mail server like it's 1995 and f*ck all this madness.
If they are announcing this, think of the ones they are under gag orders to not announce /disclose
Like you can trust your ISP?
Chances are tracing your mailserver to you isn't any harder than tracing a protonmail account to you.
Email is supposedly decentralized, but under the umbrella of "anti spam" it's really an oligopoly of providers
I do not trust protonmail with my privacy. I only use them to sign up for various services, trying to escape the data mining google does.
Not sure I want to support a company that is dishonest however. I'm reaching the bye-bye point myself slowly but surely.
There needs to be a messaging service where as well as the messages being encrypted, the graph of who is talking to who and when must be encrypted.
I'm imagining a system where your device forwards hundreds of messages for other people, hiding your own message flow.
I perhaps send a few hundred messages per day, and even multiplying that by 1000, and the typical message length of a few words, it's still a tiny amount of data transfer.
But yes, the problem with an encrypted tor-for-email would be the exit node would get all the emails and probably be responsible for the final content.
There's also a builtin I2P-Bote messaging system (bundled with the official I2P client) that is in a sense a substitute to email.
The tech is there, what the I2P ecosystem needs is a lot more users and a lot of UX improvements to make it 1-click accessible.
I suppose this would land them in hot water, but there might be something else really clever?
https://runbox.com/why-runbox/privacy-protection/email-priva...
Something is going to move.
It also seems that it is not any restaurant but one of the 'victims' of the 2015 terrorist attacks [1]
Basically political extremists trying to disguise themselves as environmental activists. Not interesting people, to say the least.
[1] https://www.tellerreport.com/news/2021-01-04-%0A---justice-o...
But
Configuring logging on a user's IP address information on a private email service for what appears to be a fairly petty crime seems rather like dropping a nuke on an ant, both on the side of the French/Europol LE, and also for Swiss authorities, and then Swiss companies to be responsive to something so petty.
For something this "Organizing a Climate Camp" [1] involved I'd expect at least a serious felony, or a dramatic terrorist incident with loss of life.
If the crimes involved are truly so minor, it raises the spectre of what would they do for an actual serious crime?
I hope I am misreading this......
[1] https://www.liberation.fr/terre/2020/09/27/camp-climat-a-par...
Or they’re just some college students spouting inconvenient truths ¯\_(ツ)_/¯
Anonymity (which is different than privacy) is something that can only be achieved in very particular circumstances for a limited time. It always involves work on the part of the person involved, usually ongoing. It isn't something you can just go out and buy. Most people have no need of it most of the time.
So a Swiss company has been apparently forced to provide details of a user who is under investigation by police in another country? I'm curious about the way that actually works, that a Swiss court receives a request from a foreign police force and a private company has no recourse to refuse or appeal the resulting order. Seems a bit weird to me, although I don't know a lot about the legal system there.
Technology people always want to imagine that technology will save/deceive them.
Imagine a situation where some "enemy of the state" is using some "secure" service like "securomail" or similar.
Is it hard to imagine Police/Interpol/KGB coming to the offices of "securomail" and demanding providing IP addresses, no longer encrypting, installing malware for this particular user, etc? Or else all the C-level of "securomail" are "helping the enemy of the state" with all the consequences.
There is always this "5$ wrench human layer" which no technology will protect from.
protonmailrmez3lotccipshtkleegetolb73fuirgj7r4o4vfu7ozyd.onionhttps://www.wired.com/2015/10/mr-robot-uses-protonmail-still...
https://protonmail.com/support/knowledge-base/imap-smtp-and-...
But you are still making an IP connection. JS/no JS is not relevant to this discussion.
try using Tor to create a protonmail account and they require both javascript and a phone number.
yeh yeh client side encryption requires javascript, but seems better to just have an unlinked email that can be read server side and there are plenty of Tor-only email providers for that.
phone number under an "anti-spam" guise is just suspect.
However, in this case just as in a few other ones before this one, it has become pretty clear to me that ProtonMail's marketing is deceptive at best an in a few cases some of their claims just blatantly not true.
