20 ms·
Proton Mail discloses user data leading to arrest in Spain
- lolmao 2y agoSwitzerland has laws? Did Proton lie to us?
- Havoc 2y agoLawless wasteland!
- pas 2y agoSwitzerland famously known for anarchism, utter chaos, irresponsible tinkering with time, space (disregarding mountains, tunnels everywhere) and spacetime (at CERN)!
- RachelF 2y agoSwiss laws protect Swiss banks and their clients. No big money, no privacy laws.
- BobFromEnzyte 2y agoThis is something that I never understood with their "oh you are safe in Switzerland" bs. If the court presents them w/ a warrant they have to comply. There is no magically safe data haven and it isn't honest to pretend that they are one.
- WhyNotHugo 2y agoSwitzerland does have strict laws on the topic. Data requests are only honoured for cases which are a crime both under the foreign country's law and under Swiss law. If you live in a country where homosexuality is illegal, and your local government is chasing you because of this, a Swiss company won't comply with data requests, and a Swiss judge has no reason to honour any data request. If your local government is chasing you because of something that is recognised as a crime in Switzerland, then they will disclose data to foreign authorities.
- barbariangrunge 2y agoNever thought of a recovery email as a risk before in this way
- deleted 2y ago[deleted]
- kylebenzle 2y agoWhy not, seems pretty obvious. If you need an email address and phone number not associated with your real identity it's pretty important the two are totally separate.
- RedComet 2y agoProtonmail gave up the recovery address. Apple gave up the name, physical address, and phone number associated with it.
- politelemon 2y agoYes it's a strangely skewed article focusing on proton, when: > Once he got it, he asked Apple for information about this second email address, and got its name, home address, and phone number. Afterwards, the Civil Guard also asked the telephone company responsible for the telephone number who was the owner of the line, which matches the name provided by Apple. Also, they say they have found that this person is registered at the same address provided by Apple.
- denton-scratch 2y agoIt focuses on Proton because Proton is the link that purports to be secure. Nobody expects Apple or telcos to guard your identity.
- BSDobelix 2y agoI can think of one country in the whole world (Iceland) where a company can tell the country it operates from, NO. However in this case (an operating police officer who gave information to a group who wants to split away from the country) i make a bold assumption that even Iceland would order the company to give the data out (since it has nothing to do with protecting journalists/whistleblowers, but espionage)
- trogdor 2y ago>I can think of one country in the whole world (Iceland) where a company can tell the country it operates from, NO. Are you claiming that businesses in Iceland are not required to comply with court orders? On what basis do you believe that to be true?
- 2y ago
- gertop 2y ago> Proton provided us with an explanation that inbox contents remain secure. Yup, until they receive a court order asking them to mitm an inbox, if they haven't already... This entire system of "receive email in clear text but store it encrypted at rest" is smokes and shadows, really.
- upofadown 2y agoIt depends on the local laws. Not all places can demand that a service provider do an active attack on a user. Of course many countries have passed such laws and others are planning to It wouldn't technically be a MITM attack, they would just capture the incoming email. Tuta was famously forced to do that once by the German authorities.
- makeitdouble 2y agoI think this is the same distinction as a phone operator providing the metadata (when, between who, for how long did phone calls happen) but not wiretapping the call itself. The former has distinctly less legal requirements than the latter, and authorities might be OK with keeping it that way, as metadata is already good enough in most cases.
- amatecha 2y agoYeah, they can just deliver an alternate version of the web client (assuming the target user uses the web interface) -- probably the easiest (or least-detectable) way for ProtonMail to read a user's encrypted email contents.
- binary132 2y agoThis is where the security stuff starts going down the rabbit-hole into Wonderland. I’m still trying to figure out how to write a compiler that won’t be subject to the “what if my ur-compiler was infected with a virus that only infects compilers” problem....
- schoen 2y agoThere's lots of work on that problem! https://dwheeler.com/trusting-trust/ https://dwheeler.com/trusting-trust/ There are also a number of people making minimal OSes, interpreters, and compilers that you can, for example, assemble by hand and type in "from scratch". There was a nice list of those that I can't find right now, but you could look at https://bootstrappable.org/projects/mes.html https://bootstrappable.org/projects/mes.html as one example in this direction.
