> so for a period of time, people working for Proton were employed by Tesonet, since Proton had no local subsidiary that could hire them. These were not "shared employees", they worked exclusively for Proton.
In 2016, Proton created its own subsidiary, and these people are now employed by Proton. But for this historical reason, the ProtonVPN keystore on Android still lists Tesonet as the organization name, even though it is fully controlled by Proton.
So either:
1. Tesonet/Nord are loose with their private keys.
2. Proton isn’t being truthful.
Anyone who understands crypto and key management knows “not your keys, not your _____.”
If those staffers worked for Proton and not Nord, why did they have Nord’s key?
This level of negligence with private key management really can’t be explained away.