What surprised me most is that when I pointed this out in the past, I was immediately attacked by what appeared to be like Apple-style fanboys, whole would not stand by anyone criticizing ProtonMail.
To this day I'm not so sure if that was just the genuinely zealous behavior of a few deranged individuals, or if it might have been a concerted commercial effort at damage control.
Either way, to me ProtonMail certainly is not what it claims to be (if not explicitly than at least implied). To me it's just another commercial entity trying to make a profit by tapping a relative niche market while convincing gullible people they are something they actually are not, in any way that will make them a bigger profit. Nothing really shocking about that, and mostly just standard behavior for any other modern commercial entity operating within a capitalistic economy.
They don't log IP, but if ordered they have to. They can't choose what criminal cases are sufficient. They have to follow the law.
> "Where can I read more about this? What was the alleged crime?"
>> "Organizing a climate camp. Some links (in French)..."
So either something else is missing, or investigations are biasedly heavy handed on these cases?
TLDR:
1. Protonmail received Swiss legal request that was based on proven legal grounds and thus had to comply with.
2. They started monitoring the user's account and informed them that their data was requested. (Informing is required by Swiss law)
3. Only data Protonmail keeps by default is account creation date. Now they also logged the IP of the tracked account.
4. This IP information was given to the Swiss authorities.
5. The Swiss authorities gave this information to Interpol.
What should Protonmail have done differently here?
The web interface is roundcube, but if you just use IMAP, it could work for you.
No custom domains though for sending stuff, catch all redirects obviously work.
Please.
That's the only way to keep this specific part of the decentralised by design, old internet alive.
Do they though? What about even less friendly states?
Why hasn't there been made a Tor-only, store-and-forward, text-only communication app? You'd think this would be a no-brainer for communities that need real private communications.
Also, their VPN...
But here, it's not climate activist. It's people illegally occupying private properties, iow squatting. They do it for political reasons, fine, but it's illegal nonetheless.
Also, I'm a bit surprised that these are climate activist at work here since gentrification (the process they fight against by squatting) is not really a climate issue but more a problem (as I read it) of capitalism.
(now I understand the whole issue down here revolves around disclosure of expected-to-be-protected information, but well, there's a big picture too...)
My bet is this, proton can't actually afford to defend against thousands of court cases, so they comply. They can't afford for their service to look insecure, so theyre selective in divulging how much surveillance they have to comply with.
so today we are redefining what "not logging data" means. it changes meaning when used in the same sentence as the expression "by default". so by default, not logging data is not really not logging data.
we've redefined quite a few things in the past few months. will be interesting to see where we go from here.
If the subject of this investigation had been using ProtonVPN to connect to ProtonMail, would this have (in a marginal way) protected their anonymity? If ProtonMail can be compelled to begin logging, surely the same must be said of ProtonVPN right?
It’s interesting how many “privacy focused” companies tout being based in Switzerland as some big badge of honor, which a layman consumer such as myself is supposed to be really impressed by due to the overall reputation of “Swiss privacy laws.”
In practice, I’ve never been to Switzerland. I don’t know any person that has had any legal issues there, let alone someone that’s litigated a digital privacy case there. I do not speak German or French, and don’t know where to start when it comes to looking up specific cases or court proceedings, so I’d be extremely slow on the uptake of the actual ins and outs of how the Swiss privacy model works from a practical standpoint.
The “based in Switzerland” thing strikes me as a bit of a black box bit of marketing speak. How much time, energy and money did ProtonMail expend fighting this surreptitious logging mandate? Does “Swiss privacy” actualy mean anything if ProtonMail is happy to hand over your IP address when spooked?
I believe it comes about due to the old trope of Swiss banks being the most secure places to hide money, which of course is not true and hasn't been for a long time. Even in that period, I am sure they complied with Interpol/Europol requests to divulge account details of evil masterminds with a beeellion dollars hidden away in a Swiss vault.
I would not pay any attention to the “Swiss X” marketing.
Were they inside the country? Were also they subject to Swiss laws? Aren't these the things that would make a company Swiss? Even if the company was started by a person that isn't Swiss, I'm pretty sure it is still a Swiss company if it is initially located in Switzerland and governed by Swiss laws.