- lordofgibbons 2y agoThe heart of the issue is this: > Under Swiss law, Proton Mail was compelled to collect and provide information on the individual’s IP address to Swiss authorities, who then shared it with French police. They can claim all the privacy guarantees they want, but unless the privacy is guaranteed by cryptography, it's an empty gesture. Nobody is willing to do prison time to protect your privacy.
- fbdab103 2y agoI think they should do like Mullvad claims and keep zero logs. You cannot share what you do not have.
- srockets 2y agoThis does not stop the host from being compelled to wiretap future communications. Just don't try to make encrypted email happen. It can't, and we don't need it to be. We have better solutions for encrypted communications, for those that need it.
- noname120 2y agoIt's harder and requires more red tape.
- GGO 2y agoyou can be required to keep logs - they need to design a system that cannot collect logs - You cannot share what you cannot have.
- lolinder 2y ago> Use a good VPN service to hide your IP address whenever possible. (Failure to do this is what compromised a Proton Mail user in France who was arrested after after police obtained IP logs.) If your VPN is tied to a payment method then all you've done is give police one extra hop to follow to get at you, which wouldn't have saved this activist. Their list of VPNs only includes Mullvad in position 9 of 10, but as far as I'm aware it's the only one that offers payment methods that preserve your anonymity.
- Dylan16807 2y agoLet's say I buy Mullvad access with a credit card, then access my otherwise-unrelated Proton Mail account via Mullvad. How are police going to find me behind that hop?
- 2OEH8eoCRo0 2y agoI assume they won't bother unless you're a pedo or terrorist. In that case, what you are you using the email address for? Request your info from all of those sites. Wait for you to get sloppy once.
- lolinder 2y agoI don't know one way or the other how easy it is, but if I were an activist in an oppressive regime I wouldn't want to use a VPN that is connected to my identity in any way. I wouldn't trust zero-log policies to keep me safe, there are too many unknowns about the way they run these services and what metadata they have to turn over.
- godelski 2y ago> but if I were an activist in an oppressive regime Then mail them your money I think most people are considering less serious threat models
- Repulsion9513 2y agoI assume by "less serious threat models" you mean non-governmental, in which case just signing up for ProtonMail without a VPN is perfectly safe.
- makeitdouble 2y agoProton Mail is in the title because it's where they went first, but the actual identification (real name, phone number etc.) seems to come from Apple on request for info related to the address. In this case the email address was the lead, but I wonder what other info would be enough to get the phone provider to spill the beans. For instance would an IP address used at a specific time be uniquely identifying if it was VPNed by Apple at that moment ? Or a Google Ad cookie that could get correlated to other devices showing similar behavior (the same way Google tracks households or related accounts) ?
- fbdab103 2y agoWhile an IP address is not an identity, it can still zero in on a location. I suspect governments and ISPs all keep historical logs of who was assigned what address.
- srockets 2y agoAn IP address in itself is not an identity, but it can be easily resolved to one. This is why IP address are considered PII, and are handled like such by any competent security organization.
- fiso64 2y ago>but it can be easily resolved to one Do you have any source to back that up? Last I heard a random person or company won't have a way to find out the real identity given just an IP in general.
- srockets 2y agoPer multiple opinions I got from people whose job was to advise me on the matter, a 2016 ECJ ruling[0] suggests that it doesn't matter if a provider can find a person from their IP address or any other detail, but that there exists a scenario where it is possible. I am not sure how the CCPA treats IP address, but unless you're at Google or Facebook, it doesn't matter. Few can afford to build separately for the EU and the rest of the world, and hence err on adapting the strictest interpretation. -- [0] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:62014CJ0582 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
- IAmGraydon 2y agoGo try to create a ProtonMail account with Tor. It will ask you to confirm your account with a phone number. It skips this if you’re using a non-proxy IP. They want to know who you are, and it’s been this way for years. I think they’ve long been a honeypot.
- immibis 2y agoThis is different each time you try it. They may use the exit node's country (I doubt they'd be so naive), some other fingerprinting, or just have a limited number of anonymous accounts to give out each day, which is what cockli does. Sometimes you need a phone number, other times an email address, other times just a CAPTCHA.
- crtasm 2y agoYes, I just tested it and was able to register by giving a (disposable) email. It did then prompt me to add an email and/or phone number as recovery methods, but that step was skippable.
