Proton seems to be working on its own web browser

While Proton appears to be creating this suite to appeal more to businesses, this makes me just question further their “commitment to privacy.” No business I’ve ever worked at was more interested in their employees’ privacy than keeping malware and spam at bay (i.e. proxies, etc) and blocking inappropriate or potentially dangerous websites. Heck, my current employer even has a “There is no expectation of privacy” policy pop-up when you login. Nothing wrong with the business protecting itself, but that necessitates privacy sacrifices. So this can only be fiscally motivated.

And before folks defend Proton’s “privacy-centric” claims, please read this analysis in its entirety. They have a history of turning over user data the vast majority of the time with NO fight, and their claim that they can’t access your e-mail is only true for intra-Proton communications.

5 Likes

What you’re describing about Proton AG is called “smoke” or, in other words, they’re selling you smoke.

As far as I’m concerned, a new “browser” is nothing new. Proton is already inconsistent; you don’t have to be an expert to see that.

2 Likes

And before folks defend Proton’s “privacy-centric” claims, please read this analysis

I saw the highlight, I sat here and crossed my fingers on my left hand, while whispering to myself before clicking, “please don’t let this be something from r/Degoogle or piece written by Sam Bent, please don’t let this be something from r/Degoogle or piece written by Sam Bent,”

…sigh.

Oh, does the source make it factually incorrect?

1 Like

groan.

…why, yes. yes it does.

Please enlighten us poor uneducated folk.

1 Like

The thing is - the idea of a new browser on the market is not useless in general if you have something, at least slightly, new to offer. Until a certain threshold it’s always better to have a choice in tools then not to have any. The idea of having every single tool in your ecosystem is not useless as well, if that’s will be and easier option to gain privacy for general public.

What is useless:

  • wasting resources, which other products desperately demand
  • doing another chromium reskin (with probably heavy integrations of own stuff like vpn, lumo ai, simplelogin; basically creating another brave browser)

I have no opinion on Proton developing a new browser. I will try to build me an educated opinion when (and if) it’s out.

That said, a couple of facts that, I think, deserve to be reminded concerning the side discussions happening here :

  1. Proton does not lock you in. All their clients are open source (with admittedly a poor record in terms of documentation, but it’s getting better) and they are releasing their common (open source) SDK supporting all their apps, to allow anyone to build interoperable software. Plus they respect standards and make it easy to export data, so that migrating in or out is very easy.
  2. Proton Mail supports the WKD standard, which allows any user from any email provider to automagically encrypt (in OpenPGP) emails sent to any Proton user without having to deal with keys or know anything about email encryption. Only condition : having a decent email client that supports WKD (i.e. not Outlook, not GMail, not Apple Mail, as they refuse to add 2 lines of code to support WKD; I know, it rules out 77% of emails, but hey, Proton did their share for encryption interoperability and adoption). Plus WKD allows every Proton users to automagically encrypt their outgoing emails to any non-Proton recipients whose email domain supports WKD (clearly, not the case of Microsoft, Google or Apple domains…) without having to ever deal with keys or know anything about email encryption too.
  3. Firefox is not (anymore) a privacy friendly option. It now contains closed source blobs, telemetry, fingerprinting and all the shit, maybe because of some of their sponsors. I’d rather recommend LibreWolf on Linux or Fennec on Android (hardenened forks where the blobs were removed).
  4. Proton is under Swiss jurisdiction (and has contingency plans to leave Switzerland swiftly in case Swiss law becomes hostile to privacy). This means that even in the case it would collect personal data in some apps, they must thoroughly justify to Data Protection Authorities the reason why they collect each data point and possibly ask for explicit consent depending on the nature of the data point. In any case, they are not allowed to make that data accessible (sharing, selling, leasing, opening) to any third party except law enforcement, which itself must thoroughly justify why they request some data.

To go back to the main topic, I don’t see why I would ever use Proton Browser, but I still think it would make sense to push a lot of Chrome/Edge/Firefox users towards more privacy-friendly products through service integration and neat design. (I don’t like the “neat design” argument, but let’s face it, it’s an incredibly powerful weapon to make large masses move).

And -let’s dream- maybe Proton Browser will just be a fork of Ladybird (which they sponsor) with some integrated Proton services, like what Google did with Chromium and Chrome, but on the bright side of the Force.

