5 ms·
If it becomes mandatory for email providers to screen emails, will services such as Protonmail become illegal in the EU? Since they don't have access to their u
by AtticHacker 5y ago
If it becomes mandatory for email providers to screen emails, will services such as Protonmail become illegal in the EU? Since they don't have access to their users' email content because of encryption.
- juniperplant 5y agoI'm wondering the same. I suppose they will have to implement some way to scan the emails, or else they will be forced out of business. That said, I wouldn't bet on it.
- onlyrealcuzzo 5y agoDoes the EU have some kind of firewall with ISPs to block domains and IP addresses?
- q3k 5y agoNo. There are some per-country implementations, but nothing EU-wide.
- effie 5y agoThat is the probable reason why this is being pushed through.
- Andrew_nenakhov 5y ago> Since they don't have access to their users' email content because of encryption. Regular emails (i.e. without home-brewn encryption that Protonmail provided - and I'm yet to receive such email from any of my contacts who use Protonmail), or any inbound email received from third-party servers are of course not encrypted and Protonmail has pretty easy access to their contents.
- tedcrilly 5y agoProtonmail uses PGP and not "home-brewn encryption" and encryption is on by default between Protonmail users.
- Andrew_nenakhov 5y agoFalse. Even when it does use PGP, it is meaningless, explanation: I just created a spare protonmail account. It asked me to pick a username and password, and my account is created. Next, I send there a message from my other account. Yes, on the receiving end it does write "End-to-end encrypted and signed message", but encrypted and signed by what exactly? I have never created a PGP keys and loaded the public key to Protonmail on either account (and never used my private key to decrypt anything. This can mean only one thing: even if there is some kind of encryption happening, Protonmail themselves generate keys, and uses it for encryption-decryption, never asking you for anything but your password. And if they can uses these keys to decrypt the messages for you, they can decrypt it for anybody. Protonmail also gives a user an option to export his private keys. Yeah, right. Your private keys.
- Telemakhos 5y agoSomeone once explained to me that any webmail service is inherently able to read your mail: otherwise it could not display your mail to you. True end-to-end encryption means keeping your private keys client-side and the client on a computer over which you have full physical control.
- Andrew_nenakhov 5y agoYou are absolutely correct, with some caveats. Browser client can generate keys on clientside and allow to offload them as a file to be used on other devices. Our own web XMPP client does that. But Protonmail does not work like this. Verification is very simple: if you log in on a new device and see all your content while using only login and password to authenticate yourself, then the content stored on a server is NOT encrypted and is readable by server owner.
- thefr0g 5y ago> If it becomes mandatory for email providers to screen emails, will services such as Protonmail become illegal in the EU? Protonmail should already be illegal in the EU because they operate under swiss mass-surveilance laws and cooperate with US-American law enforcement. Both of which violates the GDPR if they do business in an EU state. > Since they don't have access to their users' email content because of encryption. They still have access to all the unencrypted mail their users send and receive and to all the metadata of the enrypted communications.
- mikeyjk 5y ago> Protonmail should already be illegal in the EU because they operate under swiss mass-surveilance laws and cooperate with US-American law enforcement. :O Seriously? Wow, off to research this I go... That's really disappointing as a paying user. I can't believe I wasn't across this.
- t0bia_s 5y agoYou can choose which narration you would believe. It is neverending story.
- upofadown 5y agoThey could conceivably add screening to the javascript client downloaded to the user that does the end to end encryption. Don't know how practical that might be. I think the more interesting question involves something like Mailvelope. It is a stand alone OpenPGP based encryption system based on the ProtonMail code that provides encryption for webmail. It can be hosted somewhere physically and politically far away from the EU and is an open source project. How will the EU approach the ancient PGP dilemma this time around?