The ProtonMail guys always said that unless they were 20 miles from the littoral, in the sea side, they had to abide by national laws. So it was bound to happen. What makes me sad is how flimsy their entire premise (not necessarily "promise") turned out to be: all it took was some minor rascal in France to hug the wrong tree (so to speak), and ProtonMail is in the open saying they can't even protect the IP address of…
And this was quite obvious for someone who actually looked into staying anonymous (or gave the Protonmail threat model page a deeper read).
> What makes me sad is how flimsy their entire premise (not necessarily "promise") turned out to be: all it took was some minor rascal in France to hug the wrong tree (so to speak), and ProtonMail is in the open saying they can't even protect the IP address of their customers.
That's a big simplification. It took quite a few authorities to wave through a very draconian request for (what appears to be) a minor crime. As Protonmail themselves pointed out, they never promised to protect the IPs and they could explicitly not promise that. In fact, they even stated very clearly that they could not. Expecting them to print that on the frontpage is quite unreasonable when their marketing has to compete with shady VPNs that promise the sky.
> From there, all it takes is for somebody to change a law in Switzerland and end-to-end encryption of the messages themselves will only be "by default."
While this is a reasonable threat, it's not like one could do this in an afternoon.