Live data from Hacker News

Proton Mail suspended journalist accounts at request of cybersecurity agency

theintercept.com

201–210 of 217 posts

Re: Proton Mail suspended journalist accounts at request of cybersecurity agency

#201

I've been following this on X/Twitter and I think one of the most egregious things that's important to point out is that folks from Phrack reached out to Proton in private multiple times, and Proton ghosted them. Proton only engaged with them and then reinstated the accounts after Phrack went public and their X/Twitter post went viral. It also looks like one of the writers filed an appeal with Proton and Proton denie…

I'll go out on a limb and say it: it's an American cybersecurity agency. Proton's CEO/Proton[1] loves the current US admin. I wouldn't be surprised if they comply now and ask questions later, if at all. 1. According to the now-deleted Reddit comment from the official Proton account glazing Republicans, so I assume they were speaking on behalf of all of Proton. https://theintercept.com/2025/01/28/proton-mail-andy-yen-…

Don't go out on a limb, RTFA. But then you wouldn't be able to have your cake and eat it too.

Re: Proton Mail suspended journalist accounts at request of cybersecurity agency

#202

Earlier quoted context omitted.

They could take government ID, or fingerprint your machine, make you submit a picture of your face, do these options seem better to you?

Nope. Zero-knowledge proofs seem to be the middle ground, IMO. Prove X without revealing X itself.

Nice. I can create 5000 different proofs that I am a human and the site can't tell they're all for the same human.

Re: Proton Mail suspended journalist accounts at request of cybersecurity agency

#203
post #18

I've need a paying subscriber to Proton since 2018, but I recently canceled my subscription (which ends in November). I just got fed up with the constant bugginess and jankiness of their offerings. Any suggestions for mail hosting and VPN? I hear good things about Fastmail and mailbox.org (I see they very recently rebranded to just mailbox and revamped their offering). Also, I've been a heavy user of the SimpleLogin…

My experience is the apps are missing very fundamental features. Which would be fine... If you could use other clients. But you can't, except for email, kind of. Like, the calendar on mobile doesnt even have a search function. What if I want to know when an event is happening? I just have to scroll and scroll until I find it? Come on now. Also no storage backup in proton drive??? What??? That's, like, 90% of the purp…

The lock in is absurdly restrictive in some ways too. For example, they don't support sieve based forwarding. I wanted to forward parcel tracking emails to shop app, but can't set up an automated way to do it

Re: Proton Mail suspended journalist accounts at request of cybersecurity agency

#204
post #91

Earlier quoted context omitted.

The common folklore is just FUD. The main issue is deliverability to the likes of Google, Microsoft, Yahoo, etc. You need a clean fixed IP in non-residential block and a sufficiently aged domain or your mail will be flagged as spam or rejected. Alternatively, you can use a relay service for outbound email. Besides the deliverability issue, hosting email is fairly trivial from a technical standpoint; on Linux, the sta…

> You need a clean fixed IP in non-residential block Feels like that's carrying a lot of load there? Where do you get those? I doubt any inexpensive VPS provider has any clean IP addresses? AWS charge you $5/month for an elastic IP address, and I bet you'd need to cycle through their pool of those looking for one that hasn't been blacklisted recently? There's another thing to consider here too. I was selfhosting my o…

I get my IP through work, but another way of obtaining one would be subscribing to a business account with a regular ISP. Normally, this also allows you to set a reverse DNS. You will likely have to pay more for your Internet, but considering that you won't have to pay for any cloud service anymore, you will probably still come out ahead and gain a huge amount of sovereignty over your computing. A VPS could be an option, but many (cheap ones) may have tainted IPs or outright filter the SMTP port.

Re: Proton Mail suspended journalist accounts at request of cybersecurity agency

#205
post #173

Earlier quoted context omitted.

Common folklore is that this is extremely onerous to self-host (and have it work successfully.) How did you go about it?

Also, how do you mask your identity if you self-host? I can have as many mailboxes as I want but they're all trivial to correlate because they share a domain that isn't providing email accounts to large amounts of users. And then there's the matter of a VPS not actually being under my control. It's a VM running in a datacenter. I could run the mail server locally, but then I'd still need to relay through a VPS to mas…

What do you mean by "masking your identity"? If you self-host at home, then your IP will be discoverable through DNS, but no one but the ISP will know who the account holder is. Registering a domain also normally requires providing a name and address, but no ID is normally required and it is an open secret that a large proportion of WHOIS information is fake.

Re: Proton Mail suspended journalist accounts at request of cybersecurity agency

#206
post #92

The true value of a company can be measured by our ability to communicate with them. If we can't communicate except after public outrage, then what does that say about the company? Here's a genuine question: is Proton Mail the least shitty of companies that provide email services? I self-host email and will continue until I die. But for others who need a company to do this for them, is Proton Mail the least shitty of…

What's your stack? After reading this, self hosting suddenly appeals to me.

I'm still running Sendmail on NetBSD, the way I've been running it since the '90s.

You'll find plenty of people telling you to not do it, but they mostly seem to think that others shouldn't do things because they can't.

The biggest problem with self-hosting email is deliverability, and it's easily handled by smarthosting through a reputable service, so anyone who says it can't be done hasn't really thought things through very much.

