15

According to Ortis, briefed him about a "storefront" that was being created to attract criminal targets to an online encryption service. A storefront, said Ortis, is a fake business or entity, either online or bricks-and-mortar, set up by police or intelligence agencies.

The plan was to have criminals use the storefront — an online end-to-end encryption service called Tutanota — to allow authorities to collect intelligence about them.

"So if targets begin to use that service, the agency that's collecting that information would be able to feed it back, that information, into the Five Eyes system, and then back into the RCMP," Ortis said.

you are viewing a single comment's thread
view the rest of the comments
[-] ReversalHatchery@beehaw.org 2 points 1 year ago* (last edited 1 year ago)

Proton can be legally ordered to start recording the IP address of a specific user. That's why they recommend that you always connect through their Onion site.
Other than that and if that's possible, I think it may also be possible to legally order Proton to keep the unencrypted form of incoming emails for a specific user, but Proton did not said it in the article, and Swiss laws might protect them against that. It's certainly possible technically, and good to be aware of it, I think.

Sorry but I can't open the second link, as it actively resists it. I suspect though that the problem with Tutanota was not their encryption, but their legal system, which required them to keep a copy of the incoming emails.

Also, don't mistake me, I'm all for protonmail, and I mean this. But did you know they only encrypt the email contents? Metadata like title, sender recipient and other things in the mail header don't get encrypted.

[-] privacybro@lemmy.ninja 1 points 1 year ago

you're right about the IP thing. that's a good clarification rather than just "spy". i suppose it's less dire than Tutanota not encrypting incoming mails if you use tor and vpn by default.

yeah basically it more or less proves that swiss privacy is a bit stronger in this case vs Germany.

on the proton encryption, i did know about this but does that apply to proton-to-proton, proton-to-NonProton, or both? if you have details on this let me know.

either way the fact that they dont makes me feel that proton is a similar honeypot to signal and telegram, where they make a compromise with the five eyes, to give them metadata even if actual contents are safe. metadata can be much more powerful than contents often times

in general email is just the worst protocol when it comes to privacy. sadly.

[-] ReversalHatchery@beehaw.org 1 points 1 year ago

on the proton encryption, i did know about this but does that apply to proton-to-proton, proton-to-NonProton, or both? if you have details on this let me know.

As I know it applies to both. Formerly they were asking (among other things) about the titles of your latest emails for account recovery. (after I have put all the links here I realized that these don't give a details on whether this also applies to inter-proton messages..)

A few sources:

https://proton.me/support/proton-mail-encryption-explained

Subject lines and recipient/sender email addresses are encrypted but not end-to-end encrypted.

https://www.reddit.com/r/ProtonMail/comments/b1ect2/a_question_about_encryption_metadata_subject/eiphhs7/?context=3

https://security.stackexchange.com/questions/196265/why-is-some-meta-data-not-encrypted-in-proton-mail

either way the fact that they dont makes me feel that proton is a similar honeypot to signal and telegram, where they make a compromise with the five eyes, to give them metadata even if actual contents are safe. metadata can be much more powerful than contents often times

Yeah, might as well be. But if it is, I'm afraid we won't get to know for a few decades, if ever. And I think it's still better than the alternatives.. the alternative email providers, that is.
If it comforts you, in their reddit comment I linked they mention (in 2019..) that there's a proposal they support for openpgp to be able to have an encrypted subject line.

[-] privacybro@lemmy.ninja 1 points 1 year ago

Really appreciate your thoughts and time, thanks.

I found out also that Tutanota is essentially the same, except that they do E2EE subject lines between tutanota users, but I am guessing that is because they don't use PGP unlike Proton. In which case, Proton is in the right in this case because they are increasing E2EE interoperability beyond just their own users. So, my comment about honeypotting was really uncalled for I think, and I apologize for that.

The OpenPGP proposal is interesting, but I couldn't find anything on it. All I found was this below, which explains that email headers can't be/aren't encrypted, and subject is one of those, so that's why. I have no clue what Proton was talking about, or where they got that info

https://www.reddit.com/r/ProtonMail/comments/cku293/cant_find_the_openpgp_subject_line_encryption/

this post was submitted on 12 Nov 2023
15 points (100.0% liked)

Privacy Guides

16263 readers
47 users here now

In the digital age, protecting your personal information might seem like an impossible task. We’re here to help.

This is a community for sharing news about privacy, posting information about cool privacy tools and services, and getting advice about your privacy journey.


You can subscribe to this community from any Kbin or Lemmy instance:

Learn more...


Check out our website at privacyguides.org before asking your questions here. We've tried answering the common questions and recommendations there!

Want to get involved? The website is open-source on GitHub, and your help would be appreciated!


This community is the "official" Privacy Guides community on Lemmy, which can be verified here. Other "Privacy Guides" communities on other Lemmy servers are not moderated by this team or associated with the website.


Moderation Rules:

  1. We prefer posting about open-source software whenever possible.
  2. This is not the place for self-promotion if you are not listed on privacyguides.org. If you want to be listed, make a suggestion on our forum first.
  3. No soliciting engagement: Don't ask for upvotes, follows, etc.
  4. Surveys, Fundraising, and Petitions must be pre-approved by the mod team.
  5. Be civil, no violence, hate speech. Assume people here are posting in good faith.
  6. Don't repost topics which have already been covered here.
  7. News posts must be related to privacy and security, and your post title must match the article headline exactly. Do not editorialize titles, you can post your opinions in the post body or a comment.
  8. Memes/images/video posts that could be summarized as text explanations should not be posted. Infographics and conference talks from reputable sources are acceptable.
  9. No help vampires: This is not a tech support subreddit, don't abuse our community's willingness to help. Questions related to privacy, security or privacy/security related software and their configurations are acceptable.
  10. No misinformation: Extraordinary claims must be matched with evidence.
  11. Do not post about VPNs or cryptocurrencies which are not listed on privacyguides.org. See Rule 2 for info on adding new recommendations to the website.
  12. General guides or software lists are not permitted. Original sources and research about specific topics are allowed as long as they are high quality and factual. We are not providing a platform for poorly-vetted, out-of-date or conflicting recommendations.

Additional Resources:

founded 1 year ago
MODERATORS