Edit: of course if they kept minimal logs & user information would help when law enforcement came knocking. Can’t give what you don’t have
Edit: of course if they kept minimal logs & user information would help when law enforcement came knocking. Can’t give what you don’t have
I'm all for privacy, and indeed, stored data should be kept to a minimal. But if a lawful order against a criminal is complied with, I definitely won't cry murder.
The problem is that Proton markets themselves as "secure, encrypted email" when in reality they have access to all your stuff and say they don't.
What I would expect from a service that kept their word: police knocks at their door, they say "sorry we cannot give you data we don't have, we don't keep records here".
They would probably battle against the authorities in court, but that should be the modus operandi if you care about your users privacy in the first place. Proton doesn't do that.
They say they are under strong Swiss laws but any subpoena or warrant they get, they just comply with it instead of battling it.
cock.li is a provider handled by a single person only and he received several gag orders and never complied to one of them, and he lives in the US. At least the guy is honest and tells people that if you're worried about privacy, you should know that he can read your emails whenever he wants to.
The problem here is that Proton sold itself as a privacy-first service that would protect you from the authorities, but it turns out it's just as normal as a service than Gmail or Outlook.
You can learn more in our Privacy Policy (https://proton.me/legal/privacy), Threat model (https://proton.me/blog/protonmail-threat-model, available publicly since the beginning), and in this support article: https://proton.me/support/proton-mail-encryption-explained.
You can also see in the Transparency report that we contest all of the legal requests we have any legal ground to contest. We are also working on improving the Swiss privacy legislation (which is already one of the strictest in the world) further - we won a major court case in 2021: https://proton.me/blog/court-strengthens-email-privacy.
I could see the proper legal (IANAL) answer (for a fully E2E encrypted system) would probably be something like:
Sure, we will gladly comply as legally obligated to, you will find the whole of the requested data we can provide attached.
<zip file>
The zip file would contain an index.txt with: This is all the content we have access to, which is none at all. This is not a bug, and neither it is a refusal to comply. We do not have access to any other data as it is encrypted when it leaves the user premises.
And maybe a csv file with headers matching the requested data fields but zero rows.The difference being one doesn't say "no we can't" to law enforcement, instead say "yes, but the result is empty"
You either build your model to be resistant to a data request (user controlled keys that never leave the device), or you don't even come to the table.
This means that the cloud model, where code is downloaded through a web browser, is right out. Regardless of where the keys are.
Currently, in the USA, the most generally accepted view among legal scholars is that this is not legal for the government to do -- mainly because of a view that it's a particular form of compelled speech / forced labor which is unconstitutional for the government to compel.
It is, however, an avenue that the law enforcement community does occasionally investigate as a possible route to get what they want. There's no clear court ruling as no cases have gone that far.
All the encryption/decryption happens locally (inside your browser/client).
Thats why, if you want to full text search in proton you have to download your complete history into your browser.
With that statement, I don't expect they have to compliant with FBI or US laws.. If that's Swiss court, it's fair game... but no way for FBI.