Post B43wyjRHWbJmioE4cC by james@bne.social
 (DIR) More posts by james@bne.social
 (DIR) Post #B43rvqw2hMNTKaQDo0 by malwaretech@infosec.exchange
       0 likes, 3 repeats
       
       It feels like Proton are being intentionally misleading in their statements. They know that most of their customers aren't familiar with how legal process actually works, so are happy to spread half-truths.Under US law, a US law enforcement agency (LEA) typically has to apply for a subpoena or search warrant with a US court. The court is then responsible for deciding if the legal bar for search a request has been met, then either grants or denies it.The problem is, if a company has no real US footprint (no US corporate entity, offices, servers, etc.), then a US court typically doesn't have the jurisdiction to compel the company to hand over customer data (except in some rare circumstances). Even if the court approved the warrant anyway, it wouldn't really be legally binding.Which is why the Mutual Legal Assistance Treaty (MLAT) exists. MLAT enables law enforcement agencies in one company to send requests for information to law enforcement agencies in another. Switzerland has such a treaty with the US. This means that the FBI can request that Swiss authorities hand over a Swiss company's data on their behalf.Any country requesting information held by a company in a foreign jurisdiction would typically do so via MLAT. Which means from Proton's perspective, the legal request would appear to originate from their local law enforcement, not the FBI. Which they clearly understand based on their Reddit post.Saying "we don't respond to legal requests from anywhere other than Swiss authorities" seems very intentionally worded to give the impression that the company does not cooperate with foreign law enforcement. But since it'd be the Swiss authorities handling any such requests, they'd have to comply, since as they admitted, they have to comply with local laws.There is, however, some useful (but more nuanced) information here: Firstly, MLAT requests are handled by local law enforcement according to local law. So if there is a difference between the law of the sending and recipient country, that might mean the MLAT request is denied. That probably doesn't mean much, because if you're on the FBI's radar, the chances are you did something that is also massively illegal in Switzerland too.Secondly, they are 100% correct in saying that no other service provider is going to do any better. They're all beholden to local laws, and the ones that think they're not tend to get their doors blown off by SWAT like CyberBunker did. The only exception is if the company resides in a country which does not cooperate with US law enforcement (which Proton does not).But the part that's extremely disingenuous is that the "we only respond to requests from the Swiss authorities". That statement is likely intended to imply they don't cooperate with law enforcement in any other countries, which is simply not true. Switzerland has MLAT agreements with over 30 counties.People really need to understand that no company is going to shield you from the FBI (or any reputable law enforcement agency). They'll use misleading statements to make it sounds like they don't cooperate with law enforcement, but they do. They have to.
       
 (DIR) Post #B43tBHZ04pcGDPZ6w4 by RandamuMaki@mstdn.social
       0 likes, 0 repeats
       
       @malwaretech The MLAT request may originate from a country other than Switzerland, but it is still brought to Proton from the Swiss authorities in accordance to Swiss law, which makes it a legal request from Swiss authorities. Proton is not misleading in this.
       
 (DIR) Post #B43tICdQnd44xNwCu0 by can@haz.pink
       0 likes, 0 repeats
       
       @malwaretech the trick is to not have that data accessible in the first place. Like Mullvad back when they were forced to give out data.
       
 (DIR) Post #B43tPIeioRXNenvS08 by james@bne.social
       0 likes, 0 repeats
       
       @malwaretech Not sure that Proton’s 100% true statement - that they only respond to requests from the Swiss authorities - is “intentionally misleading”. As you have outlined, it is literally the truth.We’re all aware that international treaties exist. But, as you also outline, they are subject to domestic law. And that isn’t a given - breaking US tax law is unlikely to have any impact on Swiss authorities, who would likely deny requests for assistance before it ever reaches Proton. I don’t like Proton much as a company - they do too many things, for one. I don’t use them (any more). But I don’t think your attempt to deliberately stir up FUD about them is warranted here.
       
