Live data from Hacker News

Climate activist arrested after ProtonMail provided his IP address

twitter.com

591–600 of 619 posts

Re: Climate activist arrested after ProtonMail provided his IP address

#591
post #573

Earlier quoted context omitted.

HTTPS still reveals the domain you're requesting, last I checked.

The eSNI/ECH extensions fix that.

It can’t fix the problem that it reveals the ip address you’re connecting to though. Even if the sites you’re visiting are all on servers that virtual host heaps of other sites as well, it certainly narrows that haystack down to a handful of bits of hay with your bright shiny needle standing out in the middle.

Re: Climate activist arrested after ProtonMail provided his IP address

#592

Earlier quoted context omitted.

>A global passive adversary is the most commonly assumed threat when analyzing theoretical anonymity designs. But like all practical low-latency systems, Tor does not protect against such a strong adversary. Instead, we assume an adversary who can observe some fraction of network traffic; who can generate, modify, delete, or delay traffic; who can operate onion routers of his own; and who can compromise some fraction…

Sounds like a 51% attack on crypto blockchains.

Yes, but this doesn't require 51%, at least as users typically use Tor.

Re: Climate activist arrested after ProtonMail provided his IP address

#593

I’m aware that this is a very silly sounding question, but I’m very confused about what’s going on here. If the subject of this investigation had been using ProtonVPN to connect to ProtonMail, would this have (in a marginal way) protected their anonymity? If Proton Mail can be compelled to begin logging, surely the same must be said of Proton VPN right? It’s interesting how many “privacy focused” companies tout being…

I used to work for a now defunct Swiss company that had “Swiss quality, security and privacy” plastered all over the website and marketing materials. The number of actual Swiss people on the team could be counted on one hand, the rest of developers being from every European country out there, with the most represented ones being Ukraine and Romania. And from talking with my coworkers, the situation is the same across…

The comment (and what people expect of a "Swiss product") was about the local/nationak law environment which certainly always holds true (for better or worse). "Created by Swiss people" as a feature would be a rather meaningless in the modern world.

Re: Climate activist arrested after ProtonMail provided his IP address

#594

Earlier quoted context omitted.

3 days ago i did this very thing. when the oppressive govt banned internet, i had to talk to someone outside india and then i dictated them some text. reddit keeps ip logs for 100 days so i had a dormant account for over a year. i asked the guy to log in, type that message and post. that way the govt can demand from reddit that account ip but since the only ip available is from outside india, they cant do shit. i was…

You think nobody can tap phone records, when you called someone outside India? Oppressive government?

ah yes. unless they are actively listening in am i not safe enough as compared to DPI censorship and network analyzers mandated by the said oppressive government?

Re: Climate activist arrested after ProtonMail provided his IP address

#595

Also mentioned in another submitted tweet: https://nitter.eu/OnEstLaTech/status/1434575322465382404 Translation: "The company @ProtonMail delivered IPs of climate activists to the police, after which the activists were arrested and searched. ProtonMail claims on its website, however, that it does not store the IP addresses of its users." Source (in French): https://secoursrouge.org/france-suisse-securite-it-protonmai…

Avoid proton mail like the plague.

Re: Climate activist arrested after ProtonMail provided his IP address

#596
post #576

Earlier quoted context omitted.

What are you using now?

Fastmail with a custom domain. I was using Lavabit before that.

From fastmail privacy policy:

> Each time you connect to our service, we log your IP address, your client identifier (browser or mail client information) and your username.

I'm sorry dude, but that decision from switching to fastmail was not very productive to counteract the specific case mentioned on the OP.

If anything, it's even worse since fastmail apparently always logs your IP.

Moreover: > We process mail sent and received from your account to block spam and fraud. We receive information from third party services to assist us in identifying spam.

Looks like your emails aren't even encrypted. If any government body what's your email bodies, they'll have it. They even share it with 3rd parties for fraud detection. With protonmail and similar services, they'll just log your IP if they're asked to do so, which you can obfuscate using a decent enough VPN.

Re: Climate activist arrested after ProtonMail provided his IP address

#597
post #50

Earlier quoted context omitted.

One of the first sentence on their website is "By default, we do not keep any IP logs". If as soon as police show up (Which is almost the only case that people would want their IP hidden) they give IP logs, it is clearly false advertising. The fact that only the anonymous feature is important to you will not change the fact that they do the opposite of what they advertise regarding IP logs

Not necessarily. It's possible that their statement is true that they don't keep IP logs, but the Swiss police showed up with a court order for the equivalent of a US wiretap or pen register, requiring them to begin logging the IP address for that account when it signed in. I think trusting your security or privacy to website-based email is a bad idea. If the email is being displayed in your browser, then the authori…

So right, people just dont get the big picture.