- mttpgn 2y agoI have never found protonmail's signup step asking for phone number verification or a recovery email to be unskippable. Protonmail can still be the best choice for a pseudonymous mail service so long as it's combined with diligent, consistent IP address obfuscation. Protonmail will continue to allow logins and new account creations over Tor. All the major free email providers have long since disallowed new signups over Tor, and most have some form of degraded user experience when logging in over Tor, if they allow it at all. Small, niche email providers appear and disappear so often that relying on them still to exist even a few months into the future is a big gamble. Hosting one's own email requires payment of some type to the hosting provider, so it is not anonymous. Other privacy-oriented free email providers, such as riseup, will do exactly what protonmail did, because if they refuse, their only option is to go the way of lavabit.
- deleted 2y ago[deleted]
- oooyay 2y agoI dislike that a website with privacy in the name collides privacy and anonymity. Privacy does not protect you from the state. Privacy is good enough to protect you from the public. If you are doing battle with or an enemy of the state, much less an agent of the state acting in bad faith simple privacy will do nothing for you. Worse your misunderstanding of it is actually a vector, like in this case. The measures for anonymity you require will not incorporate fancy UIs, nice features, or even reasonable reliability at times because they will be sacrificed in the name of leaving no trace.
- betaby 2y ago> Privacy does not protect you from the state. Privacy is good enough to protect you from the public. Public doesn't care mostly. Governments on the other hand...
- dheera 2y agoThe public might care if you are rich, influential, or conventionally highly attractive, in which case privacy is a good thing to have.
- littlestymaar 2y agoThe “public” also means the private industrial sector, and nowadays they are by far the biggest threat for people living in the Western world.
- habitue 2y agoThe public includes online mobs who send you death threats. It definitely matters to protect your identity from the public
- dathinab 2y agoPrivacy is also meant to protect you from the state, or more specifically state abuse. It's an essential aspect of privacy. Like privacy is also meant to e.g. not disclose topics you have communicated about so that it can't be abused against you. For example there is a long history of states persecuting people for idk. being gay, believing in a certain religion or being a journalist which was involved in a unpleasant disclosure. Still privacy and anonymity are two tightly related but different things. Mainly privacy of communication doesn't always imply anonymity, through sometimes does (and has too!). Anyway it is foolish and somewhat strange to believe that a legally operating email service will protect you against judge backed lawful orders (no matter if it should be lawful or not). Handing out metadata isn't even the worst which can happen, e.g. a judge might order them to make copies of unencrypted mails you receive or make copies of unencrypted mails you write or even undermine your encryption the next time you login. They can try to dispute it and that alone does reduce abuse potential (if they operate in a place which still can be called a state of law) in the end especially for mail there is just no true privacy and even less anonymity. Which doesn't mean their service is useless. Just if you worry about political prosecution by EU countries, or do crime it's not protecting you.
- mynameisnoone 2y ago[flagged]
- hwbunny 2y agohttps://proton.me/blog/protonmail-threat-model https://proton.me/blog/protonmail-threat-model
- newscracker 2y agoThat blog post was last updated in November 2022, and does not mention recovery email address as something Proton would disclose.
- protonmail 2y agoThe treatment of recovery address has been explained in our Privacy Policy: https://proton.me/legal/privacy https://proton.me/legal/privacy. From a technical perspective, one can't end-to-end encrypt a recovery email as it needs to be accessible to send the recovery email, which is typically initiated by an unauthenticated user who has lost their password.
- snvzz 2y agoStill waiting for DIME[0]. 0. https://en.wikipedia.org/wiki/Dark_Mail_Alliance#DIME https://en.wikipedia.org/wiki/Dark_Mail_Alliance#DIME
- mrmetanoia 2y agoI hope Princess has some mad computer skills.
- 0xmohit 2y agoThis case is particularly noteworthy because it involves a series of requests across different jurisdictions and companies, highlighting the complex interplay between technology firms, user privacy, and law enforcement. The requests were made under the guise of anti-terrorism laws, despite the primary activities of the Democratic Tsunami involving protests and roadblocks, which raises questions about the proportionality and justification of such measures.
- mrmetanoia 2y agoProton Mail is pretty good email. I use it since I decided to de-google as much as possible. That said, I don't consider it truly 'private.' Weird key handling in order to make pgp 'easy,' just email being what it is, and courts and governments being what they are. I'll continue to use it despite some hyperbole on the site, but as long as my mail isn't being fed to an advertising engine it's a step up.
