Interestingly, ProtonMail's privacy policy lists a number of cases in which they may log your IP address permanently (including if you breach their Terms and Conditions). But a request from law enforcement is not one them.
Moreover, I would like to point out that ProtonMail is about encryption of email *content*. It is foolish to expect more from them. They won't protect your identity: law enforcement can know who you are and who you communicate with, but they cannot know the content of your emails (if you recipient uses encryption services as well).
I see that you want to protect Protonmail, but if they want to stop being misleading they can just remove the IP log sentence
I would much prefer this, as a Protonmail paying customer.
Tor is an improvement. It's still a limited tool.
I can't but help read your post in comic book guys voice.
Traffic analysis, at a cost, could establish that the suspect is using Tor.
TorMetrics shows slightly more than 1,250 currently-running Tor exit nodes. I'll presume this is typical, history shows it's pretty consisten over the past 3 months.
https://metrics.torproject.org/relayflags.html?start=2021-06...
I'm going to presume that a court could conceivably issue an order to log all Tor-based traffic. A state actor / APT might then be able to correlate a known IP and traffic at a given point in time with other data to identify a source IP. This might be combined with other measures to encourage circuit-jumping until the suspect is on a specific known or monitored Tor circuit.
Yes, costs increase. I don't see this as technically infeasible, however.
Might not be rolled out just for a house-squatter, however.
Frankly, I don't think anyone is safe from the tip of a nation state, even small ones. But I do think we should protect everyone else and Tor would have done that.
Because this was clearly civil disobedience and that is what we really should be protecting.
Just ... don't think it's a majykal bullet. It's not. Tradecraft matters, vulnerabilities exist. Examine and review your threat models.
Even if a nation state was targeting you, it would still take months for a timing/bandwidth attack to identify a user. Even then it would only provide your adversary a probability of certainty and requires consistent traffic from the victim through a compromised exit node.
No system is 100% perfect but tor will make most attacks prohibitively expensive.
Remember: all you need is 33 bits.
Here, data enter the Tor system, but don't leave it as the onion service itself has a Tor address.
Yes, traffic analysis and timing correlations may still be used to draw inferences, but again, costs are raised, and that's the critical factor.
I'm a privacy activist and certainly think that a company should be able to not keep logs. If the law in the country they are in (or area, see for example the data retention directive in the EU) we should of course (and I am) work to change those laws.
It should come as no surprise to anyone who is privacy minded and actively seek out privacy focused services that are located within the EU or Switzerland that your IP (or other information) can be requested with a warrant and that a company is required to hand that over.
I get that you think people should already know this, but do you feel they should be punished for not already knowing this, and not reminded by a company that markets itself on protecting its users? Protonmail was forced to get an IP address, but they're not forced to keep the fact that they respond to warrants a big secret.
Not everybody who is an activist is a big techie, or even computer-literate.
> We will only disclose the limited user data we possess if we are instructed to do so by a fully binding request coming from the competent Swiss authorities (legal obligation). While we may comply with electronically delivered notices (see exceptions below), the disclosed data can only be used in court after we have received an original copy of the court order by registered post or in person, and provide a formal response.
It would also be nice if they were allowed to notify the customer but I'm not familiar enough with Swiss laws to know if they can.
(also a paying Protonmail customer)
Of course Protonmail is accessible via Tor. Not that you should need to do that to remain private.
Gmail does all of this for free though, right?
Gmail Pro (paid G Suite) has never done that, and Gmail Perso (Free) hasn't done that since 2017.
Because I am aware of no reason to think that Google stores my gmail with zero access. I don't know for a fact that ProtonMail discards this information at the earliest opportunity nor do I know for a fact that they don't try to aggregate it to learn about you (or even people in general), but that is what I interpreted the pitch as.
But, look, of course if they get a subpoena they will have to start scanning your email if they are technically able to collect it. That's just a wiretap, and little would prevent the author and operator of the server software from doing whatever they want... and they're clear that if you aren't sending email between two compatible accounts that there is no E2EE.
We can talk about how they should have been clearer about the need to use Tor to avoid IP logging (even if they don't do it, someone between you and ProtonMail certainly could). That's a good idea. But they are actually very clear that E2EE with your email is not what you should expect in general. And I don't think they have much incentive to scan my email from unencrypted sources to do anything nefarious, but I don't think anyone has any ability to prove they do or don't at present.
But that is not a proton issue that is an issue with our current governments.
"Hey, we respect your needs. However, we have to tell you that you should treat us as a bit of an adversary. We will do what we can as a private company, but ultimately we can be compelled by the government, rogue employee, or if somehow we get hacked. This is the case for any company no matter what they promise or avoid telling you. We do tell you. As our customer, here's what we recommend you do: Use Tor, fund open source, vote, etc."
You’re telling us that you never considered that an incorporated company, bound by democratic laws, would be required to respond to criminal activity warrants?
What fantasy land do HNers on this thread live in?
No service is capable of completely hiding IPs and still getting you the data. If you "threat model" includes hiding from Western governments, I'd recommend not using the internet.