# Are you all using proton stuff? Can we trust to register your entire private life to them?

**URL:** https://discuss.privacyguides.net/t/are-you-all-using-proton-stuff-can-we-trust-to-register-your-entire-private-life-to-them/13615
**Category:** Questions
**Created:** 2023-08-14T10:14:13Z
**Posts:** 51

## Post 1 by @yourmother — 2023-08-14T10:14:13Z

are you all trusting and using stuff from proton?  
Can we trust to register your entire private life with them?

- protoncalander
- protonmail
- protonvpn
- proton password manager
- proton cloud
- proton wallet

---

## Post 2 by @anon35412456 — 2023-08-14T10:37:15Z

Just a heads up, proton wallet isn’t from the same company. But yes I trust proton calendar and drive to be E2EE and for them to not log/scan my emails + internet traffic. However I trust an established password manager such as bitwarden over proton’s offering.

It’s good practice to spread out exposure but there unfortunately aren’t many reputable companies with the same offerings at a comparable price.

---

## Post 3 by @anon63378630 — 2023-08-14T10:59:41Z

> [2022](https://proton.me/legal/transparency)
> 
> - Number of legal orders: 6,995
> - Contested orders: 1,038
> - Orders complied with: 5,957

:roll_eyes:

---

## Post 4 by @yourmother — 2023-08-14T11:28:55Z

> [@anon63378630](#):
>
> :roll_eyes:

interesting but is also says:

> all emails, files and invites are encrypted and we have no means to decrypt them.

So foreign authorities car order what they want, but everything is encrypted so they can’t never use it?

---

## Post 5 by @anon63378630 — 2023-08-14T11:42:52Z

Except traditional email fundamentally cannot be encrypted and its destinations are always visible.

---

## Post 6 by @Anonymous49 — 2023-08-14T12:13:02Z

You already know better than me that email is not intended for primary communication medium. If you have an high model, then switch to e,g., signal, simplex.

Any company has to comply with law enforcement. Far from perfect, I believe proton is the most beautiful solution for an average user. Other alternatives are not privacy friendly, or lack many features. That’s my two cents.

---

## Post 7 by @purplecactus — 2023-08-15T05:08:14Z

yes. i have no intention of usin Proton Pass, but i trust and use their other products. there are more discussions comparing them to Tutanota for example if you search.

personally i do not super..need that lvl of encryption in transit and much prefer Proton to Tuta overall.

---

## Post 8 by @Dkama — 2023-08-15T14:17:16Z

This.

I trust Proton to shield me away from big tech and big ad surveillance.

If I had a higher threat model, though, I might still use their services, but I’d definitely add another level of protection by making sure I always use a VPN from another company to access them. And encrypt files before they’re sent to Proton’s cloud.

Email is an insecure and non private technology, but sometimes there’s no way around it. Proton mail + Mullvad VPN/Tor might be one solution (of course, avoiding email is always better). All the other services can be self hosted if the threat model requires it.

---

## Post 9 by @gammexane — 2023-08-15T16:21:50Z

Only mail (and simplelogin), I went from ultimate to Mail plus. I am an Android/Linux user and that makes the other products barely useless to me. Well, the mail client for Android still sucks…  
I am seriously thinking on moving my mail to Skiff. They have made more in 3 years than proton in 10. But I like [pm.me](http://pm.me) domain AND GPG… Those are the only stoppers by now.

---

## Post 10 by @purplecactus — 2023-08-15T21:34:52Z

interesting, why do you say that using android/linux makes their non email products useless (if i understand correctly)

---

## Post 11 by @Voilable — 2023-08-16T17:26:43Z

yes, I do trust them. No breach so we good.

---

## Post 12 by @Dkama — 2023-08-16T19:23:53Z

What do you mean, no breaches? Take a look at @anon63378630 's reply. They “breached” almost 6000 times to law enforcement in 2022 alone.

---

## Post 13 by @Voilable — 2023-08-16T20:13:36Z

Huh, I mean data breaches, idgaf about law/police.

---

## Post 14 by @Anonymous49 — 2023-08-17T09:37:36Z

(post deleted by author)

---

## Post 15 by @Dkama — 2023-08-17T12:04:38Z

What does your dictionary say about quotation marks?

---

## Post 16 by @dgener — 2023-08-17T19:32:15Z

unless it’s forwarded to someone else?

---

## Post 18 by @anon28734771 — 2023-08-17T20:39:20Z

A post only needs a few reports before it gets hidden automatically.

