# Frustrated by Proton, but really not seeing an alternative

**URL:** https://discuss.privacyguides.net/t/frustrated-by-proton-but-really-not-seeing-an-alternative/20630
**Category:** General
**Created:** 2024-09-05T20:27:21Z
**Posts:** 43

## Post 1 by @nobeke — 2024-09-05T20:27:21Z

Hey guys,

Maybe someone could give me some advice, but most likely it will just be my whining about not having a really great email provider (for me).

First, all the things I really like about Proton that others don’t offer:

- **offers email aliasing service** - most of my emails unfortunately have no E2EE and go through an aliasing service, so I feel safer if I only have to trust one company (not the case of _all eggs in one basket_ since both services theoretically have access to my emails), also I kinda like the simple-login “implementation” in protonmail, but it’s still far from perfect, so no big deal.
- **PGP support** - I know PGP isn’t really great, but it’s really the only encryption standard I could realistically use.
- **zero-access encryption** - oh yea, it could be _EDIT: hypothetically_ bypassed by proton. And the emails are stored unencrypted on the other (senders) side’s big-tech servers anyway. But still, I like it and it’s better than nothing.
- **email client support**
- **nice UI** - but yea, not that important to me

I liked Skiff (at least on paper). Shame it’s no longer an option.  
Tuta is great, but no unlimited aliases, no PGP, and no custom email client support. Also, their reddit mods seem crazy (I hope only reddit mods :smile: ).  
Mailbox, Posteo - I haven’t tried them yet. Probably don’t have email alias service either and have their own problems (mail spoofing drama etc.)

Ok, so why don’t I want to use Proton services?

When I pay for email and simple-login, I feel like I am literally being robbed.  
I would pay: $48 mail + $30 login /12 = **$6.5 per month**  
But if you click on ProtonVPN pricing and choose 2 year plan unlimited (no 2y plan in mail tab :upside_down_face:) it costs **$8 per month**

So basically people who pay $1.5 more than me get VPN, Pass and 500GB storage?  
Ohh, if I pay $6.5, I feel like I am sponsoring these things anyway, but getting nothing out of it. I’d rather donate the money to some other FOSS project.  
And no, I don’t want their crappy VPN (linux user here), Pass or Drive. And I don’t need more than 15GB for mail.  
ok, but that is probably just my problem.

Then there are the classic Proton things like:

- no automatic contact sync on android
- no Fdroid repo / dependency on google play services
- aggressive, awful and misleading marketing (tbf I’d say, it’s slightly improved over time)
- not releasing calendar source code
- and probably more…

But then I saw an [interview](https://www.youtube.com/watch?v=Dp7ght2fMR4) with Andy Yen. Well he explains a lot of things.  
And even if I don’t agree with some things, I could at least hope to get what I want one day.

Then the Proton Docs were announced … the amount of money and time it had to take… when most of their services are not even in a decent state!

And then I read about Proton Scribe. That was the last straw.  
Literally a product based on scraping other people’s content. By Proton, privacy by default…

And what do you think?

---

## Post 2 by @Valynor — 2024-09-05T20:38:29Z

Regarding the Proton pricing: you can get pretty good deals if you wait for the November “Black Friday” offers, they are usually quite a bit cheaper esp. for the 1/2 year subs.

---

## Post 3 by @yes — 2024-09-05T20:57:15Z

> [@nobeke](#):
>
> **“zero”-access encryption** - oh yea, it could be bypassed by proton. And the emails are stored unencrypted on the other side’s big-tech servers anyway. But still, I like it and it’s better than nothing.

Now, that’s just an absurd take. Please back your claims with actual facts/proofs.

> **[What is zero-access encryption and why is it important for security? | Proton](https://proton.me/blog/zero-access-encryption)**
>
> Some of your most sensitive data sit on the cloud, on the servers of Internet service providers. Zero-access encryption gives you control over your data online.

---

## Post 4 by @ph00lt0 — 2024-09-05T21:00:43Z

If you come from my prespective where i tried actually doing all hy myself Proton is a great relief. Pretty decent provider for good price imho and getting a lot of improvements every now and then. Surely there is still a lot that can be improved but overall very ststisified.

Your claim on zero access encryption is FUD. Please leave that out of the forum.

