Proton Mail Helped FBI Unmask Anonymous ‘Stop Cop City’ Protester

https://lemmy.blahaj.zone/post/39495957

Blåhaj Lemmy - Choose Your Interface

protonmail without PGP only has encryption for other protonmail users
Bad opsec. Of course Proton will comply with court orders. It’s your responsibility to not leave data they can hand over.

Indeed

But shouldnt it be encrypted on their servers?

Payment data? Never.
Technically stored encrypted, but they also have the keys

they shouldn’t pretend to protect your privacy if they can’t

one time they did this and only then after changed their website where it said they wouldn’t log your info

Payments are very different. Any company is required to keep track of their finances, the tax authorities don’t fuck around. If you electronically pay for something and expect anonymity, you are not very, um, educated. If you feel like you need their paid plans, pay cash and only ever access it through TOR running Tails. I feel like that’s a reasonable level of opsec for most activists.

You know that, I know that, people here probably know that.

But out in the real world where people are doing real world activism and are concerned about real world problems, they don’t necessarily know that. They are concerned about a whole lot of things that are not digital infrastructure and technology.

They should be able to trust a service that promises security and anonymity for payment.

Should is doing too much work here. Its been doing too much work for our society as a whole. While I agree with your idealist sensibilities I regret to inform you that this needs to stop, you cannot trust institutions built on corporate profit seeking. Like that’s just a hard no, it changes on a dime to seek profit somewhere else
Hence the romanticism of migrating to Proton needs to be argued every time somebody brings it up.

They should be able to trust a service that promises security and anonymity for payment. In particular one that is touted as well renowned.

Especially since other groups can manage it properly, e.g. Signal can’t link transactions to a specific user account

Introducing Signal Secure Backups

In the past, if you broke or lost your phone, your Signal message history was gone. This has been a challenge for people whose most important conversations happen on Signal. Think family photos, sweet messages, important documents, or anything else you don’t want to lose forever. This explains wh...

Signal Messenger
Yeah, there are plenty of services that manage exactly this. Most prominently VPNs.

this is victim blaming

not every activist is a tax attorney, their misleading advertising and the faulty standing in the community is the reason this awesome anti cop city activitist got repressions

Marketing claims don’t absolve you from doing your due diligence.
I can’t read the article because it’s behind a paywall, so I’ll ask here: What information was handed over specifically? The IP address of when the account was created? The payment details? Unencrypted data? Login information? Device data? Something else?

they handed over payment info with the real name

nationaltoday.com/…/protons-privacy-policies-fail…

Proton's Privacy Policies Fail to Fully Protect Payment Info - Atlanta Today

While Proton's end-to-end encryption can keep account data private, the company's policies do not fully protect payment information. Court records reveal that Proton Mail responded to a request from Swiss authorities for payment details tied to an account associated with the Stop Cop City protests in Atlanta, and that information was then shared with the FBI.

National Today
I’m still relatively new to Proton, but I thought I read early on that they would still have to comply with legal requests. I believed that their system was mostly in the realm of two secure accounts being able to hide the messages themselves. I use a card, so I am tied to my account. Does using whatever coin they take (if any) help with this? I remember reading they wanted to open more doors to alternate payment methods. I think it was to help privacy but also in large part so that they could still collect money if they ever get slapped down by other processors for making someone big mad for their privacy setup.
ProtonMail Sends User IP and Device Info to Swiss Authorities.

YouTube
Everybody seems to confuse privacy with anonymity. If Proton doesn’t comply with the law, Proton will cease to exist.
I can’t read the full article because of the paywall, but duh? If you aren’t paying physically or in crypto you can assume your government (and probably others!) already has that transaction on record, and to my knowledge those aren’t totally secure either.