16 ms·
Disclaimer: Paying Protonmail customer Their homepage says "By default, we do not keep any IP logs" In 2021, any soft language like this should be a red flag
by istingray 5y ago
Disclaimer: Paying Protonmail customer
Their homepage says "By default, we do not keep any IP logs"
In 2021, any soft language like this should be a red flag for anyone who is against surveillance. Maybe in 2018 it was good enough. But in 2021 it's not. Come on, Protonmail, you're supposed to be leading the way -- don't make me figure it out myself.
Replace immediately with "By default we don't log IP, but may be required to by local law enforcement. We recommend everyone connect through Protonmail through Tor. This month, 60% of our users connected through Tor".
- sigmoid10 5y agoPeople really don't seem to understand that Protonmail is a western company in a western country with pretty generous surveillance laws. Yes, your email text may be encrypted, but everything else is free game to the authorities unless you use additional protection.
- istingray 5y agoProtonmail should be pushing more of this messaging in their branding. "Don't trust us further than you can throw us. We're doing our best, and here's what we recommend, use Tor, etc."
- winrid 5y agoThis is just not realistic, though.
- pseudalopex 5y agoWhy not?
- umvi 5y ago"we aren't much better than Gmail from a privacy standpoint, but please still give us money"
- pseudalopex 5y agoDoes every email provider but Gmail make the same misleading claim as ProtonMail? Fastmail for example?
- bigiain 5y agoI like and respect Fastmail. but... I live in Australia - and they're totally fucked by our laws and government policy. "The Australian Federal Police (AFP) and Australian Criminal Intelligence Commission (ACIC) will now be able to access the computers and networks of those suspected of conducting criminal activity online, and even take over their online accounts covertly, under the Identify and Disrupt bill, which was passed by the Senate on Wednesday." -- https://www.innovationaus.com/extraordinary-new-hacking-powers-pass-parliament/ https://www.innovationaus.com/extraordinary-new-hacking-powe... and: "Amends: the Surveillance Devices Act 2004 and Telecommunications (Interception and Access) Act 1979 to: introduce data disruption warrants to enable the Australian Federal Police (AFP) and the Australian Criminal Intelligence Commission (ACIC) to disrupt data by modifying, adding, copying or deleting data in order to frustrate the commission of serious offences online; and make minor technical corrections; " -- https://www.aph.gov.au/Parliamentary_Business/Bills_Legislation/Bills_Search_Results/Result?bId=r6623 https://www.aph.gov.au/Parliamentary_Business/Bills_Legislat...
- pseudalopex 5y agoThe question was if email providers have to choose misleading people about privacy or going out of business. Specifically about IP logs. Fastmail's privacy page says "Your data is for you and no one else".[1] So they do mislead about that. I didn't see anything about IP logs though. And Fastmail was just an example. [1] https://www.fastmail.com/privacy-and-security/ https://www.fastmail.com/privacy-and-security/
- mikeyjk 5y agoI thought Gmail was much worse, scanning email contents etc.
- deleted 5y ago[deleted]
- Godel_unicode 5y agoBecause of the dirty little secret of protonmail; it's actually just privacy cosplay. If they told people what's actually involved in having a truly private email account, most of their customers would say screw it and go back to Gmail.
- deleted 5y ago[deleted]
- istingray 5y agoI gave an example in another post. Basically "Hey, we respect your needs. However, we have to tell you that you should treat us as a bit of an adversary. We will do what we can as a private company, but ultimately we can be compelled by the government, rogue employee, or if somehow we get hacked. This is the case for any company, they just don't tell you it. We do. As our customer, here's what we recommend you do: Use Tor, fund open source, vote, etc."
- taneq 5y agoOf course not, because a company that strikes the perfect balance of being sorta-in-the-right-direction but then also using deliberately deceptive language to pretend they're all-the-way-in-the-right-direction is going to outcompete companies that genuinely go all the way.