2 Likes

Just noticed this tweet from Proton Drive, and it made me curious about a couple of things.

  1. Is Proton trying to create a European private browser?

In other words, are they motivated by European sovereignty, even if there are great privacy browsers that are not based in Europe?

  1. Is this why Proton collaborated with Vivladi?

I had no idea Vivaldi was a European project, but I have personally never been impressed by it as a privacy browser. I never even considered it as such. The fact that Proton chose to collaborate with them instead of Brave and Firefox, who are established, or any much smaller project like, say, Zen, makes me wonder if they were motivated by European sovereignty more than privacy.

I could be wrong, but I am starting to believe that Proton would never collaborate with any non-European privacy company/service, no matter how great it is, just because they are not based in Europe. In recent interviews Andy Yen, Proton’s CEO has talked a lot about European sorvereignty, not just as a strategy for Proton, but as a political and economic strategy for Europe,

  1. If my intuition is correct, is Proton’s European sovereignty strategy wise?

I’m not sure, but I am currently leaning on no. In and of itself, being European does not make a service inherently good or better. It’s a positive feature from a data sovereignty POV, but if the service itself is terrible for privacy, it being European brings little value.

I hope it is something in this direction, but I highly doubt it, considering the potential browsing impact this would have and them probably wanting this to be a viable enterprise solution too

I agree with the ADD-ish nature of Proton’s decision-making. What happened to Proton’s notes app? Where’s a Linux client that doesn’t suck for most of its offerings? Do people even use Lumo? It’s like me with hobbies when I was 20 - get interested, get the beginner stuff, do it four times, lose interest, move on to the next project idea.

I guarantee they saw Brave getting tech bro attention, next to questionable ethics issues with Brave’s financing and then Mullvad’s CEO issues, and thought “hold my beer.” It’s not that they need to turn a profit with their browser, it’s branding on your desktop. They’re going to fork some chromium browser, weld on an ad blocker, and call it a day. When presenting European-owned business stacks, they can proudly, and accurately, say “yep, we have one of those, too.” Claude will code 95% of it.

I wouldn’t even care about this at all, or even be cautiously hopeful, if there weren’t other, lingering projects that aren’t fully polished or finished. To me, this also screams increasing attack surface for a company that claims privacy and security. Do we trust that’s being managed well? That’s not part of their audits AFAIK.

People, if you use Proton for your email, get a custom domain first. Pay the money, because this might be a 10-year ride with Proton, it might be a 5-year ride. That personal security of being able to take your email address with you will save you headaches down the line. I say this as a paid Proton user. Trust yourself before you trust a tech company. Any tech company.

5 Likes

I think I hit my maximum daily dose of negativity in just one post. Absolute day ruiner.

Firefox, Tor Browser, and Mullvad Browser are all Gecko-based, and Gecko has very real security downsides.

Brave is decent, but also has issues, like all the bloat and adding back things like MV2, which weakens security.

One thing Proton Browser could do here is have no bloat and try to eliminate the need to trust JavaScript with their products, which they already experimented with, but with extensions. That would make it a very good browser for Proton users.

As for Signal and SimpleX, neither is actually good. Signal still requires a phone number and has some other issues, while SimpleX isn’t a viable option for the mainstream because of its current UI/UX situation. So your point that we have an abundance of good options completely falls apart here.

That’s literally the point. People want an ecosystem and suite of apps for their work and productivity.

Proton’s goal is to provide a private, secure, and more freedom and user respecting alternative to Google’s, Apple’s, and Microsoft’s ecosystems. If you don’t like that, go use something else.

3 Likes

European sovereignty doesn’t guarantee privacy, but both are some what related, though.

The point here is that a European product is bound to European Law, which is not perfect but is, to date, the most privacy-friendly law.

When you collect users’ data or metadata (and you always do, at least a little bit), being bound to US law means you must make your customers’ data available to authorities, with barely any restrictions. Being bound to European law won’t completely prevent European authorities to access your customers’ data, but it’s much more restricted. (And Proton is actively lobbying to make European law even more privacy-friendly).

Plus, a European-based company or organisation must abide to higher standards of data protection, or they can be heavily fined. For example, it is strictly forbidden to share customers’ data to third-parties like advertisement companies or data brokers, unless the user has explicitly consented to it. Here, explicitly means they had to carry out actions (like clicks) to opt-in. Consent by default (even with opt-out possibility) is not permitted. It is also forbidden to collect customers’ data that you cannot demonstrate that you really need it to run your service.

