Live data from Hacker News

Climate activist arrested after ProtonMail provided his IP address

twitter.com

571–580 of 619 posts

Re: Climate activist arrested after ProtonMail provided his IP address

#571
post #412

Earlier quoted context omitted.

Protonmail will scan all messages sent from non-protonmail addresses (content and attachments) for viruses. So they do read your gmail as well.

That's an interesting point, but I'd contend there is a difference between scanning for known virus patterns vs. feeding your email into ML algorithms to do God knows what with.

If someone comes to Google, asking for the content of someone's email, is Google technically unable to provide that information for past emails?

Because I am aware of no reason to think that Google stores my gmail with zero access. I don't know for a fact that ProtonMail discards this information at the earliest opportunity nor do I know for a fact that they don't try to aggregate it to learn about you (or even people in general), but that is what I interpreted the pitch as.

But, look, of course if they get a subpoena they will have to start scanning your email if they are technically able to collect it. That's just a wiretap, and little would prevent the author and operator of the server software from doing whatever they want... and they're clear that if you aren't sending email between two compatible accounts that there is no E2EE.

We can talk about how they should have been clearer about the need to use Tor to avoid IP logging (even if they don't do it, someone between you and ProtonMail certainly could). That's a good idea. But they are actually very clear that E2EE with your email is not what you should expect in general. And I don't think they have much incentive to scan my email from unencrypted sources to do anything nefarious, but I don't think anyone has any ability to prove they do or don't at present.

Re: Climate activist arrested after ProtonMail provided his IP address

#573

Earlier quoted context omitted.

My ISP is subject to my local laws. Which are not good, in terms of my privacy. My VPN provider is not - but is obviously subject to their local laws. Which are almost certainly also not good for my privacy either. Spreading the threat across two different jurisdictions is without doubt "somehow better" than just using my ISP, at least in the case of protection against snooping by non serious crime law enforcement. (…

What threat model are you trying to protect from by using VPN, and why is HTTPS + DoH (DNS over HTTPS) not sufficient for that threat model ?

HTTPS still reveals the domain you're requesting, last I checked.

Re: Climate activist arrested after ProtonMail provided his IP address

#574
post #573

Earlier quoted context omitted.

What threat model are you trying to protect from by using VPN, and why is HTTPS + DoH (DNS over HTTPS) not sufficient for that threat model ?

HTTPS still reveals the domain you're requesting, last I checked.

The eSNI/ECH extensions fix that.

Re: Climate activist arrested after ProtonMail provided his IP address

#575

Earlier quoted context omitted.

I don’t understand what you’re attempting to achieve with this. You’re weirdly abstracting about something that doesn’t need to be. People want to be able to have a private email correspondence about, for instance, dildos, and then not have to be served dildo ads outside of that context.

> I don’t understand what you’re attempting to achieve with this. I was hoping to achieve a "yes" or "no", to at least one of the two questions. I don't know what GP thinks "scan" means when describing how a computer processes text, and was hoping that an analogy to a more natural concept would allow for that to be made clear. What's the actual action being taken that's the violation? It's clearly not simply being ab…

So if I tell a friend a secret, and they plaster it on my wallpaper, and then I have a different friend over for dinner, my different friend is the one violating my privacy?

Re: Climate activist arrested after ProtonMail provided his IP address

#576
post #323

Earlier quoted context omitted.

I didn't ever have proof, just a gut feeling, but I never really bought into Protonmail. I created an account but rarely used it and as far as I know has been deleted for a few years now.

What are you using now?

Fastmail with a custom domain. I was using Lavabit before that.

Re: Climate activist arrested after ProtonMail provided his IP address

#577

Earlier quoted context omitted.

I used to work for a now defunct Swiss company that had “Swiss quality, security and privacy” plastered all over the website and marketing materials. The number of actual Swiss people on the team could be counted on one hand, the rest of developers being from every European country out there, with the most represented ones being Ukraine and Romania. And from talking with my coworkers, the situation is the same across…

So, you are complaining that they had immigrants working for them? They are part of the EU free movement region, so that is hardly surprising. Immigrants on the payroll don't change whether or not a company is Swiss. Were they inside the country? Were also they subject to Swiss laws? Aren't these the things that would make a company Swiss? Even if the company was started by a person that isn't Swiss, I'm pretty sure…

I am not complaining about the company hiring immigrants and allowing remote work across the Europe. I just haven't seen anything inherently Swiss in it, anything different from any other European company I worked for, that would justify the "Swiss quality" marketing.

Re: Climate activist arrested after ProtonMail provided his IP address

#578
post #553

Earlier quoted context omitted.

That's sadly not how (cyber)security works. The USG persecutes and imprisons journalists for exposing its war crimes, anyways I'm going to download this Tor binary from them because it says 'totally legit' on the packaging and there's no "hard evidence" to the contrary...

Don’t those binaries come with signatures you can verify? People in the community would notice if building from source produced different signatures than the binaries provided directly by torproject

In practice the USG would not distribute malevolent binaries everywhere, but could target them to particular IP- and time-ranges.

Downloading Tor from a particular IP in Iran? We'll add a little something extra...

Or maybe you're a US citizen with a set of known IPs on a "watchlist".

Re: Climate activist arrested after ProtonMail provided his IP address

#579
post #398

Earlier quoted context omitted.

In other words, your information is safe from the police if the police doesn't want it, but the second they want it, they're getting it and Proton can't do anything about it. The "default" is only useful for hiding your past actions before the police took interest in you, but not for any action since it happened.

this is inaccurate, no one can't fetch the the body of emails.

I have a protonmail account. When I log in to the interface, I see the body of emails, without providing any key on the client (not that it'd help since the client is a generic browser running their website code). This implies the process exists to recover the body of my emails. Also, I type in the password in their web UI in cleartext - there's no other way to gain access - which means they also have access to my cleartext password and could be forced to disclose it to the third parties. So unless you provide some contrary evidence, your assertion is false.
Post reply on HN