 (DIR) Post #B43uBIIdRM9oS6TpkO by stinerman@mastodon.social
       0 likes, 0 repeats
       
       @malwaretech I think they should be more upfront about what they're selling. They sell security. They don't really sell anonymity. People think Proton is "I create an account and everything I do is anonymous." It isn't, Proton never said it was, but people make assumptions.But let's not pretend that any other similar service (Tuta, etc.) wouldn't do the same thing.
       
 (DIR) Post #B43uo2g5SI8vIPvTma by AT1ST@mstdn.ca
       0 likes, 0 repeats
       
       @malwaretech The thing that gets me is - is the company being requested by the MLAT allowed to challenge their local government on the legality of the request?Like how Apple famously refused to make a program to automatically decrypt their iPhones to federal, state, or municipal authorities to be able to decrypt a terrorist's phone, and as I recall, that actually went to court on that?Could Proton not do the same with the request made of them?
       
 (DIR) Post #B43uo2uGbZUA0OYnsu by malwaretech@infosec.exchange
       0 likes, 0 repeats
       
       @AT1ST No, Apple just outright refused and has enough money to tie most of the federal government lawyers up in court for the rest of their careers
       
 (DIR) Post #B43vUWtdUg3dBCWUam by Saupreiss@pfalz.social
       0 likes, 0 repeats
       
       @malwaretech Thing is that these requests must still comply with Swiss law and can be challenged in Swiss courts. Which IS more restrictive on these matters than US law.
       
 (DIR) Post #B43w3t1vC38JxfG3pg by DiogoConstantino@masto.pt
       0 likes, 0 repeats
       
       @malwaretech that's not misleading it's actual thruth. Italia the Switz authoroties that are collaborating with the foreign authorities under the MLAT.
       
 (DIR) Post #B43wKFIIBSjHe4iS80 by knowprose@mastodon.social
       0 likes, 0 repeats
       
       @malwaretech I don't see how dragging Proton through the mud helps privacy overall.The user paid for their email address with their credit card  then posted it as a group contact on facebook.On Facebook.Going at Proton means they might lose business. Them losing business is not in the interests of smart US citizens who don't plaster their email address on a Meta platform after they pay for it with a credit card. c'mon.The user holds the majority of responsibility in this case, imho.
       
 (DIR) Post #B43wyjRHWbJmioE4cC by james@bne.social
       0 likes, 0 repeats
       
       @malwaretech Oh, you’re someone who responds to feedback by giving personal insults. That’s a shame.
       
 (DIR) Post #B43zf6HhAzdte84ZFo by ben@mastodon.scot
       0 likes, 0 repeats
       
       @malwaretech Is Proton not moving to Sweden for this very reason?
       
 (DIR) Post #B440BSD7BtuOupMEcK by ohir@vivaldi.net
       0 likes, 0 repeats
       
       @malwaretech > It feels like Proton are being intentionally misleading in their statements [...] so are happy to spread half-truths.Yes, misleading sentence.  I can not even ascribe this to ignorance, as MLATs are mentioned below it.  It does not matter *who* is requesting the data on customer.  Across whole EU targeted business deals with *local* law enforcement presenting the warrant.  You do know no details. All you see is a valid warrant what data to hand over.  No crime-story on it.Then get back to the MLATs: in most there are "imminent threat" speed lanes, up to the point you have to act on law officer order, you can file a complaint later.  Likely a case here.> So if there is a difference between the law of the sending and recipient country, that might mean the MLAT request is denied.This seems very intentionally worded to give the impression that the company can decide. It can not. > misleading statements to make it sounds like they don't cooperate with law enforcementI have not been mislead.  Could be I have read their site before signig up.> customers aren't familiar with how legal process actually worksPS. Any data of non-citizen kept on US soil is handed on a whim of US authorities.  FISA warrant kicks-in only if a US citizen appears to the party.@protonprivacy
       
 (DIR) Post #B440fgTCjsHDpPIXs8 by AT1ST@mstdn.ca
       0 likes, 0 repeats
       
       @malwaretech So they're skirting the government request *entirely* on money and lack of compliance?I am not saying that ProtonMail has to *win* their case, but it does feel like ProtonMail is just folding right out of the gate.Like how it has been pointed out that a Filibuster where you have to keep debating an issue in the House or the Senate to block it became suddenly a "If you threaten to filibuster it, then I guess we don't bother testing that you *can* filibuster this law - it's just dead.".
       
