Live data from Hacker News

Proton Mail discloses user data leading to arrest in Spain

restoreprivacy.com

141–150 of 283 posts

Re: Proton Mail discloses user data leading to arrest in Spain

#141

Go try to create a ProtonMail account with Tor. It will ask you to confirm your account with a phone number. It skips this if you’re using a non-proxy IP. They want to know who you are, and it’s been this way for years. I think they’ve long been a honeypot.

This is not true - most of the time all you need to do is fill out the captcha. In some cases (when our systems detect something suspicious about your network), we would request an additional email address. Even in those cases, the email addresses are not tied to your account - we only save a cryptographic hash of your email. Due to the hash functions being one-way, we cannot derive your data back from the hash: https://proton.me/support/human-verification

While we did use phone verification in the past, this is not the case any longer. Phone numbers were stored in the same way as the email addresses, so, again, we have no way to derive them back from the hash.

Re: Proton Mail discloses user data leading to arrest in Spain

#142

> This individual is suspected of being a member of the Mossos d’Esquadra (Catalonia’s police force) and of using their internal knowledge to assist the Democratic Tsunami movement. ...and... > The requests were made under the guise of anti-terrorism laws, despite the primary activities of the Democratic Tsunami involving protests and roadblocks, which raises questions about the proportionality and justification of s…

Independence is a political goal. Terrorism is a means to achieve political goals. (Though I don't think it has a good track record of being successful at that.) It's not that unusual for people to combine the two and plan terrorist attacks against the state they want to be independent from. (In this case it appears the investigation concerns a suspected attack plot targeting the Spanish king.)

Re: Proton Mail discloses user data leading to arrest in Spain

#143
post #7

> Proton provided us with an explanation that inbox contents remain secure. Yup, until they receive a court order asking them to mitm an inbox, if they haven't already... This entire system of "receive email in clear text but store it encrypted at rest" is smokes and shadows, really.

This is actually not permitted by the Swiss law, so it's not going to happen.

Re: Proton Mail discloses user data leading to arrest in Spain

#145

Earlier quoted context omitted.

Some interesting facts about Proton Mail. It generates OpenPGP keys on their own servers, and if you want to use your own keys their instructions show users how to upload upload their entire OpenPGP secret keychain to Proton Mail. Not just encryption/signing subkeys, the master key also needs to be included. I've emailed them to ask that they fix this. I also created a post on their user voice thing about it. https:/…

Proton Mail also still doesn't detect WIKD keys on the other side despite reporting it over 5 years ago.

We do fetch keys from WKD, as announced almost 5 years ago: https://proton.me/blog/security-updates-2019 :)

Re: Proton Mail discloses user data leading to arrest in Spain

#146
post #68

Proton Mail is in the title because it's where they went first, but the actual identification (real name, phone number etc.) seems to come from Apple on request for info related to the address. In this case the email address was the lead, but I wonder what other info would be enough to get the phone provider to spill the beans. For instance would an IP address used at a specific time be uniquely identifying if it was…

Why are ProtonMail keeping this IP and email information in their logs?

Because of legal requirements?

Re: Proton Mail discloses user data leading to arrest in Spain

#147

Earlier quoted context omitted.

> In practice, nothing is ever secure, Well that's clearly not true.

Ever heard of thermorectal cryptanalysis? As long as your secure world is not fully isolated but has any interactions with the physical world at all (e.g a human being somewhere receiving and reading your message with his eyes), then it's only a matter of resources allocated to trace you. You can pile up layers of "hops" through uncooperative jurisdictions -- this certainly helps to raise the bar but doesn't give you…

That's technically and theoretically true but also largely practically irrelevant.

Consider a building or a server. You can absolutely make them secure. Sure, eventually, everything can be broken/bypassed/hacked/cracked whatever, but if there is no chance of that happening for the duration that the security has to persist, then it is secure.

Re: Proton Mail discloses user data leading to arrest in Spain

#148
post #6

Protonmail gave up the recovery address. Apple gave up the name, physical address, and phone number associated with it.

Yes it's a strangely skewed article focusing on proton, when: > Once he got it, he asked Apple for information about this second email address, and got its name, home address, and phone number. Afterwards, the Civil Guard also asked the telephone company responsible for the telephone number who was the owner of the line, which matches the name provided by Apple. Also, they say they have found that this person is regi…

It focuses on Proton because Proton is the link that purports to be secure. Nobody expects Apple or telcos to guard your identity.

Re: Proton Mail discloses user data leading to arrest in Spain

#149
post #145

Earlier quoted context omitted.

Proton Mail also still doesn't detect WIKD keys on the other side despite reporting it over 5 years ago.

We do fetch keys from WKD, as announced almost 5 years ago: https://proton.me/blog/security-updates-2019 :)

Actually, you have a bug that has been unfixed for 5 years now. I know because I submitted it. Still no action.

Here's my last message to Proton Mail support, request ID 822331. I was directly told no resources would be spent on fixing it:

> Well, it has been multiple years now so can you guys maybe prioritize this? How long do you want me to continue waiting on this issue? I can't count on PM users to send my mailserver E2EE mail when the mobile app doesn't support it.

Re: Proton Mail discloses user data leading to arrest in Spain

#150

Is there any real private email service? Honest question.

Email is not private, and can't be made so. Email is my preferred communications channel, but I treat it as I would a mailing list or comment forum; it's almost completely unlike whispering to someone in the middle of an empty field.
Post reply on HN