Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. If you pay Proton Mail for a service, they may hand over the payment data in response to a court order: https://www.404media.co/proton-mail-helped-fbi-unmask-anonymous-stop-cop-city-protestor/

If you pay Proton Mail for a service, they may hand over the payment data in response to a court order: https://www.404media.co/proton-mail-helped-fbi-unmask-anonymous-stop-cop-city-protestor/

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
79 Indlæg 57 Posters 1 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • maya_b@hachyderm.ioM maya_b@hachyderm.io

    @evacide @cliffle

    and with owners in the US, there's even more legal jeopardy potential. where the servers are located is less relevant than who owns them.

    contrast that with Tuta, sure it's EU owned but you have to go through more layers to get to account details, and not as easily strong-armed.

    though the French MS email saga from a while back makes it all muddier. French authorities will comply with requests made through the proper channels, a US judge said she didn't have to and demanded compliance - putting MS-France in non-compliance with the US court order, or non-compliance with French law.

    schroedingerspossum@mastodon.socialS This user is from outside of this forum
    schroedingerspossum@mastodon.socialS This user is from outside of this forum
    schroedingerspossum@mastodon.social
    wrote sidst redigeret af
    #27

    @maya_b @evacide @cliffle

    All email providers that operate legally - including Tuta - must provide this info if they have it upon court request. If your threat model includes this risk, then having owners in a different country does not protect you at all.
    To be clear, I like Tuta, but I haven't seen any evidence yet that they wouldn't be forced to do the same if they operate there.

    maya_b@hachyderm.ioM choomba@social.tchncs.deC 2 Replies Last reply
    0
    • schroedingerspossum@mastodon.socialS schroedingerspossum@mastodon.social

      @maya_b @evacide @cliffle

      All email providers that operate legally - including Tuta - must provide this info if they have it upon court request. If your threat model includes this risk, then having owners in a different country does not protect you at all.
      To be clear, I like Tuta, but I haven't seen any evidence yet that they wouldn't be forced to do the same if they operate there.

      maya_b@hachyderm.ioM This user is from outside of this forum
      maya_b@hachyderm.ioM This user is from outside of this forum
      maya_b@hachyderm.io
      wrote sidst redigeret af
      #28

      @schroedingerspossum

      agreed. however the reach of US courts is limited by entities that have no US ties. Tuta is still bound, and I expect that a properly processed request through German officials would result in a disclosure, but that requires a bit more rigour than I'd expect from an entity with US ties.

      @evacide @cliffle

      1 Reply Last reply
      0
      • stinerman@mastodon.socialS stinerman@mastodon.social

        @evacide @cliffle I will admit to being surprised that they are required to log certain information by way of court order that they don't log by default.

        porcus@hostux.socialP This user is from outside of this forum
        porcus@hostux.socialP This user is from outside of this forum
        porcus@hostux.social
        wrote sidst redigeret af
        #29

        @evacide @cliffle @stinerman There is a thin line on logging stuff for user debug (being an isp/supplier for friends, i have some clue, not pretending it's expertise), therefor where is that line. also, i might understand that proton needs to comply with swiss law (which isn't up to date vs data retention and digital data, because totally f*ing legacy.) my short swiss citizen view : we're in deep shit with this and local politics dont care. ( i'm geneva's former pirate party founder and lost)

        1 Reply Last reply
        0
        • evacide@hachyderm.ioE evacide@hachyderm.io

          If you pay Proton Mail for a service, they may hand over the payment data in response to a court order: https://www.404media.co/proton-mail-helped-fbi-unmask-anonymous-stop-cop-city-protestor/

          mxenbionix@mastodon.socialM This user is from outside of this forum
          mxenbionix@mastodon.socialM This user is from outside of this forum
          mxenbionix@mastodon.social
          wrote sidst redigeret af
          #30

          @evacide yeah proton has done this before and has made statements about it that proton is a privacy tool, not an anonymity tool. Hate to see it still though.

          Its definitely good to make people more aware of this though, thanks.

