let's kill proton mail
let's kill proton mail
I saw a post about this earlier, it is a nothingburger.
The user in question paid for his account with a personal credit card, he didn’t use an anonymous payment alternative which are available.
Proton has stated that they will comply with law enforcement requests, but are working to maintain as few logs as possible.
This is an opsec failure on the user’s side.
This is not Proton handing IDs of their customers to the government on a silver platter, this is their customer not understanding the service they use.
Arguing about what people should or should not have to do is pointless.
It changes nothing and removes the debate from being practical to being theoretical.
They clearly give you options to avoid this scenario, this is not on Proton, this is simply an opsec fail of the user.
Don’t get me wrong, opsec is hard, exhausting and just annoying, it needs discipline and constant focus, you only need to fail once for it to be ineffective.
The customer signed up for Proton, but didn’t follow their guidelines for anonymity, that is not a failure of proton, it is a failure of the user.
And that is why you would have failed at opsec.
You can’t demand warnings about stuff like that all the time, YOU need to teach yourself these things.
You can’t rely on anyone else for your own opsec.
That is the entire argument here.
The guy should have read up on protecting his anonymity before he started his activities.
Opsec fails have brought down many, many people.
From darknet site owners, to government agency operations, to countries at war and more.
Opsec sounds easy at first, but it is extremely difficult, and you can’t rely on anyone else doing your job for you.
You need to develop OCD like habits, you need to understand why they are needed, and what you are giving away when breaking them.
You imply that a warning would have prevented the guy from using his credit card, I don’t think it would have made any difference, the guy would either not understand at all, or just ignore it
Unless he intuitively understood that Proton was required to retain cc numbers for X years, and that these cc numbers were tied to a specific transaction, his account and his identity, I just don’t see him taking a warning serious.
This is the real world, it isn’t fair, it doesn’t care, you need to care about this for your self preservation.
How do you think it would play out if protob refuses lawful orders from a court in the country they operate in?
I do think proton does a lot of misleading advertising, but its still on the user to research and have good opsec. Paying with a card when crypto is an option, using the same service for both email and a vpn, using that service from a public wifi near where you are known to live while actively doing crimes.. Proton is running a business not a criminal protection racket.
Correct, but arson vandalismn and a call for violence is. I couldn’t what exactly the charges awere in the MLAT request, so i have to go what 404 wrote
One can argue if the swiss goverment should have honired the MLAT request…unfortunately, that thing was put in place before the USA whent insane, and most countries do honor agreements they sign
Well, not everyone needs to be good at opsec, most people are fine as is.
Most people are not working against the government either.
But if you are going against the government, or any large and powerful entity, you absolutely need good, reliable opsec.
When the police comes knocking on your door, you can’t just blame Proton for not informing you about not using your own CC to sign up for your service.
This isn’t a playground, you are dealing with the big boys now, and they have far more tools than you have, unless you learn and adapt, you will get burnt.
So while you are right that bot everyone can be expected to be good at opsec, that isn’t the issue.
The issue is that this was an opsec failure of the guy, it wasn’t Proton messing up.
“When the police comes knocking on your door, you can’t just blame Proton”
obviously, but the ideal we should be working towards is that privacy is the default, right? The more normal it is to have this kind of privacy, the less suspicious it is.
are they legally required to store the credit card information?
I agree that we should work toward a more private society, but we are not there yet.
And to answer your question, yes, Proton is required to store the CC info.
Reply
oh, well in that case I’m not sure what they could have done
It’s not false advertising. They don’t log your account usage, they must comply with swiss law, user ignored the anonymous payment methods and used a personal card for an account for illegal acts.
The policy clearly states that they must comply with swiss law enforcement, and never claimed that payment info or metadata is encrypted.
User error
Oh I’m sorry I didn’t realize that the credit card you used = the content of emails… Must be a new slang term I’m not familiar with.
Their policy states they must comply with Federal Swiss law enforcement. They cannot give the content of emails as they are end-to-end encrypted and they are zero logs. They are however required to cooperate and give what isn’t encrypted. ie payment info/backup email(if added) if the user had been smart and used one of the anonymous payment methods, they would have told law enforcement. Sorry we don’t have anything that can help
It’s not false advertising. Just because a company advertises with privacy, it doesn’t mean they are bullet prove.
they don’t sell your data, they actually have very little data to share at all, but they do follow the swiss law.
They even publish which kind of requests they get: proton.me/legal/transparency
I don’t use protonmail, bit the things you posted are not nearly enough to condemn the entire service.
I would say that their support of the trump admin is far more damming, but still not enough for people to drop them outright.
OK, proton isn’t perfect. I don’t like the All In One App, but its better than Google…
And the free service of email and minimal VPN is still a great entry for those trying to break away from Goole services
Wait. This is the shitpost community? What is this here???