[HN Gopher] Proton Is Trying to Become Google Without Your Data
___________________________________________________________________
Proton Is Trying to Become Google Without Your Data
Author : cpeterso
Score : 125 points
Date : 2022-05-26 20:31 UTC (2 hours ago)
(HTM) web link (www.wired.com)
(TXT) w3m dump (www.wired.com)
| thomond wrote:
| There are too many technology products called Proton.
| minsc_and_boo wrote:
| There's already a ton named Electron too - what about
| _Neutron_?
| verisimi wrote:
| yeah! And what's wrong with plain old Ron too?!
| imwillofficial wrote:
| But they'll give your data away if asked.
| cowtools wrote:
| I mean, they are legally obligated to. At least they are not
| selling my data to advertisers or arbitrarily locking me out of
| my account like google. Hell, i'd pay for their premium service
| if wasn't so expensive and they accepted anonymous payments
| through monero or something.
|
| I mean, this is what email has basically come to. I've tried to
| host my own email server, all my outbound mail ends up in spam.
| If you want privacy, use PGP
|
| Edit: please don't downvote this parent comment, I think it is
| still a pretty reasonable concern
| yupper32 wrote:
| > At least they are not selling my data to advertisers
|
| That's almost never what actually happens, though. They sell
| access to you and use your data internally to target ads.
|
| A law enforcement request does literally release your data.
| cowtools wrote:
| It doesn't matter to me whether or not they only use the
| advertising data internally. Google is such a large
| monopoly at this point that I am basically forced to deal
| with them on a daily basis through the businesses and
| institutions I work with.
|
| It's not even the surveillance that I am concerned with at
| this point. I just am trying to disentangle all these
| services that I use that demand to become linked in
| difficult ways.
|
| Like let's say you have a gmail account linked to a youtube
| account, and you upload a video or like something that sets
| off google's automated spam heuristic. Boom, your google
| account is deleted and you can no longer access your email
| or sign into your accounts that require email verification.
| All this extra surveillance is just going to increase the
| odds of my account getting falsely flagged as a bot or
| something.
|
| Let's say you lose your phone. You have to use your phone
| to login to some institution's service, so you get a new
| phone and try to reset the 2FA with your email. However you
| need access to your phone as a 2FA to access your email.
| (this exact scenario happened to a family member the other
| day, just goes to show you should NEVER link your accounts
| with a cell number).
| yupper32 wrote:
| > It doesn't matter to me whether or not they only use
| the advertising data internally.
|
| Okay, but it does matter when you say something
| significant that isn't true. Do you understand that?
| charcircuit wrote:
| >At least they are not selling my data to advertisers
|
| No they don't.
|
| >We do not scan or read your Gmail messages to show you ads
|
| https://support.google.com/mail/answer/10434152
| post_break wrote:
| Exactly, which leads me to the spiral of what's the point? If
| there is nothing truly encrypted, then what do they really
| offer?
| ziddoap wrote:
| You're conflating different things. It doesn't help that
| people who seem to have a bone to pick with companies obeying
| the laws of the country they operate in continuously leave
| out the nuance and detail of the event.
|
| The court order that Proton complied with released the IP
| address of the suspect, not the encrypted contents of the
| emails in the suspects inbox.
| ziddoap wrote:
| If asked via lawful court order, yes.
|
| Can you provide me the name of any company who does not comply
| court orders of the country it operates in and continues to
| operate freely?
|
| Edit: I thought this was a more than fair question, evidently
| people do not think so.
| metadat wrote:
| > Can you provide me the name of any company who does not
| comply court orders of the country it operates in and
| continues to operate freely?
|
| AT&T, Google, Apple, Comcast, Verizon, ...
|
| Oh, did you mean companies who refuse to comply specifically
| to legal inquiries about their users or customers? No company
| will (or even should) stick their neck out for you
| personally.
|
| With sufficient resources and clout, they will risk it for
| themselves because $$$ and power.
| ziddoap wrote:
| > _AT &T, Google, Apple, Comcast, Verizon, ..._
|
| Really? I understand that they fight court orders when they
| feel they need to, which Proton at least claims to do as
| well (have not verified that, though), but they get away
| with just... ignoring them? Or not complying after losing
| an appeal? I stand corrected if that is the case.
|
| > _With sufficient resources and clout_
|
| Does Proton have the clout to do so? I don't believe they
| do, which makes me wonder why it's such an unpopular
| opinion to believe exactly what you said ( _" No company
| will (or even should) stick their neck out for you
| personally."_) when it comes to Proton.
| metadat wrote:
| tl;dr: The climate is heading towards the best option
| being to need as little privacy as possible.
|
| Corporations and their employees have learned clever
| techniques to get away with "complying" without _really
| complying_ in instances where they 're sufficiently
| motivated. It's not always politically feasible, but is
| in many cases.
