Live data from Hacker News

Proton is taking its privacy-first apps to a nonprofit foundation model

arstechnica.com

11–20 of 82 posts

Re: Proton is taking its privacy-first apps to a nonprofit foundation model

#11

Reminder that Proton is not "private". They have all the keys, and willingly operate in a jurisdiction where they bend over backwards for ridiculous court orders. From their own transparency page: Number of legal orders: 6,378 Contested orders: 407 Orders complied with: 5,971 They did this to expose protestors and people who upset the powers that be, rarely real criminals. They could choose to operate in a country th…

From the same transparency report page, they refuse any requests from countries that are not Switzerland, and only provide information to Swiss authorities when necessary (I.E. valid international legal assistance, violations of Swiss law, etc). As well, emails and files are encrypted. And their VPN is a no-log VPN. Lastly, they can comply with an order and just give them nothing, because they don't have anything the…

Generally it goes like this:

1. Government entity (usually the US or EU country) pressures the host country's government

2. Host country's government makes a legal request to the company for info on this user.

3. Company adds logging for that specific user.

4. Logging is provided to all those interested.

5. Host country prosecutes (potentially extradites).

There's a public accounting of this happening for Proton and Mullvad too iirc.

Re: Proton is taking its privacy-first apps to a nonprofit foundation model

#12

Reminder that Proton is not "private". They have all the keys, and willingly operate in a jurisdiction where they bend over backwards for ridiculous court orders. From their own transparency page: Number of legal orders: 6,378 Contested orders: 407 Orders complied with: 5,971 They did this to expose protestors and people who upset the powers that be, rarely real criminals. They could choose to operate in a country th…

Yep. They fail Lavabit-style, but somewhat worse. They're selling security theater.

Re: Proton is taking its privacy-first apps to a nonprofit foundation model

#14

Earlier quoted context omitted.

From the same transparency report page, they refuse any requests from countries that are not Switzerland, and only provide information to Swiss authorities when necessary (I.E. valid international legal assistance, violations of Swiss law, etc). As well, emails and files are encrypted. And their VPN is a no-log VPN. Lastly, they can comply with an order and just give them nothing, because they don't have anything the…

Generally it goes like this: 1. Government entity (usually the US or EU country) pressures the host country's government 2. Host country's government makes a legal request to the company for info on this user. 3. Company adds logging for that specific user. 4. Logging is provided to all those interested. 5. Host country prosecutes (potentially extradites). There's a public accounting of this happening for Proton and…

You're making multiple conjectures to get to that conclusion, of which the only evidence presented is another company based in a different country than Proton.

It may be true, it may not be, but there needs to be more information or facts before we get to the original comments statement that Proton gives data to expose protestors to protect "the powers that be".

Re: Proton is taking its privacy-first apps to a nonprofit foundation model

#15

Reminder that Proton is not "private". They have all the keys, and willingly operate in a jurisdiction where they bend over backwards for ridiculous court orders. From their own transparency page: Number of legal orders: 6,378 Contested orders: 407 Orders complied with: 5,971 They did this to expose protestors and people who upset the powers that be, rarely real criminals. They could choose to operate in a country th…

I have been with Protonmail since 2014. And I feel that they are essentially now the same as any other company which makes loads of dollar - they give up their values.

Don’t get me wrong, I have multiple ‘Visionary Accounts’ but I have just no expectation of them protecting my data completely.

How do they get peoples passwords / keys? Easy. They just wait for you to log in and they swipe it then. It’s targeted.

They are a perfect example of why you cannot really trust any company selling ‘privacy’, like Apple, Mozilla and whoever else fakes it. Even TOR to a degree is a pile of pish because all the relays can be hosted on mostly American VPS companies… so although the rest of the world would struggle detecting who people are, five eyes are in an excellent position to be able to unmask. It’s intended for the Five Eyes spies to hide among - they need the randomers on there or it’s a useless tool for their global spies to use - I don’t think enough people actually realise that.