 (DIR) Post #B443cx4Gs71oIc1a5Y by kalfeher@infosec.exchange
       0 likes, 0 repeats
       
       @malwaretech IMHO ppl should nearly always prefer services with a legal presence in the jurisdiction they reside in. I've made the same recommendation for domain ownership decisions. In particular the info supplied for nexus requirements.TLDR: There's no magic invisibility cloak, just risk reduction.https://kalfeher.com/secure-practices-for-domain-owners/#general-registration-recommendations
       
 (DIR) Post #B447K6ABEOJ0p33PE0 by stevenray@sfba.social
       0 likes, 0 repeats
       
       @malwaretech so… misleading statements, cooperated and no company will do better? I guess if you can roll your own for the services you’ve been paying them for, time to do it. That’s not me.
       
 (DIR) Post #B447RC0pskGszU49kO by blustoftimes@mastodon.scot
       0 likes, 0 repeats
       
       @malwaretech yeah I’m pretty much down with them.  Already using another vpn instead of theirs and looking into tuta mail.
       
 (DIR) Post #B44B7dUIQ6FAEDmAU4 by james@bne.social
       0 likes, 0 repeats
       
       @malwaretech Ah, and you then respond with even more. Champ, you need to learn how to interact with other human beings.
       
 (DIR) Post #B44BH93QQRJijjk2Vs by malwaretech@infosec.exchange
       0 likes, 0 repeats
       
       @james God, you're insufferable. Enjoy the block list.
       
 (DIR) Post #B44Jp5Cg33B6GylMUS by unCoopervised@mas.to
       0 likes, 0 repeats
       
       @malwaretech If you don’t like Proton, there’s always Google! I love how readily people criticize Proton even though it’s likely the best privacy ecosystem we have now. At the same time I wish they zero encrypted the meta data enough to make this a non-issue. More than one thing is true at the same time.
       
 (DIR) Post #B44RJG5epqXcP7ocZk by malwaretech@infosec.exchange
       0 likes, 0 repeats
       
       @unCoopervised ya'll fanboys are insufferable
       
 (DIR) Post #B44SMWtstMmRMYQraa by malwaretech@infosec.exchange
       0 likes, 0 repeats
       
       lol, this post really brought out all the insufferable fanboys. I'm not gonna pretend like I didn't know which of the 3 platforms I posted this on would have a bunch of people deeply personally offended by criticism of a corporation
       
 (DIR) Post #B44UR8zFQf58YKGk1A by chrislowles@mastodon.social
       0 likes, 0 repeats
       
       @malwaretech criticism of corporations is practically the only thing mastodon is substantively capable of now lol what
       
 (DIR) Post #B44Udn9ztJWGchKOcS by Namnatulco@sueden.social
       0 likes, 0 repeats
       
       @malwaretech Re: "massively illegal", I think the core argument proton and similar corporations make is that local law includes the local law checks and balances for law enforcement access. The underlying assumption  is that this is one of the main things out of whack in American law, ie that the FBI can get warrants for anything - I can't say whether this is really true, though. It definitely _feels_ that way.
       
 (DIR) Post #B44UrCVKyPM4zWhfkm by froztbyte@mastodon.social
       0 likes, 0 repeats
       
       @malwaretech yeah that’s their usual trick. I never cared about them when they first came about, but paying attention in the last 2~3y has made clear that they do this shit a lot, alongside openwashing and other misrepresentation(Iirc @zzt has put together a small gallery of their top hits, but I don’t have the thread handy rn)
       
 (DIR) Post #B44WJUC4tkBPuskKvo by ysegrim@furry.engineer
       0 likes, 0 repeats
       
       @malwaretech They are also leaving out the fact that they only had to hand out that data because they had decided earlier to store it - because someone decided that kind of data on their users is a monetizable asset, not toxic waste. Other email providers have a better separation of payment data and email accounts, and thus can't betray their customers to adversaries via hacks or MLAT.
       
