Live data from Hacker News

Proton Mail discloses user data leading to arrest in Spain

restoreprivacy.com

91–100 of 283 posts

Re: Proton Mail discloses user data leading to arrest in Spain

#91
Proton Mail is pretty good email. I use it since I decided to de-google as much as possible. That said, I don't consider it truly 'private.' Weird key handling in order to make pgp 'easy,' just email being what it is, and courts and governments being what they are.

I'll continue to use it despite some hyperbole on the site, but as long as my mail isn't being fed to an advertising engine it's a step up.

Re: Proton Mail discloses user data leading to arrest in Spain

#92

Go try to create a ProtonMail account with Tor. It will ask you to confirm your account with a phone number. It skips this if you’re using a non-proxy IP. They want to know who you are, and it’s been this way for years. I think they’ve long been a honeypot.

Not surprised at all. Even if it did not start with this intention, one has to suspect that with enough time it will become compromised.

About the only way to even vaguely keep your email private is to use a self hosted server with GPG keys. And any lapse on security updates for that thing and you could be compromised almost immediately.

Beyond that I cannot think of anything more one could do.

I have always treated email as something to travels in the clear. My current provider (Fastmail) is compromised by authority. The Australian Privacy Act 1988 by being based in Australia and it gets caught up by PRISM as the servers are run out of New York.

Re: Proton Mail discloses user data leading to arrest in Spain

#93
post #67

Earlier quoted context omitted.

Some interesting facts about Proton Mail. It generates OpenPGP keys on their own servers, and if you want to use your own keys their instructions show users how to upload upload their entire OpenPGP secret keychain to Proton Mail. Not just encryption/signing subkeys, the master key also needs to be included. I've emailed them to ask that they fix this. I also created a post on their user voice thing about it. https:/…

Of course they will not. If you look at everything they propose there is always that one thing that makes them control everything. Their IMAP bridge, key generation etc

It's how they make OpenPGP easy to use. Everyone who's ever tried it knows how hopelessly complicated it is. Their bridge's entire purpose is to present a standard email server to email clients so that all the OpenPGP stuff can be done automatically and transparently behind the scenes.

Does that create trust issues? Absolutely. Still, OpenPGP sucks and I just can't fault them for trying to fix it. They're even participating in the standards bodies alongside other OpenPGP projects trying to modernize the whole thing. Somehow it resulted in gpg forking the standard and making everything even worse. It was hard to use before, now it's hard and fragmented.

https://lwn.net/Articles/953797/

https://news.ycombinator.com/item?id=38554393

I suppose they could have gpg or OpenPGP smartcard integration in the bridge, then it could use those keys to sign and encrypt. That's more secure but creates quite a bit of hassle. Suddenly the web and mobile apps become incapable of sending OpenPGP email unless you have the smartcard connected. I've got two NFC enabled YubiKeys and I can't even begin to imagine how to connect this stuff to a smartphone. Looks like there isn't enough support for it.

https://news.ycombinator.com/item?id=40177539

Re: Proton Mail discloses user data leading to arrest in Spain

#94

Earlier quoted context omitted.

It's a "trust me" story. Honeypot

I can't deny that possibility. Still, it should be an individual's choice to risk it or not.

It is but if I exchange emails with a Protonmail user I am writing with them like there is no encryption present.

Re: Proton Mail discloses user data leading to arrest in Spain

#95
post #46

Earlier quoted context omitted.

I’d be more interested in a system that can prove to me that it’s not collecting logs. Hard, but not impossible.

As long as we are talking about classical communication (and not quantum) it is impossible to prove that it isn't collecting at least ciphertext logs.

Not really. Tor, I2P, and Monero manage this just fine. Building on these technologies should allow one to have privacy and anonymity without any exotic quantum technology.

Re: Proton Mail discloses user data leading to arrest in Spain

#96

Earlier quoted context omitted.

It's a "trust me" story. Honeypot

I can't deny that possibility. Still, it should be an individual's choice to risk it or not.

Of course you are right, if majority of individuals were informed and if protonmail was proactive in informing their users about short commings. The problem is that most users are not informed and they think that protonmail is the bee's knees of email privacy and security, while protonmail only promotes that myth.

Re: Proton Mail discloses user data leading to arrest in Spain

#97
post #70
post #68

Earlier quoted context omitted.

Why are ProtonMail keeping this IP and email information in their logs?

The identification came from the recovery email.

In a previous case some years ago, a French activist’s IP address was provided by Proton on court order. Proton does store IP address and does provide it when legally demanded to.

Re: Proton Mail discloses user data leading to arrest in Spain

#98

The heart of the issue is this: > Under Swiss law, Proton Mail was compelled to collect and provide information on the individual’s IP address to Swiss authorities, who then shared it with French police. They can claim all the privacy guarantees they want, but unless the privacy is guaranteed by cryptography, it's an empty gesture. Nobody is willing to do prison time to protect your privacy.

You could encrypt the source IP on all your outbound TCP packets, but it might not work very well.

a minor point but you can't _encrypt_ source IPs, you can only obfuscate or more accurately, proxy.

Re: Proton Mail discloses user data leading to arrest in Spain

#99
post #31

I dislike that a website with privacy in the name collides privacy and anonymity. Privacy does not protect you from the state. Privacy is good enough to protect you from the public . If you are doing battle with or an enemy of the state, much less an agent of the state acting in bad faith simple privacy will do nothing for you. Worse your misunderstanding of it is actually a vector, like in this case. The measures fo…

Privacy is also meant to protect you from the state, or more specifically state abuse. It's an essential aspect of privacy. Like privacy is also meant to e.g. not disclose topics you have communicated about so that it can't be abused against you. For example there is a long history of states persecuting people for idk. being gay, believing in a certain religion or being a journalist which was involved in a unpleasant…

> Mainly privacy of communication doesn't always imply anonymity, through sometimes does (and has too!).

Anonymity is simply people not knowing who you are, not necessarily what you say. It's not privacy of communication, but privacy of identity.

I can post on the internet as Anonymous Coward, and those posts are public even though my identity is private.

I can encrypt an email and send it, and it will be picked up by all the relays. They can look up the source and identify me, but hopefully not read the email contents.

Post reply on HN