- truthwhisperer 5y agothey should destroy the email box due to a technical error so the user knows something is wrong
- Barrin92 5y agoI wonder how long the 'Swiss privacy' brand, which seems to be fairly valuable will hold if these things keep happening, I had to immediately think of Crypto AG https://en.wikipedia.org/wiki/Crypto_AG https://en.wikipedia.org/wiki/Crypto_AG
- TedDoesntTalk 5y agoA lot of people don’t know about Crypto AG. It’s an amazing story!
- znpy 5y agoIn the US companies can make canary statement... https://en.wikipedia.org/wiki/Warrant_canary https://en.wikipedia.org/wiki/Warrant_canary
- dredmorbius 5y agoThe canary is dead, and the fact is widely publicised, if not necessarily well known.
- rsync 5y agoOur canary[1] - the very first one[2] - is alive and well. In fact, it turned 15 years old this past April[3]. [1] https://www.rsync.net/resources/notices/canary.txt https://www.rsync.net/resources/notices/canary.txt [2] https://en.wikipedia.org/wiki/Warrant_canary#Usage https://en.wikipedia.org/wiki/Warrant_canary#Usage [3] https://twitter.com/rsyncnet/status/1387090538273206274 https://twitter.com/rsyncnet/status/1387090538273206274
- dredmorbius 5y agoWho is "our" here? rsync.net? https://www.rsync.net/resources/regulatory/privacy.html https://www.rsync.net/resources/regulatory/privacy.html
- dredmorbius 5y agoGotchya. I was referring to Protonmail's canary specifically, in the event that wasn't clear.
- istingray 5y agoThose canary things seem so 2018. In 2021 the most powerful canary statement should be "Don't trust us. Seriously, treat us as an adversary. We still want you to be our customer of course, but here's how we really recommend you use our service, Tor, semi-anonymous payments, etc. In God we trust, for everyone else use math."
- 5y ago
- ivan_gammel 5y agoTBH in 2021 people engaging in potentially dangerous activities should be literate enough to understand, that no business will guarantee them full security and decline all requests from authorities to disclose their identity. The wording you suggest is equivalent of „do not dry your cat in microwave“ instruction - a legal protection from dumb customers, that does not contribute meaningfully to safety. For the non-Swiss customers working with a Swiss provider can be a good enough protection to avoid inconvenience of Tor. After all, even in the mentioned case it required review and approval of 3 agencies before request came to Proton - from French police, from Europol, and then from Swiss authorities. If this is not enough barriers to protect from politically motivated prosecutions and corruption, then we have much bigger problem in Europe.
- akimball 5y agoIt’s not protection FROM your customers. It is protection FOR your customers. Most customers are not technically astute
- shadowgovt 5y agoA corporation is a power centralization, and government authority can lean on power centralization. In general, regardless of what their TOS say, never believe that a corporation can't be compelled by the law to do anything they could physically do. CEOs can be jailed; when's the last time we heard of one actually going to jail over user privacy?
- pessimizer 5y agoThe point being made agrees with you, and is just saying that since protonmail can't help but obey sometimes, they should make the effort to educate their customers about that fact and whatever their customers can personally do to mitigate the risks of that fact.
- bigiain 5y ago> CEOs can be jailed; when's the last time we heard of one actually going to jail over user privacy? Ladar Levison from Lavabit came close. But even he admits that was because the FBI wanted to subvert every single Lavabit user's account (attempting vast overreach on the brazen assumption that "we are after Snowden" was going to pull the wool over everybody's eyes). Levison admits though, to having "responded to" at least two dozen subpoenas and complied with at least one warrant before. https://en.wikipedia.org/wiki/Lavabit#Suspension_and_gag_order https://en.wikipedia.org/wiki/Lavabit#Suspension_and_gag_ord...
- shiado 5y agoI once tried to create a Protonmail account over TOR and I believe they require a phone number from 'malicious' IPs so if you want anonymity Protonmail is not the service for you.