---

## Post 5 by @j9ax6s61 — 2024-09-05T21:07:41Z

> [@ph00lt0](#):
>
> Your claim on zero access encryption is FUD.

On the webapp they would need to add one line of js to log your password, if they wanted.

---

## Post 6 by @ph00lt0 — 2024-09-05T21:16:09Z

Again complete FUD. If they would it is both illegal and putting them out of business.

---

## Post 7 by @asanyan — 2024-09-05T21:18:38Z

They could still do it if they wanted to, as there is no technological barrier preventing it, just a pinky promise. With all due respect I don’t see how it’s “FUD”

---

## Post 8 by @anon21060844 — 2024-09-05T21:30:51Z

asayan, I think you are referring to the “keys to the castle” dilemma. No one can know if the System Administrators aren’t reading, capturing, adding lines of code that the rest of us don’t see.  
The best we have is Open Systems, audits and “after the fact” reporting from others.  
So far most people do believe that Proton is offering a secure and safe set of services. No other proof has been presented to the contrary.

---

## Post 9 by @asanyan — 2024-09-05T21:40:08Z

Sure… I have nothing against Proton. I just don’t think it’s fair to call FUD because what was stated by the op is objectively true.

---

## Post 10 by @Cyber-Typhoon — 2024-09-05T21:40:38Z

> [@nobeke](#):
>
> And no, I don’t want their crappy VPN (linux user here), Pass or Drive. And I don’t need more than 15GB for mail.

Not defending Proton price strategy, which is quite questionable but why don’t you get the Mail Plus plan that is $4 a month in the yearly plan?

---

## Post 11 by @mentalfoss — 2024-09-05T21:56:47Z

Never liked Proton, the mentality to “put all your eggs in one basket” service was never good for privacy & security, historically.

Technically too, their apps are so aggressive pinging home by any chance given or not.

And by the road-map of their services and ecosystem they are trying to evolve, feels like taking a Neo-liberal market catch approach.

So by the end of the day i feel you, you are not alone.

---

## Post 12 by @asanyan — 2024-09-05T22:01:12Z

To reply to the actual OP, I can relate.

Paying for e-mail doesn’t seem worth it, the usefulness of something like Proton is limited to reducing miscellaneous data Google can collect, though the contents of the emails themselves are readable by Google as most people use Gmail.

Disroot seems to be a promising alternative, but they are a political organization which can be a problem.

---

## Post 13 by @xe3 — 2024-09-05T22:06:32Z

> “zero”-access encryption - oh yea, it could be bypassed by proton. And the emails are stored unencrypted on the other side’s big-tech servers anyway. _But still, I like it and it’s better than nothing._
> 
> > Now, that’s just an absurd take
> 
> > Your claim on zero access encryption is FUD

As I understand it, This is a long known “vulnerability” (“tradeoff” would probably be a better term). I think this wouldn’t be contentious if it wasn’t Proton being discussed. The point of _zero knowledge encryption_ is not needing to rely on trust/law/policy, so when that isn’t the case, its worth being aware of.

While I understand the sensitivity towards things that can read like FUD about reputable respected orgs like Proton (since we constantly deal with so much FUD in the privacy space), I don’t think it is a fair characterization of OP’s statement unless they claimed it made Proton’s encryption useless or horribly insecure (which would be untrue), but I don’t believe OP is intending to imply that.

My (basic) understanding is that this is just simply a limitation/tradeoff that comes from choosing to offer webmail (trading some security, for more convenience/usability). I don’t think its an issue specific to Proton (my mail provider makes similar compromises because even for security/privacy focused organizations, security/privacy isn’t the sole priority).

If I understand correctly, Proton even alludes to this risk in their threat model:

> Another attack vector would be if an attacker somehow gained access to Proton Mail’s servers in Switzerland without us noticing. Such an attacker could conceivably change the Proton Mail software to send bad encryption code to users’ browsers that would somehow allow the attacker to get unencrypted data. Proton Mail has implemented numerous safeguards against this on the server level which make this a difficult attack to pull off successfully in an undetectable way.

I _do not_ believe this makes Proton a bad or insecure service, its a very good service made by thoughtful and serious people. It’s just something to be aware of.

