Disclaimer: Paying Protonmail customer Their homepage says "By default, we do not keep any IP logs" In 2021, any soft language like this should be a red flag for anyone who is against surveillance. Maybe in 2018 it was good enough. But in 2021 it's not. Come on, Protonmail, you're supposed to be leading the way -- don't make me figure it out myself. Replace immediately with "By default we don't log IP, but may be req…
I was COO of a vpn company for several years. It’s almost impossible not to keep any ip info. We had issues with fraud and one of the best ways to prevent or limit it was to track IP address and save it for several months. I agree PM should be more forthright in their messaging but realistically I don’t believe any company that takes payments and doesn’t track any info at all.
Climate activist arrested after ProtonMail provided his IP address
471–480 of 619 posts
Re: Climate activist arrested after ProtonMail provided his IP address
#472ProtonMail went under fire several months back about opting to use Google's reCaptcha for login in a time crunch, rather than setting up hCaptcha even if it took a little extra time.
The tradeoff was cost vs. user privacy and they chose cost, which is NOT why a lot of us pay PM to begin with.
This is unacceptable, but unfortunately there are no alternatives that hit all the check marks PM has in terms of features.
The response of "use Tor to connect" doesn't really help. If you so much as accidentally connect once with a normal IP, that's enough to nab you.
Re: Climate activist arrested after ProtonMail provided his IP address
#473Earlier quoted context omitted.
Solid points. A report card for various privacy policies would be useful. Seen anything like that?
I wouldnt trust any of them to be honest. Privacy policies really arent worth anything. I would look for websites that generally do not ask for data. Then send them the minimum data you can get away with. I would avoid "signing in" or "signing up" to any website. There is an immense amount of data and information available from free from the web, no "account" is necessary. For example I dont send any extra HTTP heade…
Your observations are correct, the regulation is able to deal with the damage after it was done, and apply some form of punishment after the fact. It takes whistleblowers and activists to reveal some of the wrongdoings, otherwise the violations remain unknown to us.
Therefore there has to be a greater push towards proactive measures - letting people vote with their wallet by making informed choices; the prerequisite for that is for the relevant information to be available to them.
Have a look at some of the research I've been involved in, we're trying to solve this exact problem: http://privacy-facts.eu/
Re: Climate activist arrested after ProtonMail provided his IP address
#474Earlier quoted context omitted.
My ISP is subject to my local laws. Which are not good, in terms of my privacy. My VPN provider is not - but is obviously subject to their local laws. Which are almost certainly also not good for my privacy either. Spreading the threat across two different jurisdictions is without doubt "somehow better" than just using my ISP, at least in the case of protection against snooping by non serious crime law enforcement. (…
What threat model are you trying to protect from by using VPN, and why is HTTPS + DoH (DNS over HTTPS) not sufficient for that threat model ?
Re: Climate activist arrested after ProtonMail provided his IP address
#475Earlier quoted context omitted.
Put "By default we don't keep IP, but may be required to by local laws. We suggest you connect through Protonmail through Tor". I would much prefer this, as a Protonmail paying customer.
Tor helps, but is not especially robust against state-level actors / APTs. An actor running a sufficient number of entry/exit nodes could perform at least some traffic analysis. Tor is an improvement. It's still a limited tool.
Even if a nation state was targeting you, it would still take months for a timing/bandwidth attack to identify a user. Even then it would only provide your adversary a probability of certainty and requires consistent traffic from the victim through a compromised exit node.
No system is 100% perfect but tor will make most attacks prohibitively expensive.
Re: Climate activist arrested after ProtonMail provided his IP address
#476Earlier quoted context omitted.
Protonmail did not provide the authorities with the users IP address...they did allow the account to monitored which they are required by their laws to allow. It was the users sloppy OPSEC that allowed the authorities to eventually track them down. In the end, I believe, it was linking the user to a past Gmail account that finally did him in. Listen to this podcast episode, the presenter does a fairly good job summar…
> Protonmail did not provide the authorities with the users IP address...they did allow the account to monitored which they are required by their laws to allow. Something their marketing material appears to disclaim. This is just excuse-making. ProtonMail did what ProtonMail has (for years!) led their customers to believe they would not do. And they did. I think there's an argument to be made that any commercial emai…
My rule is to give any corporate statement about what they "will not do" exactly zero credence.
