Proton like all law abiding companies must follow court orders. But unlike most companies, Proton actually fights in court and won a legal victory against the Swiss government after the case in question, overturning an earlier ruling that email providers can be classified as telecommunications providers. Details here: https://proton.me/blog/court-strengthens-email-privacy.
Replace "French climate activist" with "dissenter in an oppressive regime" and that person would be dead.
Who cares if they later won in court? They still threw someone under the bus. Trusting a third-party business who is subject to the laws of where they operate means this will always be a problem, doesn't matter if they're an email provider or a VPN operator, the solutions aren't fit for purpose.
… unless they decide they want to, in which case they can, because they serve the software, and can thereby easily exfiltrate the key.
I have to keep on saying it: first-party end-to-end encryption is snake oil. https://hn.algolia.com/?query=chrismorgan+snake+oil&type=com...
It does resist casual or accidental leaking, and is even proof any form of disclosure if you have stopped using the service altogether, but is absolutely not robust against rogue employee, rogue company, legal compulsion, infiltrating attacker, &c. as long as you continue to use the service.
If you want actually valuable end-to-end encryption, start by getting your software and network services from different providers. (And avoid the web’s distribution model like the plague, and probably mobile app distribution models too.)
By default, who generates the keys?
If you are compromised and your software starts to exfiltrate the keys to a third party, how long do you think it would be before anyone noticed?
They received a court order, they cooperated with the police, for better or worse (I have zero opinion on it; frankly don't care), and handed over a customer's IP, which led to the arrest of the activist.
The problems that Proton is trying to solve, e.g., email, are better taken care of by other tools depending on a user's threat model. Likewise, if someone actually needs privacy and security because their life is on the line in an oppressive regime, utilizing a service like Proton's is a shit idea.
Anybody receiving sensitive information via email is doing email wrong. Email in and of itself is not fit for purpose as anything but a means of notification that something needs their attention on x, hence banks tell you to login to read a sensitive notification, hence the government tell you to login to the web portal to read a message.
It's a cheeky way of saying "this won't stop people from torturing shit out of you", and the rest of the article looks fine.
It's hard to take a poster seriously when they dismiss the entire model based on a hyperlink who fails to address the points in the model.
I'll agree with your point about email though: it's a tool for correspondence, not for secure transfer of sensitive info.