Live data from Hacker News

Proton Mail discloses user data leading to arrest in Spain

restoreprivacy.com

151–160 of 283 posts

Re: Proton Mail discloses user data leading to arrest in Spain

#151

Earlier quoted context omitted.

Yes it's a strangely skewed article focusing on proton, when: > Once he got it, he asked Apple for information about this second email address, and got its name, home address, and phone number. Afterwards, the Civil Guard also asked the telephone company responsible for the telephone number who was the owner of the line, which matches the name provided by Apple. Also, they say they have found that this person is regi…

It focuses on Proton because Proton is the link that purports to be secure. Nobody expects Apple or telcos to guard your identity.

I can think of one country in the whole world (Iceland) where a company can tell the country it operates from, NO.

However in this case (an operating police officer who gave information to a group who wants to split away from the country) i make a bold assumption that even Iceland would order the company to give the data out (since it has nothing to do with protecting journalists/whistleblowers, but espionage)

Re: Proton Mail discloses user data leading to arrest in Spain

#152
Proton Mail gives info only when the Swiss law mandates it and Swiss law enforcement requires it. Swiss privacy laws are quite good.

That's the strictest privacy policy any company can hope.

Proton Mail can't give email content, only things like email address, ip adressese etc.

Re: Proton Mail discloses user data leading to arrest in Spain

#153

The heart of the issue is this: > Under Swiss law, Proton Mail was compelled to collect and provide information on the individual’s IP address to Swiss authorities, who then shared it with French police. They can claim all the privacy guarantees they want, but unless the privacy is guaranteed by cryptography, it's an empty gesture. Nobody is willing to do prison time to protect your privacy.

Proton Mail can't give email content, only things like email address, ip adressese etc.

Email content is encrypted and Proton Mail has no access

Re: Proton Mail discloses user data leading to arrest in Spain

#154

Earlier quoted context omitted.

Ever heard of thermorectal cryptanalysis? As long as your secure world is not fully isolated but has any interactions with the physical world at all (e.g a human being somewhere receiving and reading your message with his eyes), then it's only a matter of resources allocated to trace you. You can pile up layers of "hops" through uncooperative jurisdictions -- this certainly helps to raise the bar but doesn't give you…

That's technically and theoretically true but also largely practically irrelevant. Consider a building or a server. You can absolutely make them secure. Sure, eventually , everything can be broken/bypassed/hacked/cracked whatever, but if there is no chance of that happening for the duration that the security has to persist, then it is secure.

> Consider a building or a server. You can absolutely make them secure.

I'm not sure it's a good example. A server that you build from off-the-shelf components will likely come with the IME, providing direct tcp-to-ram access. Motherboard manufacturers probably add their own backdoors on top. We know about Gigabyte because they were caught red-handed, but how many we don't know about? How many rootkits in the SSD firmware? In hundreds of other firmware blobs installed on your Linux server right now?

I'm not even talking about Open Source backdoors which are hard as they have to be done in the open. Hardware/firmware backdoors are not in the open, they have been around for decades, they have been found and confirmed numerous times and god only know how many were NOT found.

Building a secure server nowadays is an extremely complex task, only solvable at the government level perhaps and only an a few select countries, if solvable at all. You need full control over the whole supply chain that includes tens or hundreds of thousands of corruptible employees.

Re: Proton Mail discloses user data leading to arrest in Spain

#155

Earlier quoted context omitted.

You state this distinction as if it's established, but it's not a definition I've personally heard explicitly stated before. If I read the introduction of the Wikipedia article on "privacy", I find the following: >The right not to be subjected to unsanctioned invasions of privacy by the government, corporations, or individuals is part of many countries' privacy laws, and in some cases, constitutions. So according to…

If there's a court order from due judicial process, isnt't it sanctioned invasion of privacy?

Sanctioned by the state, which the right to privacy should protect you from. The fact that your country habitually violates your rights doesn't change anything about the fact that you have a right to them.

Re: Proton Mail discloses user data leading to arrest in Spain

#156

Earlier quoted context omitted.

In this case an activist in the oppressive regime of...Spain?! Opsec is hard and most activists in western countries don't take it seriously. It's not like we live in PRC or DPRK right? Ironically, it is likely far harder for PRC or DPRK to get data from Proton than it is for Spanish police.

> It's not like we live in PRC or DPRK right? Right. Western governments are much, much better at mass covert surveillance. > it is likely far harder for PRC or DPRK to get data from Proton than it is for Spanish police You balk at the idea of a western government being oppressive while pointing out that our “secure” email services can be easily compromised by government action.

[deleted]

Re: Proton Mail discloses user data leading to arrest in Spain

#157
There are some serious anti-proton-vibes in this thread, so just my 2 cents as a paying customer: I'm rather happy with their service. I pay them money, they make sure that Joe in Marketing won't be able to harvest data from my emails. I'm also fairly optimistic that they take security serious enough that the blast radius of some dataleak is hopefully very limited.

I have zero delusions however that they can protect me from state agents, let alone state agents with malicious intent. And I don't think it's realistic to expect that for the amount of money they cost. But that's fine with me - it's Joe from Marketing I'm scared about, and so far they seem to do a good job keeping Joe at bay :)

Re: Proton Mail discloses user data leading to arrest in Spain

#159
It seems there is some mental conflict going in readers between the reality of what ProtonMail does for its customers and their expectations of what kinds of protections a legitimate business can provide.

Both ProtonMail and Apple will challenge subpoenas when they believe they are not valid, however neither company has the final say in the matter and can be compelled to provide access to data that they reasonably have access to. It is up to the user to plan what information they provide to service provides in order to not leave a trail of crumbs, and also evaluate what kind of man-in-the-middle weaknesses a service might have for the possibility of wiretapping. It should go without saying that linking a phone number or back-up email address can be a pretty large crumb.

The learning here is to recognise that these services can be compelled to provide whatever small information that they have reasonable access to, and that this information may be useful in unmasking an identity.

I suppose the second learning is to elect governments which respect democratic freedoms, even if that puts them on the back foot.

Re: Proton Mail discloses user data leading to arrest in Spain

#160

Earlier quoted context omitted.

Privacy is also meant to protect you from the state, or more specifically state abuse. It's an essential aspect of privacy. Like privacy is also meant to e.g. not disclose topics you have communicated about so that it can't be abused against you. For example there is a long history of states persecuting people for idk. being gay, believing in a certain religion or being a journalist which was involved in a unpleasant…

> Mainly privacy of communication doesn't always imply anonymity, through sometimes does (and has too!). Anonymity is simply people not knowing who you are, not necessarily what you say. It's not privacy of communication, but privacy of identity. I can post on the internet as Anonymous Coward, and those posts are public even though my identity is private. I can encrypt an email and send it, and it will be picked up b…

yes but also sometimes just knowing a persons identity can infringe on their privacy

I would say anonymity is an aspect of privacy, one you sometimes but not always need.

e.g. I would say leaking who was present at a anonymous self help group isn't just breaking anonymity but also infringing on privacy

Post reply on HN