• mushroomman_toad@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    5
    arrow-down
    22
    ·
    1 day ago

    People shouldnt need to think about opsec to have private emails. False advertising on Protonmails part, and government policy issue in the countries in question.

    • tuhriel@discuss.tchncs.de
      link
      fedilink
      arrow-up
      3
      ·
      13 hours ago

      It’s not false advertising. Just because a company advertises with privacy, it doesn’t mean they are bullet prove.

      they don’t sell your data, they actually have very little data to share at all, but they do follow the swiss law.

      They even publish which kind of requests they get: https://proton.me/legal/transparency

    • starblursd@lemmy.zip
      link
      fedilink
      English
      arrow-up
      6
      ·
      21 hours ago

      It’s not false advertising. They don’t log your account usage, they must comply with swiss law, user ignored the anonymous payment methods and used a personal card for an account for illegal acts.

      The policy clearly states that they must comply with swiss law enforcement, and never claimed that payment info or metadata is encrypted.

      User error

      • mushroomman_toad@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        2
        arrow-down
        1
        ·
        19 hours ago

        Where on their website does it say that fascists can subpoena your payment information on their website? All I see is false advertising saying that no one can read your emails and that their service is secure.

        • starblursd@lemmy.zip
          link
          fedilink
          English
          arrow-up
          4
          ·
          11 hours ago

          Oh I’m sorry I didn’t realize that the credit card you used = the content of emails… Must be a new slang term I’m not familiar with.

          Their policy states they must comply with Federal Swiss law enforcement. They cannot give the content of emails as they are end-to-end encrypted and they are zero logs. They are however required to cooperate and give what isn’t encrypted. ie payment info/backup email(if added) if the user had been smart and used one of the anonymous payment methods, they would have told law enforcement. Sorry we don’t have anything that can help

    • stoy@lemmy.zip
      link
      fedilink
      English
      arrow-up
      13
      ·
      1 day ago

      Arguing about what people should or should not have to do is pointless.

      It changes nothing and removes the debate from being practical to being theoretical.

      • ChristerMLB@piefed.social
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        4 hours ago

        Expecting everyone to be good at opsec is not a practical solution - making it the problem of the company that can and should hire people to be good at opsec, is.

        • stoy@lemmy.zip
          link
          fedilink
          English
          arrow-up
          1
          ·
          4 hours ago

          Well, not everyone needs to be good at opsec, most people are fine as is.

          Most people are not working against the government either.

          But if you are going against the government, or any large and powerful entity, you absolutely need good, reliable opsec.

          When the police comes knocking on your door, you can’t just blame Proton for not informing you about not using your own CC to sign up for your service.

          This isn’t a playground, you are dealing with the big boys now, and they have far more tools than you have, unless you learn and adapt, you will get burnt.

          So while you are right that bot everyone can be expected to be good at opsec, that isn’t the issue.

          The issue is that this was an opsec failure of the guy, it wasn’t Proton messing up.

      • mushroomman_toad@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        3
        arrow-down
        8
        ·
        1 day ago

        It’s not theoretical. Protonmail should not have handed over the personal data for victims of political persecution, but they did.

        The system is broken. The practical next step is to solve the problem.

        • stoy@lemmy.zip
          link
          fedilink
          English
          arrow-up
          7
          arrow-down
          1
          ·
          1 day ago

          They clearly give you options to avoid this scenario, this is not on Proton, this is simply an opsec fail of the user.

          Don’t get me wrong, opsec is hard, exhausting and just annoying, it needs discipline and constant focus, you only need to fail once for it to be ineffective.

          The customer signed up for Proton, but didn’t follow their guidelines for anonymity, that is not a failure of proton, it is a failure of the user.

          • mushroomman_toad@lemmy.dbzer0.com
            link
            fedilink
            arrow-up
            1
            arrow-down
            2
            ·
            19 hours ago

            Maybe they’ve changed the website, but when I started using Proton, they never gave me any warning about paying with a credit card.

            Anyways, my point is that both the government and service here need to be changed. Switzerland should not be responding to subpoenas from a fascist regime, protonmail should not be based in Switzerland, and Protonmail is too captured by capitalists that want to be Google to have the morals to give up instead of giving in.

            See Mullvad for example of a service that will just not offer services like port forwarding instead of pretending they’re secure. They have the same credit card opsec issue but they actively discourage it, and they don’t pretend that unencrypted email is secure.

            • stoy@lemmy.zip
              link
              fedilink
              English
              arrow-up
              2
              arrow-down
              1
              ·
              19 hours ago

              And that is why you would have failed at opsec.

              You can’t demand warnings about stuff like that all the time, YOU need to teach yourself these things.

              You can’t rely on anyone else for your own opsec.

              That is the entire argument here.

              The guy should have read up on protecting his anonymity before he started his activities.


              Opsec fails have brought down many, many people.

              From darknet site owners, to government agency operations, to countries at war and more.

              Opsec sounds easy at first, but it is extremely difficult, and you can’t rely on anyone else doing your job for you.

              You need to develop OCD like habits, you need to understand why they are needed, and what you are giving away when breaking them.


              You imply that a warning would have prevented the guy from using his credit card, I don’t think it would have made any difference, the guy would either not understand at all, or just ignore it

              Unless he intuitively understood that Proton was required to retain cc numbers for X years, and that these cc numbers were tied to a specific transaction, his account and his identity, I just don’t see him taking a warning serious.


              This is the real world, it isn’t fair, it doesn’t care, you need to care about this for your self preservation.

        • How do you think it would play out if proton refuses lawful orders from a court in the country they operate in?

          I do think proton does a lot of misleading advertising, but its still on the user to research and have good opsec. Paying with a card when crypto is an option, using the same service for both email and a vpn, using that service from a public wifi near where you are known to live while actively doing crimes. A lot of mistakes made on the users part. Proton is running a business not a criminal protection racket, you cant expect them to help you get away with crimes just because they claim to value privacy.

            • tuhriel@discuss.tchncs.de
              link
              fedilink
              arrow-up
              2
              ·
              4 hours ago

              Correct, but arson vandalismn and a call for violence is. I couldn’t what exactly the charges awere in the MLAT request, so i have to go what 404 wrote

              One can argue if the swiss goverment should have honired the MLAT request…unfortunately, that thing was put in place before the USA whent insane, and most countries do honor agreements they sign