For privacy purpose, that’s the whole point of having European alternatives, which then mechanically relates to European sovereignty.

Besides these rational arguments, there might be some hard feelings from Proton founders against the USA. Proton was founded by CERN scientists out of rage after discovering (from Vault7 and the Snowden files) that they had been heavily spied on by the US intelligence agencies for years, in the context of heavy competition between CERN’s LHC and the US attempt to build a competing particle accelerator. And all that spying was mostly done through Microsoft, Google and other US Big Tech products, with the active collaboration of those companies (who have billion-dollar contracts with the US military and intelligence).

3 Likes

Proton couldn’t care less about your privacy; Proton Browser will serve no other purpose than to collect even more metadata. Whether or not Gecko has security issues, it remains a reliable option, just like Brave, and soon we’ll have Ladybird – Proton won’t offer anything extra

As for Signal, which requires a phone number, they’re considering removing that requirement – and don’t go thinking that Proton Chat will be any better than SimpleX; only the user experience is likely to be an improvement.

Proton’s aim is simple: to lock you into their paid ecosystems whilst harvesting as much metadata as possible under the guise of privacy.

I’m starting to think that Proton is a honeypot; this proliferation of services is more than a bit suspicious, in my view and that of others.

I can’t wait for Tuta to release its Drive in public beta so I can leave this ‘Google clone’ ecosystem.

the product no one asked for.

1 Like

Collecting more user data is an economic model. It’s only meaningful if you can monetize that data.

In European law, monetizing personal data is strictly forbidden, unless users have explicitly consented to it, meaning they had to carry out explicit actions to opt-in, which nobody does, even the average Joes and Janes. And “dark patterns” to push someone into opting in, not really knowing what they do, is also forbidden.

So really, for a European software company, even if they don’t really care for privacy, there is no point in collecting more users data than what they need to run their service or abide by law. There’s actually a risk in doing so because fines for doing so can be very heavy.

1 Like

“If I had asked people what they wanted, they’d have answered ‘faster horses’”

  • Henry Ford (possibly… But as Napoleon said, don’t trust everything you read on Internet)
2 Likes

Proton is a great company, but I don’t think this product diversification strategy is a positive thing. Are they enshittifying in order to get a larger number of users, or are they shooting themselves in the foot? At the end of the day, their biggest problem is that, despite having very good products like Mail, Pass/SL and VPN, others are half-finished: Drive (they need to improve the macOS client and offer one for Linux), Lumo (it got much better with the switch to GLM 5.2, but the app’s UX is pretty bad since there’s no native application), the payment/subscription system (they don’t allow separate subscriptions for Lumo and Unlimited, for example), Calendar (fairly basic but functional).

They say they have a team for each service and that releasing new products doesn’t affect the development of the rest. But I don’t buy it. Without this diversification I think they’d have more resources to improve their existing products.

With this strategy, the trust we subscribers have in Proton drops considerably. Many of us pay not only for the current quality but also for the promises they make about the future, and to support the company. Those promises aren’t being kept. For example, they said Visionary users would always have the best services available; now we find that the Standard Notes subscription isn’t included and that they’re going to limit usage on Lumo.

A browser like Proton’s has its niche, especially when trust in Proton is high. I use Brave, and if Proton’s is based on Chromium I’ll happily switch to it, because Brave is a great browser, but with a fairly questionable track record and CEO.

6 Likes

I think it has legs but god damn it’s disappointing that it’s probably going to be another Chromium browser. I’m still holding out hope that Ladybird can against all odds do the impossible and become the fourth internet browser.

Proof?

That’s an empty assumption. Also, what metadata does Proton currently collect and why does Proton need it so much?

Another pointless assumption.

Third pointless assumption.

Their aim is to lock you into their ecosystem, but they have separate plans and offers for each of their products, coupled with the ability to easily export your data and move to other services. Yeah, right.

Baseless accusation? What proof do you have of Proton being a honeypot?

You have a big issue with Proton expanding their business but have no issue with Tuta, which is a company that actively promotes scammers and grifters like Murena, Volla, etc., who make insecure devices and services that put people at actual risk while marketing them as the cream of the crop.

3 Likes