- istingray 5y agoYes, Protonmail requires a phone number to register over Tor! Even though they claim no identity is required to register. I confirmed this today when I created a fresh Protonmal account over Tor: https://news.ycombinator.com/item?id=28428092 https://news.ycombinator.com/item?id=28428092
- dangero 5y agoIf they don’t do this then spammers will use their service en masse and degrade the service for all customers by black holing their ips and domain through all other email providers.
- istingray 5y agoToo bad, figure out a way to solve for it. I'm paying for private email service, not a pretty picture of the Swiss Alps on their website. If they don't provide it, someone else will, and I'll pay them instead. This isn't the Hotmail age where everyone expects free email.
- bigiain 5y ago> This isn't the Hotmail age where everyone expects free email. It totally is. I was running my own mail server for a while. The thing that finally pushed me into not bothering any more was when I looked at my logs and realised 82% of my non-spam non-marketing email was captured by google (where at least one recipient was either @gmail.com or a gsuite custom domain).
- LightG 5y agoSo you gave up? Decided to play dead?
- cabalamat 5y agoI wonder how many TOR nodes are run by the NSA?
- calvinmorrison 5y agoDoesn't matter if you are going to an internal onion address
- KeepFlying 5y agoWhy not? It would just mean that the NSA needs to own more routers than it would to break TOR->Public internet routing. From what I understand, connecting to an onion address 'just' involves 6 routers, not the typical 3. (Of course an oversimplification.) Or am I misunderstanding your threat model here?
- sweetbitter 5y agohttps://svn-archive.torproject.org/svn/projects/design-paper/tor-design.pdf https://svn-archive.torproject.org/svn/projects/design-paper...
- Thorrez 5y ago>A global passive adversary is the most commonly assumed threat when analyzing theoretical anonymity designs. But like all practical low-latency systems, Tor does not protect against such a strong adversary. Instead, we assume an adversary who can observe some fraction of network traffic; who can generate, modify, delete, or delay traffic; who can operate onion routers of his own; and who can compromise some fraction of the onion routers.
- dragonelite 5y agoSounds like a 51% attack on crypto blockchains.
- 5y ago
- anothernewdude 5y ago"Also, our VPNs are useless"
- georgyo 5y ago_all_ VPNs are useless. They are the biggest security theater and a massive success of marketing. But really, it's completely bazaar to trust a VPN provider. They provide protection from your local network, but you they can do all the same things and more.
- falcolas 5y agoYes. Yes! I’ve never understood how people argue that they are somehow better than an ISP by default.
- hnaccy 5y agoI get letters and my internet turned off if I torrent on my ISP I don't using VPN. Simple as.
- bigiain 5y agoMy ISP is subject to my local laws. Which are not good, in terms of my privacy. My VPN provider is not - but is obviously subject to their local laws. Which are almost certainly also not good for my privacy either. Spreading the threat across two different jurisdictions is without doubt "somehow better" than just using my ISP, at least in the case of protection against snooping by non serious crime law enforcement. (Where I am, organisations like local councils, the taxi commission, fishing inspectors, and dog catchers - can all access our "mandatory telecommunications metal data retention" stuff with very little oversight... While my VPN is still in five eyes, so there's no point pretending national security, intelligence, or serious crime like terrorism/drugtrafficing would have no trouble getting cross jurisdictional access, I'm pretty sure the fishing inspectors or dog catchers won't have that sort of access.)
