Live data from Hacker News

ProtonMail deletes 'we don't log your IP' from website after activist arrested

theregister.com

141–150 of 352 posts

Re: ProtonMail deletes 'we don't log your IP' from website after activist arrested

#141
post #60
post #22

The ProtonMail guys always said that unless they were 20 miles from the littoral, in the sea side, they had to abide by national laws. So it was bound to happen. What makes me sad is how flimsy their entire premise (not necessarily "promise") turned out to be: all it took was some minor rascal in France to hug the wrong tree (so to speak), and ProtonMail is in the open saying they can't even protect the IP address of…

>I think there is a market for datacenters in open seas. The idea of having a isolated sovereign floating platform in the ocean doesn't doesn't really solve the problem of escaping the rules of national governments because it still needs network connections into those countries . Whether it's underseas fiber optic cables or bouncing signals off of satellites, the datacenter will be rendered useless if nations' citize…

>Whether it's underseas fiber optic cables or bouncing signals off of satellites, the datacenter will be rendered useless if nations' citizens get a "This site can’t be reached. [...] ERR_CONNECTION_TIMED_OUT"

Not if Elon succeeds with Starlink:

>>@thesheetztweetz: How does transmitting into a country without a local downlink work on the regulatory side?

>@elonmusk: They can shake their fist at the sky [0]

For context, certain countries like India have quite strict regulation of satellite comms, requiring special permission[1] even to use plain consumer tech like Iridium. I presume EU would also try to tightly regulate consumer satellite comms, just like it requires real (government issued) ID to use cell phones - specifically to register locally purchased SIM cards, again for national security reasons.

[0] https://twitter.com/elonmusk/status/1433123220643717120

[1] https://www.osac.gov/Content/Report/9db45731-1eec-477a-a7af-... >There are multiple instances of authorities confiscating undeclared satellite phones from foreign travelers upon arrival in India. The official notice states: "All foreigners travelling to India are hereby informed that it is illegal to use/carry Thuraya or other such satellite phones in India. Custom authorities in India may seize such phones and legal action may be taken against the passenger concerned."

Re: ProtonMail deletes 'we don't log your IP' from website after activist arrested

#142
post #90

Earlier quoted context omitted.

> I think there is a market for datacenters in open seas. Sealand's HavenCo tried it back in the 2000s. As it turned out, it didn't work well. https://en.wikipedia.org/wiki/HavenCo See: Death of a data haven: cypherpunks, WikiLeaks, and the world’s smallest nation https://arstechnica.com/tech-policy/2012/03/sealand-and-have...

I find Sealand fascinating. Imagine founding an off-grid location as a data haven, and it got popular. What would happen? I can see covert operations from foreign governments happening for example, driven by copyright lobbyists. Would they then need to hire security forces or train their own armed forces? Would it eventually join global political organizations to influence and protect its position? It gets really int…

Another major challenge is communication. Even when you have a data haven, how do you plug into the Internet backbone? How do you get Tbps bandwidth to serve the world? The Cypherpunks did some related research in the 90s, nearly all communication lines are controlled by the major ISP or the state, and they are extremely expensive to build.

> The dot-com crash not only cut the bottom out from colocation pricing, but also took out HavenCo's fiber-optic link when the company providing it went bankrupt. That left the entire operation with a pokey 128 Kbps satellite link, which staggered badly under denial-of-service attacks.

In Neal Stephenson's novel Cryptonomicon, the data haven is a main theme in its plot.

Re: ProtonMail deletes 'we don't log your IP' from website after activist arrested

#143

Earlier quoted context omitted.

Let us suppose for a moment that you could put a ship out in the sea, using solar panels and wind power, and satellites, you could provide a service. It might not be a service that’s always available, or all that fast, but it is technically feasible.

A ship is way too easily intercepted by any country with a navy. And your flag bearing country probably won't care, if you even have one. You need to go to space!

But it is technically feasible! I hear your point, but even in space, you are not safe.

https://en.m.wikipedia.org/wiki/2007_Chinese_anti-satellite_...

