I found new ways how Proton could read your data: https://schaerli.org/5/
- Desktop clients auto-update without signature checks or user permission
- Key Transparency was never active on ProtonPass despite being advertised
- Key Transparency for all apps is broken and does not protect against MITM attacks




