- cross-posted to:
- technology@lemmy.world
- cross-posted to:
- technology@lemmy.world
Summary
Proton Mail, known for its privacy-first email services, faced backlash after CEO Andy Yen praised the Republican Party and its antitrust stance.
The company initially posted and deleted a statement supporting Yen’s comments, later claiming an “internal miscommunication” and reiterating its political neutrality.
Critics question Proton’s impartiality, particularly as it cooperates with Swiss authorities on legal data requests.
Privacy advocates warn that political alignments could undermine trust, especially for Proton’s users—journalists and activists wary of government surveillance under administrations like Trump’s.
Yeah Proton already burned that bridge. “Politically Neutral” is no longer an option for them.
Curious how so many people decided to ditch them and switch (vocally on Lemmy at least) and now they back pedal/clarify/whatever. Turns out we have power and using it works. Sorry not sorry. Edited: pedal instead of petal.
I am currently entrenched in Google. Slowly digging my way out so I could transfer to proton. I was probably within about a month maybe two or pulling the trigger. Zero chance that happens now. I don’t like Google But I know what they’re going to do. If I’m going to put the effort into move that critical data it’s got to be with some place I can trust or I’m going to have to host it myself.
yap I’m exactly on the same boat. I am testing the waters with proton to leave google… and then I see this… Can’t find an alternative
Email:
Mailbox https://mailbox.org/en/
Posteo https://posteo.de/en
Startmail https://www.startmail.com/
Runbox https://runbox.com/
Cloud File Storage:
Filen https://filen.io/
Tresorit https://tresorit.com/
VPN:
Air VPN https://airvpn.org/
(sorry, didn’t have time to link more VPNs. I’m at work.)
Thank you, I have been looking at some of these but there are some there I haven’t checked. However, these all sound like complicated services to convince my family to switch. Something like Proton seemed perfect since it looked easy to use and I could easily explain that instead of “all your google services” here are (almost) all equivalent services on Proton here.
I’m researching the suggestions that people have made here: tuta, bitwarden, and mullvad.
Main downside of Mullvad is no port forwarding anymore
AirVPN is still great if you need port forwarding (e.g. for P2P services). Unfortunately they limit it to 5 ports for new accounts - used to be 20.
BW is great Chefs Kiss $40 a year for 6 people, it’s a good product made by people who seem to care.
I’m using PIA, it’s not great, but i’m not doing great things nor and I doing them quickly. They’ll give you openssl certs and you can do programmatic crap AND have a dedicated port.
Tuta is pricey for what you get. 8/month/user for email/cal with reasonable storage, No office apps, i need to replace a LOT of google services. Still have a lot tied up in their auth/store. And honestly encrypted email (AAS) is mostly worthless. It’s not encrypted between them and office 365 or google and everyone is already reading those in transit. And Google/MS are already mining/selling the content. If you’re not talking tuta<->tuta you might as well be broadcasting it.
The $3 for the shared box seems like a slap in the face. You’re literally already paying them for service/storage.
You can host thousands of email users on a couple of modest boxes for a couple hundred a month.
Personally going with option 2 on an old PC, learning a lot about docker lol
Personally going with option 2 on an old PC, learning a lot about docker lol
Have to be careful in planning, a lot of ISP’s block common ports needed to host dns/web/email
Getting DKIM and SPIF running locally has a bit of a learning curve.
The real pain is SMTP. Even if you set up everything perfectly, a lot of mail providers won’t accept SMTP traffic from a home IP.
I think my longterm plan is to just keep a free gmail and try like hell to never use it.
Was looking into https://mailcow.email/
Haven’t gone past the cursory look tho
At first glance, they check all the boxes for me.
Im so sorry. I tried not to, but the pull was to strong. Ignore me please…
But…
The saying is “back pedal”, not “back petal”. “Back pedal” as in trying to pedal backwards on a bike. Not “back petal” as in trying to pick flowers at the back of a bush, maybe? Trying to not lie down on a bed of roses? Unsure.
Oof. Kinda awkward, but…
*too
I really don’t think there’s anything wrong with a respectful and well-intentioned correction.
I fixed that twice!