If they were forced to log the IP address, they can be forced to log user password. This makes entire encrypted mailbox useless.

Re: Climate activist arrested after ProtonMail provided his IP address

#598

Earlier quoted context omitted.

doesn't the amount of available IPv6 mean you can get a new one every time?

Theoretically yes but if your ISP assigns your home a /64 you can use 2^64 different addresses to access the internet. This still doesn’t protect your privacy because your ISP knows what prefix they gave you and will likely provide that to the authorities if you broke the law while using that address. Just like they would even if you used NAT and ipv4 so I don’t get where the parent comment thinks that is protecting…

Plausible deniability. My NAT and DHCP leases can be shortened, and not logged. At best you know something came from my network, and I may have many users on my network. For nodes, VPN, etc...

IP's address Internet endpoints, not people using them, yet States, prosecutors, and law enforcement regularly try to create the illusion that an IP has anything to do with who uses something.

IPv6 makes that temptation worse. IPv4 forces you to realize IP's can be ambiguous. IPv6, through having more addresses than people on Earth, checks off the Institutional checkbox for "raw material to contribute to a UUID identity scheme". Just look at China's proposals for a more governable international Telecom network, and the intention to use device persistent addressing as a control mechanism becomes obvious.

Where IPv4 creates enough decentralization and localized namespace unscrambling to provide enough friction via statefulness to thwart these types of efforts, I'm not at all confident IPv6 will do the same. I believe it is just what the Doctor ordered for laying the foundation of coupling IP's and net addresses in the minds of the masses to personal identifiers.

Which is not by any stretch the way we want things to go.

Re: Climate activist arrested after ProtonMail provided his IP address

#599

Earlier quoted context omitted.

Theoretically yes but if your ISP assigns your home a /64 you can use 2^64 different addresses to access the internet. This still doesn’t protect your privacy because your ISP knows what prefix they gave you and will likely provide that to the authorities if you broke the law while using that address. Just like they would even if you used NAT and ipv4 so I don’t get where the parent comment thinks that is protecting…

Plausible deniability. My NAT and DHCP leases can be shortened, and not logged. At best you know something came from my network, and I may have many users on my network. For nodes, VPN, etc... IP's address Internet endpoints, not people using them, yet States, prosecutors, and law enforcement regularly try to create the illusion that an IP has anything to do with who uses something. IPv6 makes that temptation worse.…

If your location is assigned a /48 you can then set up over 65,000 subnets with 2^64 possible endpoints in each.

My iPhone spoofs the MAC address each time it connects to WiFi, so support for changing your /64 is not going to be a challenge even with consumer devices. Whether we lose this ability or not is another question (but they could easily make the same requirements of “hard device uuid” on IPv4 if they wanted. These are laws and regulations after all, not technical limitations).

If anything IPv6 gives you an even greater amount of plausible deniability because like you said you could be running a vpn with a billion different devices connecting to it.

IPv6 just means your laptop could have an internet routable IP associated with it. You can easily change to one of the billions upon billions of possible addresses that your assigned prefix will give you (just like you could have something like 10.0.0.0/8 with millions and millions of addresses behind your internet routable IPv4 address. Your ISP will turn you over all the same if the authorities ask who that address belongs to.

Re: Climate activist arrested after ProtonMail provided his IP address

#600

Earlier quoted context omitted.

> I don’t understand what you’re attempting to achieve with this. I was hoping to achieve a "yes" or "no", to at least one of the two questions. I don't know what GP thinks "scan" means when describing how a computer processes text, and was hoping that an analogy to a more natural concept would allow for that to be made clear. What's the actual action being taken that's the violation? It's clearly not simply being ab…

So if I tell a friend a secret, and they plaster it on my wallpaper, and then I have a different friend over for dinner, my different friend is the one violating my privacy?

In that case no-one has violated your privacy - your wallpaper is private, so friend A didn't, and you invited friend B over, so they definitely didn't.

I would entertain the idea that friend A is being a bit of a douchebag by painting stuff all over your house without you asking them to, but if you subscribe to that thought process you'd already be running an ad-blocker and this scenario wouldn't ever occur in the first place.

Post reply on HN