8 ms·
Is Protonmail logging my email content?
evidences:
1. https://s3.laisky.com/uploads/2021/12/proton-1.jpg
2. https://s3.laisky.com/uploads/2021/12/proton-2.jpg
3. https://s3.laisky.com/uploads/2021/12/proton-3.jpg
- zaarn 5y agoThis is likely the spam filter scanning over the Links it finds in the E-Mail not actually something spitting the mail content into log4j (and I mean honestly, why would you even do that?)
- SahAssar 5y agoHow would that work with e2e encryption? What spam filter system would even follow ldap links?
- zaarn 5y agoProton is not e2e for mails coming from outside Proton, if they aren't GPG encrypted. And in that case they apply very standard spam filters to your mail.
- jsnell 5y agoThat should be quite easy to check, by changing the URI scheme and rerunning the experiment.
- zaarn 5y agoUnlikely, spammers tend to get creative to bypass spam filters, it would probably scan anything that looks like a URL or Domain just to see if the IP behind it is sus.
- jcims 5y agoThat’s the point. You’ll still get a hit. If it’s the RCE you won’t. Just went through this with an email security provider, would get 3-4 pings with log4j payloads, 2-3 with inert ones.
- zaarn 5y agoYou're free to experiment, though the ProtonMail team has already responded upthread that this is in fact their SpamFilter.
- itsthecourier 5y agowhat the actual fuck
- rpadovani 5y agoWas the email sent TO or FROM a protonmail address? Does it also happen if it is protonmail to protonmail? Unrelated: what's the name of the tool you use to "listen" to DNS calls?
- cassianoleal 5y ago> what's the name of the tool you use to "listen" to DNS calls? Just found that out myself. It's http://dnslog.cn/ http://dnslog.cn/ .
- sparkling 5y agoAlternative: https://canarytokens.com/generate https://canarytokens.com/generate
- 1cvmask 5y agoThey have already being known to log emails when enforced by the Swiss authorities: https://techcrunch.com/2021/09/06/protonmail-logged-ip-address-of-french-activist-after-order-by-swiss-authorities/ https://techcrunch.com/2021/09/06/protonmail-logged-ip-addre... https://protonmail.com/blog/transparency-report/ https://protonmail.com/blog/transparency-report/ —— In case you trust Swiss companies blindly: https://en.wikipedia.org/wiki/Crypto_AG https://en.wikipedia.org/wiki/Crypto_AG https://www.thebureauinvestigates.com/stories/2021-12-06/swiss-tech-company-boss-accused-of-selling-mobile-network-access-for-spying https://www.thebureauinvestigates.com/stories/2021-12-06/swi...
- ziddoap 5y agoThis is always posted like some 'gotcha', despite it being right there in the transparency report. In case you trust any company blindly: any company that wants to keep playing the money game will follow the laws forced upon them by the government they are beholden to.
- inter_netuser 5y agointeresting way to put it, "the money game". did you see that somewhere?
- edoceo 5y agoI first heard that in the 1990s. And the TV show "The Wire" (c2004?) made frequent use of the phrase "the game" to describe the process of street-dealing drugs, and the money, and the police, etc. As in "it's all in the game" - ie: all's fair in love and war.
- tejohnso 5y agoIsn't this what seasteading, and other jurisdiction avoidance schemes attempt to address? I wonder if anything like that has ever worked out.
- pavel_lishin 5y ago
- ProtonTeam 5y agoPlease be aware that we don't log email content (and we are also not vulnerable to Log4j). Our anti-spam systems do check for malicious links from third party email services so we can proactively warn users about phishing attempts.
- top_sigrid 5y agoIf you are not vunerable to log4j, how did the screenshots come about?
- TYMorningCoffee 5y agoI believe ProtonTeam's claim is that the spam filter visits the links in the email content. As a result, it's not the log4shell vulnerability making the connection, it's the spam filter.
- adamhp 5y agoI.e. try to send some e-mails without the log4j vuln syntax (just put your IP) and see if you still get hit. It's just the fact that there is the IP, not that it happens to use the jndi syntax.