The only thing worth anything in that context is open source where independent programmers can verify that the code cannot support undesirable behaviors. And even then you're not safe, because code running on someone else's machine might actually be anything. So in the end, self-hosted open source software is the only way.
Right now that requires some degree of technical know-how, but I believe that's a solvable problem the same way operating systems have turned the technical practice of process management into something users don't even need to think about.
Re: Climate activist arrested after ProtonMail provided his IP address
#477Earlier quoted context omitted.
I wouldnt trust any of them to be honest. Privacy policies really arent worth anything. I would look for websites that generally do not ask for data. Then send them the minimum data you can get away with. I would avoid "signing in" or "signing up" to any website. There is an immense amount of data and information available from free from the web, no "account" is necessary. For example I dont send any extra HTTP heade…
Wow neat how do you browse the web, Lynx?
For reading HTML I prefer links. It has the best rendering of HTML tables, IMO, and is for me the easiest source code to work with. I did use lynx back in the late 90's but would never go back to it. Its bloated. Its slow. Im not sure why anyone interested in text-only browsers would use it other than they are unaware of or have not tried alternatives.
Re: Climate activist arrested after ProtonMail provided his IP address
#478Earlier quoted context omitted.
I once tried to create a Protonmail account over TOR and I believe they require a phone number from 'malicious' IPs so if you want anonymity Protonmail is not the service for you.
That is what a “2FA mule” is for. I have two - both on MVNOs, not in my name, and sitting in my office doing nothing but relaying sms to email: https://news.ycombinator.com/item?id=28251107
But the mule only gives you some extra functionality, resilience, and is like having an email address just for spam or a home VPN endpoint. It gives you very little in terms of anonimity, which is why you'd go to Tor anyway. It's still in your proximity even if it's not in your name so anyone able to obtain your IPs from the services you use would also be able to get the location of your mule. And you forward to your own mail server which again does little to hide anything. That's a long traceable chain that can be compromised or at least broken (to force you out) at every link.
This is great to make sure companies don't sell your phone number or use it to create some social graph, and to access your accounts independent of your normal phone. But if you're looking to hide your identity or location from your service provider and the authorities then it's barely a speedbump.
Re: Climate activist arrested after ProtonMail provided his IP address
#479Earlier quoted context omitted.
> Does anyone here have a feasible way to solve this? Current solutions like TOR, I2P, VPNs and/or mobile proxy services are just a matter of time and legality until they come obsolete due to their publicly known nature. I am convinced that the only way to solve this is by simply not downloading the website from its origin. The origin tracks you, so don't talk to them. Talk to your peers and receive a ledged copy of…
While you’re not technically wrong about IP address hiding, that wasn’t my question. I’m asking if there’s any feasible way for ProtonMail to not have the ability to know which IP addresses connect to their services.
Maybe ProtonMail could offer an alternative .onion service? This way they couldn't legally be forced to give a way the IPs, because on the other end it's a TOR exit node anyways. And by design they cannot see the real IP from their point of view, so a legal enforcement would be useless.
Re: Climate activist arrested after ProtonMail provided his IP address
#480Earlier quoted context omitted.
Too bad, figure out a way to solve for it. I'm paying for private email service, not a pretty picture of the Swiss Alps on their website. If they don't provide it, someone else will, and I'll pay them instead. This isn't the Hotmail age where everyone expects free email.
> This isn't the Hotmail age where everyone expects free email. It totally is. I was running my own mail server for a while. The thing that finally pushed me into not bothering any more was when I looked at my logs and realised 82% of my non-spam non-marketing email was captured by google (where at least one recipient was either @gmail.com or a gsuite custom domain).