|
| A quick (and ironic) Google search for "google lawsuit
| federal compliance" turns up many instances:
|
| https://www.dol.gov/newsroom/releases/ofccp/ofccp20170104
|
| https://www.justice.gov/opa/pr/justice-department-sues-
| monop...
|
| These violations are all calculated risks on their part.
| Internally, they intentionally keep certain
| communications off of email to ensure it will never be
| discoverable through a legal process.
|
| It's not like Big-G is the only one, do you think this is
| ubiquitously commonplace across the megacorps in
| virtually every industry in the United States?
|
| Here's what happens when they come for your / our data:
|
| https://www.nytimes.com/2006/01/20/technology/google-
| resists...
|
| > even as three of its competitors agreed to provide
| information
|
| > Rather than seeking data on individuals, it says it is
| trying to establish a profile of Internet use that will
| help it defend the Child Online Protection Act, a 1998
| law that would impose tough criminal penalties on
| individuals whose Web sites carried material deemed
| harmful to minors.
| yabones wrote:
| The value of proton is not that they'll break the law for you
| -- they absolutely will not. They are bound by the laws of the
| land, and when compelled will hand over all the data they are
| required.
|
| The value IS that they simply don't have that much data. All
| your emails are encrypted at rest with a key they can't read.
| All your data is stored in such a way that they can't decrypt
| it on demand.
|
| Think about it. When Microsoft gets served a FISMA warrant,
| everything they have is stored in plaintext, so they have to
| hand it all over. With Proton, all they have is your IP, the
| date you created your account, the last login date, potentially
| the subject lines of any messages in their mail queue, and
| that's about it.
|
| Nobody is going to risk their business to help people hide from
| law enforcement, and anybody that says they will is probably
| lying to you.
| ptero wrote:
| Proton is not perfect, but nothing is. We need more competition
| on the internet, and if Proton has a chance to provide an email
| and storage for an upfront price without trying to distract me
| with ads or pimp my data to advertisers, I want to support them.
| As a data point, I have been a very happy user of their plus
| service for the last 3 years.
| Terry_Roll wrote:
| There is a silent backlash against Proton, the most obvious is
| the domain is blocked by the US Antivirus company who scans all
| UK politicians emails through the UK parliament email address
| parliament.uk or British politicians are ignoring their
| constituents, some website contact forms reject protonmail
| email address as well. So I hope they give Google a run for
| their money.
| kodah wrote:
| My company VPN also blocks ProtonMail. I'm not sure exactly
| why, and I have zero evidence, but I suspect it's because
| it's the email that a whistleblower used a while back that
| was featured in congressional testimony.
| jrockway wrote:
| I've definitely blocked protonmail domains before. The
| calculus is that 100% of the accounts from that domain are
| fraud and 0% are legitimate, so it just saves a lot of time
| to block it. Stops fraud before it even starts. This is, of
| course, annoying for the 1 legitimate customer mixed in with
| the billions of bots. But basically, they have an abuse
| problem that they need to solve. Gmail also has plenty of
| fraudulent accounts, but it also has a lot of legitimate
| accounts, so they avoid the *@gmail.com ban.
|
| It sucks that people use wide swaths like this, but that's
| how the cookie crumbles when you have a problem at 3 in the
| morning that you need to fix now and then go back to bed.
| almet wrote:
| The only thing that bugs me with Proton is that it's still very
| complicated to integrate with thunderbird (or any mail app?),
| which makes it practically unusable for my needs.
|
| Having a tab always open in my browser for my mail seems so
| wrong.
| BoyBlunder wrote:
| Their mobile apps are also very lackluster and devoid of
| basic features. I understand that they are unable to open up
| to other mail apps due to the encryption, but for the past
| few years there have been little to no updates to their iOS
| suite.
| adamhearn wrote:
| Genuine question, how is a browser tab different than
| thunderbird? Besides storing a local copy of mail (which is
| obviously a huge win), I don't see a big difference. If
| anything I like the web UI better.
|
| However, for my uses I simply installed proton bridge + apple
| mail. It just works with all email services I use.
| mr_toad wrote:
| > Genuine question, how is a browser tab different than
| thunderbird?
|
| Different protocols for one thing - HTTP vs IMAP and/or
| POP/SMTP.
|
| Each webmail app does things it's own way. Webmail
| conflates the app and the protocol and the provider. Some
| people prefer to have mail from different providers in a
| unified app.
| blangk wrote:
| I find it works very well using the bridge on my Manjaro
| desktop, and was fine on Debian before that.
| ptero wrote:
| I have the same experience, for me it works flawlessly with
| the bridge, but the bridge itself is a complication. I
| would prefer a straight imap option (in addition to the
| bridge option). My 2c.