- ementally 2y agoThis is not the first time they have provided recovery emails to the feds. https://www.forbes.com/sites/thomasbrewster/2023/08/08/protonmail-fbi-search-led-to-a-suspect-threatening-a-2020-election-official/ https://www.forbes.com/sites/thomasbrewster/2023/08/08/proto... Archive: https://web.archive.org/web/20230814144638/https://www.forbes.com/sites/thomasbrewster/2023/08/08/protonmail-fbi-search-led-to-a-suspect-threatening-a-2020-election-official/ https://web.archive.org/web/20230814144638/https://www.forbe...
- zzz999 2y ago[dead]
- ein0p 2y ago[flagged]
- submeta 2y agoIs there any real private email service? Honest question.
- denton-scratch 2y agoEmail is not private, and can't be made so. Email is my preferred communications channel, but I treat it as I would a mailing list or comment forum; it's almost completely unlike whispering to someone in the middle of an empty field.
- contextnavidad 2y agoTake a look at Posteo. Seem to have a similar philosophy as Mullvad.
- onhacker 2y agoI hate when companies mislead, they claim email encryption. but the question is how they know the email is suspicious. it means they monitor emails and obviously, Proton Mail is (not) the trusted choice for secure and private communication.
- NicuCalcea 2y agoWhat email was suspicious? From what I can read. Proton provided the Spanish authorities with a recovery email address, which the latter then used to find an associated Apple account. While I agree this makes Proton unreliable for many things, there's no indication they were reading any emails.
- onhacker 2y agoNo service can read all emails of a platform, but spying is still not good anyway, if someone is misleading it's a government problem to find and punish them, communication should be safe anyway, old face-to-face communication is good then internet.
- jamesholden 2y agoThis situation is interesting, but the article mentions using a VPN for example, and also the recovery email. What if my recovery email is to another proton mail account? What if my VPN used is Proton VPN?
- obelus 2y agoA recovery email is optional, and Proton VPN is no logs.
- XXxXr 2y agoQweu
- felsokning 2y ago> This individual is suspected of being a member of the Mossos d’Esquadra (Catalonia’s police force) and of using their internal knowledge to assist the Democratic Tsunami movement. ...and... > The requests were made under the guise of anti-terrorism laws, despite the primary activities of the Democratic Tsunami involving protests and roadblocks, which raises questions about the proportionality and justification of such measures. As I understand it, Catalonia has long desired for independence[1]. Is the Democratic Tsunami movement something different, entirely? If not, can someone fill-in the blanks of how vying for independence (in this case) gets umbrella'ed under terrorism? [1] - https://en.wikipedia.org/wiki/Catalan_independence_movement https://en.wikipedia.org/wiki/Catalan_independence_movement Edit: Accidental caps-lock on a word. My bad.
- yorwba 2y agoIndependence is a political goal. Terrorism is a means to achieve political goals. (Though I don't think it has a good track record of being successful at that.) It's not that unusual for people to combine the two and plan terrorist attacks against the state they want to be independent from. (In this case it appears the investigation concerns a suspected attack plot targeting the Spanish king.)
- GardenLetter27 2y agoThey did extreme protests like road blockages, and some other stuff which the government considered sabotage and so pursued them with anti-terrorist legislation. Also some members were arrested apparently planning even more extreme things. The IRA and ETA were vying for independence too... That said, I think it's crazy how much time the government wastes on this when the cities are full of petty criminals acting with impunity. Someone was stabbed to death outside my apartment just in a robbery and yet nothing changes.
- wolfhumble 2y agoThe Democratic Tsunami was/is(?) more of a pure action based protest group lead by an anonymous leader structure. The leaders were/are probably certain leader figures within the independence seeking community; but that is just a speculation on my part. Its biggest action was probably at the Barcelona Airport in October 2019, a protest a couple of years after the Catalan independence election in October 2017. The election itself was deemed unconstitutional by the Spanish government. The registered voters/turnout of this election was 43.03%; where 92.01% voted for separation from Spain and 7.99% voted to stay within Spain –– see: https://en.wikipedia.org/wiki/2017_Catalan_independence_referendum https://en.wikipedia.org/wiki/2017_Catalan_independence_refe... –– but this was not a normal election by any means (read the link for more). Typically the ANC –– see: https://en.wikipedia.org/wiki/Assemblea_Nacional_Catalana https://en.wikipedia.org/wiki/Assemblea_Nacional_Catalana –– has been the leading organization in the independence movement. They have been organizing big independence rallies etc. and the actions has been peaceful (from what I've read and seen). The Democratic Tsunami based protests were different in this regard, where more direct confrontation was more the norm. From what I have read Democratic Tsunami is not particularly active at the moment, but of course this might change.
