Live data from Hacker News

Climate activist arrested after ProtonMail provided his IP address

twitter.com

221–230 of 619 posts

Re: Climate activist arrested after ProtonMail provided his IP address

#221
post #136

Earlier quoted context omitted.

Tor is open source. Point to the vulnerability you are claiming, or stop spreading FUD.

https://nusenu.medium.com/tracking-one-year-of-malicious-tor...

This wouldn't even have resulted in the catching of the person in question, due to the use of an Onion Service, your link referring to the guy downgrading HTTPS on bitcoin exchanges. Hacker News users have surprisingly little comprehension of just what Tor is, so much so that I made an account here just now. Lurkers, please read:

Tor is a powerful tool for increasing the privacy of its users, though it is worth noting that it prioritizes performance over privacy. Tor's threat model does not include global adversaries, particularly those who can access traffic metadata for large numbers of ISPs- though, hidden services do fare significantly better than your usual clearnet services, usually requiring DoS attacks to deanonymize their hosts, and protecting their users especially. But note that Tor is not a mix network- it does not provide mathematically provable anonymity against a global passive adversary, unlike systems such as Loopix. See from this paper describing Tor in 2004, and consider reading the whole thing for a better understanding of Tor: https://www.usenix.org/legacy/publications/library/proceedin...

Tor's Threat Model "A global passive adversary is the most commonly assumed threat when analyzing theoretical anonymity designs. But like all practical low-latency systems, Tor does not protect against such a strong adversary. Instead, we assume an adversary who can observe some fraction of network traffic; who can generate, modify, delete, or delay traffic; who can operate onion routers of his own; and who can compromise some fraction of the onion routers. In low-latency anonymity systems that use layered encryption, the adversary’s typical goal is to observe both the initiator and the responder. By observing both ends, passive attackers can confirm a suspicion that Alice is talking to Bob if the timing and volume patterns of the traffic on the connection are distinct enough; active attackers can induce timing signatures on the traffic to force distinct patterns. Rather than focusing on these traffic confirmation attacks, we aim to prevent traffic analysis attacks, where the adversary uses traffic patterns to learn which points in the network he should attack. Our adversary might try to link an initiator Alice with her communication partners, or try to build a profile of Alice’s behavior. He might mount passive attacks by observing the network edges and correlating traffic entering and leaving the network by relationships in packet timing, volume, or externally visible user-selected options. The adversary can also mount active attacks by compromising routers or keys; by replaying traffic; by selectively denying service to trustworthy routers to move users to compromised routers, or denying service to users to see if traffic elsewhere in the network stops; or by introducing patterns into traffic that can later be detected. The adversary might subvert the directory servers to give users differing views of network state. Additionally, he can try to decrease the network’s reliability by attacking nodes or by performing antisocial activities from reliable nodes and trying to get them taken down—making the network unreliable flushes users to other less anonymous systems, where they may be easier to attack."

Tor increases the costs to uncover your identity, especially so in the context of a hidden service, which the entity in question (Protonmail) actually does offer to users. Perfection is the enemy of the good- Tor is not built to deal with global adversaries unlike a mix network, but surely any increase in privacy is a good thing, no? You do not complain that your wrench does not serve the purpose of a hammer quite as well as a hammer might- you either put some more energy into it, or you buy a hammer.

Re: Climate activist arrested after ProtonMail provided his IP address

#222
post #50
post #37

Disclaimer: I have a ProtonMail account that I pay for. I have seen a ton of disturbing pieces about ProtonMail. Every time I've looked into them, they seem to be maliciously motivated and usually not true, or otherwise twisting of the truth. This has been a confusing thing for me because why is there a small subset of people so vehemently against them? In this case, I'm not surprised. They say quite clearly they can…

One of the first sentence on their website is "By default, we do not keep any IP logs". If as soon as police show up (Which is almost the only case that people would want their IP hidden) they give IP logs, it is clearly false advertising. The fact that only the anonymous feature is important to you will not change the fact that they do the opposite of what they advertise regarding IP logs

Not necessarily. It's possible that their statement is true that they don't keep IP logs, but the Swiss police showed up with a court order for the equivalent of a US wiretap or pen register, requiring them to begin logging the IP address for that account when it signed in.

I think trusting your security or privacy to website-based email is a bad idea. If the email is being displayed in your browser, then the authorities can coerce the company that owns the website to include JavaScript in that page that sends the plaintext content to them too -- or demand the website's TLS key and start intercepting the traffic that you see.