| noman-land wrote:
| I agree it's not perfect but they have some pretty great
| instructions. I've been using the Bridge with thunderbird for
| multiple accounts and it works awesome.
| Ansil849 wrote:
| It's kind of disingenuous to keep touting "Swiss privacy laws" as
| some sort of selling point on their homepage, when shit like this
| happens https://techcrunch.com/2021/09/06/protonmail-logged-ip-
| addre...
|
| Why's a privacy-first service logging IPs in the first place?
| emendation wrote:
| As the article states, they were forced to by Swiss
| authorities. They tried to fight against it, but in the end no
| reputable provider is going to put the whole company on the
| line for 1 user against a lawful order from their government.
| Ansil849 wrote:
| Uh-huh. Then perhaps they shouldn't be touting Swiss privacy
| laws like they're some holy golden shield. And once again:
|
| > Why's a privacy-first service logging IPs in the first
| place?
| fsflover wrote:
| See also: https://news.ycombinator.com/item?id=31522082.
| ntoskrnl wrote:
| Proton Is Trying to Become Google, indeed.
| kobieyc wrote:
| Hmmm, that does seem somewhat suspect.
| [deleted]
| [deleted]
| hammock wrote:
| PeterWhittaker wrote:
| Source? Citation?
| loufe wrote:
| Obviously it's not been exposed, yet. That said, I think it's
| pretty safe to assume in the post-lavabit world that these
| companies are fronts for Western intelligence. We clearly
| don't live in a world that respects privacy anymore, take the
| recent "anti-csm" bullshit the EU is pushing. Personally, I
| won't need proof to seriously doubt this, tutanota, etc. Yes,
| your data may be more hidden, but it would be used as
| evidence in a parallel-construction case based on what they
| "illegally" siphon from your data.
| kobieyc wrote:
| I think this is a safe assumption.
|
| Guilty until proven innocent, by making your code open
| source.
| ziddoap wrote:
| > _Obviously it 's not been exposed, yet._
|
| Then it should not be stated as fact.
| kromem wrote:
| Do you think the same thing about Signal?
| kobieyc wrote:
| Yes, especially since Moxi cashed out and bought a big
| mansion after they released their spy-coin
| cryptocurrency.
| junon wrote:
| Hahahahahahaha. This can't be serious.
| notriddle wrote:
| What can be asserted without proof can be denied without proof.
| newfonewhodis wrote:
| > The safety of Protonmail has been discussed many times on HN.
|
| Lol what are you talking about specifically?
| uoaei wrote:
| Probably the whole "oops we actually DO share IP addresses
| despite our ToS" followed by a rushed revision of the ToS to
| include that fact, among other recent news stories.
| ziddoap wrote:
| This is such a disingenuous retelling of what happened.
|
| Terms of Service don't trump lawful orders issued by a
| government. Never have, never will, for any service or
| company. They were issued a lawful order, did you expect
| them to just close the company instead?
|
| Whether or not you use Proton before or afterwards is of no
| matter, but please at least try to be honest with what
| happened.
| uoaei wrote:
| > Terms of Service don't trump lawful orders issued by a
| government.
|
| No, obviously they do not. But misrepresenting your
| policies (i.e., lying) to your users ("we don't track IP
| addresses" was understood literally at the time) is a
| serious error and, especially if you're marketing to a
| privacy-aware crowd, one of your top priorities should be
| to maintain their trust or else your customer base is
| going to fall out from under you.
|
| What's disingenuous is implying that lawful orders trump
| the ethics of lying to your customer base, when saying
| "we don't track IPs..." but meaning "...until the
| government asks us to".
| Klonoar wrote:
| Eeeehhhhh, I interviewed and was offered a role there a few
| years ago. Talked with a number of teams and employees, they
| were very candid about what they were working on during every
| step of the interview. I never saw anything to indicate either
| of these claims.
|
| The safety of encryption/decryption in browser-JS payloads is a
| different discussion entirely, but you can't make wild claims
| about it being a front for state-level actors without some
| reasonable sourcing.
| imwillofficial wrote:
| coffeeblack wrote:
| Then the only explanation is that you are in on it11 *adjusts
| tinfoil hat*
| lawrenceyan wrote:
| Everything is a front for state-level actors. I think we can
| still appreciate technology for what it is.
| glerk wrote:
| No idea if it's a "front", but if your threat model is state
| level actors Protonmail is not gonna cut it.
| edgyquant wrote:
| If your threat model is state level actors the only thing
| that will cut it is another state level actor
| stingraycharles wrote:
| What do you mean with that?
|
| From what I understand, there are legitimate issues around
| Protonmail and its affiliation with government agencies
| [1]. It's not as if it's impossible to find a different
| provider that does better in this regard.
