Live data from Hacker News

Proton Mail discloses user data leading to arrest in Spain

restoreprivacy.com

81–90 of 283 posts

Re: Proton Mail discloses user data leading to arrest in Spain

#81
post #2

Switzerland has laws? Did Proton lie to us?

This is something that I never understood with their "oh you are safe in Switzerland" bs. If the court presents them w/ a warrant they have to comply. There is no magically safe data haven and it isn't honest to pretend that they are one.

Re: Proton Mail discloses user data leading to arrest in Spain

#82

Earlier quoted context omitted.

Some interesting facts about Proton Mail. It generates OpenPGP keys on their own servers, and if you want to use your own keys their instructions show users how to upload upload their entire OpenPGP secret keychain to Proton Mail. Not just encryption/signing subkeys, the master key also needs to be included. I've emailed them to ask that they fix this. I also created a post on their user voice thing about it. https:/…

fix it? are you kidding! that they demanded the private key tells you _everything_ you need to know about protonmail.

Well, they are literally in the business of making OpenPGP easy to use. I understand your worry but I can also understand where they're coming from. The fact is PGP is stupidly hard. I once ran into a gpg bug that deleted my master key. I got so frustrated I just gave up and forgot about it for years. Without services like Proton Mail, this stuff is just never going to be mainstream.

The only way to retain full control over all the keys is to do it the hard way: manually encrypt the emails and send that payload via SMTP. If we refuse to give them the keys, we can't enjoy the convenience of Proton Mail doing that automatically for us. Proton Mail offers a middle ground and it's a very attractive one if you accept the inherent risks associated with giving them the keys.

I'm not willing to give them the master key though. I want the ability to generate a bunch of subkeys just for them. Then I can just revoke those keys if they're ever compromised, and the emails will be encrypted and signed by my actual OpenPGP identity that I'm investing time into, not a separate master key generated for my Proton Mail account.

The support guys confirmed to me in writing via email that Proton Mail only ever uses the signing and encryption subkeys. They don't need the master key.

> We use the signing subkey for signing and the encryption subkey for encryption, and you will have to import the whole OpenPGP at once.

So I asked them directly to add support for importing just the subkeys.

I made a post on their user voice thing about this too. It's garnered a bit of support already.

https://protonmail.uservoice.com/forums/284483-proton-mail/s...

Let's see what happens.

Re: Proton Mail discloses user data leading to arrest in Spain

#83
post #6

Protonmail gave up the recovery address. Apple gave up the name, physical address, and phone number associated with it.

Yes it's a strangely skewed article focusing on proton, when:

> Once he got it, he asked Apple for information about this second email address, and got its name, home address, and phone number. Afterwards, the Civil Guard also asked the telephone company responsible for the telephone number who was the owner of the line, which matches the name provided by Apple. Also, they say they have found that this person is registered at the same address provided by Apple.

Re: Proton Mail discloses user data leading to arrest in Spain

#84

Go try to create a ProtonMail account with Tor. It will ask you to confirm your account with a phone number. It skips this if you’re using a non-proxy IP. They want to know who you are, and it’s been this way for years. I think they’ve long been a honeypot.

[flagged]

And in no way is it possible that compromises have to be made in the real world.

Re: Proton Mail discloses user data leading to arrest in Spain

#85

Earlier quoted context omitted.

Privacy protects some things from the state, which is why the western world has the concepts of warrants and such. But the concept certainly doesn't mean that a business is going to help you cover your tracks in regards to data you've already shared. (in this case, the recovery email address) If you give out your personal information, commit a crime, and ask that person to help you hide, you're not asking for anonymi…

I think that is the GP's point. Privacy means the data is reasonably hidden, though it still exists somewhere in a readable state. Anonymity means the information of who did what really doesn't exist anywhere. In the case of governments, private data is only hidden until the government decides that it needs to look for it (or ask for it). Anonymity means the data isn't there, regardless of whether the government deci…

I slightly disagree with your distinction. Privacy is about minimising the amount of data collected that's visible to anyone but you. Your data stays with you and/or only you can see your data, therefore, private. Anonymity isn't about the amount of data collected, but that the data collected or accessible by others can't be linked to you.

Re: Proton Mail discloses user data leading to arrest in Spain

#86

Earlier quoted context omitted.

fix it? are you kidding! that they demanded the private key tells you _everything_ you need to know about protonmail.

Well, they are literally in the business of making OpenPGP easy to use. I understand your worry but I can also understand where they're coming from. The fact is PGP is stupidly hard. I once ran into a gpg bug that deleted my master key . I got so frustrated I just gave up and forgot about it for years. Without services like Proton Mail, this stuff is just never going to be mainstream. The only way to retain full cont…

It's a "trust me" story. Honeypot

Re: Proton Mail discloses user data leading to arrest in Spain

#87

Earlier quoted context omitted.

Well, they are literally in the business of making OpenPGP easy to use. I understand your worry but I can also understand where they're coming from. The fact is PGP is stupidly hard. I once ran into a gpg bug that deleted my master key . I got so frustrated I just gave up and forgot about it for years. Without services like Proton Mail, this stuff is just never going to be mainstream. The only way to retain full cont…

It's a "trust me" story. Honeypot

I can't deny that possibility. Still, it should be an individual's choice to risk it or not.

Re: Proton Mail discloses user data leading to arrest in Spain

#88
post #31

I dislike that a website with privacy in the name collides privacy and anonymity. Privacy does not protect you from the state. Privacy is good enough to protect you from the public . If you are doing battle with or an enemy of the state, much less an agent of the state acting in bad faith simple privacy will do nothing for you. Worse your misunderstanding of it is actually a vector, like in this case. The measures fo…

> Privacy does not protect you from the state. Privacy is good enough to protect you from the public.

While I get what you are saying, that is a little too black and white for the entire field. Privacy can be used to shield whistle blowers from the state.

Re: Proton Mail discloses user data leading to arrest in Spain

#89

Earlier quoted context omitted.

While an IP address is not an identity, it can still zero in on a location. I suspect governments and ISPs all keep historical logs of who was assigned what address.

> I suspect governments and ISPs all keep historical logs of who was assigned what address. They do. It's often required by law.

1 maybe 2KB of storage for the IP addresses of an individual for a year. Of course they are doing it even if accidentally.
Post reply on HN