Live data from Hacker News

Proton is taking its privacy-first apps to a nonprofit foundation model

arstechnica.com

61–70 of 82 posts

Re: Proton is taking its privacy-first apps to a nonprofit foundation model

#61
post #59

Earlier quoted context omitted.

I have been with Protonmail since 2014. And I feel that they are essentially now the same as any other company which makes loads of dollar - they give up their values. Don’t get me wrong, I have multiple ‘Visionary Accounts’ but I have just no expectation of them protecting my data completely. How do they get peoples passwords / keys? Easy. They just wait for you to log in and they swipe it then. It’s targeted. They…

Are you aware of a better alternative? I am trying to see if I should commit to using Proton or not. I am just a normal users who do not want to be tracked or my data used. Maybe Proton is still very decent for that

Not really, no. Unless you want to self-host in your own home hardware.

Re: Proton is taking its privacy-first apps to a nonprofit foundation model

#63

Earlier quoted context omitted.

Besides, none of it really matters when their customer service backdoor lets you into an account if you can enumerate recent emails that account has received. I'd never trust anything serious with Protonmail. (Try it)

Do you have any evidence for this claim? Here’s their recovery process: https://proton.me/support/set-account-recovery-methods I don’t see there customer support call as a recovery method. I‘d expect that for paid accounts you could theoretically verify your identity to CS via payment, but in that case you lose the data anyway.

Even if the attacker cant decrypt existing e-mail the concern is by hijacking the account they can intercept future e-mail received such as password resets.

Some searching finds this comment. [1] I would be interested if such a password reset were possible against someone who for instance had 2FA enabled, no recovery information and only accessed their account using the Tor onion-service. ;-)

[1] https://news.ycombinator.com/item?id=19367063

Re: Proton is taking its privacy-first apps to a nonprofit foundation model

#64
post #57
post #37

Earlier quoted context omitted.

There is an FAQ. They sat the emails get decrypted in your browser, or in the "bridge" which runs locally. Your decrypted key isn't sent off your local computer. So it's not a case of waiting for you to log in and swipe your key. They never get the key. In the past you could have a separate login password and decryption password. You still can in the advanced settings if you want.

The key has to be on their servers though? If I log into a proton account on a new computer I could see all my emails decrypted. I don't have to store the key somewhere and move it to my new computer. Second, I am not talking about swiping the key, but the password. When you log in, you send your password to their server. They presumably hash the password and compare the hashes then send you the decryption key if the…

You never send your password to their servers, they use the "secure remote password protocol" : https://en.wikipedia.org/wiki/Secure_Remote_Password_protoco...

They explain what they do here : https://proton.me/blog/encrypted-email-authentication

Re: Proton is taking its privacy-first apps to a nonprofit foundation model

#65
post #6
post #5

Earlier quoted context omitted.

You should back up your claim of "they have all the keys", because for things like email and file contents they claim they cannot decrypt them because they do not have those keys (which you have said they do). I believe it was stated on the page you copied those stats from https://proton.me/legal/transparency > As stated in our Privacy Policy, all emails, files and invites are encrypted and we have no means to decryp…

They're all encrypted by themselves and if you use your own gpg key they will replace it. They're all encrypted except when you pay more for dedicated smtp. They're all encrypted except when they give up logs they promised they didn't have. And so on.

This is pretty inaccurate. Proton's E2EE works by encrypting client side, and we can't just replace the GPG key because we have both key pinning and key transparency: https://proton.me/support/key-transparency

Proton does not claim no logs and has never claimed no logs. We do not retain logs by default, but our privacy policy has always been clear that we are legally obligated to follow Swiss court orders, which can ask for IP logging on specific accounts.

Re: Proton is taking its privacy-first apps to a nonprofit foundation model

#66
post #5

Earlier quoted context omitted.