---

## Post 19 by @gammexane — 2023-08-19T19:21:51Z

- U2F only works on web mail
- No Drive client for Linux nor ETA
- The VPN clients for Linux is basically a script my nephew can code and he is 5 years old.
- No Sync for contacts or Calendar (Linux or Android)  
– The contacts… well, useless…  
– Calendar only works online.
- Mail client for Android, doesn’t have even group mails…

---

## Post 20 by @Ganther — 2023-08-20T17:34:25Z

To me, it’s not a matter of _how often_ they hand out customer info. It’s about _what_ they hand out.

Also as with every time Proton is mentioned and people mention their police cooperation: what’s the brilliant alternative?

I know email as a protocol is terrible, but I still need an email. And what’s the least bad email service? To me, that seems like it would be ProtonMail.

---

## Post 21 by @Dkama — 2023-08-21T00:29:36Z

> [@Ganther](#):
>
> Also as with every time Proton is mentioned and people mention their police cooperation: what’s the brilliant alternative?

If you read my message just 3 or 4 replies before that one you’d get your answer:

- you don’t need an alternative if you’re not a target and are just looking to avoid mass surveillance.

- if you’re a (potential) target, the not so brilliant alternative is to distrust Proton just like you’d distrust any other service that will sell you out: use their email behind a VPN that’s not ProtonVPN (or even Tor) and use the free version so that you don’t have to share personal information in order to pay them. Everything else, you just self host.

Edit: grammar

---

## Post 22 by @Anonymous49 — 2023-08-21T13:42:24Z

There are only two free and trustworthy VPNs; windscribe and proton. The former has a limit of 10 Gb. So, which VPn are you planing to use? Why is TOR not secure in this case?

Besides, having a high level threat model and using email for communication are inconsistent. Why will you need to use email for communication instead of secure messengers?

This would be a very very niche case such as being a whistleblower or sth like that, and you only have an email address and no other way of communication.

---

## Post 23 by @Cyber-Typhoon — 2023-08-21T19:02:12Z

I’m interested in the answer but wondering when this became a discussion about which VPN should we use.

---

## Post 24 by @Reset0609 — 2023-11-05T02:06:43Z

> [@Dkama](#):
>
> use the free version so that you don’t have to share personal information in order to pay them

Even to use the free version you have to provide them with an email address and theyre picky about it. For example, they do not accept @vivaldi.net addresses. Why would that be?

---

## Post 25 by @Average_Joe — 2025-09-09T21:15:41Z

Isn’t it a bad idea to place all your eggs into one basket? :worried::worried:

---

## Post 26 by @anon39279085 — 2025-09-09T21:22:58Z

usually yes, it depends  
the bare minimum to do is that you could stick all eggs into one basket but don’t stick the uniquely painted eggs into them

in other words, your 2FA and Password manager should be seperated away from that basket with all the eggs as a bare minimum.

if you’re planning to use proton for 2fa and password manager do but dont use drive and its other ecosystems, instead use alternatives like tuta.

---

## Post 27 by @ph00lt0 — 2025-09-09T21:41:55Z

The annoying awswer: It depends.

It mostly depends on exit strategy —A topic we probably should cover more — How easy is it to move away and do you know to what and how? If moving is not a problem using an ecosystem can he beneficial in terms of UX and adoption.

Privacy can be overwhelming for many so simple solutions that offer a great alternative with similar convenience is also worth something.

Ask yourself, if the provider goes away suddenly, what are your options, and do you minimize the risk and thus reduce the impact. If you can get to a minimum impact, like a few hours of work to move to other services, this can be acceptable depending on your requirements.

Now this is all a lot of security management theory but I will add a little bit more. Because it is good to realize that when using multiple services you also introduce more risk. Namely for example you add complexity of your IT landscape which requires more knowledge to stay in control, more maintainance effort and costs, and a bigger attack factor. The last one meaning there are more ways to compromise you.

In other words: “Don’t shit where you eat and” and “keep it simple stupid” are good rules to follow and you need to find the right balance for your situation between them.

---

## Post 28 by @anon63117981 — 2025-09-09T23:56:43Z

> [@ph00lt0](#):
>
> The annoying awswer: It depends.

this is in most cases the correct answer — everyone’s situation and knowledge is different

---

## Post 29 by @investigatorcloset — 2025-09-10T01:10:03Z

I love proton but I would never put all my eggs in one basket. It’s not a smart decision regardless of threat model.

---

## Post 30 by @Average_Joe — 2025-11-18T09:33:46Z

> [@ph00lt0](#):
>
> The annoying awswer: It depends.

I appreciate your reply!

This seems like a decision that’ll take a long time to figure out… Proton seems like the best company out there but what if one of their services/apps has a user privacy breach? Then your whole life could be turned upside down… Very scary thought!

---

## Post 31 by @ph00lt0 — 2025-11-18T17:52:14Z

Using multiple services does not mitigate the breach impact really. And if you trust the cryptography (which you should) the impact or breaches of providers like these are limited.

