4 ms·
I don't follow your logic here. Why can't a company legitimately focus on a niche sub set of users who value privacy in their products? I'm thinking of products
by slickdork 4y ago
I don't follow your logic here. Why can't a company legitimately focus on a niche sub set of users who value privacy in their products? I'm thinking of products like protonmail, standard notes, and signal.
- jeffbee 4y agoYeah ... i mean ... everyone who uses protonmail non-ironically is a dupe. It is virtually certain that it is a front for state intelligence agencies.
- slickdork 4y agoI'm not sure why it is 'virtually certain'. It seems very likely to me that a company, which takes payments as a funding model, could exist with end 2 end and be a legitimate business. Do you have any source at all to back a claim like that?
- aaaaaaaaata 4y agoConnections with big academia and their custom syncing thing are red flags, if only that.
- rank0 4y agoI would love to hear your explanation for that claim. They have publicly entered legal battles over compliance with LE requests. The government doesn’t have the resources to compromise every online service. There’s money on the line for entities like proton.
- zdragnar 4y agoGood faith actors want to serve a market. Bad faith actors want to exploit it. If you are seeking out a way to hide information, you are part of a market that is signalling you have something worth hiding (to you, at minimum). As a bad analogy, it's a bit like putting up a sign in front of your house that says "We went on vacation, but the door is locked!"... basically, begging to be exploited. Short of regular, independent audits, you are mostly reduced to guessing who to trust, and even then (as demonstrated by Lavabit) the trustworthiness of the actor isn't always the only relevant factor.
- pessimizer 4y ago> Why can't a company legitimately focus on a niche sub set of users who value privacy in their products? No one is saying that they can't, somebody is saying that they are, but not in that customer's best interest. ----- edit: with parallel construction, there are absolutely no drawbacks to narking on your users, assuming that the way you do it is an obvious possibility that you just minimize or ridicule the likelihood of. e.g. "Everybody knows that they can use Method A to break your encryption, but that would be company suicide! Do you seriously think they're stupid enough to do that!? They even made the client open source to be open about what they can or can't do." rather than "Guys, I just noticed a process running on my phone that isn't supposed to be there." Which is what we've been taught to watch out for.