|
| [1] This provides a decent summary:
| https://encryp.ch/blog/disturbing-facts-about-protonmail/
| coffeeblack wrote:
| And every time it was discussed, the conclusion was the exact
| opposite of what you are claiming.
| [deleted]
| photochemsyn wrote:
| This is a rather interesting interview style, it seems as if the
| interviewer is presenting the viewpoints of the national security
| state complex ("we need total access to all data to prevent
| terrorism and child abuse") and of the major tech conglomerates
| ("competition reduces privacy"), aka Big MAMAA (FAANG is
| obsolete), but it does provide the interviewee with opportunity
| to counter those points, so I guess it's a decent interview
| approach.
|
| I'd add that the solution to child abuse and terrorism is the
| same it has ever been, i.e. targeted investigations relying on
| tactics like infiltration of criminal rings with undercover
| officers. There's no justification for Gestapo/NKVD
| authoritarianism and mass surveillance tactics.
|
| However, there doesn't seem to be any plausible way to
| communicate with others using any infrastructure-type system
| (from postal mail to fiber optic cable) that doesn't reveal the
| network of communication (i.e. metadata), and Tor is hardly an
| exception. Tor seems to have been designed to allow remote
| government agents (aka spies) operating in hostile environments a
| means to communicate with a known base of operations without
| revealing their actual remote locations or identity. Similarly it
| could be used by individuals to communicate with journalists (as
| Edward Snowden did) without revealing their identity or location,
| but only if they take a lot of precautions (i.e. not using their
| device for any other online activity that could be traced to
| them). I imagine NSA has backdoors into almost all Tor nodes
| anyway. The content can be securely encrypted, but
| location/identity? Probably not.
| unboxingelf wrote:
| Big MAMAA
|
| Microsoft, Alphabet, Meta, Apple, ?
| shemtay wrote:
| ...Amazon?
| unboxingelf wrote:
| Lol, oh, right...
| [deleted]
| daemon_of_chaos wrote:
| Amazon?
| photochemsyn wrote:
| AWS, or Amazon. According to The Economist, those are now the
| big five tech players.
| airstrike wrote:
| MAGMA is still a better acronym
| lvass wrote:
| Using Google and Meta in the acronym sounds wrong. I'd rather
| MAAMA or MAGFA.
| almet wrote:
| In french we say GAFAM, I naively though it was the same in
| the US. Gasp, I'm still too focused on my culture =D
| photochemsyn wrote:
| But now we can talk about "the outsized influence of Big
| MAMAA on the tech industry", which has a nice ring to it.
| MAGMA has a decent ring as well, though.
| bayindirh wrote:
| > There's no justification for Gestapo/NKVD authoritarianism
| and mass surveillance tactics.
|
| I think many people are missing the point and see the issue as
| "Governments trying to get capabilities".
|
| No, they always had the capability because of lower population,
| slower communication, more effective mass media and information
| bubbles. Now, they're losing this capability, and want to keep
| their abilities while making them automated & cheaper.
|
| Also, there's CryptoAG stuff, which is the same thing, but
| international.
| uoaei wrote:
| What was that in the news a year or so back about the FBI
| having a significant number of Tor endpoints, making the
| routing effectively transparent? I would imagine if the FBI
| pulled that off, so did many other state actors.
| floren wrote:
| > The analogy to terrorism is interesting because, during the
| Bush-era War on Terror, there was a sense of literally anything
| being justified in the name of stopping terrorism. The US
| government was secretly spying on its own citizens.
|
| Yeah, Wired, they only did the spying during the Bush era...
| edit: I guess it was less _secret_ after the Bush era
|
| > It's even harder to say, look, we've got to accept that some
| amount of child exploitation is going to happen and people are
| going to use digital tools to spread it. But at some point, I
| think you do have to defend the principle that we have to
| tolerate a certain amount of even the very worst things if we
| want to have meaningful civil liberties.
|
| Not a very popular argument at this particular instant in time /
| news, bold of them to write this without a giant asterisk.
| r3trohack3r wrote:
| > Yeah, Wired, they only did the spying during the Bush era...
| edit: I guess it was less secret after the Bush era
|
| I don't understand - it never ended. In fact, Obama ran on a
| platform of protecting whistleblowers and cracking down on
| government overreach. But, once he took office, he legalized
| the Presidential Surveillance Program that Snowden whistleblew
| and doubled down on pursuing Snowden.
| floren wrote:
| I was attempting sarcasm, because as you say, Obama _loved_
| that surveillance shit.
| [deleted]
| bsder wrote:
| > It's even harder to say, look, we've got to accept that some
| amount of child exploitation is going to happen
|
| Except that every big kiddie porn case was cracked by old-
| fashioned policework--"Get someone inside". And, most of the
| time, it isn't even that difficult to pull off.
