Live data from Hacker News

Proton is taking its privacy-first apps to a nonprofit foundation model

arstechnica.com

71–80 of 82 posts

Re: Proton is taking its privacy-first apps to a nonprofit foundation model

#71

Earlier quoted context omitted.

I have been with Protonmail since 2014. And I feel that they are essentially now the same as any other company which makes loads of dollar - they give up their values. Don’t get me wrong, I have multiple ‘Visionary Accounts’ but I have just no expectation of them protecting my data completely. How do they get peoples passwords / keys? Easy. They just wait for you to log in and they swipe it then. It’s targeted. They…

>How do they get peoples passwords / keys? Easy. They just wait for you to log in and they swipe it then. It’s targeted. Under Swiss law, Proton cannot be compelled to do this. Nor is this "easy" to execute if you are using the open source mobile or desktop apps.

Ok, I may have made an incorrect assumption (sorry).

But, do you have a method which results in the data being accessible to anyone other than the account owner?

I don’t know exactly what you provide. Or how you do it. But it does feel secretive, and that in itself makes people think the worst.

But I do know how NDA’s work, so that might be a part of it.

Re: Proton is taking its privacy-first apps to a nonprofit foundation model

#72

Earlier quoted context omitted.

>How do they get peoples passwords / keys? Easy. They just wait for you to log in and they swipe it then. It’s targeted. Under Swiss law, Proton cannot be compelled to do this. Nor is this "easy" to execute if you are using the open source mobile or desktop apps.

Ok, I may have made an incorrect assumption (sorry). But, do you have a method which results in the data being accessible to anyone other than the account owner? I don’t know exactly what you provide. Or how you do it. But it does feel secretive, and that in itself makes people think the worst. But I do know how NDA’s work, so that might be a part of it.

No, in fact we have no way to decrypt the emails on our servers, nor can we share them in an unencrypted format with any third parties (law enforcement included). All the data requests we comply with only include metadata which needs to remain unencrypted for the services to function properly.

Re: Proton is taking its privacy-first apps to a nonprofit foundation model

#73

Get rid of SMS based anti-spam on signup to be a convincing privacy first Find a different anti-spam measure

In the last few months, we have reduced the SMS verification upon signup to a minimum.

just because a VPN or exit node has been used before doesn't mean SMS is the best anti spam measure, I don't know what data you're operating on or what's better for that data, but it undermines the privacy aspect for an SMS prompt to ever be triggered

Re: Proton is taking its privacy-first apps to a nonprofit foundation model

#74

Earlier quoted context omitted.

Even if the attacker cant decrypt existing e-mail the concern is by hijacking the account they can intercept future e-mail received such as password resets. Some searching finds this comment. [1] I would be interested if such a password reset were possible against someone who for instance had 2FA enabled, no recovery information and only accessed their account using the Tor onion-service. ;-) [1] https://news.ycombin…

Tor onion service relays are mostly on VPS. And those VPS are mostly American. The number of tutorials I have seen about spinning up a tor relay on a VPS is crazy. These tutorials are probably written by three letter agencies - though I have no proof. Regardless, protonmail doesn’t let people register when connecting with Tor unless you use phone number or card to make a payment. You will have to give up something wh…

Traffic of onion-services is encrypted. Traffic correlation to deanonymize the client can still be theoretically performed but ultimately you need to draw the line in the sand somewhere.

> Regardless, protonmail doesn’t let people register when connecting with Tor unless you use phone number or card to make a payment

Actually if you attempt enough times you will get the option to verify the registration with an e-mail. And they are rather liberal with which options they accept. So it is not exactly a circular dependency.

From there is it an exercise to the reader to create an account not linked to any other identity.

Re: Proton is taking its privacy-first apps to a nonprofit foundation model

#75

Earlier quoted context omitted.

Honestly, if you try it, you will find it doesn't really work this way. A lot of heuristics are used for recovery, many which are not visible to the outside for security reasons. Also, data recovery is never possible because of the use of zero access encryption.

Thank you. Is there any way you can share the exact things you do or provide when you are forced by a court order to give data about someone?