---

## Post 32 by @anon71786485 — 2025-11-18T18:52:50Z

I agree, this is why I would like Proton to move to post-quantum encryption. Each day that passes without this encryption brings us a little closer to a hypothetical case where encrypted data from Proton’s servers is stolen and then decrypted in a few years.

---

## Post 33 by @anon98749087 — 2025-11-18T19:06:58Z

I agree with your post that anyone who complies with law enforcement is a red flag. Genuinely curious what the solution to this is though, since basically any provider of technology can be compelled to do so in most or all of the countries where they operate. We could use tiny open source products, but once they reach a certain size, or if they are not anonymous, they will also be compelled to hand over data at some point. Or am I missing something?

---

## Post 34 by @yes — 2025-11-18T19:22:28Z

> [@anon98749087](#):
>
> I agree with your post that anyone who complies with law enforcement is a red flag.

:person_facepalming:t2:

How do you expect a company as big as Proton to operate in other countries, or even in Switzerland, without complying with law enforcement? Sometimes people seem to forget how things work.

---

## Post 35 by @anon57862721 — 2025-11-18T19:38:17Z

> [@anon98749087](#):
>
> Genuinely curious what the solution to this is though

Even Andy Yen of Proton has said that the only solution is to operate in international waters. But even that would not work as countries through which you may receive resources to run your operation in international waters may force you to comply to their rules if you want to continue needing their support. If you keep extrapolating the logic, open operating in international waters will not work (as silly or cartoonish as that idea is to begin with)

Or run the organization anonymously and in a decentralized fashion but monetizing it will be an issue and won’t be sustainable.

No real solution.

Also, if you think a company complying with law enforcement is a red flag, I don’t think anyone can change your value system enough to see a more rational, logical, and a pragmatic way to look at the world/understand how the world works given reasonableness of the lived human experience. All these words to say this really: what you’re thinking is really silly and makes little to no sense. Every entity has to comply with legal requests. That’s how they exist. But Proton offers you to use and access all its services privately and anonymously. This is a non issue if done right.

---

## Post 36 by @anon98749087 — 2025-11-18T19:40:53Z

If you read my whole post (four sentences), you’d see that I literally made the exact point that you took your time to post (while also condescending to me).

---

## Post 37 by @anon98749087 — 2025-11-18T19:44:05Z

there are plenty of “rational, logical, and pragmatic” reasons why someone would distrust the motives or actions of “law enforecement” in a very, very large number of countries (all of them, perhaps).

i also use proton. i think both you and the previous response are misunderstanding my question.

---

## Post 38 by @anon57862721 — 2025-11-18T19:45:28Z

I think it’s the way you wrote it then. But alright..

---

## Post 39 by @anon98749087 — 2025-11-18T19:47:39Z

my point was that i don’t know of any ways that a company would be able to _not_ hand over the user data they have when compelled to.

i think maybe some people got triggered by my suggestion that law enforcement is not a trustworthy entity. (hint, it’s not.)

---

## Post 40 by @yes — 2025-11-18T19:50:20Z

> [@anon98749087](#):
>
> i think maybe some people got triggered by my suggestion that law enforcement is not a trustworthy entity. (hint, it’s not.)

You didn’t state that in your initial reply though :face_with_monocle:

---

## Post 41 by @anon98749087 — 2025-11-18T19:51:23Z

you didn’t read my (4 sentence) post which literally says “any provider of technology can be compelled to do so [hand over user data] in most or all of the countries where they operate”.

---

## Post 42 by @anon57862721 — 2025-11-18T19:55:46Z

> [@anon98749087](#):
>
> I agree with your post that anyone who complies with law enforcement is a red flag.

I think the main contention here was this statement of yours. But let’s drop it now.

---

## Post 43 by @yes — 2025-11-18T19:57:46Z

No, I read the whole thing. Anyway, refer to what @anon57862721 said.

---

## Post 44 by @The_Centurion — 2025-11-18T20:07:36Z

I primarily use Proton for their email, VPN, and calendar. I don’t do a ton of cloud storage but I do have some important stuff saved on my drive. I have not used any of their other products. For my password manager I use Bitwarden for my password manager, and I use SimpleLogin (technically now a Proton product) for disposable email addresses. I also have an email address with Tutanota which I haven’t used too much yet, but I got my account name secured incase I decide to start using it.

---

## Post 45 by @anon57862721 — 2025-11-18T20:10:14Z

> [@The_Centurion](#):
>
> For my password manager I use Bitwarden for my password manager, and I use SimpleLogin (technically now a Proton product) for disposable email addresses.

