Live data from Hacker News

Proton Mail suspended journalist accounts at request of cybersecurity agency

theintercept.com

101–110 of 217 posts

Re: Proton Mail suspended journalist accounts at request of cybersecurity agency

#101

Earlier quoted context omitted.

I've been on Zoho for my (and my partner's) email for 4+ years and it has been great. Chose them because there is no per-domain charge, so I have like 12 domains on it. The configurability is extensive in both web app and ios email app. Service has been fast and stable. They rarely change anything in the UI (no random tinkering is what I mean) so it is predictable and easy to use.

what are the charges?

Entry level is $12/year. Bring your own domain.

Re: Proton Mail suspended journalist accounts at request of cybersecurity agency

#102

The silence of proton can only be interpreted to their disadvantage. This is not very smart and will make everyone doubt on them. While I like the idea of a safe and uncompromising service, proton seems less so now.

Ladar Levison and Lavabit certainly earned themselves credibility there a dozen years or so back.

Sadly https://lavabit.com/ currently just says "We are not accepting new users at this time. Mail services remain online, while we work on improving our website code. "

Re: Proton Mail suspended journalist accounts at request of cybersecurity agency

#103
post #48

Earlier quoted context omitted.

Proton seems to have a lot of cheerleaders that come out of the woodwork when anyone complains. I'm happy that somehow their code is magically bug free for you, since you've somehow never encountered any bugs whatsoever in their code (despite their release notes mentioning literal bugs they've fixed). I'm glad it works for you, but their offering is frequently buggy and broken for me.

It'd be useful if you pointed out bugs instead of just implying that anyone who doesn't share your experience is some sort of shill

The person I was responding to literally said they were "a paying user for a very long time" and "never encountered a bug". No software is bug free. I can't think of a single software service I've used for as long as Proton (7 years now) where I haven't encountered a single issue over that time. I take their statement to be so incredibly unlikely as to be facetious or intentionally duplicitous.

So I responded in kind, because I've definitely seen company cheerleaders, and I'll have no part of it. I'm glad you all are happy with Proton. I'm not telling you to leave.

And if you really want to see complaints, you don't have to look far. Read the other comments on this thread. I don't have to spell everything out for you.

Re: Proton Mail suspended journalist accounts at request of cybersecurity agency

#104
post #91

Earlier quoted context omitted.

Common folklore is that this is extremely onerous to self-host (and have it work successfully.) How did you go about it?

The common folklore is just FUD. The main issue is deliverability to the likes of Google, Microsoft, Yahoo, etc. You need a clean fixed IP in non-residential block and a sufficiently aged domain or your mail will be flagged as spam or rejected. Alternatively, you can use a relay service for outbound email. Besides the deliverability issue, hosting email is fairly trivial from a technical standpoint; on Linux, the sta…

> You need a clean fixed IP in non-residential block

Feels like that's carrying a lot of load there?

Where do you get those? I doubt any inexpensive VPS provider has any clean IP addresses? AWS charge you $5/month for an elastic IP address, and I bet you'd need to cycle through their pool of those looking for one that hasn't been blacklisted recently?

There's another thing to consider here too. I was selfhosting my own mail, but back in 2013/14 I investigated all my mail, and even though I'd avoided Google/Microsoft,Yahoo et al. - over 80% of my personal email was on their servers because that's where my correspondents were. I pretty much gave up maintaining my own (slightly over complicated) stuff and gave in and chose to accept the "Do no evil" company at face value. 4 or 5 years later that company no longer existed, even though they continue with the same name today.

Re: Proton Mail suspended journalist accounts at request of cybersecurity agency

#105

proton always glowed but just straight up bending to unnamed agencies puts em rank and file with every single other provider

Is refusal realistic? It's nice in the abstract, but in practice, there are plenty of ways to coerce illegitimate compliance.

No company is gonna seriously refuse when their jurisdiction's equivalent of the FBI or NSA turn up with a court authorised order. As James Mikkens said: "YOU'RE STILL GONNA BE MOSSAD’ED UPON"

But it'd be nice to be able to expect your email provider to not cave in to a request from some other counties CERT organisation without pushing back for evidence and some sort of proper judicial authority behind the request.