- drivebycomment 5y ago
- o8r3oFTZPE 5y ago"Their homepage says..." Is the parent suggesting that no one should bother to read the Terms and Privacy Policy, linked to from the homepage. https://protonmail.com/privacy-policy https://protonmail.com/privacy-policy Despite the parent's claim, the Privacy Policy says the company may log IP address. Temporarily. Irrespective of any request from local authorities regarding a specific user. IOW, they may log anyone's IP address temporarily regardless of whether the particular user is casuing trouble; they can log IP address for everyone. The policy says they log this data for the purposes of preventing fraud and abuse. The problem for privacy-conscious users is that if they log the data, then that entices authorities to try to successfully request it. The policy, which imposes no obligations on the company BTW, reads as follows: "IP Logging: By default, we do not keep permanent IP logs in relation with your use of the Services. However, IP logs may be kept temporarily to combat abuse and fraud, and your IP address may be retained permanently if you are engaged in activities that breach our terms and conditions (spamming, DDoS attacks against our infrastructure, brute force attacks, etc). The legal basis of this processing is our legitimate interest to protect our Services against nefarious activities." There is nothing that says "By default we do not retain any logs". This clearly states they may be expected to retain IP logs. ("IP logs may be kept temporarily...") But wait there's more. "We will only disclose the limited user data we possess if we are instructed to do so by a fully binding request coming from the competent Swiss authorities (legal obligation)." This clearly states the company may disclose the data they possess, e.g., IP logs collected to combat fraud and abuse, if in response to a request from competent local authorities. Further down is a curious statement about decrypting messages. "If a request is made for encrypted message content that we do not possess the ability to decrypt, the fully encrypted message content may be turned over." Why include a statement such as this, specifically the part that says "that we do not possess the ability to decrypt". The company already specified it may disclose the data it possesses. This further statement suggests there could be some situation where they may have the ability to decrypt some messages. Besides their own communications with customers, why would they ever have encrypted messages that they can decrypt. They could state something like "If the request is made for encrypted communications addressed to us or sent by us, ...", but they do not. As such, their statement must include other messages, too.
- istingray 5y ago
- istingray 5y agoAll the Protonmail customers out there, what did you do about this? For starters, I emailed Protonmail support. Here's mine: Hi, Your homepage reads "By default, we do not keep any IP logs..." This language is soft and misleading. Maybe in 2018 when I first began using ProtonMail it was good enough. But in 2021 it's not. I expect better from ProtonMail. Replace immediately with something clearer. "By default we don't log IP, but may be required to by law enforcement. We recommend all customers connect through Protonmail through Tor. This month, 60% of our users connected through Tor". If you can't come up with anything better for users, just fall back on your privacy statement verbatim and avoid any marketing language. Think about a journalist in Afghanistan, a whistleblower in the USA, or a human rights activist in China. They're all engaging in potentially dangerous activities. I advocate on behalf such people by supporting services like Protonmail with my money. If Protonmail isn't supporting these users, why should I bother supporting Protonmail? I expect Protonmail to educate users like this about how Protonmail itself can be turned into an adversary. Educate users about how to use Tor. Do better. Improve the internet. I look forward to your reply. Also, registering a new account through Tor requires a phone number for verification, even though Proton says no unique identification is required to register. If this requirement isn't removed by the time I renew my account I will no longer renew.
- penagwin 5y agoFrom my understanding it depends on how naughty your current exit node has been. Most tor exits in my experience allow creation and you just need to verify another email (just use a random burner- they only block a few. Supposedly some well behaved exits require just a captcha but I've never seen it.
- monkey_552 5y agoProtonmail did not provide the authorities with the users IP address...they did allow the account to monitored which they are required by their laws to allow. It was the users sloppy OPSEC that allowed the authorities to eventually track them down. In the end, I believe, it was linking the user to a past Gmail account that finally did him in. Listen to this podcast episode, the presenter does a fairly good job summarizing the situation. The Privacy, Security, & OSINT Show – Episode 227
- NackerHughes 5y agoLie that you care about user privacy, give sucke- I mean, users' data to law enforcement anyway, blame the users when they get nailed due to your snitching. It's a perfect business model!
- istingray 5y agoDon't call it a "HoneyProt"!