You should back up your claim of "they have all the keys", because for things like email and file contents they claim they cannot decrypt them because they do not have those keys (which you have said they do). I believe it was stated on the page you copied those stats from https://proton.me/legal/transparency > As stated in our Privacy Policy, all emails, files and invites are encrypted and we have no means to decryp…

Proton has the burden of proof, and has continually failed to ensure their systems are E2E. They have failed to develop better tech like signal, and continue to change their infrastructure to appease swiss orders that come from other countries. They have every means to decrypt, they control both the client software, server, and data. You would never know if they logged your key, and they can be compelled to by flimsy…

This is inaccurate. First, Swiss law does not allow the breaking of E2EE. All of Proton's client side code is open source. We cannot arbitrarily change keys in an undetected way due to Key Transparency: https://proton.me/support/key-transparency. We also have open source mobile and desktop apps, so you don't even need to rely on the web app if you don't want.

Re: Proton is taking its privacy-first apps to a nonprofit foundation model

#67

Earlier quoted context omitted.

I have been with Protonmail since 2014. And I feel that they are essentially now the same as any other company which makes loads of dollar - they give up their values. Don’t get me wrong, I have multiple ‘Visionary Accounts’ but I have just no expectation of them protecting my data completely. How do they get peoples passwords / keys? Easy. They just wait for you to log in and they swipe it then. It’s targeted. They…

Besides, none of it really matters when their customer service backdoor lets you into an account if you can enumerate recent emails that account has received. I'd never trust anything serious with Protonmail. (Try it)

Honestly, if you try it, you will find it doesn't really work this way. A lot of heuristics are used for recovery, many which are not visible to the outside for security reasons. Also, data recovery is never possible because of the use of zero access encryption.

Re: Proton is taking its privacy-first apps to a nonprofit foundation model

#68

Reminder that Proton is not "private". They have all the keys, and willingly operate in a jurisdiction where they bend over backwards for ridiculous court orders. From their own transparency page: Number of legal orders: 6,378 Contested orders: 407 Orders complied with: 5,971 They did this to expose protestors and people who upset the powers that be, rarely real criminals. They could choose to operate in a country th…

I have been with Protonmail since 2014. And I feel that they are essentially now the same as any other company which makes loads of dollar - they give up their values. Don’t get me wrong, I have multiple ‘Visionary Accounts’ but I have just no expectation of them protecting my data completely. How do they get peoples passwords / keys? Easy. They just wait for you to log in and they swipe it then. It’s targeted. They…

>How do they get peoples passwords / keys? Easy. They just wait for you to log in and they swipe it then. It’s targeted.

Under Swiss law, Proton cannot be compelled to do this. Nor is this "easy" to execute if you are using the open source mobile or desktop apps.

Re: Proton is taking its privacy-first apps to a nonprofit foundation model

#69

Earlier quoted context omitted.

Do you have any evidence for this claim? Here’s their recovery process: https://proton.me/support/set-account-recovery-methods I don’t see there customer support call as a recovery method. I‘d expect that for paid accounts you could theoretically verify your identity to CS via payment, but in that case you lose the data anyway.

Even if the attacker cant decrypt existing e-mail the concern is by hijacking the account they can intercept future e-mail received such as password resets. Some searching finds this comment. [1] I would be interested if such a password reset were possible against someone who for instance had 2FA enabled, no recovery information and only accessed their account using the Tor onion-service. ;-) [1] https://news.ycombin…

Tor onion service relays are mostly on VPS. And those VPS are mostly American.

The number of tutorials I have seen about spinning up a tor relay on a VPS is crazy. These tutorials are probably written by three letter agencies - though I have no proof.

Regardless, protonmail doesn’t let people register when connecting with Tor unless you use phone number or card to make a payment. You will have to give up something which identifies you, and so it really doesn’t matter when you connect with Tor after you have already registered - there is a way to connect who you are.

Re: Proton is taking its privacy-first apps to a nonprofit foundation model

#70

Earlier quoted context omitted.

Besides, none of it really matters when their customer service backdoor lets you into an account if you can enumerate recent emails that account has received. I'd never trust anything serious with Protonmail. (Try it)

Honestly, if you try it, you will find it doesn't really work this way. A lot of heuristics are used for recovery, many which are not visible to the outside for security reasons. Also, data recovery is never possible because of the use of zero access encryption.

Thank you. Is there any way you can share the exact things you do or provide when you are forced by a court order to give data about someone?
Post reply on HN