The only encryption-based security that you can reliably trust is encryption that happens locally on a device you control, and that doesn't involve a web page or website loaded from a 3rd party.

If you want privacy protection with real end-to-end encryption that the government can't get past trivially with court orders, use services where the decryption happens on devices that you own, such as WhatsApp or Signal or iMessage. If you must use email, do the encryption yourself on a hardened Linux distribution like Tails using PGP for email encryption; but this is much harder to set up than the above secure messengers.

I wouldn't say ProtonMail is a scam, but a trivial software change on their server-side would let the authorities see your email every time you do. If they can be compelled to make that change then the "encryption" you're paying for is worth nothing. The next time you sign in, a court-required modified version of their server software can capture your password, and then use whatever key derivation function gives them your encryption key.

This might not even require the company to actively participate. In the case of Snowden and LavaBit email, the US Government demanded LavaBit's TLS certificate so as to intercept the communications themselves at the ISP layer when LavaBit refused to comply with narrower court orders to provide information about his account.

What could police do with ProtonMail's TLS certificate and court authority to intercept and MITM traffic for your account? They can probably capture your password, use that to read all of your old email, and at minimum read your email as you read it. Even if decryption is happening in the browser somehow with JavaScript, that JavaScript is coming from the origin server that the government now controls by virtue of MITMing the traffic with the site's TLS cert, and so they can insert JavaScript that logs a plaintext copy of either the emails or the encryption key needed to decrypt them.

There is no security with web-based communications if the companies involved can be coerced with a court order. US based firms would be required to hand over their TLS cert if they weren't willing to help track someone, and at that point the government could do anything to your traffic.

The only secure encryption happens on your device with no browser involved.

By comparison, if you're using an iPhone, in theory the US Government could try to force Apple to modify WhatsApp/Signal on your phone, or force the App developers to do so. These companies would all fight tooth-and-nail in court against doing so. Plus, you can configure your iPhone to disable automatically updating apps, so once you have a working version of WhatsApp installed, unless Apple has some backdoor-ability to push an update of it to your phone anyway, you could turn off app update and be cautious & picky about when you choose to update WhatsApp or Signal. What I don't know how to do is verify the integrity of their binaries: to confirm that what you're getting is the same app distributed to everyone. Facebook would appeal to SCOTUS before allowing a government to install a backdoor into WhatsApp; so would Apple, based on their response to the government's request to unlock the San Bernadino shooter's phone.

All that being said, if the government's goal is simply to discover your identity, which was the case here, then Signal and WhatsApp won't help you. Their accounts are based on a phone number. If the govt has your phone number then unless it's a burner acquired with no name registration then they'll know who you are, and regardless will be able to find out approximately where you are, if you continue to use that phone number. They can triangulate where you are fairly rapidly with modern technology, and this is assuming that the cell company can't simply send a signal asking the phone for its GPS-based location; but even if the govt only knows your nearest cell towers, narrowing that down to a building is a matter of minutes once they're in the area.

If you need to communicate in a way that keeps your identity a secret then you're probably best off using a free email service over Tor from a machine running Tails Linux, accessed from various locations that provide public wifi.

Re: Climate activist arrested after ProtonMail provided his IP address

#223
post #136
post #58

Earlier quoted context omitted.

Tor is a State Dept/DARPA project, so at best a sidegrade from Proton if your concern is being surveilled by Western governments.

Tor is open source. Point to the vulnerability you are claiming, or stop spreading FUD.

"Open source" means literally nothing for the majority of Tor users that are downloading prebuilt binaries from US Government-funded www.torproject.org/download/

Re: Climate activist arrested after ProtonMail provided his IP address

#224

Cryptographers and developers need to step up their game... There needs to be a messaging service where as well as the messages being encrypted, the graph of who is talking to who and when must be encrypted. I'm imagining a system where your device forwards hundreds of messages for other people , hiding your own message flow. I perhaps send a few hundred messages per day, and even multiplying that by 1000, and the ty…

I'm interested. Currently spending ~$58/year with Protonmail including a custom domain.

Re: Climate activist arrested after ProtonMail provided his IP address

#225

What does Youth for Climate do that required arrest? I’m unfamiliar with them.

Same but it’s not out of the realm of possibility that they’re a Greenpeace-like organization that jeopardizes human life and property.

Or they’re just some college students spouting inconvenient truths ¯\_(ツ)_/¯

Re: Climate activist arrested after ProtonMail provided his IP address

#226

Earlier quoted context omitted.

