Earlier quoted context omitted.
> Snake oil companies will always hide behind "it's encrypted" and "it's hosted in Switzerland" tropes that mean nothing to anyone who has done a modicum of research. Do you have evidence that Proton does not actually encrypt their emails? > Real privacy is not the result of some product, I do wholeheartedly agree with this, at least. Privacy is a scale and there are many, many pieces which tip the scale one way or t…
> Do you have evidence that Proton does not actually encrypt their emails? Their encryption is based on PGP and therefore only message contents are "E2E" encrypted. Subject, From, To, etc. are not. These fields contain most of the information already. For example, Amazon puts the name of the ordered item in the subject line, so they can still see what you ordered. And I'm putting "E2E" in quotes because if the sender…
I never claimed they were.
>These fields contain most of the information already
Except, you know, the body of the email.
>Amazon puts the name of the ordered item in the subject line, so they can still see what you ordered.
Yes, Proton is not a panacea. Again, never claimed it was. You can't just abandon all opsec because you use Proton, I agree.
>Long story short: you still have to trust your email provider after all. If I'd want to switch away from Google, I'd probably switch to some "normal" email provider (Fastmail, Apple, etc.). The benefits of "E2E" encryption for email are questionable and the drawbacks huge (for example search is very limited).
I agree with the point about trust. You have to trust your hardware wasn't backdoored on the way out of the factory, too. Security and privacy are about trade-offs and weighing risks. I've weighed my risks and made my choices.