https://proton.me/blog/protonmail-threat-model
That blog post was last updated in November 2022, and does not mention recovery email address as something Proton would disclose.
Proton Mail discloses user data leading to arrest in Spain
271–280 of 283 posts
Re: Proton Mail discloses user data leading to arrest in Spain
#272Earlier quoted context omitted.
Are you sure? > The core of the controversy stems from Proton Mail providing the Spanish police with the recovery email address associated with the Proton Mail account of an individual using the pseudonym ‘Xuxo Rondinaire.’
The recovery email is optional, the rest of the information was provided by Apple.
We're saying that Proton Mail provided the authorities with user data, which it did.
Re: Proton Mail discloses user data leading to arrest in Spain
#273Earlier quoted context omitted.
>Doh. I read it as "a company can tell the country it operates from, Norway." Really Norway? Are you guys stupid?
NO is the country abbreviation for Norway. In answer to your question: firstly I am not "guys", I'm one person; and secondly, yes, I feel pretty stupid.
Re: Proton Mail discloses user data leading to arrest in Spain
#274Earlier quoted context omitted.
I don't think this is solely the issue that users don't understand that the companies are obliged to provide the data requested by the authorities. The whole controversy surrounding Proton started when they marketed themselves as "secure and private email", promising they would NEVER give away their users' data, until they did. I had a similar discussion with my friends today about this topic and the issue I have wit…
I disagree, while the marketing is carefully worded, it doesn't say that and both Proton's privacy policy and their transparency report detail what kinds of information they gather and how often they hand over that data. https://proton.me/legal/privacy https://proton.me/legal/transparency I standby the assertion that people will believe what they want to, despite there being easily accessible information that contrad…
Re: Proton Mail discloses user data leading to arrest in Spain
#275Earlier quoted context omitted.
Why are ProtonMail keeping this IP and email information in their logs?
They say quite clearly why in their privacy policy: https://proton.me/legal/privacy (section 2.5: IP Logging). > 2.5 IP logging: By default, we do not keep permanent IP logs in relation with your Account. However, IP logs may be kept temporarily to combat abuse and fraud, and your IP address may be retained permanently if you are engaged in activities that breach our terms and conditions (e.g. spamming, DDoS attacks…
Re: Proton Mail discloses user data leading to arrest in Spain
#276Earlier quoted context omitted.
This is something that I never understood with their "oh you are safe in Switzerland" bs. If the court presents them w/ a warrant they have to comply. There is no magically safe data haven and it isn't honest to pretend that they are one.
Switzerland does have strict laws on the topic. Data requests are only honoured for cases which are a crime both under the foreign country's law and under Swiss law. If you live in a country where homosexuality is illegal, and your local government is chasing you because of this, a Swiss company won't comply with data requests, and a Swiss judge has no reason to honour any data request. If your local government is ch…
Re: Proton Mail discloses user data leading to arrest in Spain
#277Earlier quoted context omitted.
It works sometimes. Usually, it requires phone number or email verification. This is important for protonmail to maintain a revenue stream as they don't allow multiple free accounts for the same person.
Note that even in those cases when additional verification is requested, the email addresses are not tied to your account - we only save a cryptographic hash of your email. Due to the hash functions being one-way, we cannot derive it back from the hash: https://proton.me/support/human-verification
Re: Proton Mail discloses user data leading to arrest in Spain
#278Earlier quoted context omitted.
That's technically and theoretically true but also largely practically irrelevant. Consider a building or a server. You can absolutely make them secure. Sure, eventually , everything can be broken/bypassed/hacked/cracked whatever, but if there is no chance of that happening for the duration that the security has to persist, then it is secure.
> Consider a building or a server. You can absolutely make them secure. I'm not sure it's a good example. A server that you build from off-the-shelf components will likely come with the IME, providing direct tcp-to-ram access. Motherboard manufacturers probably add their own backdoors on top. We know about Gigabyte because they were caught red-handed, but how many we don't know about? How many rootkits in the SSD fir…
You make a good point, as when I made my comments I was considering an 'average' usecase, typically wanting to guard against malicious attacks from unknown actors on the internet.
You're talking here though about absolute security against basically a state level actor. No one else is going to be dealing with exploiting backdoors in firmware for specific targets.
But I still maintain my points is correct, it just requires substantially more money. If guarding against state actors is the requirement, that can be met by having custom or at least verified (at every stage of manufacturer) hardware. Expensive, but far from impossible. As for software issues, that's why we have stuff like SELinux and SEL4.
So yeah, I maintain you can absolutely secure a server. You just have to be clear about what the threats you are wanting to protect against are, and for most people that isn't state actors.
Re: Proton Mail discloses user data leading to arrest in Spain
#279Earlier quoted context omitted.
An IP address in itself is not an identity, but it can be easily resolved to one. This is why IP address are considered PII, and are handled like such by any competent security organization.
>but it can be easily resolved to one Do you have any source to back that up? Last I heard a random person or company won't have a way to find out the real identity given just an IP in general.
I am not sure how the CCPA treats IP address, but unless you're at Google or Facebook, it doesn't matter. Few can afford to build separately for the EU and the rest of the world, and hence err on adapting the strictest interpretation.
--
[0] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
Re: Proton Mail discloses user data leading to arrest in Spain
#280Earlier quoted context omitted.
We've worked on improving it in the meantime, so we recommend that you try again. If you come across any issues, please contact our support team at: https://proton.me/support/troubleshooting?product=account
Yes please report back if it works