You can learn more in our Privacy Policy: https://proton.me/legal/privacy and Transparency Report: https://proton.me/legal/transparency.

Re: Proton is taking its privacy-first apps to a nonprofit foundation model

#76

Earlier quoted context omitted.

From the same transparency report page, they refuse any requests from countries that are not Switzerland, and only provide information to Swiss authorities when necessary (I.E. valid international legal assistance, violations of Swiss law, etc). As well, emails and files are encrypted. And their VPN is a no-log VPN. Lastly, they can comply with an order and just give them nothing, because they don't have anything the…

Generally it goes like this: 1. Government entity (usually the US or EU country) pressures the host country's government 2. Host country's government makes a legal request to the company for info on this user. 3. Company adds logging for that specific user. 4. Logging is provided to all those interested. 5. Host country prosecutes (potentially extradites). There's a public accounting of this happening for Proton and…

Switzerland is one of the few countries not instantly putting up with US demands, so it's not that clear and obvious.

Re: Proton is taking its privacy-first apps to a nonprofit foundation model

#77

Earlier quoted context omitted.

Do you have any evidence for this claim? Here’s their recovery process: https://proton.me/support/set-account-recovery-methods I don’t see there customer support call as a recovery method. I‘d expect that for paid accounts you could theoretically verify your identity to CS via payment, but in that case you lose the data anyway.

Even if the attacker cant decrypt existing e-mail the concern is by hijacking the account they can intercept future e-mail received such as password resets. Some searching finds this comment. [1] I would be interested if such a password reset were possible against someone who for instance had 2FA enabled, no recovery information and only accessed their account using the Tor onion-service. ;-) [1] https://news.ycombin…

Valid point, however that happened at least 5 years ago. Proton was smaller. I don’t know if this is still the case for today: I would expect that they continuously improve security of user accounts as they grow.

Re: Proton is taking its privacy-first apps to a nonprofit foundation model

#78

Earlier quoted context omitted.

Can you be more specific about how Mozilla has gone astray?

After Eich was ousted and formed Brave, Mozilla's C-suite are led by an ex-Kinsey person and are extracting all the wealth from the company in the form of massive executive bonuses. They are now an "AI company" and Firefox isn't a concern anymore. I expect Mozilla to die within the next few years and the web to become Chromium only, finally solving my chronic online-ness.

(McKinsey -- but bad under any name!)

Re: Proton is taking its privacy-first apps to a nonprofit foundation model

#79

Earlier quoted context omitted.

Besides, none of it really matters when their customer service backdoor lets you into an account if you can enumerate recent emails that account has received. I'd never trust anything serious with Protonmail. (Try it)

Honestly, if you try it, you will find it doesn't really work this way. A lot of heuristics are used for recovery, many which are not visible to the outside for security reasons. Also, data recovery is never possible because of the use of zero access encryption.

Protonmail's customer service agent CCed my recovery email (me) in the email thread where the attacker was social engineering them. And the attacker was successful until I had to reply to the email chain myself to tell them to stop.

And yes, signing up to Home Depot's email newsletter and other services so that they could tell the customer service agent "my last few emails were from Home Depot and ..." was successful against their customer support system. That's just how amazing it is.

Finally, I don't expect the social media guy running protonmail's HN account to give us much insight into protonmail's customer support security issues, but if you're going to show up, I would've at least expected you to forward my email somewhere for follow up.

Re: Proton is taking its privacy-first apps to a nonprofit foundation model

#80

Earlier quoted context omitted.

Besides, none of it really matters when their customer service backdoor lets you into an account if you can enumerate recent emails that account has received. I'd never trust anything serious with Protonmail. (Try it)

Do you have any evidence for this claim? Here’s their recovery process: https://proton.me/support/set-account-recovery-methods I don’t see there customer support call as a recovery method. I‘d expect that for paid accounts you could theoretically verify your identity to CS via payment, but in that case you lose the data anyway.

Your link doesn't apply here. The attacker's recovery process is to just send an email to support@protonmail.zendesk.com and start flapping their gums.

It doesn't matter if you lose data. If you control an email address, you get all future email including forgot-my-password emails.

Post reply on HN