Live data from Hacker News

Proton Mail discloses user data leading to arrest in Spain

restoreprivacy.com

241–250 of 283 posts

Re: Proton Mail discloses user data leading to arrest in Spain

#241

Earlier quoted context omitted.

I think they should do like Mullvad claims and keep zero logs. You cannot share what you do not have.

How would a recovery email feature be possible without them knowing what your recovery email is?

If you are super duper serious about securing yourself, recovery email is non-viable. Every piece of data is a potential vector towards exposure.

Which comes directly into the problem of security vs convenience.

Re: Proton Mail discloses user data leading to arrest in Spain

#242

Earlier quoted context omitted.

>I can think of one country in the whole world (Iceland) where a company can tell the country it operates from, NO. Are you claiming that businesses in Iceland are not required to comply with court orders? On what basis do you believe that to be true?

Doh. I read it as "a company can tell the country it operates from, Norway." I thought "Huh? Why would an Icelandic company operate from Norway?" Well, I thought, I suppose there must be quite a few. But why's he mentioning it here? Thanks for inadvertently clarifying.

>Doh. I read it as "a company can tell the country it operates from, Norway."

Really Norway? Are you guys stupid?

Re: Proton Mail discloses user data leading to arrest in Spain

#243
> Catalan independence organization, Democratic Tsunami

OK, I think I grokked this. You might think that a Greco-Nipponese name for this organization poorly conveys Catalan nationalist pride. But in fact it quite effectively says "anything but Spanish". That's almost certainly the gag.

Re: Proton Mail discloses user data leading to arrest in Spain

#244
post #221

Earlier quoted context omitted.

An IP address in itself is not an identity, but it can be easily resolved to one. This is why IP address are considered PII, and are handled like such by any competent security organization.

>but it can be easily resolved to one Do you have any source to back that up? Last I heard a random person or company won't have a way to find out the real identity given just an IP in general.

But the threat actor in this case is a state, which does have that ability. (And data brokers of varying degrees of shadiness can and do provide this info to anyone for a price.)

Re: Proton Mail discloses user data leading to arrest in Spain

#245
post #159

It seems there is some mental conflict going in readers between the reality of what ProtonMail does for its customers and their expectations of what kinds of protections a legitimate business can provide. Both ProtonMail and Apple will challenge subpoenas when they believe they are not valid, however neither company has the final say in the matter and can be compelled to provide access to data that they reasonably ha…

>I suppose the second learning is to elect governments which respect democratic freedoms, even if that puts them on the back foot. Democratic freedoms, in the United States at least, protect people from UNREASONABLE search and seizure. Compelling a third party to reveal information about a customer via a court order is not now, has never been, and will never be until the end of time and space, unreasonable. The order…

> Compelling a third party to reveal information about a customer via a court order is not now, has never been, and will never be until the end of time and space, unreasonable.

Its unreasonable if the standards for issuing the court order (as applied, even if not in theory) are unreasonable.

And that is often now, and has often been, and will often be (likely until the end of human history), unreasonable.

Re: Proton Mail discloses user data leading to arrest in Spain

#246

Earlier quoted context omitted.

>I suppose the second learning is to elect governments which respect democratic freedoms, even if that puts them on the back foot. Democratic freedoms, in the United States at least, protect people from UNREASONABLE search and seizure. Compelling a third party to reveal information about a customer via a court order is not now, has never been, and will never be until the end of time and space, unreasonable. The order…

>Democratic freedoms, in the United States at least, protect people from UNREASONABLE search and seizure. You're conflating what's written in the law and the sad reality of how a lot of that is simply ignored by law enforcement, while they are standing on your neck, searching your car.

Pretty fun, that precisely for you "standing on neck, searching car" is REASONABLE search and seizure, not for him. Pretty expected.

Re: Proton Mail discloses user data leading to arrest in Spain

#247

Earlier quoted context omitted.

How would a recovery email feature be possible without them knowing what your recovery email is?

If you are super duper serious about securing yourself, recovery email is non-viable. Every piece of data is a potential vector towards exposure. Which comes directly into the problem of security vs convenience.

Of course, but you can't blame Proton that you chose to prioritize convenience over security. If you don't want Proton to know who you are, don't use that feature.

Re: Proton Mail discloses user data leading to arrest in Spain

#248
post #213
post #130

Earlier quoted context omitted.

RFC4880 uses ElGamal for the asymmetric encryption and so it's a discrete log problem. Roughly the private key x should satisfy `a=b^x mod n` where b and n are known, and a is part of the public key. It goes through similarly for elliptic curve-based schemes.

FWIW, OpenPGP doesn't only offer ElGamal, and we never use that algorithm. We use Curve25519 by default since quite a while, before which we used RSA. We've never used ElGamal and also don't allow importing ElGamal keys, since they're insecure and deprecated in the crypto refresh (the upcoming update to the OpenPGP standard): https://datatracker.ietf.org/doc/html/draft-ietf-openpgp-cry... .

Good point, I just picked the simplest example. In fact I use Proton for my personal email and wouldn't dream of it if I didn't think your crypto was up to scratch.

Re: Proton Mail discloses user data leading to arrest in Spain

#249
Instead of blaming corporations for following the law, blame the laws and the government for what they force others to do.

It is not up to corporations to decide which laws should be enforced, and this again shows how futile this specific kind of corporate resistence is.

Just change the law.

Re: Proton Mail discloses user data leading to arrest in Spain

#250
post #234

Earlier quoted context omitted.

Not really. Tor, I2P, and Monero manage this just fine. Building on these technologies should allow one to have privacy and anonymity without any exotic quantum technology.

These technologies give privacy and anonymity under normal conditions, but they do not prevent anyone from logging ciphertexts. If someone has logged ciphertext, and the government subponies someone to divulge their private key and subponies whoever has the ciphertext, those ciphertexts as good as plain text.

I mean, I don’t think anyone really expects that encrypted messages are necessarily secure in context of stolen private keys. I assume that a lot of encrypted traffic is either recorded at the ISP/backbone level or at least can be on demand.
Post reply on HN