          1 Reply Last reply
          0
          • evacide@hachyderm.ioE evacide@hachyderm.io

            If you pay Proton Mail for a service, they may hand over the payment data in response to a court order: https://www.404media.co/proton-mail-helped-fbi-unmask-anonymous-stop-cop-city-protestor/

            orca@nya.oneO This user is from outside of this forum
            orca@nya.oneO This user is from outside of this forum
            orca@nya.one
            wrote sidst redigeret af
            #31
            @evacide@hachyderm.io Glad that I paid them nothing while I was still using Proton Mail.
            wonkothesane@mstdn.socialW 1 Reply Last reply
            0
            • evacide@hachyderm.ioE evacide@hachyderm.io

              If you pay Proton Mail for a service, they may hand over the payment data in response to a court order: https://www.404media.co/proton-mail-helped-fbi-unmask-anonymous-stop-cop-city-protestor/

              powerfromspace1@mstdn.socialP This user is from outside of this forum
              powerfromspace1@mstdn.socialP This user is from outside of this forum
              powerfromspace1@mstdn.social
              wrote sidst redigeret af
              #32

              @evacide cause of course 🙄

              1 Reply Last reply
              0
              • caitp@mstdn.socialC caitp@mstdn.social

                @evacide so the only real solution is to run your own mail server, because corporations will always do this if pressured?

                flipper@mastodonapp.ukF This user is from outside of this forum
                flipper@mastodonapp.ukF This user is from outside of this forum
                flipper@mastodonapp.uk
                wrote sidst redigeret af
                #33

                @caitp @evacide i would think it would be even easier to track someone with their own server. If you run it in the cloud, they can pressure the cloud provider. If it's under your desk, they can presumably track your DNS registration.

                The only real solution is probably to use something like Signal.

                caitp@mstdn.socialC 1 Reply Last reply
                0
                • flipper@mastodonapp.ukF flipper@mastodonapp.uk

                  @caitp @evacide i would think it would be even easier to track someone with their own server. If you run it in the cloud, they can pressure the cloud provider. If it's under your desk, they can presumably track your DNS registration.

                  The only real solution is probably to use something like Signal.

                  caitp@mstdn.socialC This user is from outside of this forum
                  caitp@mstdn.socialC This user is from outside of this forum
                  caitp@mstdn.social
                  wrote sidst redigeret af
                  #34

                  @flipper @evacide Doesn't signal have the ssme stuff, paid accounts associated with handles or phone numbers they could find on an arrested person's phone?

                  flipper@mastodonapp.ukF 1 Reply Last reply
                  0
                  • caitp@mstdn.socialC caitp@mstdn.social

                    @flipper @evacide Doesn't signal have the ssme stuff, paid accounts associated with handles or phone numbers they could find on an arrested person's phone?

                    flipper@mastodonapp.ukF This user is from outside of this forum
                    flipper@mastodonapp.ukF This user is from outside of this forum
                    flipper@mastodonapp.uk
                    wrote sidst redigeret af
                    #35

                    @caitp @evacide no paid accounts, possibly could track you with phone number. I don't know if they store that.

                    1 Reply Last reply
                    0
                    • orca@nya.oneO orca@nya.one
                      @evacide@hachyderm.io Glad that I paid them nothing while I was still using Proton Mail.
                      wonkothesane@mstdn.socialW This user is from outside of this forum
                      wonkothesane@mstdn.socialW This user is from outside of this forum
                      wonkothesane@mstdn.social
                      wrote sidst redigeret af
                      #36

                      @Orca @evacide This actually how you avoid this issue…your credit card is tied to you, full stop. Either pay with an alternative method or not at all

                      1 Reply Last reply
                      0
                      • evacide@hachyderm.ioE evacide@hachyderm.io

                        If you pay Proton Mail for a service, they may hand over the payment data in response to a court order: https://www.404media.co/proton-mail-helped-fbi-unmask-anonymous-stop-cop-city-protestor/

                        jab01701mid@mastodon.socialJ This user is from outside of this forum
                        jab01701mid@mastodon.socialJ This user is from outside of this forum
                        jab01701mid@mastodon.social
                        wrote sidst redigeret af
                        #37

                        @evacide I support the idea that you should pay for your email service, if you value your privacy.
                        Using ANY commercial email service exposes you to surveillance and your identity being exposed. Especially if you use your iOS or Google device as a computer.
                        I continue to hold that Proton is better than a "free" gmail or microsoft account.
                        For example, I currently support my mastodon instance via Patreon. Patreon could and would expose my identity. They have my email. Still I persist.

