7 ms·
The problem I have with ProtonMail or ProtonVPN is that they rely upon Neustar to handle all of their perimeter security, meaning that every single client that
by barrister 6y ago
The problem I have with ProtonMail or ProtonVPN is that they rely upon Neustar to handle all of their perimeter security, meaning that every single client that accesses their services will be inspected by Neustar, which IMO defeats the purpose. At the moment, I don't trust Neustar, and presume they're a US military contractor (located in Virginia).
- guerby 6y agoprotonmail states they're using Neustar for DDoS protection of their network: https://protonmail.com/support/knowledge-base/email-ddos-protection/ https://protonmail.com/support/knowledge-base/email-ddos-pro... Very few players have the capacity by themselve to handle a large DDoS these days. And I'm not sure when talking about protonmail kind of encryption that Neustar has any special access to keys relative to say Level3, cogent or any transit provider between you and protonmail. But may be I misunderstood your comment?
- barrister 6y agoNot as long as it's understood that I feel Neustar was a poor choice given their line of business.
- imwillofficial 6y agoOr, they are a great choice. Defense contractors have unique defensive insight, and if properly fire-walled off from their other lines of business, can be of a net benefit. I worked for a British defense contractor, as an American working with the U.S. DoD. We were careful to dot our I's and cross our T's, but over all it worked well.
- XMPPwocky 6y agoWould you say the same thing if it was, say, a Chinese defense contractor?
- jjcon 6y agoNo why would you? The US has checks and balances to minimize abuse and keep data requests limited to the national security domain (like most countries in the western world or eyes alliances). The other has no such checks on those powers.
- AnonHP 6y agoDo those "checks and balances" really matter in the light of what we've learned over the last seven years (and even before that)? It doesn't seem like there's much of "minimization" going on from the three letter agencies.
- jjcon 6y agoThey do matter, completely. Has the data from national security programs ever been used for non-national security purposes (ie in public policing for instance)? It is rare if not unheard of in most western countries. Conversely, it is used all the time for censorship and policing in China. These checks and balances declared the metadata programs unconstitutional. https://www.cnet.com/news/appeals-court-finds-nsas-bulk-phone-data-collection-was-unlawful/ https://www.cnet.com/news/appeals-court-finds-nsas-bulk-phon... Is the system perfect? Not even close, but it does strive to minimize abuse. Plenty of countries here in the EU have national security programs that operate in a similar fashion. The goal shouldn’t be no data collection, it should strive to minimize abuse and keep collection limited to that national security concerns. None of that is true of the programs in China.
- XMPPwocky 6y ago"Conversely, it is used all the time for censorship and policing in China." Sure- in China. I'm not in China. Censorship might be a problem, but outside of that, I'd much rather have the Chinese government (and even Chinese local police!) have my metadata, and even data, than give the US national security apparatus the same access. Corporate IP is another exception to this- it's pretty clearly better that the US, rather than China, have access to my work data. But for, say, a Snowden-esque whistleblower in the US- can you really say they'd be better off with, say, DHS having access to all their data instead of the Chinese government? Obviously ideally nobody would, but for them, a system whose failure mode is "China can associate your IP and email address" is, I believe, dramatically better than "DHS/NSA can associate your IP and email address".
- Yc4win 6y agoIt's like when they used Radware for _protection_ but I do give them credit for abandoning them after all the public outcry. I'm very curious op, where/when did you first read about them using Neustar? I didn't know that until I read your comment.
- barrister 6y agoIn trying to resolve some of their latency issues for their Linux client (on Github) I realized everything was being funneled through Neustar, which was the issue. So I questioned them about it, and they confirmed it.
- Yc4win 6y agoThanks, I see another poster found a link to a statement they have on their site about it now it seems. There is a particular leaks site that also called out Proton for routing their connection thru a similar shady service in the past.
- protonmail 6y agoThe other service was Radware. The problem some people had was not the tech (it uses GRE tunnels that doesn't compromise our TLS), but that Israelis are allegedly shady. We don't think that's a fair characterization. We have switched from Radware for other reasons in 2018.
- axaxs 6y agoI'm not sure that's a fair presumption. Neustar was spun as a separate entity out of Lockheed many years ago, as a neutral body to do number porting mainly. It was a government contract, but not a military one AFAIK. Source: https://www.home.neustar/about-us/our-history https://www.home.neustar/about-us/our-history