Re: Proton Mail suspended journalist accounts at request of cybersecurity agency

#106

It's because the journalists were covering the professor-student rape scandal at UIUC Champaign that was covered up by Champaign and other governing bodies.

Citation required?

That's not what Phrak says here: https://phrack.org/issues/72/7_md

Where they say "Proton was used only for email and only to communicate with South Korea"

Re: Proton Mail suspended journalist accounts at request of cybersecurity agency

#107
post #78
post #68

Earlier quoted context omitted.

Proton does not require a shred of proof that you are a real human being either, fyi. I'm not actually attacking them for this specifically, because I feel that we need privacy focused tools, however the fact that I was able to create a few hundred proton email addresses in seconds by injecting usernames/passwords was scary, even to me. I'm surprised they aren't on spam block lists worldwide. Their captcha is child's…

Their controls are buffed up: all of those accounts are linked due to having been created with the same IP address. If one is blocked, they all are. If you try to circumvent this with a well-known proxy (such as Tor or a V"P""N") you will find that captcha activation will not exist as an option.

That definitely doesn't look good for privacy POV. If they do not want abuse, they ought to use other means. They should not associate IPs with account creation. That is kind of scary. In fact, if what you have said is true, then one's account can be blocked by someone else's mischief on the same IP, which is not very uncommon at all i.e sharing the IP.

Re: Proton Mail suspended journalist accounts at request of cybersecurity agency

#108

Proton dropped from the top spot on my list of “user-first email platforms” when they announced they’ll be deleting accounts that haven’t logged into their service in some arbitrary amount of time. If I can’t rely on my email / messaging / phone / communications provider to keep an open line for as long as I need it – whether that’s one year or two years or twenty years, then I’m not going to use it. And if they requ…

> deleting accounts that haven’t logged into their service in some arbitrary amount of time

One year, to be exact: https://proton.me/support/inactive-accounts

Re: Proton Mail suspended journalist accounts at request of cybersecurity agency

#109
post #35

Earlier quoted context omitted.

You are trusting them. They control the client, how the keys are created/stored, etc. Javascript, etc. If they were to suddenly turn one day, they could. This is the weakness of cloud services.

It is very possible for them to inject custom JS to a specific user. You are the bosses at Protonmail, do you want police at 6 am shaking your kids, seize all your devices, loose all agreements with PayPal and Visa/MasterCard, because you want to protect a guy who distributes child pornography or plans a terrorist attack ? No way, so you tap on the shoulder of the CTO and ask him to push a temporary update or turn on…

From what we (at least I) know, this wasn't the police in Switzerland waking up senior management.

t was - without anyone admitting to it - probably KrCERT who requested the account suspension. KrCERT don't seem to have any legal jurisdiction in Switzerland.

"KrCERT/CC, which is an internal division of KISA, is a CSIRT with national responsibility and a focal point of contact for Korea on international cybersecurity incident handling." -- https://en.wikipedia.org/wiki/Korea_Internet_%26_Security_Ag...

I'd like to think if they 'tapped on the shoulder of the CTO ' of a company headquartered in Switzerland, he'd say "maybe, come back with an order from a relevant court or security agency in Switzerland and I'll get my team right on that".

Re: Proton Mail suspended journalist accounts at request of cybersecurity agency

#110
post #17

I've been following this on X/Twitter and I think one of the most egregious things that's important to point out is that folks from Phrack reached out to Proton in private multiple times, and Proton ghosted them. Proton only engaged with them and then reinstated the accounts after Phrack went public and their X/Twitter post went viral. It also looks like one of the writers filed an appeal with Proton and Proton denie…

> Phrack reached out to Proton in private multiple times, and Proton ghosted them. According to Proton's response in the linked reddit post: https://news.ycombinator.com/item?id=45227356 They say: "Regarding Phrack’s claim on contacting our legal team 8 times: this is not true. We have only received two emails to our legal team inbox, last one on Sep 6 with a 48-hour deadline. This is unrealistic for a company the si…

> a 48-hour deadline. This is unrealistic for a company the size of Proton

and yet suspending the account...

Post reply on HN