|
| It particularly grinds my gears because the powers that be only
| trot out kiddie porn when they want to shove legislation down
| our throats. The rest of the time enforcement against kiddie
| porn stays heavily underfunded.
| r3trohack3r wrote:
| > It's even harder to say, look, we've got to accept that some
| amount of child exploitation is going to happen and people are
| going to use digital tools to spread it. But at some point, I
| think you do have to defend the principle that we have to
| tolerate a certain amount of even the very worst things if we
| want to have meaningful civil liberties.
|
| This is not how I'd articulate it. We tolerate some terrible
| things because trying to stop them would be even worse. There
| are really bad people out there. Unfortunately those bad people
| can also run for office and/or get hired on to 3 letter
| agencies.
|
| A pedophile with a camera is less dangerous than a senator
| without the 4th amendment. A racist on social media is less
| dangerous than a president without the first amendment.
|
| Fascism doesn't happen because you elect a fascist president.
| The seeds of fascism had to be sown long before that. Fascism
| is the result of eroding protections designed to prevent a
| leader from over-reaching. The path to fascism is paved in good
| intentions.
| _jal wrote:
| > we've got to accept that some amount of child exploitation is
| going to happen
|
| Funny, that's the exact deal with have with guns - we accept
| some amount of mass child murder as the cost of the 2nd
| Amendment.
|
| Another datapoint that the 2nd is now considered more absolute
| the 1st.
| drcongo wrote:
| Email and calendar aren't the things that keep people on Google,
| it's Docs etc. You can get good email and calendar anywhere. If
| their plan is really to take on Google, that's the bits they need
| to target.
| brewdad wrote:
| Meh. Different users have different needs. GDocs could go away
| tomorrow and I would hardly miss it. I don't think I've created
| anything new on the service in over a year. I use email and
| calendar every day and need them available and accessible.
| greazy wrote:
| I don't agree. The reason why people use Google products is
| varies. Some rely on docs heavily, others need (like myself)
| just email + cal + drive
| Havoc wrote:
| Definitely plan to stick to proton for the long run.
|
| Don't think they'll keep me private & safe...but I do think
| they'll try harder & more earnestly than the rest of the gang
| attempting it.
| 0daystock wrote:
| > I do think they'll try harder & more earnestly than the rest
| of the gang attempting it.
|
| Why, though? What do people base this assertion on, other than
| clever marketing materials which extol virtually meaningless
| controls like "it's hosted abroad" (which is actually much
| worse for foreign nationals' privacy, for example)?
| Havoc wrote:
| >Why, though?
|
| Not US based for starters - definitely willing to pay a
| premium for that.
|
| Nor five eyes or any of the other [0] eyes.
|
| > extol virtually meaningless controls like "it's hosted
| abroad"
|
| There is no value in abroad in itself, what matters is how
| trigger happy countries are with warrants etc.
|
| I'd like to be in a jurisdiction where it is possible for law
| enforcement to get to the data...but I'd like the
| logistically/legal hurdles to be rather high so that it is
| only done for serious concerns not trawler net catch all
| surveilance operations. Switzerland seems to tick those boxes
|
| [0] https://protonvpn.com/blog/5-eyes-global-surveillance/
| 0daystock wrote:
| A US Citizen has more legal and practical safeguards with
| their data hosted in the US than abroad, but unfortunately
| the widespread privacy anti-marketing has obscured this
| critical concept entirely in exchange for "Swiss are
| probably good at privacy stuff".
| Havoc wrote:
| >A US Citizen has more legal and practical safeguards
|
| Indeed. I'm part of the 96% of the world that is not
| though and I'm very wary of US tendencies to trawler net
| data collection.
|
| >"Swiss are probably good at privacy stuff".
|
| I think you missed my point if that is what you got from
| my post. I don't attribute any special merit to
| Switzerland in the Swiss banking sense...they just aren't
| in any of the major data sharing agreement from what I
| can tell. My data needs to be somewhere...so I'm just
| picking this on a lesser evil basis not perfect basis.
| brewdad wrote:
| >A US Citizen has more legal and practical safeguards
| with their data hosted in the US than abroad
|
| Citation needed.
|
| I get that, in theory, US state level actors shouldn't be
| spying on US citizens acting within the US but the vast
| majority of us are more likely to get caught up in bog
| standard law enforcement activities. A US based provider
| will be forced to comply with a lawful court order from a
| US court. A Swiss based company (for example) can safely
| ignore such requests.
| _xoo wrote:
| This very much feels like ep. 3 of Star Wars. You don't suspect
| anything bad, but it'll happen...