 (DIR) Post #B44WSX05pevtEASBdY by tobinbaker@discuss.systems
       0 likes, 0 repeats
       
       @malwaretech also the screenshotted response reads like AI
       
 (DIR) Post #B44Yj388LHslPxDchM by troed@masto.sangberg.se
       0 likes, 0 repeats
       
       @malwaretech What do you suggest they should do?
       
 (DIR) Post #B44ZphhOWOvcvmRsXY by cwbussard@ioc.exchange
       0 likes, 0 repeats
       
       @malwaretech It's surprising to me how many people don't get this."[W]e do not respond to legal requests from anywhere other than the Swiss authorities." is misleading because it implies the existence -- and ever-so-brave denial -- of legal requests from the FBI made directly to Proton, when that **never** actually happens because all requests go through the MLAT. They're boasting about denying a class of requests that has zero members. While neglecting to mention that the class of requests that they obey constitutes 100% of requests.And this matters because it reflects poorly on Proton's honesty and candor. Users need clear information about what threats Proton's service protects against, and what threats it doesn't. If they aren't telling is the full truth in this matter, what else aren't they telling us?More fundamentally, it casts doubt on their motives, values, and principles. Companies that would go to the mat for their users, even in the face of existential risk, Lavabit-style, are vanishingly rare. Few people expect that of Proton. So what are they then? Is Proton a company that at least *wants* to go to that mat for their users, but backs down in the face of existential risk? Or is it a company that's indifferent and disinclined to go to the mat for their users anyway? Their disingenuity here suggests their motives are mercenary and their values insincere.On that topic, it would be interesting to know if Proton fought this subpoena before complying. Did they at least attempt the Swiss equivalent to a motion to quash? Or did they just roll over immediately?(Here Proton tells us "Swiss authorities determined that the legal threshold was met because...," but doesn't tell us the context. Was that determination made in the course of a proceeding objecting to the subpoena, or in the course of the standard MLAT processing procedure? Was anyone present to argue the position that the standard was not met? And specifically which "authorities" made this determination?)No, Proton isn't responsible for the Swiss MLAT regime. But they **are** responsible for telling the full, unvarnished truth about how they interact with that regime. And they did not.
       
 (DIR) Post #B44aFTMkQxuu0V4xDU by choomba@social.tchncs.de
       0 likes, 0 repeats
       
       @malwaretech I don't know about that. In your screenshot I can't find Proton at fault. They provide a detailed explanation below their tweet. If it were just the tweet, sure. That'd be slightly misleading. But there is a long explanation right below.I don't think it's the responsibility of a service provider to explain all possible scenarios regarding law enforcement to all customers. It's simply not an issue for >99% of their customer base. If you are an individual with higher opsec requirements it's your own responsibility to research how to remain anonymous. There are a lot of guides for that. Every one of them will tell you that digital payments are never anonymous.
       
 (DIR) Post #B44blpPs5QNncFX3Gi by troed@swecyb.com
       0 likes, 0 repeats
       
       @malwaretech Maybe the users of one of those three platforms are slightly more tech savvy and simply don't agree with your feelings?I've been a paying Proton user (Visionary) since nine years and I've never felt they're misleading me.Maybe you shouldn't react to that by considering those than don't agree with you as being fanboys, but rather knowledgeable.
       