Re: Proton Mail suspended journalist accounts at request of cybersecurity agency

#207
post #92

Earlier quoted context omitted.

What's your stack? After reading this, self hosting suddenly appeals to me.

So, now you have to worry about your VPS/Internet provider deplatforming you. Or about your domain name being seized. And spam filtration, backups, redundancy... I'm not saying email self hosting should not be done, I just say a bit of planning should be done. DNS seems like the most annoying part, it is SPoF by design. The problem can be mitigated, but seems like cannot be solved. For example, owning multiple domain…

> So, now you have to worry about your VPS/Internet provider deplatforming you. Or about your domain name being seized. And spam filtration, backups, redundancy...

Your VPS / ISP better have a good reason to "deplatform". If you're really worried, use two different ones.

Also, people have more problems with being "deplatformed" by Google, often with no reason given, and with no way to communicate with a human about the issue. Look it up. I'd be more worried about that.

DNS isn't a single point of failure. Nor is email when it comes to reception (that's what backup MXs are for). If you need redundancy when it comes to being able to fetch email, you can easily have the primary MX also forward to mailboxes on another host so you have two (or more) copies of everything. None of this is all that hard, and people have been doing it for ages. Give it a try :)

Re: Proton Mail suspended journalist accounts at request of cybersecurity agency

#208

Earlier quoted context omitted.

I am a Fastmail customer. Absolutely horrible customer support but pretty solid email. Do not even think about using the "suit" they offer alongside email. The rebranding and "revamp" is limited to the logo and colour changes :D everything under the hood is still the same good old OX inferiority. Hell, you may never want to use their webmail either (my 99.9999% mail usage is via IMAP clients). They are fine other tha…

Interesting. I've used their customer service a couple of times, and it's been okay for me. What was horrible that you experienced?

One of the times I wish there was a longer edit window on HN

> I am a Fastmail customer. Absolutely horrible customer support but pretty solid email. Do not even think about using the "suit" they offer alongside email.

I meant to type “Mailbox” (I find their support horrible) but mobile and typo/confusion. Anyway my fault.

Whenever I had something to ask - Fastmail has been stellar! I don’t use it because it’s too costly for me and offers resources I absolutely do not need.

(You might already have guessed I meant mailbox though as I mentioned Fastmail separately later, did you?)

What was horrible about mailbox support? Too many instances and examples and also I wouldn’t want to mention exact examples here as I have those in their forum and also on support tickets.

Re: Proton Mail suspended journalist accounts at request of cybersecurity agency

#209

Earlier quoted context omitted.

Nope. Zero-knowledge proofs seem to be the middle ground, IMO. Prove X without revealing X itself.

Nice. I can create 5000 different proofs that I am a human and the site can't tell they're all for the same human.

Not necessarily.

Ever heard of linkable systems? They can detect when multiple proofs come from the same person, even if they can't identify who that person is. The system can also force reuse of the same secret, which stops the "infinite proof factory" problem.

Unique secrets can also be tied directly to identity. For example, if the ZKP is about knowledge of a secret key bound to your identity, then you can't just mint 5000 independent proofs unless you also have 5000 identities.

There's also the concept of nullifiers, used in privacy-preserving identity protocols. A nullifier is basically a one-time marker derived from your identity secret that prevents double-use of a proof.

On top of that, zk-SNARK-based credentials or verifiable credentials can prove "I am a unique registered person" without revealing which one. These systems enforce uniqueness at registration, so you can't magically spawn 5000 ZKPs that all look like 5000 humans. Similar ideas exist with linkable ring signatures and even biometric-based ZK proofs.

So there are plenty of ways to counteract your "5000 ZKPs per human" story (what's usually called a Sybil attack).

If you're being pedantic, yes: a bare ZKP alone doesn't enforce "one proof = one person", but ZKP + uniqueness enforcement (nullifiers, credentials, commitments, etc.) does, and that's what I had in mind. I thought it was obvious, but then again, nothing is obvious, and I should have specified. My bad.

In any case, people ought to know just how powerful and useful these ZKP-based systems can be when designed properly. I think this is the only way forward if we want to preserve our privacy, and at the same time we want to prove we're human without sacrificing anonymity, or verify we know the password without revealing it, or prove we're eligible to vote without revealing our identity, or demonstrate we meet age requirements without showing our birthdate, or verify we have sufficient funds without disclosing our balance, or show we're authorized to access something without revealing our credentials, or verify our qualifications without exposing personal details, and so on.

Edit: excuse the technical brain dump, I literally just woke up. I hope this helps to clear up some things, however.

Happy to dig deeper if you want.

Re: Proton Mail suspended journalist accounts at request of cybersecurity agency

#210

Earlier quoted context omitted.

No company is gonna seriously refuse when their jurisdiction's equivalent of the FBI or NSA turn up with a court authorised order. As James Mikkens said: "YOU'RE STILL GONNA BE MOSSAD’ED UPON" But it'd be nice to be able to expect your email provider to not cave in to a request from some other counties CERT organisation without pushing back for evidence and some sort of proper judicial authority behind the request.

This article, right? https://www.usenix.org/system/files/1401_08-12_mickens.pdf

indeed
Post reply on HN