- BSDobelix 2y agoJust to make it clear. Proton is a Swiss Company and is not answering to any request from Spain, directly. Spanish authority's ask Swiss authority's and if everything is in order Proton HAS to give the data out (or contest it).
- deleted 2y ago[deleted]
- nabla9 2y agoProton Mail gives info only when the Swiss law mandates it and Swiss law enforcement requires it. Swiss privacy laws are quite good. That's the strictest privacy policy any company can hope. Proton Mail can't give email content, only things like email address, ip adressese etc.
- blitzar 2y agoProton Mail can give email content, however, it is encrypted and they do not have the encryption keys. Anything that is stored by anyone can be handed over. That information may be useful, may be useless or may be useless now and useful tomorrow when they have the key.
- wepple 2y ago> they do not have the encryption keys. True, but they can trivially obtain them given they control everything in the browser. The question then becomes, does the law allow compelling to that degree? Apple fought back in the San Bruno case, but they’re very well lawyered up
- kobalsky 2y ago> True, but they can trivially obtain them given they control everything in the browser. Open source clients that you can self-host are available. I mean of course you still have to trust the code if you can't audit it. But hijacking your keys won't be as easy as visiting their webmail.
- obelus 2y agoBut Swiss law can't make a request like that.
- wepple 2y agoI would hope so, but is that confirmed? Is there a clear definition between handing over data they have and being compelled to make modifications in order to intercept?
- Shacklz 2y agoThere are some serious anti-proton-vibes in this thread, so just my 2 cents as a paying customer: I'm rather happy with their service. I pay them money, they make sure that Joe in Marketing won't be able to harvest data from my emails. I'm also fairly optimistic that they take security serious enough that the blast radius of some dataleak is hopefully very limited. I have zero delusions however that they can protect me from state agents, let alone state agents with malicious intent. And I don't think it's realistic to expect that for the amount of money they cost. But that's fine with me - it's Joe from Marketing I'm scared about, and so far they seem to do a good job keeping Joe at bay :)
- sevagh 2y agoSeconded, happy Proton customer for years since de-Googling my life. Par for the course at HN to have a "vaguely dislike-ish" relationship with Protonmail. Fastmail is the poster child of HN on the other hand. I would guess the gist of it is that if you promise _any_ amount of security (or whatever feature), HN will nitpick you to death on not going 100% (despite the general improvement to your security). If you don't promise security at all, it doesn't matter that you're less secure than Proton. Something like that.
- fifteen1506 2y agoIt's normal. Dropbox was derided on HN because it wasn't much more than a glorified FTP.
- brongondwana 2y agoI've just been poking around at the Dropbox APIs recently when I got so frustrated by the fact that the Fastmail "attach from Dropbox" feature has been loading directly into my personal files space rather than showing the shared team folders since we switched over to using those last year - and I now have to download and re-upload files from those folders. It's more than a glorified FTP. FTP does some heinous things with a separate control channel and stuff (let me tell you about adding encryption support to the Perl FTP server some other day), but this is next level! https://developers.dropbox.com/dbx-team-files-guide https://developers.dropbox.com/dbx-team-files-guide It's not even as simple as just sending a fixed string in the "Dropbox-API-Path-Root" header for every API request (and they're all path based, so you have to make sure you always send that header or the paths won't parse right) - you have to get an ID for the real root, with a separate request, with a scope that we weren't requesting on refresh tokens. So I hacked together something that worked on my testbed on the train ride home, but making it good is going to include adding a caching layer to the token refresh code, and suddenly it's not just a casual project. I'm still going to do it though, because dammit I have a file to attach to an email on Friday and I'm happy to spend hours on this to save myself 30 seconds.