Fist Curse you autocorrect! Fist
Imagine being so fucking brainwashed you believe Republicans are for “the little guy”
I already switched from Proton Mail to Tuta. No regrets
Again privacy oriented companies that bend to demagogues and desperate profiteers cannot be trusted to handle sensitive data.
Switched from ProtonVPN to Mullvad and ProtonMail to Posteo. Wiped my ProtonDrive. I sleep pretty soundly at night.
I cannot fathom being that stupid to believe that Republicans are anti-monoploy when they give huge corporation massive tax breaks and removes barriers for mega mergers
I just cancelled my subscription and moved everything to Tuta. Tuta also seems to have a political stance much more aligned with my own: diversity, privacy oriented, and eco friendly.
I really don’t understand why smart people put their eggs in the proton basket.
Big (shady) money rule Switzerland. A Swiss server or company isn’t safer or more trustworthy. Quite the opposite.
Excluding Switzerland from the equation, most in the US don’t have + or - for Switzerland unless it’s banking.
You can never trust any company to put your needs first. A good moral company has at least its founders, private funders, employees, and vendors to look after before they worry about your wants and needs.
Proton was kinda small. 500 employees for a communications company isn’t bad.
Good start.
Proton made a name for itself. WE ARE PRIVACY FIRST and they mostly delivered on that in technical capabilities.
So far, so good.
Then they doxed someone’s IP (french?) due to a remote government order.
Not great, but anyone would do that. There have to be limits. That said, they now clearly play ball with governments.
All the other providers would do the same. They’re now on par with most, but less likely to sell all my data down the river. But my needs are to keep my secrets state secret level. (or so I think)
Then he crawls up Trumps ass.
Now, I’m doing nothing illegal. Nothing immoral. Nothing questionable by the previous administrations standards, but what happens If I start to protest? If I subscribe to democratic news sources, is this jackass going to train an AI on my and hand my name address and phone number to the neo facists running my country now?
We put our eggs wherever we think they can best be served conveniently and for the best price.
You can also choose to not put your eggs anywhere. You can secure your email but not sending any.
we were trying to choose price+convenience+security.
knock one of those legs out, it’s not a table anymore.
This comment needs more upvotes inmho. This is exactly right. It’s how I followed this history myself. They built on Privacy first. Now there are red flags which were not clear before.
On the hacker news thread: https://news.ycombinator.com/item?id=42837181
They discuss the topic and there is only a single reply from ProtonPrivacy, saying it’s miscommunication and blah blah.
It was not enough to dispel my sense of unease and concern and a single comment isn’t exactly ‘fighting to set the record straight’.
My 2¢.
They’ve done a lot of damage control. They were on Reddit too, They spin it that the pick he made was actually a reasonable pick, (1/50 even if they’re right on this one and I don’t think they are) but they don’t address that he went on to Twitter and tagged Trump to try to gain favor.
One can’t reach out to the man trying to dismantle democracy and say “hey buddy, you’re doing great! Can I get in on some of that?” and still try to claim centrist.
I mean, “spin it”, that’s literally what the tweet said, in a response to a tweet (from trump, hence the tag) that announced that pick. He praised the pick and generalized on the fact that republicans are more likely than democrats to fight big tech. Good or wrong that’s everything that was said and a perfectly legitimate opinion, even if I may disagree.
This also happened in December, not yesterday.
Thank you! I was also very confused how all these privacy-conscious people warned against big corporations, and then starting using a product… By a big corporation. Just because they say they’re privacy conscious and nice and safe and whatever doesn’t mean it’s true. I mean, they might be substantially better, but there’s no proof of that. Every company always makes promises, at first. I guess people really like to believe in an underdog.
It’s like if someone warned you against eating sweets because they’re unhealthy, but then pulls out their own bag of sweets saying “oh no, these sweets are fine because the company that makes them promised they’re healthy”.
They’re not big. 500 people at a communications company that develops their own stuff is relatively tiny.
Team looks great. 14 employees in 2020, I bet they’re honestly serious about security
Either due to spectrum or other, I can’t interpret this without questioning if it’s sarcasm 😆
Straight up honest. I can’t* argue with 14 people running a 2 million-user service and openly talking about the team on their page.