 (DIR) Post #B44dQzTZgnjiduSK1o by iju@mastodon.social
       0 likes, 0 repeats
       
       @malwaretech Never used Proton, and the only exposure I've ever had to them are some unpaid-ads on Mastodon. With this context:>They know that most of their customers aren't familiar with how legal process actually works..It's very difficult to assume what the customers of an internationally working company know. Different mandatory curriculums at school, and all that.Tbs, if a privacy-promoting company accepts payment in cash, I'd recall why mobsters in films never ask for an IBANN.
       
 (DIR) Post #B44ebZKHM27cgCiRIO by malwaretech@infosec.exchange
       0 likes, 0 repeats
       
       @troed nah, it’s definitely not this one. My LinkedIn connections are actual domain expert not a bunch of “tech savvy” vpn fanboys
       
 (DIR) Post #B44em5a6HkBVc58HTc by malwaretech@infosec.exchange
       0 likes, 0 repeats
       
       @tobinbaker pretty sure it is
       
 (DIR) Post #B44gJvz2Zklbe8V6J6 by pewnack@aus.social
       0 likes, 0 repeats
       
       @malwaretechOCR #AltTextProton @ + Follow @proton.me You are mistaken, we do not respond to legal requests from anywhere other than the Swiss authorities. It is unlikely that one could build a business through ignoring the laws of the jurisdiction that it is in. The mail provider you're moving to included. Proten_Team - 6h ago First, let’s correct the headline: Proton did not provide information to the FBI. What happened is that the FBI submitted a Mutual Legal Assistance Treaty (MLAT) request, which was processed by the Swiss Federal Department of Justice and Police. Proton operates exclusively under Swiss law, and we only respond to legally binding orders from Swiss authorities, after all Swiss legal checks have been passed. This is an important distinction. Second, let's talk about what this case actually involved This wasn't a routine investigation. Swiss authorities determined that the legal threshold was met because a law enforcement officer was shot, and explosive devices were found during a protest in 2024. Switzerland has one of the strongest legal frameworks for privacy in the world, and its standard for granting international legal assistance is exceptionally huge. This case met that standard. Third, let's talk about what was actually disclosed No emails were handed over. No message content. No metadata about who the user communicated with. The only information Proton could provide was a payment identifier because the user Chose to pay with a credit card. Ths 1s information the user themselves provided to us through their choice of payment method. Proton aiso accepts cryptocurrency and cash payments, which would not have been linkable to an identity. As anything, this case demonstrates exactly what we've always said: Proton holds very Iittle user data by design. Even under the most serious legal circumstances, the only data that could be produced was a payment record. Our encryption means we simply cannot access email content even # ordered to We understand that stories like this can be alarming, and we take our users’ trust seriously. We will continue to fight for privacy and challenge any legal order we believe does not meet the strict requirements of Swiss law. But we also want to be transparent: no service Can Operate outside the law entirely, and Swiss law requires compliance with valid legal orders in serious criminal cases What we can promise is that the legal bar in Switzerland Is among the highest in the world, and our architecture ensures we have as little  data as possible to hand over. For users who want maximum anonymity: use Proton VPN or Tor, pay with cash or cryptocurrency, and Don't add 9 recovery email.
       
 (DIR) Post #B44hSBBM3FHX3Skvcu by troed@swecyb.com
       0 likes, 0 repeats
       
       @malwaretech Perhaps, although most of us have left LinkedIn now since leaving US owned social media is European self defense.
       
 (DIR) Post #B44jKKzft7F14ogIJE by davidbcohen@twit.social
       0 likes, 0 repeats
       
       @malwaretech That marketing works on a certain type of stan, convincing them that a corporate will stand up for their values. They are rubes. How dare they, given you have personal experience of the pressure exerted by a country’s law enforcement if they decide to come after you.
       
 (DIR) Post #B44lKaDrT2ZqDTYtMm by simon_brooke@mastodon.scot
       0 likes, 0 repeats
       
       @malwaretech US law is completely and totally irrelevant here.Proton are not in the US: they're in Switzerland.
       
 (DIR) Post #B44mAmwlP7GkjpSRcm by StrawDog@infosec.exchange
       0 likes, 0 repeats
       
       @malwaretech thanks for sharing your analysis! Super interesting.
       
