5 ms·
The problem is that engaging in "potentially dangerous activities" includes such a wide range of people. Think about a journalist in Afghanistan, a whisteblower
by istingray 5y ago
The problem is that engaging in "potentially dangerous activities" includes such a wide range of people. Think about a journalist in Afghanistan, a whisteblower in the USA, or a human rights activist in China. They're all engaging in potentially dangerous activities. Are they "dumb" because they don't understand all the ins and outs of surveillance? How about some empathy for them as users?
The proposed statement above is intended to help people like that.
Do I have such activities? Nope. But I believe that those activities should be enabled, whether for me in the future or others around the world.
I advocate on behalf such "dumb" people by supporting simple services like Protonmail with my money. If Protonmail isn't supporting these users, why should I bother supporting Protonmail?
- jelling 5y agoAlso ProtonMail's only reason for being is that they are supposed to provide some higher level of privacy. If they don't, how are they any different than a commodity grade SMTP/IMAP provider? I will withhold judgement until I know more about the case but the early context does not look good for ProtonMail's value proposition, which is the least of things.
- lavabiopsy 5y agoIs it though? I don't know much about this company but their main selling point seems to be end to end encryption for mail messages. That's not a "privacy" feature by itself. Now it is a tool that you can use it to gain more privacy, but you could also have people who use it to cc all their emails to their entire facebook list. So it seems it all depends on how you use it and what type of privacy you try to achieve.
- blululu 5y agoEnd to end encryption is a privacy feature by itself. The example of using an email service to send a mass email to a dislist is irrelevant to the possibility that it would also be able to preserve privacy in other communications. You could send an email directly to the local police chief if you wanted but that does not preclude wanting privacy elsewhere.
- lavabiopsy 5y agoI think you are confusing privacy with security, which is a common mistake, not your fault -- end-to-end encryption is what secures the messages, by itself it does not ensure that the messages get to the right place or that the encryption keys are belonging to the right people. It needs to be used in combination with other methods and techniques. Explicit features that are in the domain of "privacy" would be ensuring messages are deleted on a regular basis, or some kind of key cycling, or an anonymizing service like tor, etc. To use your example of emailing the police chief: let's say your threat profile is that you're being stalked by a criminal, and you want to email the police to give them information on this crime, but you don't want the criminal to know. If the criminal breaks into your email, or if your house is broken into and a hidden camera is placed behind your computer, it makes little difference whether you have end-to-end encryption or not, your privacy is still violated. Does that explain it better? Maybe Proton could have some better messaging around this, if their customers are getting privacy and security confused?
- dvdkon 5y agoI think you're using a definition of end-to-end encryption that's too narrow, same with privacy. E2E schemes try to ensure that your messages can only be read by their intended recipient. That's undeniably a privacy feature, since having private messages read by a third party (without consent) would be a privacy violation. Security and privacy are intertwined, imagine your server getting hacked (security problem) leading to your private documents being exposed on the internet (privacy violation).
- lavabiopsy 5y agoI understand they are billed that way but in practice I don't believe they fulfill that goal, as the job of making the messages unreadable is mostly already done by transport security (SMTP TLS). Sure it can protect against some things if the mail server is the target, but as we see here, there is still a large amount of identifying metadata that they (unavoidably) have on you. The goal with "privacy" is to ensure that your communications are undetectable and unidentifiable, and I would hardly call it that if it's still regularly going through a well-known mail server attached to a highly identifiable account. And of course it depends on how much you actually use the E2E encryption which is technically optional, for example if you send/receive a lot of mail from gmail users that aren't using S/MIME, which still seems to be the case for a lot, then it won't be enabled and your messages are still vulnerable in a server hack.
- blub 5y ago* Think about a journalist in Afghanistan, a whistleblower in the USA, or a human rights activist in China* The former's safe because no one's going to deliver IPs to Afghanistan and the latter are doomed, because the US and China are following a policy of total surveillance. That ship has sailed decades ago.
- lobocinza 5y agoI wouldn't be surprised if they or anyone else in the future deliver users IPs to the Taliban government specially with they get recognition from more nations.
- ivan_gammel 5y agoYou do not have to understand all aspects of privacy to realize that governments may have sufficient resources to track your identity and to put enough pressure on businesses to provide information they need. At the same time, Tor is not the only, the required and the sufficient way to ensure privacy. There are different circumstances requiring different approaches. In many cases Tor will be redundant, in some cases it may be impossible to use, will offer insufficient protection or will actually put the person in an immediate danger, so giving this kind of advice is at least equally harmful as not having full disclosure on logs.
- raxxorrax 5y ago> Are they "dumb" because they don't understand all the ins and outs of surveillance? US military personell and from other nations is posting on TikTok. At least those probably don't work in reconnaissance. They aren't stupid and this isn't a technical problem, it is a legislative problem. Real security has been undermined since the early 2000 and before. Western powers just ape China or Russia at this point. That the Swiss people gave authorities these surveillance capabilities is pretty stupid though. Alpine air must have been pretty thin that day.