Re: Proton is taking its privacy-first apps to a nonprofit foundation model

#16

Earlier quoted context omitted.

Generally it goes like this: 1. Government entity (usually the US or EU country) pressures the host country's government 2. Host country's government makes a legal request to the company for info on this user. 3. Company adds logging for that specific user. 4. Logging is provided to all those interested. 5. Host country prosecutes (potentially extradites). There's a public accounting of this happening for Proton and…

You're making multiple conjectures to get to that conclusion, of which the only evidence presented is another company based in a different country than Proton. It may be true, it may not be, but there needs to be more information or facts before we get to the original comments statement that Proton gives data to expose protestors to protect "the powers that be".

I'm not making conjectures, these events happened.

That's the flow of how government legal requests work with no-log vpn services.

What do you think "Orders complied with" means then?

Here's an instance of Proton adding logging of an activist's IP Address and Device ID after a request from the French authorities:

https://techcrunch.com/2021/09/06/protonmail-logged-ip-addre...

> French police sent a request to Swiss police via Europol to force the company to obtain the IP address of one of its users.

It's right there in the police report.

Re: Proton is taking its privacy-first apps to a nonprofit foundation model

#17

Well this is only as strong as the makeup of the board! OpenAI has the same model. > Among other members of the Foundation's board is Sir Tim Berners-Lee, inventor of HTML, HTTP, and almost everything else about the web. Well that's good news!

That seems to be a board of ex-CERNers.

Re: Proton is taking its privacy-first apps to a nonprofit foundation model

#18
post #6
post #5

Earlier quoted context omitted.

You should back up your claim of "they have all the keys", because for things like email and file contents they claim they cannot decrypt them because they do not have those keys (which you have said they do). I believe it was stated on the page you copied those stats from https://proton.me/legal/transparency > As stated in our Privacy Policy, all emails, files and invites are encrypted and we have no means to decryp…

They're all encrypted by themselves and if you use your own gpg key they will replace it. They're all encrypted except when you pay more for dedicated smtp. They're all encrypted except when they give up logs they promised they didn't have. And so on.

Listen, if you don’t trust their ProtonDrive - GPG encrypt before uploading. If you don’t trust their email, GPG your message and paste it in or include as an attachment. There are a lot of ways to be able to use proton without trusting them… and if you are an activist of any sort, like just stop oil or cnd, then I am sure they will be doing all of that.

I am not an activist so I don’t need to jump through such loopholes.

I don’t despise proton as much as I despise most of Silicon Vally though. I just hope they fight every single court order, because there will be lots of good people being targeted. However, I reckon that is wishful thinking.

Re: Proton is taking its privacy-first apps to a nonprofit foundation model

#19
post #6

Earlier quoted context omitted.

They're all encrypted by themselves and if you use your own gpg key they will replace it. They're all encrypted except when you pay more for dedicated smtp. They're all encrypted except when they give up logs they promised they didn't have. And so on.

Listen, if you don’t trust their ProtonDrive - GPG encrypt before uploading. If you don’t trust their email, GPG your message and paste it in or include as an attachment. There are a lot of ways to be able to use proton without trusting them… and if you are an activist of any sort, like just stop oil or cnd, then I am sure they will be doing all of that. I am not an activist so I don’t need to jump through such looph…

Cryptomator is great for the ProtonDrive example: https://cryptomator.org/

Re: Proton is taking its privacy-first apps to a nonprofit foundation model

#20

Reminder that Proton is not "private". They have all the keys, and willingly operate in a jurisdiction where they bend over backwards for ridiculous court orders. From their own transparency page: Number of legal orders: 6,378 Contested orders: 407 Orders complied with: 5,971 They did this to expose protestors and people who upset the powers that be, rarely real criminals. They could choose to operate in a country th…

Yep. They fail Lavabit-style, but somewhat worse. They're selling security theater.

[deleted]
Post reply on HN