---

## Post 14 by @nobeke — 2024-09-05T22:10:16Z

I probably didn’t express myself very well. I’ve edited my post.  
I mean, I really do like what they are doing with _zero-access encryption_  
And I know that it’s fundamentally impossible to make it better, more private or more secure.  
But I don’t like how they call it, because it’s a bit misleading.

---

## Post 15 by @nobeke — 2024-09-05T22:12:00Z

Mail Plus does not include unlimited aliases.

---

## Post 16 by @bigdzi — 2024-09-05T22:47:21Z

Long time Proton user here, so I think its ok for me to jump right in :slight_smile:

> [@nobeke](#):
>
> Mail Plus does not include unlimited aliases.

True, but there is simple workaround this: free [addy.io](http://addy.io) account (offers unlimited aliases), create it, set real email address (in [addy.io](http://addy.io)) to your Proton one, install addy extension, and you are free to go :slight_smile:

> [@nobeke](#):
>
> Tuta is great,

@nobeke not so much. Ive been with them for 2 years and, well, thats enough of them :slight_smile:

As of [mailbox.org](http://mailbox.org): UI-wise it feels like middle of '90 but the service itself is outstanding.  
Havent tried Posteo.

> [@nobeke](#):
>
> When I pay for email and simple-login, I feel like I am literally being robbed.  
> I would pay: $48 mail + $30 login /12 = **$6.5 per month**

As for separate payments for Proton and SL: this is not true. When you buy `Proton unlimited` you get SL Premium for free. **For one, flat price**.

> [@nobeke](#):
>
> And I don’t need more than 15GB for mail.

Believe me, **you do need**. Start sending/receiving mails with attachements (say, JPGs) and you will see.

> [@nobeke](#):
>
> no contact sync

Again, not true at all. When I created Proton account, there was a wizard to import contacts from . Worked like a charm.

> [@nobeke](#):
>
> no Fdroid repo / dependency on google play services

True.

> [@nobeke](#):
>
> - aggressive, awful and misleading marketing (tbf I’d say, it’s slightly improved over time)
> - not releasing calendar source code

Have no idea/dont care one bit.

> [@nobeke](#):
>
> and probably more…

Probably. Just remember: no service is perfect.

> [@nobeke](#):
>
> Then the Proton Docs were announced … the amount of money and time it had to take… when most of their services are not even in a decent state!

Not using. So will not start this convo.

> [@nobeke](#):
>
> And then I read about Proton Scribe. That was the last straw.

I dont like Scribe either, but, instead of quiting, I just dont use it.

---

## Post 17 by @Cyber-Typhoon — 2024-09-05T23:11:43Z

Correct. I keep managing the 20 available (10 Proton and 10 SimpleLogin) like I do with the 15GB space and find it enough for my case.

---

## Post 18 by @beantaco — 2024-09-06T01:07:00Z

As @xe3 said, I think OP’s claim about zero-access encryption bypass is reasonable and shouldn’t be dismissed as FUD. In the absence of OpenPGP E2EE, it’s _technically possible_ for Proton to steal email plaintext as emails enter/exit their server. This is a valid concern shared by email users considering email leakage that happened under PRISM, worthy enough to warrant using OpenPGP. Law/policy shouldn’t be relied upon for security. I recall (maybe incorrectly) that Proton discussed this and suggested OpenPGP for E2EE.

However, considering Proton’s track record to date, I don’t think it’s probable or likely risk that Proton routinely bypasses the zero-access encryption. It might happen to a specific user if Proton is served a valid court order though.

---

## Post 19 by @beantaco — 2024-09-06T01:12:11Z

I don’t like the idea of putting my email, VPN, calendar, files, passwords etc into a single service, let alone a service that requires internet access. It might be a good idea to use just part of the suite (for example just email) for non-critical use cases, and don’t rely on Proton for any critical use cases.

---

## Post 20 by @ikelatomig — 2024-09-06T05:26:39Z

> [@bigdzi](#):
>
> free [addy.io](http://addy.io)

How about DuckDuckGo’s email protection service ?

> [@bigdzi](#):
>
> When I created Proton account, there was a wizard to import contacts from. Worked like a charm.

I think OP is referring to sync with device contacts like Google contacts.

> [@beantaco](#):
>
> I don’t like the idea of putting my email, VPN, calendar, files, passwords

Indeed, no one should. It may be good for beginners or novices or senior citizens.