- YXNjaGVyZWdlbgo 5y agoCum hoc ergo propter hoc
- aleister_777 5y agoNobody believes you. Your track record is trash and I was happy to cancel all services and never pay you anymore money.
- dang 5y agoYou can't attack others like that on HN, regardless of how right you are or you feel you are. Please review https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html and don't post like this again. You may not feel you owe your target better, but you owe this community much better if you're participating in it. The damage this sort of poison causes to the ecosystem greatly exceeds any benefits it may have.
- gizdan 5y agoSeems odd for PM to be vulnerable by the log4j CVE considering (from what I understand) they're mostly Go house. Maybe in the Android app, but otherwise I'd be surprised. Unrelated: I've been getting quite frustrated with some of the functionality and limitations of PM especially for the price I pay (I have 2 catch-all domains, 1 user for each, which requires 2 times pro accounts), so recently I've been trying to migrate away to mailbox.org. Mailbox allows for automatic PGP encryption when the emails come in which is great. However, there is no way to move all my PM emails onto my mailbox.org account while keeping the encryption (not via the original key set up in Protonmail, nor via new key set up in mailbox.org). Has anyone ever run into such a scenario, and what can be done in this scenario?
- cf100clunk 5y agoThat would be a good Ask HN.
- INTPenis 5y agoYou should expect mail to be public. There's no security at all in those protocols, by default. Only encrypted e-mails are somewhat safe. So I just don't understand who's upvoting this. It's a silly post.
- ac130kz 5y agoIf I were you, I would not use any kind of non open source and non self-hosted email service pretending to be "secret", in the best (!) case it has some sort of silent metadata/access logging. While common shady services like Protonmail bluntly store plain text archives, and even if they claim they don't, there's no zero-knowledge proof on this highly sensitive topic.
- NabiDev 5y agoSeems Proton scan the emails. Including domains in the body.
- Maro 5y agoThe screenshots are to show that that link is processed by log4j, because it exploits a log4j vulnerability and gets it to make a dns call, right?
- md_ 5y agoIt's good to be cautious, but this is sort of a silly test. Protonmail doesn't have to "log" messages; they have them already. If I were Protonmail and I had to comply with lawful intercept requirements, I'd just: a) make sure that message content isn't deleted from the mailbox when the user thinks it is b) make sure I retain access to server-managed PGP keys (by logging key material and user-supplied passphrases) But I sure as hell would not call some Java logger.trace() on every goddamn email! That's totally nonscalable and just silly.
- speedgoose 5y agoI'm not sure they are a Java company, they are more Python, PHP, Golang, and Node. At least Java is not described in their job offers, which are usually a very nice way to know about the company stacks by the way. https://careers.protonmail.com/o/devops-engineer-remote-europe-barcelona-london-vilnius-prague https://careers.protonmail.com/o/devops-engineer-remote-euro...
- randy408 5y agoThis needs more detail, what is the body of the mail supposed to show? Did you run an experiment? How was it run? Is this between protonmail addresses?
- tpoacher 5y agoHate to be that guy, but evidence has no plural. Similar words often wrongly used in plural: - advices - feedbacks - codes (when referring to source code) - moneys - datas - syntaxes
- dankwizard 5y agoIf you're going to be that guy at least be correct https://dictionary.cambridge.org/dictionary/english/moneys https://dictionary.cambridge.org/dictionary/english/moneys
- tpoacher 5y agoBut I am correct. :) I didn't say a plural form doesn't necessarily exist. I said they're words that are often used wrongly in the plural. Moneys is used specifically when it denotes different sources of income. Similar to fruits meaning a variety of different kinds of fruit, but the ordinary plural of fruit is fruit, and fishes denoting a variety of different kinds of fish, but the ordinary plural of fish is fish. "How much moneys does this cost "is obviously as wrong as "how much fruits / fishes did you buy". Same with codes, you can talk about "nuclear codes" but not "morse codes" or "source codes".
- polack 5y agoRecipient or sender using Proton VPN?
- elikoga 5y agoThis seems to me very worth looking into
- favourable 5y agoAgreed