|
| btw. I'm drunk
| vzaliva wrote:
| I have been a ProtonMail user for a long time but have yet to
| make it my default email provider. The main problem is that I
| keep an email archive of all my emails: all sent and most
| received since 1995. It is 17Gb. I've imported it into Gmail, and
| it is instantly searchable. With ProtonMail, such a search must
| happen on the client-side due to encryption. I suspect it will
| not work very well.
| metadat wrote:
| The _searching encrypted content_ problem goes away once you
| build an MS Outlook-ish standalone desktop (or otherwise
| offline-first, in the case of mobile) email client app which
| builds local-only indexes.
|
| The real cost (or long-term benefit) is you'll need a bit more
| local storage to have your cake and eat it privately.
| Nathanael_M wrote:
| "have your cake and eat it privately" has now permanently
| entered my lexicon, thank you.
| glitchc wrote:
| The most private option is to delete (most of) that email. Then
| no one has it and your secrets are safe forever.
| hammock wrote:
| Proton is mired in shenanigans.
|
| Evidence points to ProtonVPN being a white-labeled version of
| Nord VPN. Source: https://news.ycombinator.com/item?id=23571653
| and https://archive.is/iZ2l2 (archive of relevant but broken [2]
| link @ HN thread)
|
| Protonmail has its own issues that have been discussed on HN.
| Source: https://encryp.ch/blog/disturbing-facts-about-protonmail/
|
| Obviously Gmail and such are piped directly into global
| intelligence databases, but Proton is not a panacea, and no
| guarantee they aren't compromised themselves.
| jibcage wrote:
| As someone who works for Proton VPN, I can assure you we do not
| resell any white label VPN services, and that the people I work
| with every day are incredibly smart people who truly, deeply
| care about users' online privacy.
|
| I'll concede that this isn't much better evidence than the
| links you provided, but that archived site in your comment
| really doesn't read like a reputable source of truth, either.
| metadat wrote:
| How can we really know? At the end of the day, trusting a
| company to protect your best interests is, on average, a
| losing proposition.
| ghspoll wrote:
| Obviously any provider can be a honeypot in theory, but I don't
| understand the following either:
|
| - How can ProtonVPN be free and why is it in Lithuania?
|
| - Why does a Swiss privacy company get EU funding if the EU
| wants to erode privacy all the time?
|
| - Why is a cell phone number required for registration?
|
| - In general, how do they make money? Other free providers like
| gmx are full of cheesy advertisements.
| [deleted]
| dimensionc132 wrote:
| Proton .... the Fed honeypot that nobody wants to talk about,
| except, some sane and rational people who have looked at the
| evidence.
| DashAnimal wrote:
| "Obviously Gmail and such are piped directly into global
| intelligence databases"
|
| Wait --- 'obviously'?!? Do you have any info on this because
| that is a wild claim.
| hosteur wrote:
| Snowden docs
| charles_kaw wrote:
| >Do you have any info on this because that is a wild claim.
|
| Not only has the concept and implementation of automated law
| enforcement portals been around since the 90s, the Snowden
| docs revealed that major providers were providing such
| portals. AND that their inter-datacenter communications were
| being piped directly into global intelligence databases
| without.
|
| These portals, NSLs, and other mechanisms have also been
| codified into law for over a decade, and their existence is
| extremely well documented as well as reinforced.
|
| It sounds like a wild claim, but unfortunately, it is
| extremely based in reality. And, it's so well documented that
| to be ignorant of it at this point is akin to incompetence.
| mden wrote:
| You're making a wildly different claim than the initial
| one. The initial claim is "obviously Gmail and such are
| piped directly into global intelligence databases". Portals
| for law enforcement which likely require some kind of
| warrant and very likely have regular audits are not
| slightly the same thing as directly piping the data to the
| intelligence community. As for "their inter-datacenter
| communications were being piped directly", that was
| revealed by Snowden and you correctly used the past tense
| "were". Is there evidence that either Alphabet or Meta are
| giving direct access to their users' data beyond what the
| law requires?
|
| (Disclaimer, employee of Google, my opinions are my own and
| all that. I have no info beyond what is public knowledge.)
| doliveira wrote:
| Lots of "likely" and "were" in your comment...
|
| I'll be honest, this is really the first time I've seen a
| tech circle in which this whole surveillance apparatus is
| not a common established knowledge.
| bhk wrote:
| > Portals for law enforcement which likely require some
| kind of warrant
|
| It was recently reported that major tech companies
| (including Google) release user data without warrants,
| and without even authenticating the party requesting the
| data: https://news.ycombinator.com/item?id=30842757
| doliveira wrote:
| We've known it for literally a decade now... How can you be
| ignorant of the whole Snowden docs?