Personal opinion : Tuta, Filen, Bitwarden. VPN, It’s a precarious narrative most people don’t need one and depends on their threat model. Generally for VPN, I would advise using a DNS based filtering and rely on your ISP as everything is encrypted TLS. And use free VPN services such as Proton or Windscribe in the case, where you need to hide something from ISP.

---

## Post 21 by @nobeke — 2024-09-06T11:59:50Z

Thanks for your reply and suggestions!

> [@bigdzi](#):
>
> not so much. Ive been with them for 2 years and, well, thats enough of them

@bigdzi May I ask why?

> [@bigdzi](#):
>
> As for separate payments for Proton and SL: this is not true. When you buy `Proton unlimited` you get SL Premium for free. **For one, flat price**.

I know, I complained about the unfair disproportion in pricing:  
$6.5 for Mail and SL vs $8 for unlimited  
But that is probably just my internal problem rather than a valid criticism.

> [@bigdzi](#):
>
> Believe me, **you do need**. Start sending/receiving mails with attachements (say, JPGs) and you will see.

No, I don’t. :smile: I do a local backup and delete useless emails once in a blue moon and I am fine with that.

> [@bigdzi](#):
>
> Again, not true at all. When I created Proton account, there was a wizard to import contacts from . Worked like a charm.

Oh, I messed that up.  
I meant [automatic contact sync on android](https://protonmail.uservoice.com/forums/284483-feedback/suggestions/32521357-sync-contacts-with-phone-address-book).

---

## Post 22 by @ryanoyeah — 2024-09-06T14:26:34Z

> [@nobeke](#):
>
> no Fdroid repo / dependency on google play services

I don’t have google play services and all the proton android apps are working fine for me. I got them using obtainium. [https://apps.obtainium.imranr.dev/](https://apps.obtainium.imranr.dev/)

---

## Post 24 by @nobeke — 2024-09-06T14:50:25Z

But no notification then, I suppose.  
(Unless you also use [You Have Mail](https://f-droid.org/en/packages/dev.lbeernaert.youhavemail/))

---

## Post 25 by @Gh0st — 2024-09-09T20:03:13Z

I personally use Riseup and have for years, however it’s invite only and have paused invites temporarily. I also would wait on Black Friday deals for ProtonMail when it comes around. Best time to get it if you’re looking for decent prices.

---

## Post 26 by @KeepItSimple — 2024-09-10T18:35:31Z

> [@yes](#):
>
> Now, that’s just an absurd take. Please back your claims with actual facts/proofs.

But Zero Access is like a marketing trick? They do say private keys are generated client-side with their ‘trusted js’, yet you can not be sure about it, they can store a copy of it like Super easy. While zero knowledge is about client generates keys/passwords himself without service providing any ‘trusted js’…

Or as example Proton Drive is zero-access. Cryptomator container stored on Proton Drive is zero knowledge.

---

## Post 27 by @bigdzi — 2024-09-11T19:09:56Z

> [@nobeke](#):
>
> May I ask why

Sure. Because no easy support of external mail apps.

---

## Post 28 by @M-A9NPV — 2024-09-12T00:34:15Z

I’m not hating, but I don’t get why people need/want notifications for email. Just check it a few times throughout the day. If something is time sensitive it should be be emailed or there should be a call/text ahead of time saying the email was sent be on the lookout.

---

## Post 29 by @Bhaelros — 2024-09-12T06:47:35Z

Try that in a business environment

---

## Post 30 by @bigdzi — 2024-09-12T16:00:07Z

Yea man, good luck with this approach in business setting…  
Truth is you’d be workless in no time…

---

## Post 31 by @camp — 2024-09-12T17:54:58Z

> [@nobeke](#):
>
> **zero-access encryption** - oh yea, it could be _EDIT: hypothetically_ bypassed by proton. And the emails are stored unencrypted on the other (senders) side’s big-tech servers anyway

I see this mentioned often and have a question. Although a copy of the email is on the senders server, if someone wanted to get access to your email, isn’t it still much harder with Proton?

What would their game plan be? Check every possible site you might use from the senders side? That sounds way harder than if the emails were stored unencrypted and everything is in one place for them.

