4 ms·
Protonmail did not provide the authorities with the users IP address...they did allow the account to monitored which they are required by their laws to allow.
by monkey_552 5y ago
Protonmail did not provide the authorities with the users IP address...they did allow the account to monitored which they are required by their laws to allow. It was the users sloppy OPSEC that allowed the authorities to eventually track them down. In the end, I believe, it was linking the user to a past Gmail account that finally did him in. Listen to this podcast episode, the presenter does a fairly good job summarizing the situation.
The Privacy, Security, & OSINT Show – Episode 227
- NackerHughes 5y agoLie that you care about user privacy, give sucke- I mean, users' data to law enforcement anyway, blame the users when they get nailed due to your snitching. It's a perfect business model!
- istingray 5y agoDon't call it a "HoneyProt"!
- istingray 5y agoNot my problem. I pay Protonmail to work on behalf of users, and empower users to the extent allowed by law. This includes educating users about the adversarial actions that Protonmail itself can take against them (warrant, rogue employee, hackers). Otherwise I can take my $ elsewhere, email services are cheap.
- newacct583 5y ago> Protonmail did not provide the authorities with the users IP address...they did allow the account to monitored which they are required by their laws to allow. Something their marketing material appears to disclaim. This is just excuse-making. ProtonMail did what ProtonMail has (for years!) led their customers to believe they would not do. And they did. I think there's an argument to be made that any commercial email/messaging provider simply can't do what ProtonMail claimed to do. But that doesn't change the fact that ProtonMail did it.
- indigochill 5y ago> ProtonMail did what ProtonMail has (for years!) led their customers to believe they would not do. My rule is to give any corporate statement about what they "will not do" exactly zero credence. The only thing worth anything in that context is open source where independent programmers can verify that the code cannot support undesirable behaviors. And even then you're not safe, because code running on someone else's machine might actually be anything. So in the end, self-hosted open source software is the only way. Right now that requires some degree of technical know-how, but I believe that's a solvable problem the same way operating systems have turned the technical practice of process management into something users don't even need to think about.
- IncRnd 5y ago> ProtonMail is a well-known and well-regarded mail service and is often recommended to users looking to distance themselves from Google's less-than-ideal security practices. Unfortunately, however, ProtonMail was recently forced to cooperate with Swiss authorities in providing user data (date of account creation), which was subsequently handed over to American security authorities and enforcement agencies. and > Proton reached out to us to confirm that the only data provided to Swiss authorities was the date of account creation. [1] [1] https://proprivacy.com/privacy-news/protonmail-authorities-user-data https://proprivacy.com/privacy-news/protonmail-authorities-u...
- istingray 5y agoIs this the same case? Maybe I'm missing some crucial info. A week ago: "Proton reached out to us to confirm that the only data provided to Swiss authorities was the date of account creation." [1] Today: Article published claiming Proton gave up user data. Did Proton officially now state they "allowed the account to be monitored"? Am I getting this right? [1] https://proprivacy.com/privacy-news/protonmail-authorities-user-data https://proprivacy.com/privacy-news/protonmail-authorities-u...
- VBprogrammer 5y agoI've worked with back end webservices for 10 years or so but I'm struggling to understand the concept of allowing a singular account to be monitored. What does this actually mean? An account in all of the systems I've dealt with is basically the collective understanding of a bunch of database queries. How does one allow an account to be monitored in any way which is less frightening than providing an IP address from a log?
- samhw 5y agoIt means: ``` if user.isUnderInvestigation { log(request.sourceIP) } ```