If you didn’t know, you get all of Simplelogin and more if you used Proton Pass Plus instead. But you also get Proton Pass Plus if you pay for Simplelogin. So, perhaps check it out to see if PP meets your needs and save a little (even though $10 may not be much) if you move to Proton Pass for all your credential management needs.

---

## Post 46 by @ph00lt0 — 2025-11-18T20:32:34Z

You are misunderstanding. Quantum computing will not break the data at rest encryption at all. This is a big misconception. Quantum computing is only a real risk for encryption in transit for which many are already having or taking the right mitigations.

---

## Post 47 by @beantaco — 2025-11-18T23:28:22Z

> [@yourmother](#):
>
> are you all trusting and using stuff from proton?  
> Can we trust to register your entire private life with them?

No. I use Proton only for email and VPN.

> [@anon71786485](#):
>
> I agree, this is why I would like Proton to move to post-quantum encryption. Each day that passes without this encryption brings us a little closer to a hypothetical case where encrypted data from Proton’s servers is stolen and then decrypted in a few years.

> [@ph00lt0](#):
>
> You are misunderstanding. Quantum computing will not break the data at rest encryption at all. This is a big misconception. Quantum computing is only a real risk for encryption in transit for which many are already having or taking the right mitigations.

It looks like Proton Mail uses AES256 (symmetric key encryption a.k.a. cipher), ed25519 (public key signing) and cv25519 (public key encryption) algorithms by default.

The best known _theoretical_ quantum attack of AES256 is [Grover’s algorithm](https://en.wikipedia.org/wiki/Grover%27s_algorithm) which can search an unsorted database of N entries in O(√N) operations. An attack on AES256 using Grover’s algorithm would be as successful as a brute-force attack on AES128. If AES128 is considered secure against conventional attack methods then AES256 should be considered quantum resistant. I would consider 2^128 operations (worst case) to attack AES256 is secure enough. AES256 is [believed to be quantum resistant](https://www.fiercesensors.com/electronics/aes-256-joins-quantum-resistance) and [GnuPG](https://www.gnupg.org/documentation/manuals/gnupg/Compliance-Options.html) has a `--require-pqc-encryption` flag that enforces AES256 use.

Public key cryptography appears to be a different story, more prone to quantum attacks. There has been activity ([Signal 1](https://signal.org/blog/pqxdh/), [Signal 2](https://signal.org/blog/spqr/), [Tuta](https://tuta.com/blog/post-quantum-cryptography)) to transition to quantum-resistant public key algorithms. To my knowledge Proton Mail (based on OpenPGP) has not yet adopted a quantum-resistant public key encryption algorithm. AFAICT while Proton Mail stores emails using AES256 by default, if public key cryptography (let’s say it’s cv25519) is used to encrypt an email, it may be theoretically possible to use some kind of quantum attack to extract the symmetric key from the encrypted packet (cv25519) that protects the symmetric key, then use that key to decrypt the email (AES256).

---

## Post 48 by @ph00lt0 — 2025-11-19T00:14:02Z

> [@beantaco](#):
>
> The best known _theoretical_ quantum attack of AES256 is [Grover’s algorithm](https://en.wikipedia.org/wiki/Grover%27s_algorithm)

> … even for AES-128, the practical security impact of Grover with existing techniques  
> on plausible near-term quantum hardware is limited.

> **[on-practical-cost-of-grover.pdf](https://csrc.nist.gov/csrc/media/Events/2024/fifth-pqc-standardization-conference/documents/papers/on-practical-cost-of-grover.pdf)**
>
> 679.51 KB

---

## Post 49 by @ph00lt0 — 2025-11-19T00:15:39Z

> [@beantaco](#):
>
> To my knowledge Proton Mail (based on OpenPGP) has not yet adopted a quantum-resistant public key

Also this is being sorted:

> **[Proton is building quantum-safe PGP encryption for everyone | Proton](https://proton.me/blog/post-quantum-encryption)**
>
> Quantum computers may someday break current encryption. Proton is leading the standardization of quantum-resistant encryption in OpenPGP for all to use.

---

## Post 50 by @The_Centurion — 2025-11-19T07:29:50Z

I’ve used Bitwarden longer than I have SimpleLogin so my flag was already staked there. I know its fairly easy to switch but I don’t want to put all my eggs in one basket with Proton, hence why I keep a few alternative products in my toolbox (Bitwarden, Tutanota)

---

## Post 51 by @kissu — 2025-11-19T10:09:51Z

Hopefully:

- Proton can be used for a few of those
- while other trustworthy companies full-fill the gap of features for the rest
- and if you feel adventurous, self-hosting can go a long way too

With all those 3, I think we covered all the use cases in a healthy way. :hugs:
