Live data from Hacker News

Someone claims to have hacked ProtonMail

pastebin.com

1–10 of 14 posts

Re: Someone claims to have hacked ProtonMail

#3
>We are offering it back to Protonmail for a small fee, if they decline then we will publish or sell user data to the world.

That doesn't make sense. Why are they posting this if they are hoping for some successful extortion? How would extortion even make sense in the first place? You can't return data.

Re: Someone claims to have hacked ProtonMail

#5
This stinks to high heaven IMO - they're threatening to release e-mails detailing "rampant pedophilia" among high-placed individuals? Sure, that's not odd at all. I guess that's there to leverage the pizzagate believers for extra publicity.

That said, there is a claim that should be verifiable - that Protonmail have not enable SRI and that this leaves users vulnerable. Does this claim hold up? I'll admit I'm not familiar enough with SRI to even say whether it does what the pastebin suggests it does. Them calling it "mandatory" seems like another manipulation, though - mandated by who?

Re: Someone claims to have hacked ProtonMail

#6

This stinks to high heaven IMO - they're threatening to release e-mails detailing "rampant pedophilia" among high-placed individuals? Sure, that's not odd at all. I guess that's there to leverage the pizzagate believers for extra publicity. That said, there is a claim that should be verifiable - that Protonmail have not enable SRI and that this leaves users vulnerable. Does this claim hold up? I'll admit I'm not fami…

that claim doesn't make sense. SRI protects your site against third-parties changing the files you include from them in your site. Here the claim seems to be that ProtonMail changed files to snoop on users using their website, SRI doesn't help against that.

Re: Someone claims to have hacked ProtonMail

#7
> Protonmail compromises their users data without their knowledge and charges each user a monthly subscription fee. Therefore we felt morally justified compromising Protonmail’s data without their knowledge and charging them a fee for it’s return.

> If they decline again we will [...] sell [all customer data] in bulk to the highest bidder on the darknet

Funny that their moral sense tells them to compromise Protonmail's data because it "charges each user a monthly subscription fee", but it ignores the fact that they might affect users' private information if they release it to the public. Even if they're not lying about the hacking, what's really bullshit is their belief that they're doing the right thing.

Post reply on HN