8 ms·
Reminder that Proton is not "private". They have all the keys, and willingly operate in a jurisdiction where they bend over backwards for ridiculous court order
by devwastaken 2y ago
Reminder that Proton is not "private". They have all the keys, and willingly operate in a jurisdiction where they bend over backwards for ridiculous court orders.
From their own transparency page:
Number of legal orders: 6,378
Contested orders: 407
Orders complied with: 5,971
They did this to expose protestors and people who upset the powers that be, rarely real criminals.
They could choose to operate in a country that respects rights and design their tech so that there's nothing valuable to hand over. This is what Mullvad did.
*Edit: HN has been overwhelmed with poor quality users and bots growing in the last few years. Same as reddit there are paid services used to manipulate voting. HN needs to migrate away from this in order for real discussions to return.
- drpossum 2y agoYou should back up your claim of "they have all the keys", because for things like email and file contents they claim they cannot decrypt them because they do not have those keys (which you have said they do). I believe it was stated on the page you copied those stats from https://proton.me/legal/transparency https://proton.me/legal/transparency > As stated in our Privacy Policy, all emails, files and invites are encrypted and we have no means to decrypt them.
- gobip 2y agoThey're all encrypted by themselves and if you use your own gpg key they will replace it. They're all encrypted except when you pay more for dedicated smtp. They're all encrypted except when they give up logs they promised they didn't have. And so on.
- WhackyIdeas 2y agoListen, if you don’t trust their ProtonDrive - GPG encrypt before uploading. If you don’t trust their email, GPG your message and paste it in or include as an attachment. There are a lot of ways to be able to use proton without trusting them… and if you are an activist of any sort, like just stop oil or cnd, then I am sure they will be doing all of that. I am not an activist so I don’t need to jump through such loopholes. I don’t despise proton as much as I despise most of Silicon Vally though. I just hope they fight every single court order, because there will be lots of good people being targeted. However, I reckon that is wishful thinking.
- jszymborski 2y agoCryptomator is great for the ProtonDrive example: https://cryptomator.org/ https://cryptomator.org/
- WhackyIdeas 2y agoCool idea. But, if I personally wanted that functionality I would code my own solution with a shell script I think (because it is super easy to do).
- protonmail 2y agoThis is pretty inaccurate. Proton's E2EE works by encrypting client side, and we can't just replace the GPG key because we have both key pinning and key transparency: https://proton.me/support/key-transparency https://proton.me/support/key-transparency Proton does not claim no logs and has never claimed no logs. We do not retain logs by default, but our privacy policy has always been clear that we are legally obligated to follow Swiss court orders, which can ask for IP logging on specific accounts.
- ImJamal 2y agoHow do the emails get decrypted then? I imagine your password would decrypt the keys which would allow them to decrypt the emails? It seems like the next time you log in they would be able to capture your password and decrypt your emails.
- roomey 2y agoThere is an FAQ. They sat the emails get decrypted in your browser, or in the "bridge" which runs locally. Your decrypted key isn't sent off your local computer. So it's not a case of waiting for you to log in and swipe your key. They never get the key. In the past you could have a separate login password and decryption password. You still can in the advanced settings if you want.
- ImJamal 2y agoThe key has to be on their servers though? If I log into a proton account on a new computer I could see all my emails decrypted. I don't have to store the key somewhere and move it to my new computer. Second, I am not talking about swiping the key, but the password. When you log in, you send your password to their server. They presumably hash the password and compare the hashes then send you the decryption key if the hash is correct. The problem with that is they could keep the password you entered (pre hash). If hashes are good then use the password you entered themselves with the key to decrypt your email. It sounds like the separate decryption password may work around this, but is not the default meaning a large chunk of the users are vulnerable to proton logging passwords.
- FranckRJ 2y agoYou never send your password to their servers, they use the "secure remote password protocol" : https://en.wikipedia.org/wiki/Secure_Remote_Password_protocol https://en.wikipedia.org/wiki/Secure_Remote_Password_protoco... They explain what they do here : https://proton.me/blog/encrypted-email-authentication https://proton.me/blog/encrypted-email-authentication
- devwastaken 2y agoProton has the burden of proof, and has continually failed to ensure their systems are E2E. They have failed to develop better tech like signal, and continue to change their infrastructure to appease swiss orders that come from other countries. They have every means to decrypt, they control both the client software, server, and data. You would never know if they logged your key, and they can be compelled to by flimsy order.