                        1 Reply Last reply
                        0
                        • evacide@hachyderm.ioE evacide@hachyderm.io

                          @Tekchip Feel free to reply to them while leaving me out of it.

                          haste@mastodon.socialH This user is from outside of this forum
                          haste@mastodon.socialH This user is from outside of this forum
                          haste@mastodon.social
                          wrote sidst redigeret af
                          #38

                          @evacide More polite rebuttal than I could have managed.

                          1 Reply Last reply
                          0
                          • evacide@hachyderm.ioE evacide@hachyderm.io

                            If you pay Proton Mail for a service, they may hand over the payment data in response to a court order: https://www.404media.co/proton-mail-helped-fbi-unmask-anonymous-stop-cop-city-protestor/

                            celeste_42bit@infosec.exchangeC This user is from outside of this forum
                            celeste_42bit@infosec.exchangeC This user is from outside of this forum
                            celeste_42bit@infosec.exchange
                            wrote sidst redigeret af
                            #39

                            @evacide Privacy != Anonymity. Beware!

                            1 Reply Last reply
                            0
                            • evacide@hachyderm.ioE evacide@hachyderm.io

                              If you pay Proton Mail for a service, they may hand over the payment data in response to a court order: https://www.404media.co/proton-mail-helped-fbi-unmask-anonymous-stop-cop-city-protestor/

                              steff@soc.femme.catS This user is from outside of this forum
                              steff@soc.femme.catS This user is from outside of this forum
                              steff@soc.femme.cat
                              wrote sidst redigeret af
                              #40

                              @evacide@hachyderm.io My reading and understanding of this, is that the Swiss govt order came from an MLAT request from the FBI, and not a US court warrant. Thus, the issue, to me, is how US law enforcement essentially uses MLAT to bypass what in the US could be withheld without an appropriate judicial review. Maybe I’m projecting a misunderstanding, but when I had to respond to such requests, in the ISP I ran, we would, generally, only comply with a legal warrant or order authorized by a court.

                              evacide@hachyderm.ioE 1 Reply Last reply
                              0
                              • evacide@hachyderm.ioE evacide@hachyderm.io

                                If you pay Proton Mail for a service, they may hand over the payment data in response to a court order: https://www.404media.co/proton-mail-helped-fbi-unmask-anonymous-stop-cop-city-protestor/

                                victor_mori@infosec.exchangeV This user is from outside of this forum
                                victor_mori@infosec.exchangeV This user is from outside of this forum
                                victor_mori@infosec.exchange
                                wrote sidst redigeret af
                                #41

                                Proton alternatives, for everyone's consideration:

                                ✉️ Email: Tuta (free) or Proton (free tier)

                                🌐 VPN: Mullvad or IVPN (pay with Monero)

                                🔐 Password manager: Bitwarden (free)

                                🥷🏻 Email aliasing: Addy.io (pay with Monero) or SimpleLogin (belongs to Proton, but still, and Monero is an option apparently)

                                Of course, those services and Monero might be honeypots, who knows. They're all FOSS as far as I'm tracking, but I didn't audit any of them personally. That's probably the best we've got I guess. And I believe some take cash payments too, if Monero isn't an option.

                                ahrienby@mk.absturztau.beA 1 Reply Last reply
                                0
                                • steff@soc.femme.catS steff@soc.femme.cat

                                  @evacide@hachyderm.io My reading and understanding of this, is that the Swiss govt order came from an MLAT request from the FBI, and not a US court warrant. Thus, the issue, to me, is how US law enforcement essentially uses MLAT to bypass what in the US could be withheld without an appropriate judicial review. Maybe I’m projecting a misunderstanding, but when I had to respond to such requests, in the ISP I ran, we would, generally, only comply with a legal warrant or order authorized by a court.