"Also, our VPNs are useless"

_all_ VPNs are useless. They are the biggest security theater and a massive success of marketing. But really, it's completely bazaar to trust a VPN provider. They provide protection from your local network, but you they can do all the same things and more.

Yes. Yes! I’ve never understood how people argue that they are somehow better than an ISP by default.

Re: Climate activist arrested after ProtonMail provided his IP address

#227

Cryptographers and developers need to step up their game... There needs to be a messaging service where as well as the messages being encrypted, the graph of who is talking to who and when must be encrypted. I'm imagining a system where your device forwards hundreds of messages for other people , hiding your own message flow. I perhaps send a few hundred messages per day, and even multiplying that by 1000, and the ty…

Basically, you want to run a messaging service over an onion routing network (Tor, I2P), or even better, a mix network. You should check out Nym (https://nymtech.net/) and come back with what you think about it. It is very suitable to what you want, and Loopix is resistant to global adversaries. https://arxiv.org/abs/1703.00536 (Loopix's paper)

Re: Climate activist arrested after ProtonMail provided his IP address

#228
post #202
post #194

Earlier quoted context omitted.

It depends on jurisdiction. For example the UK has the infamous gag orders that are even harder to fight in court (successfully) than their US counterparts. Sure, ProtonMail and its current operators could opt to stop operating in such jurisdictions, but usually it's too late for that when you get the [secret] court order, because if you refuse the operators personally are quickly found in contempt of court (or whate…

Aren't they in Switzerland though? A UK gag order can only have teeth within the UK, right?

But if you ever want to do business in the UK or travel to/through the UK, or in/to/through any country that might have MLAT with the UK ... then you're highly incentivized to take them at least a bit seriously to avoid really (sorry, royally!) pissing them off.

Re: Climate activist arrested after ProtonMail provided his IP address

#229

"We won't store your IP, except when its sought by the government, which is the only reason you'd ever realistically pay for a service that doesn't store your IP." Brilliant!

Even if ProtonMail had not stored these data, it could have easily been, legally or not, collected from the ISP(s) providing Proton with their internet access.

Re: Climate activist arrested after ProtonMail provided his IP address

#230

Disclaimer: Paying Protonmail customer Their homepage says "By default, we do not keep any IP logs" In 2021, any soft language like this should be a red flag for anyone who is against surveillance. Maybe in 2018 it was good enough. But in 2021 it's not. Come on, Protonmail, you're supposed to be leading the way -- don't make me figure it out myself. Replace immediately with "By default we don't log IP, but may be req…

"Their homepage says..."

Is the parent suggesting that no one should bother to read the Terms and Privacy Policy, linked to from the homepage. https://protonmail.com/privacy-policy

Despite the parent's claim, the Privacy Policy says the company may log IP address. Temporarily. Irrespective of any request from local authorities regarding a specific user. IOW, they may log anyone's IP address temporarily regardless of whether the particular user is casuing trouble; they can log IP address for everyone. The policy says they log this data for the purposes of preventing fraud and abuse. The problem for privacy-conscious users is that if they log the data, then that entices authorities to try to successfully request it.

The policy, which imposes no obligations on the company BTW, reads as follows:

"IP Logging: By default, we do not keep permanent IP logs in relation with your use of the Services. However, IP logs may be kept temporarily to combat abuse and fraud, and your IP address may be retained permanently if you are engaged in activities that breach our terms and conditions (spamming, DDoS attacks against our infrastructure, brute force attacks, etc). The legal basis of this processing is our legitimate interest to protect our Services against nefarious activities."

There is nothing that says "By default we do not retain any logs". This clearly states they may be expected to retain IP logs. ("IP logs may be kept temporarily...")

But wait there's more.

"We will only disclose the limited user data we possess if we are instructed to do so by a fully binding request coming from the competent Swiss authorities (legal obligation)."

This clearly states the company may disclose the data they possess, e.g., IP logs collected to combat fraud and abuse, if in response to a request from competent local authorities.

Further down is a curious statement about decrypting messages.

"If a request is made for encrypted message content that we do not possess the ability to decrypt, the fully encrypted message content may be turned over."

Why include a statement such as this, specifically the part that says "that we do not possess the ability to decrypt". The company already specified it may disclose the data it possesses. This further statement suggests there could be some situation where they may have the ability to decrypt some messages. Besides their own communications with customers, why would they ever have encrypted messages that they can decrypt. They could state something like "If the request is made for encrypted communications addressed to us or sent by us, ...", but they do not. As such, their statement must include other messages, too.

Post reply on HN