Once again - Proton is legally obligated to comply with the laws of the country in which they are based. This isn't specific to Proton, and they are not going behind your back to do this. In case it's not clear, this data is directly from Proton.
post
I don’t think that’s bad on Proton’s part. They are obeying the law they are obliged to obey.
Yeah, more important is what data was it
Privacy is not anonymity. In this case they were required to supply IP addresses of users logging into a certain account in an active investigation.
As usual, the devil is in the details—ProtonMail’s original policy simply said that the service does not keep IP logs “by default.” However, as a Swiss company itself, ProtonMail was obliged to comply with a Swiss court’s injunction demanding that it begin logging IP address and browser fingerprint information for a particular ProtonMail account.
"From time to time, Proton may be legally compelled to disclose certain user information to Swiss authorities, as detailed in our Privacy Policy. This can happen if Swiss law is broken. As stated in our Privacy Policy, all emails, files and invites are encrypted and we have no means to decrypt them. "
Proton threads are where the leftists equivalents to sovereign citizens pop up. Learn the technology a bit and about legal systems. That's what you have to operate within. If you want to feel more in control, encrypt everything yourself and only communicate/share in encrypted channels. At least then the primary sources of leaks is you and the receiver. If not, you're whining about streamlined performant services that will never be perfect enough for your standards because they operate legally rather than the user unfriendly solutions that you aren't willing to operate yourself for your life (maybe to be passed on) and/or won't run/can't afford to operate the illegal operation
I using proton more as a middle finger to google than anything else and at that it works fine.
Um...obviously, yeah? The alternative to complying with the authorities is to challenge it in court, which is extremely expensive. The important question is not how much information they do hand over, but how much information they have themselves. For example, if your keys are private, proton has nothing useful to share. This is why end-to-end encryption matters, the only avenue to real privacy is to make sure Proton has nothing useful to share. They're not going to host their servers on international waters.
Granted, it’s been awhile since I read this, but don’t their subpoenas driven info essentially say yes, this is so and so’s email account with no discourse content due to encryption?
This holds true for any kind of secure communication you want to do.
Manually handling keys and encryption with GPG is the core of good opsec, and also a reason why 99% of "crime prevention" backdoors are probably not going to do much. But people are lazy, been a while since I saw a drug dealer hand out public GPG keys, ever since Telegram and the like got popular.
top 50 comments