| tediousdemise wrote:
| https://en.wikipedia.org/wiki/XKeyscore
|
| > XKeyscore (XKEYSCORE or XKS) is a secret computer system
| used by the United States National Security Agency (NSA) for
| searching and analyzing global Internet data
|
| > XKeyscore is a complicated system, and various authors have
| different interpretations of its actual capabilities. Edward
| Snowden and Glenn Greenwald explained XKeyscore as being a
| system which enables almost unlimited surveillance of anyone
| anywhere in the world, while the NSA has said that usage of
| the system is limited and restricted.
|
| Think about that for a split second: anyone, anywhere. Also,
| who would you trust more: the US government, or a man who
| sacrificed his life, health and wellbeing to expose this
| scandal to the world?
|
| Alas, privacy for the masses is dead.
| charcircuit wrote:
| The privacy of GMail is good enough, if not better than
| ProtonMail. Client side encryption also comes with downsides
| since they can't allow third party email clients to work and you
| have to do all processing client side.
| ziddoap wrote:
| > _The privacy of GMail is good enough, if not better than
| ProtonMail._
|
| How do you figure? Google actively scans both email and drive
| for CSAM. If they can scan it for CSAM, they can scan it for
| whatever the hell they want.
| jacooper wrote:
| And they already do, google and Microsoft both scan emails
| for ADs and tracking.
| pete_nic wrote:
| > We believe the best way to protect user data is to not have it
| in the first place
|
| I like the exchange of value that comes from paying money for a
| service. With free products from companies like Google you do not
| pay for the service and there is no exchange of value. This
| results in the myriad of HN threads discussing how Google Docs
| did them wrong (locked out, privacy violation, etc.)
| 0daystock wrote:
| Asserting "private email" is a modern litmus test for someone's
| technical understanding and capabilities, or lack thereof. Snake
| oil companies will always hide behind "it's encrypted" and "it's
| hosted in Switzerland" tropes that mean nothing to anyone who has
| done a modicum of research. Real privacy is not the result of
| some product, especially not when its so desperately and
| obviously shilled.
| tediousdemise wrote:
| Couldn't have said it better myself! Privacy is first and
| foremost a discipline and a practice, just like security. It's
| a form of self-respect, in my eyes. Some would say it's even a
| natural human right.
|
| Commoditizing it is a recipe for disaster.
|
| Edit: Expansion of the self-respect tidbit. Lack of privacy
| enables others to have control over you. Feeling like you are
| not in control, or actually being controlled by someone (shame,
| blackmail, etc.) can be very damaging to your mental health.
| Respect yourself, strive for privacy. You deserve it as much as
| anyone else.
| randomhodler84 wrote:
| I don't know. I don't think all "commoditization" of privacy
| is a bad thing. WhatsApp commoditized it, Signal; SSL/TLS;
| Tor; Privacy Coins; these all vastly improved the privacy of
| comms on the planet. One needs to determine outcomes rather
| than declaring it app disasters.
|
| maybe democratizing privacy is a better way to phrase than
| commoditization -- which implies some cost savings rather
| than the just consumer availability.
| tediousdemise wrote:
| Thanks for chiming in. I've been having some difficulty
| expressing my thoughts lately so sometimes I don't make the
| most sense.
|
| Yes, I definitely agree with you--democratization is a much
| better way to put it.
| [deleted]
| ziddoap wrote:
| > _Snake oil companies will always hide behind "it's encrypted"
| and "it's hosted in Switzerland" tropes that mean nothing to
| anyone who has done a modicum of research._
|
| Do you have evidence that Proton does not actually encrypt
| their emails?
|
| > _Real privacy is not the result of some product,_
|
| I do wholeheartedly agree with this, at least. Privacy is a
| scale and there are many, many pieces which tip the scale one
| way or the other.
| 0daystock wrote:
| What does "encrypting" an email mean to you? If a Gmail user
| contacts me on Protonmail and Protonmail "encrypts" the
| message to me after receipt - what problem have we solved?
| ziddoap wrote:
| I wonder why you used quotes around encryption? They
| encrypt the email. That _very obviously_ does not mean
| Proton somehow encrypted the sent email in the senders
| Gmail account.
|
| However, lacking the other data point (e.g. knowing who has
| sent me an email from a service that does not encrypt their
| emails, and being able to access that email from that
| account), my emails are not readable without my secret.
|
| I never claimed that Proton can encrypt someone else's
| emails.
| 0daystock wrote:
| I think the point of contention is exactly how obvious
| this is to most Protonmail users. I worry too many read
| "it's encrypted" and make dangerous assumptions about
| what can actually be guaranteed rather than investigating
| first-hand; this is the real risk of such services, in my
| opinion.