I like it more if that top tier was about $5, but the probably lack the scale to decrease cost.
edit: missed a 't
Aside from the political stuff, I’m also concerned about proton from a technological standpoint. You can’t use a standard mail client with proton, you have to use their own. So, if they wanted to, they could push out a single malicious update which would render all of the end-to-end encryption stuff pointless. You could argue that using Thunderbird + GPG + Gmail is more secure/private.
You can’t use a standard mail client with proton, you have to use their own.
Part of the reason is that the protocol that’s uses for retrieving emails (IMAP) is pretty old and doesn’t support end-to-end encryption. JMAP is supposed to be a modern replacement, but it’s not widespread yet, and also intentionally doesn’t support E2EE.
E2EE is hard, for example searching has to be done client side rather than having a search index on the server side (since the server is not able to decrypt the data to index it). I haven’t tried Proton but I’m curious as to how they solve this… I guess they’d sync the entire mailbox and index it locally, like what (non-mobile) Thunderbird does.
I really question the value of E2EE for emails, though. Communication between servers (e.g. someone on Gmail sending an email to a Proton user) uses TLS but is not, and will likely never be, end-to-end encrypted. Emails you send to other providers are also not likely to be encrypted on the other provider’s end.
You can if you use the bridge, which is not perfect but basically does the GPG encryption/decryption for you and exposes IMAP etc. (I think you can also do your own PGP encryption on top, not sure).
The supply chain issue you discuss is the same with any tool, with the exception that with proton you have an automated update system (I.e. every time the page loads js code), while with more traditional tooling you upgrade based on your choice (more or less). You are likely not checking the code in either case, but a malicious update could backdoor or bypass your encryption either way. Technically you can build the proton client yourself but anyway, this is just theoretical stuff, nobody does that.
Gmail + GPG is anyway worse, first of all from a UX perspective, where every device needs to be managed separately (GPG keys need to be available, you need to manage them, managing keys and keeping them secure is hard). Second, you will use GPG only with selected people of whom you have the key. With proton you will use it automatically for all Proton users at the very least and all proton users can use it with you automatically too.
Then there is the problem with metadata. They cannot be encrypted of course, and with gmail you are 100% sure they are using them to profile you and mine whatever data can be mined (e.g., who you talk to), while with proton you can reasonably be confident they don’t.
Yep and if you look at some corrupt sports bosses like Sepp Blatter, Gianni Infantino and Rene Fasel, all are Swiss.
What’s the alternative in your opinion? Google, or something else, and why?
Tuta has been good for me.
I just set up a bunch of purelymail addresses on a couple domains I own. I bought into proton for 2 years just a couple months ago. So I’ll transition away slowly.
Anything + PGP + Tor + VPN.
There are countless mail servers one can use. I use a mail server hosted by Swedish ISP Bahnhof (which I trust). You can also self host. But then you need to be on the dark webs if you really care about privacy (I dont recommend this).
Or Delta Chat. Or Signal/Matrix/Session/Whatever. This is the preferred choise. EMail is legacy.
Tbh it seems like there are no good alternatives to protonmail. You just have to host your own
Host your own probably isnt a good idea unless youre on the dark webs. Probably not worth it.
If super privacy is a requirement. For normal work/junk mail, sure!
Okay, I feel like the part that people are skipping over is the “cooperating with authorities on legal data requests” part. No. As a privacy company; You DO NOT save and store ANY information apart from what is crucially and imminently necessary to run your service. Anything beyond that is a blatant conflict of interests and should not be trusted. Corruption and data sharing that CAN happen, WILL happen when it comes to data security based companies. Full stop.
Maaaan, what the fuck?!?
More theater do to this today:
And today I got an email saying they’re donating a million dollars to support non-profits for privacy and freedom. Timing, timing, timing.
Oh ffs, I just made the move to Proton with some stuff a few months ago. I’m really keen on switching the address out on a load of accounts.
Sure hope their praises don’t include giving your data to their heroes
They would hand over your liver for an atta-boy and a small government contract.
The Swiss just can’t help themselves