---

## Post 32 by @whoami4 — 2024-09-13T06:52:27Z

> I don’t want their crappy VPN (linux user here)

Linux user here as well. What about phone VPN?  
I actually use proton VPN on the phone and in one browser where I want to control country (browser extension). Otherwise for the rest of the system I have Safing’s Portmaster (payed in Monero yayy). I found that to be the best combo.

> Then the Proton Docs were announced … the amount of money and time it had to take

I don’t think time. They acquired Simple Notes and I think they mostly copy/pasted their solution. Also note that

a) Each team has different expertise, its not like you can have e.g. calendar developers and make them work on VPN.

b) that also mean you need to find specific developers on the market for particular case, which is not easy, trust me I am a developer :grinning_face:

c) Also there is only so much developers you can use at a time - its like if you want to dig a hole. If you put 100 people (instead of e.g. 5) for a 5x5 hole you will probably slow the process down.

Just to let you know, its not alwasy black and white. Good or bad.

---

## Post 33 by @anon23293884 — 2024-09-16T23:28:08Z

> [@whoami4](#):
>
> They acquired Simple Notes

Just to be clear, they [aquired](https://proton.me/blog/proton-standard-notes-join-forces) Standard Notes  
and [aquired](https://proton.me/blog/proton-and-simplelogin-join-forces) Simple Login

---

## Post 34 by @whoami4 — 2024-09-17T07:49:31Z

Yes, my bad, I meant Standard Notes, thanks :slight_smile:

---

## Post 35 by @anon32558482 — 2024-09-17T11:27:14Z

I have my voip set to send all voicemail and sms to my Proton account if the sip app isn’t running. I need real-time email notifications.

---

## Post 36 by @certainty — 2024-10-06T20:30:56Z

> [@KeepItSimple](#):
>
> But Zero Access is like a marketing trick? They do say private keys are generated client-side with their ‘trusted js’, yet you can not be sure about it, they can store a copy of it like Super easy. While zero knowledge is about client generates keys/passwords himself without service providing any ‘trusted js’…

Hypothetically, does this hold good for other providers [recommended](https://www.privacyguides.org/en/email/) by Privacy Guides?

---

## Post 38 by @anon82275511 — 2025-01-01T18:49:01Z

> [@nobeke](#):
>
> have their own problems (mail spoofing drama etc.)

Can you please describe it? Actually, I’m going to take a paid plan in Posteo and Mailbox, so I need to know that.  
I was a user of both Proton and Tuta, as I only receive mails, so I didn’t face any major problems, but there are mainly two reasons for switching.

- Their strongest level of encryption only works under the same provider, which is not possible most of the time.
- They are building their own ecosystem, which I really don’t like. I always prefer decentralisation in privacy.

---

## Post 39 by @ETA08 — 2025-01-02T04:42:30Z

Personally, I have been using the Mail plus with simple login premium like you were talking about. It is expensive and I was originally on proton unlimited, but I want to spread my eggs out a bit. I understand the frustration. I hate how proton is pricing things, but I must say that it is a great starter option for someone looking to begin their privacy journey.

---

## Post 40 by @brinerustle — 2025-01-02T11:50:41Z

I’m using mega (drive and vpn), riseup (mail), disroot (calendar / contacts via nextcloud) and syncthing for keepass databases

---

## Post 41 by @anon39279085 — 2025-01-02T11:52:13Z

I uh wonder why mega exactly?  
Do you really trust them by any chance? Then again it varies from person to person but like why not Mullvad + Protn Drive (Or Tuta Drive if that comes out?) for example.

---

## Post 42 by @brinerustle — 2025-01-02T12:02:30Z

because I want a zero-knowledge solution, and MEGA offers a lot of space at a very reasonable price. But I´d like to self-host a nextcloud when i get the hardware to do so.

---

## Post 43 by @anon39279085 — 2025-01-02T12:05:29Z

I see but why not say a Filen + ProtonVPN right.  
it basically costs:  
30 Bucks lifetime for 100 Gigs of Filen  
with 10 bucks a month on Proton or free depending on how you wanna use it.  
If you want to buy the vpn why not a Mullvad solution for 5 bucks per month.  
Even then, proton unlimited, 13 bucks a month and you get 500 Gigs of Drive + ProtonVPN, much better deal
