Proton AG of ProtonMail can provide FBI with your account recovery email
fxtwitter.com
fxtwitter.com
> In that post, altoid asked for some programming help and gave his email address: rossulbricht@gmail.com. Doing a Google search for Ross Ulbricht, Mr. Alford found a young man from Texas who, just like Dread Pirate Roberts, admired the free-market economist Ludwig von Mises and the libertarian politician Ron Paul — the first of many striking parallels Mr. Alford discovered that weekend.
https://www.nytimes.com/2015/12/27/business/dealbook/the-uns...
I don’t doubt for a second that a non-zero number of people similarly create a ProtonMail address for something shady and then provide a Gmail address using their real name as recovery address.
https://twitter.com/monetaryreset/status/1766156285249012151
Apple (iCloud, Mail, etc.): https://www.apple.com/legal/transparency/
Facebook / Meta (Instagram, etc.): https://transparency.fb.com/reports/
Google (Gmail, Google Voice, Search, etc.): https://transparencyreport.google.com/user-data/overview
Microsoft (Skype, Outlook 360, LinkedIn, etc.): https://www.microsoft.com/en-au/digitalsafety/transparency-r...
Proton: https://proton.me/legal/transparency
TikTok: https://www.tiktok.com/transparency/en/reports/
Twitter / X: https://transparency.x.com/en.html
The actual warrant can be found here and has the important missing details: https://drive.proton.me/urls/57QC5F26BW#nseYl6ICaQHm
The only data we could provide (in response to a binding Swiss legal order), was the user's recovery email address, which the user added himself, and is optional to begin with.
Unfortunately, said user also used that recovery address to create a Twitter account, and Twitter turned over his phone number and IP address.
Coincidentally, this case again proves that Proton Mail's encryption cannot be bypassed by law enforcement.
The only data we could provide (in response to a binding Swiss legal order), was the user's recovery email address, which the user added himself, and is optional to begin with.
Unfortunately, the said user also used that same recovery address to create a Twitter account, and Twitter turned over his phone number and IP address.
Coincidentally, this case again proves that Proton Mail's encryption cannot be bypassed by law enforcement.
Hence I think it's pretty clear for ZK customers that a company has to abide to the local law...
The article is about what Proton knows, not what they will or will not do if the law knocks on their door.
I feel you are being disingenuous though and you perfectly know what is commonly referred to as "zero knowledge", and specifically that the critical point is always "what does the zero knowledge applies to?".
Proton sees your IP, your login, email headers, for example. They don't know your email body and can't hand it over.
Of course, Proton is not such an entity, but they are happy that you have fooled yourself into paying for this imaginary property.
I think abuse of power by government is common and wanting to get protection against it is a fair ask.
And luckily this is not illegal in some countries.
Finally, some government are not representing the people at all (dictatorship) and I am lucky I do not live in such a country, because then the existence of proton has a whole other level of merits.
How far should this extend, in your opinion? Should the US be bombing cartels in Mexico? How about manufacturers of illicit goods like “Glock switches” in China? Tax avoidance firms in the US? The company registration division of the Turks and Caicos?
How about the headquarters of domestic companies found to be in violation of federal regulations?
ALL companies must abide by the law. What did you expect? That they break the law? Not a very sustainable business model...
1. Use a custom domain for your emails with Proton
2. Set an address @ that domain as the recovery address
3. If you need to recover, simply update your MX records to point elsewhere, and begin the recovery process from another provider temporarily.
How’s that for privacy?
Coming back to the question, the roads you travel, the vehicle you commute are all under constant surveillance, FYI.
I've been a customer for a few years now. Long enough to watch the company steadily scope creep in ways I don't agree with. I wasn't 100% against the VPN idea. But then came Drive. And calendar. And ...
Thing is, their core Mail product kinda sucks. End to end encryption is great, but have you ever actually tried to search for emails in Proton Mail? It's embarrassingly bad. I've lost count of the number of times I know exactly what I'm looking for in my mail archives, but no matter what search incantations I try, I can't find it.
Their bridge clients are stupid. The way threaded replies are handled are stupid. Their web UI is frustratingly laggy in Firefox. I didn't particularly like their iOS app, and now that I'm on Android, I don't particularly like their Android app, either.
For me, the next step is to self host my email. Yes yes, I know: "but self hosting your email is notoriously hard and bla bla bla!". Yes, no doubt. But email is important, and I've been burned by GMail, appalled by Fastmail spying for the Aussie govt (god, what a shitshow that was/is), and suffered constant disappointment as a Proton customer. Self hosting feels like the only option left.
I have found success, using SPF and DKIM signing. I had to do that, to get emails from my current app, through Apple's anonymizer.
Are they holding you hostage? Is there a contractual obligation preventing you from cancelling? Why can’t you just cancel it if it sucks?
I've implemented a few e2ee apps, both for myself and clients, and every single time this comes up, along with other business metrics / queries.
If the encryption model ensures the server cannot process the data in any way, it means everything has to be done locally by clients, and only on their own data.
Also, bye bye BI.
That I think is a pretty small sliver of Proton users. Users who want to maximize privacy are certainly there, but I think most simply want a stable email provider that respects customer preferences instead of Google shenanigans. My 2c.
For example, I am a happy, paying Proton customer for my primary email that clearly identifies me by its domain.
Services that are primarily used to hide shady stuff from the FBI tend to get shut down or, failing that, heavily stigmatized.
They need a page like this to explain what exactly is E2EE and what isn't: https://support.apple.com/en-us/102651
Is that claim itself not accurate?
I mean just look at the end-to-end encryption block, it's such an obvious dark pattern to make people believe they're getting end to end encryption, but when you actually read it they don't claim it at all, but how is someone who doesn't understand technobabble supposed to know that? They're just trying to pretend it's the same thing.
If Proton was an American company they would have been fined into the ground for this stunt. Google wasn't even safe from the Incognito mode lawsuit.
> With Proton Mail, emails are encrypted at all times, so we can never access your messages. The content of your emails is encrypted on your device before being sent to our servers, meaning only you and your intended recipient can decrypt it.
> You can also use our Password-protected Emails feature to quickly send end-to-end encrypted emails to any email address, not just Proton Mail accounts.
That first sentence, if left alone, could be interpreted to include incoming email from non-Proton Mail accounts. But as soon as you keep reading it clears that right up:
* It clearly says that the security comes from encrypting outbound email on your device.
* It clearly says that there is a way to encrypt outgoing email even to non-Proton Mail accounts.
This isn't technobabble either, it's using terminology that is as accessible to laypeople as possible while still being precise in its language.
C'mon man, even you should know how much BS that is. They are misleading people and they know it, just hoping nobody reads the fine print. I have 0 trust in Proton because of this shit.
It doesn't matter what they say in the fine print, telling people there's strong encryption at all times right next to "end-to-end encryption" would fool anyone into thinking Proton can't read email in transit to non-Proton emails (in fact they even claim this, and it's false). They wouldn't be able to gain any users if they told the truth that they are the same as any other email provider except when they email their own users.
They even have the gall to say they offer a more secure business email but don't offer SAML or log integration, very basic things any actual business is required to have if they want to even meet baseline security measures.
If someone can't be bothered to even read beyond the first sentence of the marketing page, then privacy and encryption aren't actually important to them, it's just an aesthetic.