ProtonMail Complied with 5,957 Data Requests in 2022 – Still Secure and Private?
restoreprivacy.com
restoreprivacy.com
ProtonMail’s communication needs to be a lot more clear on these issues, they need a dumb docs page or slideshow or YouTube video that address all the concerns in a super concise way that can be linked when these concerns come up.
And especially they need a warrant canary that says “we’ve never handed a government the contents of a private accounts emails or the metadata for when/whom they sent/received emails from”.
—————————-
Definitely not[0].
Black market sellers are often kicked off protonmail for “illegal activity”.
LavaBit was probably the last “secure” email provider, they got an NSL for Edward Snowden and chose to fold up the entire company rather than carry out the orders in the NSL.
CounterMail may deserve an honorable mention, but you’d likely want all parties that you need to communicate securely with to also have a countermail account and it’s invite-only. P.S. I would love an invite if anyone has one: HNrunnerup@protonmail.com
Similarly it seems relatively easy for signal to move away from needing a phone number.
I don't know how good Session and Simplex are.
Regarding the "MITM" for every email sent, this is related to their "bridge" software which allows regular IMAP/SMTP software to use Proton Mail. This software must edit the emails to encrypt them in their scheme.
This software is open source and can be inspected and/or built locally. https://github.com/ProtonMail/proton-bridge
Email contents could still be siphoned, copied and shipped before the encryption process starts.
How can you clarify that does not occur between then and that?
The part that is easier to misunderstand is encryption-at-rest, where normal emails are still readable at ingress before they are encrypted with an appropriate public key.
Also, secure and private != willing and capable of hosting illegal activity. They can kick suspicious behavior without having to read your emails.
What more do you want from them?
Unless you read and compiled the code yourself and run it locally, some level of trust is always required.
Consider Gmail, they send 20% of outbound email as clear text and 4% inbound is unencrypted[1]. Of the encrypted email, it's unclear how much actually validates DNSSEC/DANE or a trustworthy CA and refuses to send when these are missing.
Encryption on email is generally about as secure as using http:// for 20% of your web browsing and ignoring certificate errors when you use https://. We tolerate it because email clients generally don't warn end users when this happens and there's not much we can do without harming delivery.
Worrying about legally compelled metadata sharing misses the larger context email operates in.
[1] https://transparencyreport.google.com/safer-email/overview?h...
If you want a communications system that’s safe from government snooping, don’t use email. Stick to signal or maybe WhatsApp. Or if you must, self host. At least then the court order to see your server will come to you.
And if you're restricting your conversation to people on protonmail for security, why bother with email at all? Seems easier to just put the conversation on signal anyway. And then you get all of signal's other security benefits, like E2E encryption, crypto ratcheting, disappearing messages and so on.
This second restriction is especially damning: They accept cryptocurrency, but only for existing accounts - after you've already doxxed yourself.
The idea that "as the webmaster of the email server, i could get a notice and i can conveniently, confidently say "fuck off" sounds fun".
This isn't about protecting pedos or serious bad people but dmca nonsense or such "legal requests" that you are confident you can say no.
3 years ago:
gmail/outlook was an ass. They marked all emails as spam. I had to call recipients to check spam and mark as not spam. this was on-off for the first few months. then things went good on their own. They would mark spam initially all emails, then emails with attachments then once marked as not spam, things got better.
today i have 0 issues in outgoing email. funnily, i have a website that sends me emails and there is some unknown problem on "receiving emails". just one website so haven't had much look into it.
last month: followed the same setup and gmail/outlook made no complaints. this was surprising to me as i deliberately sent attachments but nothing.
one thing to note. i once send 15-20 mails in bulk (not cc/bcc but separate) at once and that triggered some spam response. marked as not spam fixed it though on recipient side.
both times i used mailinabox and a cheap vps from lowendbox deals. racknerd or something on offer.
takes 1 hour almost from domain/vps purchase to full setup and sending emails. backup on backblaze b2.
takes 5 minutes every 6 odd months to update the software but that's about it.
Do not bring your server up without securing the email setup and setting up essentially useless things like DKIM, SPF (and DMARC). Large providers want to see those.
If you get into a block list, know quickly and fix quickly.
Use a well established domain suffix like .com. The cheap vanity ones are usually blocked more.
If you need software recommendations, there is nothing Postfix+Dovecot cannot do.
* Proper A and MX record set up in DNS per SMTP standards
* Proper SPF record in DNS
* Proper DMARC record in DNS
* Proper DKIM record in DNS
* SMTP server (postfix) is not configured as an open relay
* SMTP server is configured with a DKIM milter to sign outgoing messages
I used basic guides for the DMARC/DKIM stuff since that was new to me and tested with a Gmail account. The first few messages were marked as spam but I was able to unmark them. Once I was able to verify a correct SMTP setup, after two or three unmarkings, all messages were just delivered normally and no longer marked as spam. Google will even email you a report to help debug issues if your DMARC record is set up for it.As far as I know this is about the best you can do. Everything else is pretty much getting your mail server IP addresses removed from various blacklists which can be easy to impossible depending on the service. The other option would be to forward to another service that allows relaying and has IP addresses with better spam scores but I personally prefer to avoid that.
