this post was submitted on 18 Jan 2025
271 points (95.0% liked)
Privacy
477 readers
220 users here now
Protect your privacy in the digital world
Welcome! This is a community for all those who are interested in protecting their privacy.
Rules
This includes the instance rules of dbzer0, which can be tl;dr'd to: this is a libertarian socialist space, no right wing nutjobs or tankies are allowed. As for the community rules:
- Be nice
- No bigotry/prejudice
- No tankies/right wingers
- Don't promote proprietary software
- Stay on topic
- No crypto
- Don't be a smartass and try to game the system, we'll know if you're breaking the rules when we see it!
- If you post news exclusive to a country please name it. (This isn't a bannable rule, but just a recommendation :) )
founded 2 months ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
While I get the sentiment, what could possibly happen to Proton that makes it unsafe and you wouldn't know? We already known they do comply with the law and hand over basic information.
But they do not give access or decrypt the actual content of your mailbox and that's not because they choose not to but because it is technically not possible, or am I wrong about that. If the plan to change that it would hopefully become obvious through some announcements.
It's moreso the trust factor for me. Proton is secure, I know; but the company behind it has been making many bad decisions lately.
They were extremely unprofessional dealing with this. I mean, who comments their own political views on a company account then doubles down??? That's just stupid to me.
I should have specified that I might not even switch off of proton, I'd like to know alternatives JIC shit hits the fan :(
Same. After the whole AI fiasco and the crypto fiasco, this is just adding insult to injury.
Oh shit, what did I miss?
The security vulnerability behind any decent VPN is the VPN provider. When they're signalling support of fascists and technocrats you need to move on because their mask slipped and their real motives have been exposed. The sheer gall it takes to pretend you can believe Trump supports privacy goals is laughable.
The question is really who is an actual alternative.
None, really.
All companies have skeletons in their closets, it's not a matter of if, it's a matter of when. I don't trust companies, but not everyone can self-host. As for your question; Mullvad seems good, but be wary.
Agree, always good to be prepared
If you complie your clients, Proton cannot decrypt your data.
But there's a lot more than Proton can do.
They could log your IP, the exact time you log in or use Proton services
They could keep a copy of every email you receive, most of them are probably unencrypted.
If you use VPN, they could log everything you do, they wont be able to decrypt the HTTPS data, but if they log all your traffic, it defeats the purpose of using a VPN.
They could potentially swap the web javascript, if you ever log in via browser.
When you send emails to another Protonmail user, Proton could potentially do a mitm and swap Proton's public key and make the other user's client think its your public key, and also give Proton's public key, and make your client think its that user's public key. Proton essentially act as a keyserver, so they could maliciously replace keys.
And most people don't compile their user clients, so if you just download the clients they compile, they could just not use the source code to compile it, sending you a malicious client.
There's just a lot of attack vectors if the company itself becomes hostile.