                                  evacide@hachyderm.ioE This user is from outside of this forum
                                  evacide@hachyderm.ioE This user is from outside of this forum
                                  evacide@hachyderm.io
                                  wrote sidst redigeret af
                                  #42

                                  @steff A lot of people use Proton Mail because they think its location in Switzerland gives their data greater legal protections than it might have in the US or the EU. In some cases, this may be true, but as you can see in this example, these protections are not absolute.

                                  steff@soc.femme.catS 1 Reply Last reply
                                  0
                                  • evacide@hachyderm.ioE evacide@hachyderm.io

                                    If you pay Proton Mail for a service, they may hand over the payment data in response to a court order: https://www.404media.co/proton-mail-helped-fbi-unmask-anonymous-stop-cop-city-protestor/

                                    starlight@mk.absturztau.beS This user is from outside of this forum
                                    starlight@mk.absturztau.beS This user is from outside of this forum
                                    starlight@mk.absturztau.be
                                    wrote sidst redigeret af
                                    #43

                                    @evacide@hachyderm.io Fuck me, I've been trusting Proton to keep their heart and soul. ​​

                                    Not that I'm in the US or doing anything criminal, but it still sucks to lose trust.

                                    I'm deeply locked in with Passmail and stuff tho, so it's not trivial to change providers.
                                    ​​

                                    1 Reply Last reply
                                    0
                                    • victor_mori@infosec.exchangeV victor_mori@infosec.exchange

                                      Proton alternatives, for everyone's consideration:

                                      ✉️ Email: Tuta (free) or Proton (free tier)

                                      🌐 VPN: Mullvad or IVPN (pay with Monero)

                                      🔐 Password manager: Bitwarden (free)

                                      🥷🏻 Email aliasing: Addy.io (pay with Monero) or SimpleLogin (belongs to Proton, but still, and Monero is an option apparently)

                                      Of course, those services and Monero might be honeypots, who knows. They're all FOSS as far as I'm tracking, but I didn't audit any of them personally. That's probably the best we've got I guess. And I believe some take cash payments too, if Monero isn't an option.

                                      ahrienby@mk.absturztau.beA This user is from outside of this forum
                                      ahrienby@mk.absturztau.beA This user is from outside of this forum
                                      ahrienby@mk.absturztau.be
                                      wrote sidst redigeret af
                                      #44

                                      @victor_mori@infosec.exchange @evacide@hachyderm.io speaking of #Bitwarden, you could self-host #Vaultwarden

                                      1 Reply Last reply
                                      0
                                      • evacide@hachyderm.ioE evacide@hachyderm.io

                                        If you pay Proton Mail for a service, they may hand over the payment data in response to a court order: https://www.404media.co/proton-mail-helped-fbi-unmask-anonymous-stop-cop-city-protestor/

                                        bascule@mas.toB This user is from outside of this forum
                                        bascule@mas.toB This user is from outside of this forum
                                        bascule@mas.to
                                        wrote sidst redigeret af
                                        #45

                                        @evacide never understood why people liked them. I thought they were clowns ever since their first trivial reflected XSS when they initially launched

                                        1 Reply Last reply
                                        0
                                        • evacide@hachyderm.ioE evacide@hachyderm.io

                                          If you pay Proton Mail for a service, they may hand over the payment data in response to a court order: https://www.404media.co/proton-mail-helped-fbi-unmask-anonymous-stop-cop-city-protestor/

                                          T This user is from outside of this forum
                                          T This user is from outside of this forum
                                          theangelofinsanity@mastodon.social
                                          wrote sidst redigeret af
                                          #46

                                          @evacide Anyone who thinks Proton, Tuta or any other company is going to disobey a court order to protect a user is delusional. Proton states upfront that for absolute anonymity, use a free account (or pay with cash or whatever) and only connect using their onion site. They've never given up the content of emails (cause its encrypted in such a way that they can't access). They've never given any log info for VPN use (cause they have a strict no logs policy). Its as simple as that.

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper