Proton Mail provided user data that led to an arrest in Spain

https://lemmy.world/post/17481678

Proton Mail provided user data that led to an arrest in Spain - Lemmy.World

cross-posted from: https://programming.dev/post/14053776 [https://programming.dev/post/14053776] > - Proton Mail assisted Spanish authorities in identifying and arresting a member of the Catalan independence organization Democratic Tsunami. > - The company’s end-to-end encrypted email platform aims to protect user data, but recent events suggest potential vulnerabilities. > - Proton Mail was also required to provide user data to Swiss authorities for a separate case involving a French climate activist, emphasizing the importance of proper Operational Security measures. > > Also obligatory video: https://www.youtube.com/watch?v=iH626CXyNtE [https://www.youtube.com/watch?v=iH626CXyNtE]

This is old drama at this point. I’ll repeat what’s been said the previous times this was posted.

Proton did what they were legally required to do in the jurisdiction where they operate as a legitimate business. As an encrypted email provider they offer privacy but not necessarily anonymity, and they’re open about that. They even have multiple blogposts about how to use their service more anonymously. If you thought that by using ProtonMail you were getting full anonymity that’s your mistake.

In both the cases mentioned the users made OpSec mistakes: not using a VPN in one and linking their personal Apple email as a recovery email in the other. In the first case Proton wasn’t even logging the user’s IP until the police forced them to.