- protonmail 2y agoThis is inaccurate. First, Swiss law does not allow the breaking of E2EE. All of Proton's client side code is open source. We cannot arbitrarily change keys in an undetected way due to Key Transparency: https://proton.me/support/key-transparency https://proton.me/support/key-transparency. We also have open source mobile and desktop apps, so you don't even need to rely on the web app if you don't want.
- notaustinpowers 2y agoFrom the same transparency report page, they refuse any requests from countries that are not Switzerland, and only provide information to Swiss authorities when necessary (I.E. valid international legal assistance, violations of Swiss law, etc). As well, emails and files are encrypted. And their VPN is a no-log VPN. Lastly, they can comply with an order and just give them nothing, because they don't have anything they can give. No files (E2EE), no VPN network info (No-logging), no emails (E2EE), etc. That's still, legally, an order they complied with.
- theultdev 2y agoGenerally it goes like this: 1. Government entity (usually the US or EU country) pressures the host country's government 2. Host country's government makes a legal request to the company for info on this user. 3. Company adds logging for that specific user. 4. Logging is provided to all those interested. 5. Host country prosecutes (potentially extradites). There's a public accounting of this happening for Proton and Mullvad too iirc.
- notaustinpowers 2y agoYou're making multiple conjectures to get to that conclusion, of which the only evidence presented is another company based in a different country than Proton. It may be true, it may not be, but there needs to be more information or facts before we get to the original comments statement that Proton gives data to expose protestors to protect "the powers that be".
- theultdev 2y agoI'm not making conjectures, these events happened. That's the flow of how government legal requests work with no-log vpn services. What do you think "Orders complied with" means then? Here's an instance of Proton adding logging of an activist's IP Address and Device ID after a request from the French authorities: https://techcrunch.com/2021/09/06/protonmail-logged-ip-address-of-french-activist-after-order-by-swiss-authorities https://techcrunch.com/2021/09/06/protonmail-logged-ip-addre... > French police sent a request to Swiss police via Europol to force the company to obtain the IP address of one of its users. It's right there in the police report.
- hi-v-rocknroll 2y agoYep. They fail Lavabit-style, but somewhat worse. They're selling security theater.
- deleted 2y ago[deleted]
- WhackyIdeas 2y agoI have been with Protonmail since 2014. And I feel that they are essentially now the same as any other company which makes loads of dollar - they give up their values. Don’t get me wrong, I have multiple ‘Visionary Accounts’ but I have just no expectation of them protecting my data completely. How do they get peoples passwords / keys? Easy. They just wait for you to log in and they swipe it then. It’s targeted. They are a perfect example of why you cannot really trust any company selling ‘privacy’, like Apple, Mozilla and whoever else fakes it. Even TOR to a degree is a pile of pish because all the relays can be hosted on mostly American VPS companies… so although the rest of the world would struggle detecting who people are, five eyes are in an excellent position to be able to unmask. It’s intended for the Five Eyes spies to hide among - they need the randomers on there or it’s a useless tool for their global spies to use - I don’t think enough people actually realise that.
- hombre_fatal 2y agoBesides, none of it really matters when their customer service backdoor lets you into an account if you can enumerate recent emails that account has received. I'd never trust anything serious with Protonmail. (Try it)
- WhackyIdeas 2y agoCan you explain more about this, I am clueless to this? Appreciated!
- ivan_gammel 2y agoDo you have any evidence for this claim? Here’s their recovery process: https://proton.me/support/set-account-recovery-methods https://proton.me/support/set-account-recovery-methods I don’t see there customer support call as a recovery method. I‘d expect that for paid accounts you could theoretically verify your identity to CS via payment, but in that case you lose the data anyway.
- hombre_fatal 2y agoYour link doesn't apply here. The attacker's recovery process is to just send an email to support@protonmail.zendesk.com and start flapping their gums. It doesn't matter if you lose data. If you control an email address, you get all future email including forgot-my-password emails.
- freehorse 2y ago> They did this to expose protestors and people who upset the powers that be, rarely real criminals. Source? How exactly do you know what cases of people the legal orders were about?
- tredre3 2y agoI agree with you that Proton is security theatre. Even if they were truly benevolent, they ultimately control both the server and the client. It would be trivial to serve a special js to a specific user to capture their key. Nobody would ever know. But that part: > HN has been overwhelmed with poor quality users and bots growing in the last few years. Same as reddit there are paid services used to manipulate voting. HN needs to migrate away from this in order for real discussions to return. is absurd. Is it really the only way you can explain why you're downvoted? Could it not be because you've made several unsubstantiated claims?
- aniviacat 2y agoYou can choose to only use the open source apps. Using the website is optional.