I believe it was stated on the page you copied those stats from https://proton.me/legal/transparency
> As stated in our Privacy Policy, all emails, files and invites are encrypted and we have no means to decrypt them.
I believe it was stated on the page you copied those stats from https://proton.me/legal/transparency
> As stated in our Privacy Policy, all emails, files and invites are encrypted and we have no means to decrypt them.
They're all encrypted except when you pay more for dedicated smtp.
They're all encrypted except when they give up logs they promised they didn't have.
And so on.
I am not an activist so I don’t need to jump through such loopholes.
I don’t despise proton as much as I despise most of Silicon Vally though. I just hope they fight every single court order, because there will be lots of good people being targeted. However, I reckon that is wishful thinking.
Proton does not claim no logs and has never claimed no logs. We do not retain logs by default, but our privacy policy has always been clear that we are legally obligated to follow Swiss court orders, which can ask for IP logging on specific accounts.
They have every means to decrypt, they control both the client software, server, and data. You would never know if they logged your key, and they can be compelled to by flimsy order.
It seems like the next time you log in they would be able to capture your password and decrypt your emails.
Your decrypted key isn't sent off your local computer. So it's not a case of waiting for you to log in and swipe your key. They never get the key.
In the past you could have a separate login password and decryption password. You still can in the advanced settings if you want.
Second, I am not talking about swiping the key, but the password. When you log in, you send your password to their server. They presumably hash the password and compare the hashes then send you the decryption key if the hash is correct.
The problem with that is they could keep the password you entered (pre hash). If hashes are good then use the password you entered themselves with the key to decrypt your email.
It sounds like the separate decryption password may work around this, but is not the default meaning a large chunk of the users are vulnerable to proton logging passwords.
They explain what they do here : https://proton.me/blog/encrypted-email-authentication