2 ms·
Really nothing to see here. They had a copy of the email from the victim that it was sent to, unencrypted. That would include metadata such as Message-ID. Pro
by dngray 5y ago
Really nothing to see here.
They had a copy of the email from the victim that it was sent to, unencrypted. That would include metadata such as Message-ID.
Protonmail can see metadata from the email, they are quite transparent about what is encrypted https://protonmail.com/support/knowledge-base/what-is-encrypted/ https://protonmail.com/support/knowledge-base/what-is-encryp... that data can't be encrypted, because well, it's email, it's needed in order for SMTP to work.
They also say quite clearly, and have since the beginning they will comply with MLAT https://protonmail.com/law-enforcement https://protonmail.com/law-enforcement
Therefore parent post about "no longer private" is misinformation.
Also they're quite clear on what the threat model is https://protonmail.com/blog/protonmail-threat-model/ https://protonmail.com/blog/protonmail-threat-model/
> If you are attempting to leak state secrets (as was the case of Edward Snowden) or going up against a powerful state adversary, email may not be the most secure medium for communications. The Internet is generally not anonymous, and if you are breaking Swiss law, a law-abiding company such as ProtonMail can be legally compelled to log your IP address.