Maybe they’ve changed the website, but when I started using Proton, they never gave me any warning about paying with a credit card.
Anyways, my point is that both the government and service here need to be changed. Switzerland should not be responding to subpoenas from a fascist regime, protonmail should not be based in Switzerland, and Protonmail is too captured by capitalists that want to be Google to have the morals to give up instead of giving in.
See Mullvad for example of a service that will just not offer services like port forwarding instead of pretending they’re secure. They have the same credit card opsec issue but they actively discourage it, and they don’t pretend that unencrypted email is secure.
You can’t demand warnings about stuff like that all the time, YOU need to teach yourself these things.
You can’t rely on anyone else for your own opsec.
That is the entire argument here.
The guy should have read up on protecting his anonymity before he started his activities.
Opsec fails have brought down many, many people.
From darknet site owners, to government agency operations, to countries at war and more.
Opsec sounds easy at first, but it is extremely difficult, and you can’t rely on anyone else doing your job for you.
You need to develop OCD like habits, you need to understand why they are needed, and what you are giving away when breaking them.
You imply that a warning would have prevented the guy from using his credit card, I don’t think it would have made any difference, the guy would either not understand at all, or just ignore it
Unless he intuitively understood that Proton was required to retain cc numbers for X years, and that these cc numbers were tied to a specific transaction, his account and his identity, I just don’t see him taking a warning serious.
This is the real world, it isn’t fair, it doesn’t care, you need to care about this for your self preservation.
Maybe they’ve changed the website, but when I started using Proton, they never gave me any warning about paying with a credit card.
Anyways, my point is that both the government and service here need to be changed. Switzerland should not be responding to subpoenas from a fascist regime, protonmail should not be based in Switzerland, and Protonmail is too captured by capitalists that want to be Google to have the morals to give up instead of giving in.
See Mullvad for example of a service that will just not offer services like port forwarding instead of pretending they’re secure. They have the same credit card opsec issue but they actively discourage it, and they don’t pretend that unencrypted email is secure.
And that is why you would have failed at opsec.
You can’t demand warnings about stuff like that all the time, YOU need to teach yourself these things.
You can’t rely on anyone else for your own opsec.
That is the entire argument here.
The guy should have read up on protecting his anonymity before he started his activities.
Opsec fails have brought down many, many people.
From darknet site owners, to government agency operations, to countries at war and more.
Opsec sounds easy at first, but it is extremely difficult, and you can’t rely on anyone else doing your job for you.
You need to develop OCD like habits, you need to understand why they are needed, and what you are giving away when breaking them.
You imply that a warning would have prevented the guy from using his credit card, I don’t think it would have made any difference, the guy would either not understand at all, or just ignore it
Unless he intuitively understood that Proton was required to retain cc numbers for X years, and that these cc numbers were tied to a specific transaction, his account and his identity, I just don’t see him taking a warning serious.
This is the real world, it isn’t fair, it doesn’t care, you need to care about this for your self preservation.