There wasn't any of that there. The only detail in the complaint was about the non-Swiss folks working there. And I really, really don't understand how it just isn't low-key racism. Could you explain it better for me?
it does not; witness the swiss banking system's capitulation to the US, crypto AG, etc
I can only confirm your doubts about the "Swiss privacy laws". The current laws in Switzerland are very week (at least compared to the GDPR) and it has powerful surveillance laws in place (6 months data retention for telecommunication data, mass surveillance of internet traffic entering and leaving the country). If at all, being based in Switzerland as a privacy friendly company is rather a risk than giving you a "badge of honor".
I can only speculate where this myth and reputation of "Swiss privacy laws" is coming from. I guess it is related to the bank secret we had in place for a long time: It allowed you to own a bank account anonymously. While many states (especially the US) protested strongly (and for good reasons), it gave Switzerland an aura of discretion.
Even the government sucks at online security, see the debacle of the city of Rolle and the cyberattack they suffered last month. If this is not pure ignorance and incompetence, I don’t know what is.
Not even mentioning several “made in Switzerland” software company whose only claim to Swissness is that they have an office with two people in Switzerland and all the rest are European or Indian contractors (not that these people are worse, just that it’s a marketing thing to tout Swiss software if you’re going to outsource 90% of your development offshore)
Most of the time, claiming Swiss anything is a marketing move and an excuse to justify charging much much more for something.
The reason I use tutamota (similar to protonmail) is to stop the Googles and Yahoos and hotmails from scanning all of my emails, using them to advertise to me, selling the information to advertisers. Could you imagine if the US post office opened up all your mail, read it, and sold this information to anyone who asked? Preposterous. And keep track and sell who you send stuff to and who you receive info from? Of course, if the government decided to monitor you regular mail, they could. Fine. Nothing anyone can do about that. But at least the USPS doesn't read everything you send and sell that info to commercial entities.
So, that is why I use those types of services. I don't want to be anywhere near Googlemail, or Yahoomail, or Hotmail, etc.
So not too sure on your point that you're trying to make. Yeah, if there's a subpoena, I'm sure the government could open and read every single piece of mail you send or receive, but that's what I said.
But, Google or Yahoo or Facebook is not going to have access to this information. But they will if you use their email system. Why do you think they offer it for free? Through the generosity of Sergey Brinn and Larry Page's black, black hearts?
https://www.forbes.com/sites/adamtanner/2013/07/08/how-the-p...
I personally don't fill out the change of address forms.
Edit: Note, this is a "nice assurance to have" because private shipping companies generally reserve the right to open anything that they are shipping.
And again, with private shipping companies, it's not like they are going to open 100% of everything. But the large email companies can, and have it forever. Can look at it 10 years from now, if they choose.
They don't sell your information to advertisers. So your threat model here is factually false.
Personally, I've switched from Protonmail to Fastmail. Yes, Fastmail is in Australia which has draconian state surviellance laws and will comply with state requests for your data and share it with other countries. But you can't assume that any other email provider won't, as evidenced by what Protonmail just did. And Fastmail has better features for protecting you from being profiled, such as unlimited wildcard aliases, and the ability to create filters and deactivate aliases directly from incoming messages, in addition to a far better overall email experience.
You are right about Protonmail and Fastmail giving up info to legit governmental agency subpoenas. It's just obvious. Any company will do this, no matter what.
I chose tutanota after an extensive search, because I don't want aliases, I want completely separate email accounts, because if you have aliases, they all still come to the same exact account and I would still have to wade through all the emails. The filters really don't do it for me personally.
And tutanota was the least expensive option that I found. Emails are only $1 per month - $12 per year, while Protonmail is $5 per month after the first email address, at least that is what I remembered at the time. So that is 500% more in cost. So if I have Protonmail, it would cost me $240 per year (if paid annually, otherwise more if paid monthly) for 5 extra email accounts, while tutanota is $60 per year.
Tremendously disappointed.
What’s next? Is ddg selling search data to google?
Brilliant!