- istingray 5y agoNot my problem. I pay Protonmail to work on behalf of users, and empower users to the extent allowed by law. This includes educating users about the adversarial actions that Protonmail itself can take against them (warrant, rogue employee, hackers). Otherwise I can take my $ elsewhere, email services are cheap.
- newacct583 5y ago> Protonmail did not provide the authorities with the users IP address...they did allow the account to monitored which they are required by their laws to allow. Something their marketing material appears to disclaim. This is just excuse-making. ProtonMail did what ProtonMail has (for years!) led their customers to believe they would not do. And they did. I think there's an argument to be made that any commercial email/messaging provider simply can't do what ProtonMail claimed to do. But that doesn't change the fact that ProtonMail did it.
- 5y ago
- modzu 5y agotheyre quite transparent about their service, and far more transparent than any of their competitors. the same criticism can also be leveled against your comment. "but i used tor, the defualt mode for which has js enabled and somehow it leaked my ip!" if you dont know what youre doing, and want to evade state law enforcement, you better figure out what youre doing. thats not on proton.
- hk1337 5y agoI didn't ever have proof, just a gut feeling, but I never really bought into Protonmail. I created an account but rarely used it and as far as I know has been deleted for a few years now.
- ranguna 5y agoWhat are you using now?
- hk1337 5y agoFastmail with a custom domain. I was using Lavabit before that.
- ranguna 5y agoFrom fastmail privacy policy: > Each time you connect to our service, we log your IP address, your client identifier (browser or mail client information) and your username. I'm sorry dude, but that decision from switching to fastmail was not very productive to counteract the specific case mentioned on the OP. If anything, it's even worse since fastmail apparently always logs your IP. Moreover: > We process mail sent and received from your account to block spam and fraud. We receive information from third party services to assist us in identifying spam. Looks like your emails aren't even encrypted. If any government body what's your email bodies, they'll have it. They even share it with 3rd parties for fraud detection. With protonmail and similar services, they'll just log your IP if they're asked to do so, which you can obfuscate using a decent enough VPN.
- Bellamy 5y agoI was a paying customer. I just cancelled. I can't understand what just happened. I truly believed it's all save and secure.
- istingray 5y agoI hope you emailed them to say why. Share the email here if you don't mind.
- heavyset_go 5y agoOne thing I've noticed is that many HN users don't believe that courts can compel companies to take positive actions to surveil their customers. This incident illustrates that, yes, courts can compel companies to keep logs even if their infrastructure is built to not keep them at all. We cannot rely on what companies say about their privacy guarantees, or rely on vendors' technical analysis of their own black box systems, because a simple court order can essentially be a backdoor.
- Causalityl 5y agoI don't trust any "secure" communications service that hasn't been subpoenaed and provided nothing in return. Having a national security letter canary doesn't hurt either.
- jraby3 5y agoI was COO of a vpn company for several years. It’s almost impossible not to keep any ip info. We had issues with fraud and one of the best ways to prevent or limit it was to track IP address and save it for several months. I agree PM should be more forthright in their messaging but realistically I don’t believe any company that takes payments and doesn’t track any info at all.
- truthwhisperer 5y agomaybe you should have been little more creative. People who have paid a few months in a row or have a good history you don't need to store the actual IP addresses maybe only the number of used ipaddresses and increase your level of monitoring if the numbers hits a certain threshold the only reason you store IP address is because of laziness. Fair enough
- xvector 5y agoDid your company market itself as a no-logs VPN company?
- jraby3 5y agoI don’t remember the actual marketing message as it was about 7 years ago, but I know in the TOS it was carefully written to include that it had to collect some ip info to prevent fraud.
- istingray 5y ago24 hours later, ProtonMail deletes "By default, we do not keep any IP logs". I'll call that a win for all customers who emailed Protonmail about this. HN discussion: https://news.ycombinator.com/item?id=28443449 https://news.ycombinator.com/item?id=28443449