|
| I put "encryption" in quotes to indicate nuance in the
| characterization. A locksmith installs an amazing door
| and lock at my home, but keeps a copy of the key at the
| shop - I think a fitting analogy for what Protonmail is
| essentially doing here. This isn't a value judgement -
| such a setup is perfectly reasonable for most people's
| threat model - rather an honest apprehension of actual
| trust boundaries.
| ziddoap wrote:
| I absolutely agree that the marketing and branding around
| _almost_ every service that either does (or claims to)
| promote privacy and security leaves a lot to be desired.
|
| It's a hard problem, and a problem applicable to many
| domains. How do you communicate nuance that requires
| multiple years of education to people who don't have
| multiple years of education? I don't know.
| pretext-1 wrote:
| > Do you have evidence that Proton does not actually encrypt
| their emails?
|
| Their encryption is based on PGP and therefore only message
| contents are "E2E" encrypted. Subject, From, To, etc. are
| not. These fields contain most of the information already.
| For example, Amazon puts the name of the ordered item in the
| subject line, so they can still see what you ordered.
|
| And I'm putting "E2E" in quotes because if the sender does
| not send encrypted emails, then they can read the full
| content at delivery time, obviously. They immediately encrypt
| them with your public key and they claim that they discard
| the unencrypted version after that but there is no way we can
| verify that.
|
| Long story short: you still have to trust your email provider
| after all. If I'd want to switch away from Google, I'd
| probably switch to some "normal" email provider (Fastmail,
| Apple, etc.). The benefits of "E2E" encryption for email are
| questionable and the drawbacks huge (for example search is
| very limited). But competition is good and I'm glad they are
| advancing.
| ziddoap wrote:
| > _Subject, From, To, etc. are not._
|
| I never claimed they were.
|
| > _These fields contain most of the information already_
|
| Except, you know, the body of the email.
|
| > _Amazon puts the name of the ordered item in the subject
| line, so they can still see what you ordered._
|
| Yes, Proton is not a panacea. Again, never claimed it was.
| You can't just abandon all opsec because you use Proton, I
| agree.
|
| > _Long story short: you still have to trust your email
| provider after all. If I 'd want to switch away from
| Google, I'd probably switch to some "normal" email provider
| (Fastmail, Apple, etc.). The benefits of "E2E" encryption
| for email are questionable and the drawbacks huge (for
| example search is very limited). _
|
| I agree with the point about trust. You have to trust your
| hardware wasn't backdoored on the way out of the factory,
| too. Security and privacy are about trade-offs and weighing
| risks. I've weighed my risks and made my choices.
| Tijdreiziger wrote:
| > Do you have evidence that Proton does not actually encrypt
| their emails?
|
| It doesn't matter. Proton supplies the client software, so if
| they want (or are forced to by law enforcement), they can
| easily push an update that exfiltrates decrypted data back to
| their server.
| ziddoap wrote:
| It seems rather harsh to brand them as pure snake oil based
| on a hypothetical situation that applies to basically every
| single piece of software and hardware ever invented, but
| fair enough.
| tediousdemise wrote:
| I like to see it as an unsolved problem. Similar to when
| Diffie and Hellman revolutionized cryptography with the
| concept of public/private keys, I like to think that one
| day, a revolutionary proof will drop that demonstrates a
| true trustless privacy model where backdooring isn't even
| a remote possibility.
| Tijdreiziger wrote:
| I suppose you always have to trust someone. (I'm not the
| one who branded them as snake oil, BTW)
| jacooper wrote:
| Its the best you can get. Its fully end-to-end encrypted when
| stored, they don't scan anything, no ADs, no tracking, and they
| support laws and organization that improve individuals privacy.
|
| Why wouldn't I support them ? If i care about privacy I should
| support companies that care about it too, no?
|
| Proton is not perfect, the android mobile app currently doesn't
| have conversion view neither contact sync, and the desktop
| bridge doesn't implement Dav protocol, but its the best out
| there for people who want to protect their privacy.
|
| And if you care about privacy, you shouldn't be using anything
| made in Australia.
| almet wrote:
| Thanks for stating this. It's still good to have people working
| on tools to help us have better usable solutions though.
|
| Depending who is your enemy (threat model), I guess proton
| tools can help you protect your intimacy though.
| k__ wrote:
| They should take some hints from the Gmail UI.
|
| The last Protonmail UI update was just new styles, but still as
| clunky as before.
| coffeeblack wrote:
| The one they rolled out yesterday was pretty good. Including
| phone apps. Now just waiting for the the iOS calendar to
| finally be released.
| k__ wrote:
| It looked nice, but it was essentially the same UI.
|
| But I didn't try the new phone apps, they were really bad in
| the past.
| _xoo wrote:
| I'm on android.. phone app is great
___________________________________________________________________
(page generated 2022-05-26 23:01 UTC)