 (DIR) Post #B44np1H7ePU0iLjCIC by botvolution@mastodon.sdf.org
       0 likes, 0 repeats
       
       @malwaretech " if you're on the FBI's radar, the chances are you did something that is also massively illegal in Switzerland "Or, you're someone who's upset Trump/Patel/Miller, maybe.(My point being not that everything the FBI do is in bad faith, but bad faith is certainly more likely under the current leadership)
       
 (DIR) Post #B44sYqzIdC2jwhVCnw by c0coChannel@infosec.exchange
       0 likes, 0 repeats
       
       @malwaretech I think a lot of the time the fanboyish responses are a self-defense mechanism. They're not necessarily trying to defend proton as much as they are trying to defend their own coping like:"If I can't trust proton? then who?" -> [The correct answer is "noone", which is unacceptable] -> "No, proton is fine! It's definitely ok!"
       
 (DIR) Post #B44sbR81ES5Sc4oQbo by dtwx@mastodon.social
       0 likes, 0 repeats
       
       @malwaretech I don't get why you felt the need to write this when the image you linked says exactly the same?Was it JUST to say you think "we only respond to requests from the Swiss authorities" is "extremely disingenuous"?I don't think it's disingenuous. I think it's clear and unequivocal.In fact, I think everything Proton "promises" is extremely clear. I think it has to be, or they'd get sued based on Swiss law, right?
       
 (DIR) Post #B44xUuX40gfFYGEbK4 by atraidez@infosec.exchange
       0 likes, 0 repeats
       
       @malwaretech Its just a plethora of, "I think that you need a drink from this well, actually..." in the comments.
       
 (DIR) Post #B45AfJWVFQx3MMGNLk by h0ru2@cyberplace.social
       0 likes, 0 repeats
       
       @malwaretech I have only read things "people wrote online about the incident" and nothing by Proton, because I don't use the VPN and don't plan to.Tbh, I don't really get what's outrageous about that post. This is the MO I heard from more than company."We don't cooperate with LE, but of course we have to respect the law."Their interpretation of cooperating is: "We give away customer data without a warrant or give LE direct access.", but the statement is made exactly because people confuse it.
       
 (DIR) Post #B45DBGEPDqcsKD9x2G by donw@mastodon.coffee
       0 likes, 0 repeats
       
       @malwaretech @acdha I think misleading is a bit strong. You can contend they should have elaborated on how easily outside countries can get Swiss LE to make requests for them, but they conclude strongly with the most important information: you cannot maintain anonymity if you’re using a credit card.That is a FAR more important message than trying to communicate an exact risk calculus on foreign subpoenas, which is inherently unpredictable.
       
 (DIR) Post #B45RgjT9xtCfL9xfvs by malwaretech@infosec.exchange
       0 likes, 0 repeats
       
       @c0coChannel I think you're probably right. I see similarly aggressive responses when talking about how VPNs don't protect you from surveillance. People seem to be uncomfortable with the idea that serious privacy is actually difficult and not just something you can buy
       
 (DIR) Post #B45WK1QBYMP27zYoDo by mkb@mastodon.social
       0 likes, 0 repeats
       
       @malwaretech This makes me realize I’ve been making an assumption that might not be true:In most European countries, local LE fulfilling an MLAT request either needs to obtain a local court order or the LE request does not have the force of law. Do you know whether that is true?Also, my understanding is US LE does not need a US warrant in order to make requests under MLAT.
       
 (DIR) Post #B46XmMj6EGsLQPRk2K by unCoopervised@mas.to
       0 likes, 0 repeats
       
       @malwaretech Perfect is the enemy of good.
       
 (DIR) Post #B477VPlhGMooHnsUBU by betaphish@infosec.exchange
       0 likes, 0 repeats
       
       @malwaretech so many bootlickers in here, just because proton focuses on ‘privacy’ doesn’t mean they should always be respected to this degree lol