Re: ProtonMail deletes 'we don't log your IP' from website after activist arrested

#144
post #34

Be careful when companies market themselves as Swiss or that due to them being located in Switzerland means there is some extra layer of security or privacy. Sure, it's a more stable country than many other countries in the world, but not much different from most EU countries for example. And privacy wise there is no difference. Be also aware of the fact that many companies market themselves as Swiss, but all it mean…

> Their servers are based in Texas, USA and Luxemburg, Europe and their development team in Bulgaria

I don't believe it means anything. They form a company in Switzerland, which makes them compliant to the Swiss laws, they rent infrastructure from a provider where these services are most favourable for their business(which in this case could be USA and Luxembourg) and they do their tech dev work in Bulgaria(Which is in EU) because they get the most bang for their buck in this country.

What I see is simply business as usual. Are there even single origin tech companies? Even if everything is Swiss, if you have your app on the Apple App Stor or Google Play, you would be required to comply with US laws. You came up with an interesting encryption? Well, you will be asked to document it as part of you export compliance if you are going to make the app available outside of the US.

Re: ProtonMail deletes 'we don't log your IP' from website after activist arrested

#146

Earlier quoted context omitted.

The premise of "we'll never log your IPs" is something that no company can hold. - Local law enforcement can force the to do so. - Locals laws can change. - Guys with guns might barge in and demand it. Mostly, you can understand that they don't _intend_ to log IPs, and aren't in the business of collecting and redistributing data. But that doesn't mean you can count on absolute and unconditional secrecy.

Add to your list: - engineer troubleshooting might do so temporarily.

Including accidentally - `log(locals())` or `log(user)` or similar.

Re: ProtonMail deletes 'we don't log your IP' from website after activist arrested

#147
post #34

Be careful when companies market themselves as Swiss or that due to them being located in Switzerland means there is some extra layer of security or privacy. Sure, it's a more stable country than many other countries in the world, but not much different from most EU countries for example. And privacy wise there is no difference. Be also aware of the fact that many companies market themselves as Swiss, but all it mean…

The funny thing is, while advertising all of that, they're not providing free SMTP service that actually allow you to send properly GPG encrypted emails to protect your privacy.

So for me, ProtonMail is basically a web email service, a nice web email service to be completely fair, but without perks. I will never call them an "encrypted email" service.

Re: ProtonMail deletes 'we don't log your IP' from website after activist arrested

#148
post #22

The ProtonMail guys always said that unless they were 20 miles from the littoral, in the sea side, they had to abide by national laws. So it was bound to happen. What makes me sad is how flimsy their entire premise (not necessarily "promise") turned out to be: all it took was some minor rascal in France to hug the wrong tree (so to speak), and ProtonMail is in the open saying they can't even protect the IP address of…

The premise of "we'll never log your IPs" is something that no company can hold. - Local law enforcement can force the to do so. - Locals laws can change. - Guys with guns might barge in and demand it. Mostly, you can understand that they don't _intend_ to log IPs, and aren't in the business of collecting and redistributing data. But that doesn't mean you can count on absolute and unconditional secrecy.

Indymedia UK didn't log the IPs of website visitors. They used an Apache module that stripped IPs from Apache log messages. I know this, because I had root on the server.

Indymedia was widely infiltrated, I think; certainly there were some infiltrators, and they often trolled that Indymedia loggeed IP addresses.

There was a tool we could use to capture addresses; they were captured to memory only, and the tool could only be switched on for a limited time; it usually got switched on for less than an hour - long enough to find and block the addresses of particularly egregious spammers and trolls.

An SMTP server could be run without address logging; but a commercial SMTP server would be damned hard to administer without IP addresses in the logs.

[Edit] Indymedia had two servers seized in the UK; one was the property of Bristol Indymedia, and didn't run Apache. The other was run by Indy UK, and didn't log addresses. There was therefore no fallout from the seizure, except that the cops hung onto it for about 5 years. When we finally got it back, we retired it - we couldn't trust it, and it was by then obsolete kit anyway.

Post reply on HN