- quitit 2y agoIt seems there is some mental conflict going in readers between the reality of what ProtonMail does for its customers and their expectations of what kinds of protections a legitimate business can provide. Both ProtonMail and Apple will challenge subpoenas when they believe they are not valid, however neither company has the final say in the matter and can be compelled to provide access to data that they reasonably have access to. It is up to the user to plan what information they provide to service provides in order to not leave a trail of crumbs, and also evaluate what kind of man-in-the-middle weaknesses a service might have for the possibility of wiretapping. It should go without saying that linking a phone number or back-up email address can be a pretty large crumb. The learning here is to recognise that these services can be compelled to provide whatever small information that they have reasonable access to, and that this information may be useful in unmasking an identity. I suppose the second learning is to elect governments which respect democratic freedoms, even if that puts them on the back foot.
- dennis_jeeves2 2y ago>I suppose the second learning is to elect governments which respect democratic freedoms, This will _never_ happen. It's the human condition....
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- wepple 2y ago> It is up to the user And therein lies the problem. We on HN may have a few ideas about how to do this, but the typical user of a secure email/VPN/tor unfortunately doesn’t and realistically can’t understand the corner cases and tricks. Realistically, even HN users would make enough mistakes. This is why I’m dubious of these types of products marketing to average consumers
- pc86 2y agoIf your threat model is "utilize secure email/VPN/tor to evade organizations on the spectrum of [law enforcement...intelligence services]" you are not a typical user even of those services and saying that it's on you to understand all the corner cases and tricks to avoid persecution, prosecution, execution, etc. seems pretty reasonable.
- cynicalsecurity 2y ago[flagged]
- Alfagun74 2y agoProtonMail itself probably is some GOV honeypot, why should anyone offer such service
- wepple 2y agoWhen thinking about these types of cases, always keep Parallel Construction in mind: https://en.m.wikipedia.org/wiki/Parallel_construction https://en.m.wikipedia.org/wiki/Parallel_construction There’s a reasonable chance that they already had this info (possibly even cleartext email via an ISP lawful intercept), and the proton/apple jig whilst bad, wasn’t as bad as the real source
- fifteen1506 2y agoI never thought of ProtonMail as a secure-from-state-surveillance provider. Only as a secure-from-civil-surveillance-aparatus provider. A replacement for Gmail, no more than that. If I wanted to conduct illegal activities I would not use my main account on it, at minimum. Protonmail is a step up from Gmail/Outlook, but no more than that. You need more layers on top of it.
- probably_jesus 2y ago[dead]
- nairboon 2y agoQuite interesting how the Spanish authorities got the recovery email: (from a link in the article) > In the police cooperation form requesting the information, the Spanish officers indicate to the Swiss authorities that the investigation is for the crime of terrorism.
- moosemess 2y agoIt is 2024 and there are still people who cling to the idea there can be privacy with email, so much so they are willing to be parted with their money for the "privilege". I really cannot imagine a more diametrically opposed schism in privacy threat modeling.
- jimmydoe 2y agoIf avoiding Europe governments is a priority, would it be better to use mail service from China or Russia?
- beretguy 2y agoI use Proton to protect myself from Google, Microsoft, advertisements, tracking, terrible, slow, “too much padding everywhere” UI, my emails/data being sold to 3rd parties, etc. I’m not worried about Proton cooperating with law enforcement agencies to catch criminals. However. What if say, russia/nk/china wants to catch somebody some journalist for speaking truth about their regimes? Or, like say, Jason Bourne exposing some IronHand in “democratic” country like USA? How can we protect good actors without enabling adversaries to do “bad stuff”? Is it even possible? I still don’t know the answer…
- obelus 2y agoBut requests have to meet Swiss standards, which makes all the difference.
- kazinator 2y ago> Catalan independence organization, Democratic Tsunami OK, I think I grokked this. You might think that a Greco-Nipponese name for this organization poorly conveys Catalan nationalist pride. But in fact it quite effectively says "anything but Spanish". That's almost certainly the gag.
- i8comments 2y agoInstead of blaming corporations for following the law, blame the laws and the government for what they force others to do. It is not up to corporations to decide which laws should be enforced, and this again shows how futile this specific kind of corporate resistence is. Just change the law.
- nsoolo 2y agoI understand that no person or company is above the law and that the user should have used a VPN or Tor but I find it funny that Proton promotes itself as a private provider which does not give out user information when it can log any type of user information and give it to the authorities, it is certainly not a private service.