Once again Proton hand over data on an activist to authorities, this time to the FBI via the Swiss High Court.

Proton is unsafe for use by frontliners.

https://www.404media.co/proton-mail-helped-fbi-unmask-anonymous-stop-cop-city-protestor/

#infosec #opsec

Proton Mail Helped FBI Unmask Anonymous ‘Stop Cop City’ Protester

A court record reviewed by 404 Media shows privacy-focused email provider Proton Mail handed over payment data related to a Stop Cop City email account to the Swiss government, which handed it to the FBI.

404 Media

Group-wide selfhosted mail is so often the solution here, but it needs to be done right, and with strong operational security posture. This includes the jurisdictional layer relative to operating context.

And yet #selfhosted mail is famously hard. We dedicate much time to this, deploying a full blown high-reputation MTA with webmail frontend, in the Fortress sessions https://courses.nikau.io/fortress/

#selfhosting

Fortress – Nīkau Courses

@JulianOliver with modern mailers like Mox, Stalwart, or even Mailcow, self-hosting mail is not hard anymore. And considering the profile I would advise against running such thing on a VPS, rather deploy this in your own premisse where they have no jurisdiction.

@ronnylam those turnkey solutions are good for very simple setups but can be awfully inflexible and easily outgrown. I believe also people invite risk running complex infra they don't understand. Mail is complex. The way it is.

For the longhaul, esp so far as adding new mailing domains and forwarding, aliasing and even hardening, it is hard to beat native Postfix/Dovecot/OpenDKIM for MTA with webmail frontend on separate host. No containerisation, all legible, fast, tunable and readily secured.

@JulianOliver from your answer I get the feeling that you have never looked at, let even tried Mox or Stalwart. Both are all-in-one single binary mail solutions, one written in Go, the other in Rust. Both are very easy to set up, flexible and secure. Maybe they can be outgrown, but not by families or small associations that want to run their own mail. No containerisation, all legible, fast, tunable and readily secured.
@ronnylam I have not tried Mox no. I have been meaning to setup a sandbox for this. Thank you.
@JulianOliver I am really interested in your findings.