Or Session?
(typo - wrong link corrected)
Edit: of course if they kept minimal logs & user information would help when law enforcement came knocking. Can’t give what you don’t have
You either build your model to be resistant to a data request (user controlled keys that never leave the device), or you don't even come to the table.
This means that the cloud model, where code is downloaded through a web browser, is right out. Regardless of where the keys are.
Currently, in the USA, the most generally accepted view among legal scholars is that this is not legal for the government to do -- mainly because of a view that it's a particular form of compelled speech / forced labor which is unconstitutional for the government to compel.
It is, however, an avenue that the law enforcement community does occasionally investigate as a possible route to get what they want. There's no clear court ruling as no cases have gone that far.
All the encryption/decryption happens locally (inside your browser/client).
Thats why, if you want to full text search in proton you have to download your complete history into your browser.
I'm all for privacy, and indeed, stored data should be kept to a minimal. But if a lawful order against a criminal is complied with, I definitely won't cry murder.
The problem is that Proton markets themselves as "secure, encrypted email" when in reality they have access to all your stuff and say they don't.
What I would expect from a service that kept their word: police knocks at their door, they say "sorry we cannot give you data we don't have, we don't keep records here".
They would probably battle against the authorities in court, but that should be the modus operandi if you care about your users privacy in the first place. Proton doesn't do that.
They say they are under strong Swiss laws but any subpoena or warrant they get, they just comply with it instead of battling it.
cock.li is a provider handled by a single person only and he received several gag orders and never complied to one of them, and he lives in the US. At least the guy is honest and tells people that if you're worried about privacy, you should know that he can read your emails whenever he wants to.
The problem here is that Proton sold itself as a privacy-first service that would protect you from the authorities, but it turns out it's just as normal as a service than Gmail or Outlook.
You can learn more in our Privacy Policy (https://proton.me/legal/privacy), Threat model (https://proton.me/blog/protonmail-threat-model, available publicly since the beginning), and in this support article: https://proton.me/support/proton-mail-encryption-explained.
You can also see in the Transparency report that we contest all of the legal requests we have any legal ground to contest. We are also working on improving the Swiss privacy legislation (which is already one of the strictest in the world) further - we won a major court case in 2021: https://proton.me/blog/court-strengthens-email-privacy.
I could see the proper legal (IANAL) answer (for a fully E2E encrypted system) would probably be something like:
Sure, we will gladly comply as legally obligated to, you will find the whole of the requested data we can provide attached.
<zip file>
The zip file would contain an index.txt with: This is all the content we have access to, which is none at all. This is not a bug, and neither it is a refusal to comply. We do not have access to any other data as it is encrypted when it leaves the user premises.
And maybe a csv file with headers matching the requested data fields but zero rows.The difference being one doesn't say "no we can't" to law enforcement, instead say "yes, but the result is empty"
With that statement, I don't expect they have to compliant with FBI or US laws.. If that's Swiss court, it's fair game... but no way for FBI.
For the majority of users, it's better to have a recovery email on their account, as the risk of losing their password is higher than the risk of being targeted by a legal request. However, even in those cases you can have both, by setting up a new email address which you don't use for anything else as a recovery email.
The cases mentioned in the article above actually confirm that our encryption works as advertised and cannot be bypassed by legal means - we are not able to share any content stored encrypted on our servers, because we don't have access to it.
But they can't share actual data if everything is encrypted.
- Does not use the email notification sound on iOS
- Cannot open iCal attachments in the system Calendar on iOS - this is infuriating!
- Proton Calendar itself doesn't support shared calendars, despite being advertised as 'for business'. Almost every business needs a calendar that multiple people can modify.
Aside from that I've been generally satisfied, but the problems mean I can't recommend Proton for a business.
I'm sincerely curious, I'd like to understand why protonmail is getting so much hate on HN, is it they are getting too mainstream?...
Does the writer of the article even consider who the audience if the "opsec" section are? Unless i am missing something about swiss law, that section is advicing criminals who wish to evade the law.
I use Proton, and the metadata they do keep unencrypted would only be useful to LE/feds if some other source (ISP, IXP, OS, etc) has given up info, which you certainly can't blame Proton for.
The article is bad for trying to insinuate that responding to warrants indicates failed security, when the reality is that what you respond with is what matters, and in this case it appears to be metadata only.
Warrant canaries are useless in any jurisdiction that partners with foreign police and courts. At that point, you need an "unencrypted content sharing canary".
Email wasn't designed to be such, and trying to workaround the design to make it, is fragile and error prone, with multiple opsec pitfalls, it's practically impossible long term.
I also see that ProtonMail is headquartered in Geneva, about 2km from the French border... which I suspect means that a fair number of employees commute from France on a daily basis...
What does this imply?
Not sure what happened with the US, but US is a bit special because they have extraterritorial laws (i.e. laws that apply everywhere in the world) and the means to enforce it. Because the USD is used as an international money, and the US position in the world, if the US wants to punish you they'll find a way even if you're based outside US.