Without having a good anonymous starting point, protonmail does not let you get that starting point, at least the last time I tired (maybe a year ago).
Without having a good anonymous starting point, protonmail does not let you get that starting point, at least the last time I tired (maybe a year ago).
It's a stark contrast to Tuta, which allows anonymous account creation with Tor Browser if you pay with cryptocurrency (Monero or Bitcoin, via their partner ProxyStore) and doesn't require a whitelisted verification email address or any other data.
"They accept cryptocurrency, but only for existing accounts - after you've already doxxed yourself" (during the initial signup flow, where this payment option has been removed)
This looks very bad to me.
And what suspicious thing about the network would you be detecting for Tor Browser users arriving on the .onion? Their network is uniform as far as you can tell, and you are blocking them from opening either a free account without an invasive verification method (non-disposable email or phone) if it works at all, or a paid account without an invasive payment method.
For Tor users arriving on proton.me, what sense is there in saying "There's a surprise in every 100th exit node! If you cycle through enough of them maybe you too will be allowed to open an account anonymously!" Not treating them as equivalent to .onion visitors is a you problem.
> It takes a while for the Bitcoin transaction to come through, which is why we the process is the way it is.
By not allowing this payment option at all in the signup flow? Removing what would be the only way for Tor users to sign up to your service anonymously without beating lottery odds. Just use any normal off-the-shelf checkout page that waits for however many transaction confirmations you want! (Let's not even get into the lack of privacy coin support, e.g. Monero. For a privacy focused service, Bitcoin L1 only is substandard in 2023.)
Meanwhile, whenever people are concerned about user data being handed over to the authorities again, you counter by pointing out the supposed Tor support: https://web.archive.org/web/20210906132309/https://protonmai...
I'm not saying you are a honeypot. I'm saying you've cultivated such a careless indifference to data minimization that you've become indistinguishable from one.
To add an exemption for proton.me: The list of Tor exit IPs is public. For the .onion: That's loopback traffic from the tor daemon running on your own load balancer or wherever you've put it.
The email addresses, however, are not tied to your account - we only save a cryptographic hash of your email address. Due to the hash functions being one-way, we cannot derive your data back from the hash: https://proton.me/support/human-verification.
https://protonmailrmez3lotccipshtkleegetolb73fuirgj7r4o4vfu7ozyd.onion/
and I was never asked to provide any personally identifying information.Did you access the .onion with something more fingerprintable like Brave?