# Secure encryption and online anonymity are now at risk in Switzerland

**URL:** https://discuss.privacyguides.net/t/secure-encryption-and-online-anonymity-are-now-at-risk-in-switzerland/26181
**Category:** News
**Created:** 2025-03-26T19:07:00Z
**Posts:** 72

## Post 1 by @jonah — 2025-03-26T19:07:00Z

> **[Secure encryption and online anonymity are now at risk in Switzerland –...](https://www.techradar.com/vpn/vpn-privacy-security/secure-encryption-and-online-anonymity-are-now-at-risk-in-switzerland-heres-what-you-need-to-know)**
>
> NymVPN, Proton, and Threema are ready to fight back

> The changes – which experts argue will put people’s anonymity and secure encryption at risk – would widen the net of impacted service providers to virtual private networks (VPNs), messaging apps, and social networks, having previously only impacted mobile networks and internet service providers (ISPs).

---

## Post 2 by @anon36940904 — 2025-03-26T19:16:35Z

Well… shit.

(I got nothing else to say for now..)

---

## Post 3 by @anon29374801 — 2025-03-26T19:30:40Z

> It’s important to note that the current amendment is not subject to a parliamentary vote or public referendum under Swiss law.

That to me feels like the most concerning part in terms of the ability to fight this.

---

## Post 4 by @anon39279085 — 2025-03-26T19:36:27Z

That pretty much summarizes everyone reactions, our last bastion of privacy friendly country. Now torn in pieces.

---

## Post 5 by @anon36940904 — 2025-03-26T19:38:40Z

We will still have to wait and see what actually happens. But this is terrible news nonetheless.

---

## Post 6 by @phnx — 2025-03-26T20:01:03Z

So much for direct democracy. :face_with_diagonal_mouth:

---

## Post 7 by @anon36940904 — 2025-03-26T20:05:12Z

I’m pretty sure 404 Media will report on this should anything major happen. Atleast I hope they do.

---

## Post 8 by @anon98488147 — 2025-03-26T20:05:52Z

Did Switzerland even try to provide a rationalization for this?

---

## Post 9 by @ignoramous — 2025-03-27T07:32:15Z

> [@jonah](#):
>
> NymVPN, Proton, and Threema are ready to fight back

Between this, [this](https://discuss.privacyguides.net/t/google-refuses-to-deny-it-received-encryption-order-from-uk-government/25803/12), and [this](https://discuss.privacyguides.net/t/google-refuses-to-deny-it-received-encryption-order-from-uk-government/25803/5), all 3 of PG’s recommendations won’t / don’t meet min criteria for VPNs?

* * *

May be I’m mistaken, but I don’t find any criteria on PG for “secret backdoor mandates” for encryption software like Messengers? In fact, this criteria should also apply to Web Browsers, since (most) email providers & (some) messengers are accessible over web.

---

## Post 10 by @anon6884803 — 2025-03-27T10:33:36Z

I can see the point. Jurisdictions are important, and almost all the recommendations usually presented come from compromised jurisdictions (US, Sweden, France, India, etc.).

I think excluding all tools based on legislation made in origin country would mean no tool will pass the criteria. Adding warnings everywhere will make the site look ugly. A solution can be to rethink recommendations from scratch and only suggest the ones that have taken precautions to mitigate legislative threats, keeping in mind practicality.

For example, a tor based messaging app should have reproducible clients, a decentralized server one should have reproducible clients and verifiable servers, or have clear disclaimers about the extent of damage an actively malicious server can do along with a reproducible client.

Email clients should be reproducible. VPNs should have verifiable servers, and/or multi provider mixnet/hops, and/or protocols that preserve privacy/security by design. Reproducible clients and use of common protocol implementations instead of custom ones.

DNS providers should have public transparency logs that are immutable to discourage DNS poisoning, similar to CAs.

Cloud storage should have verifiable servers and reproducible clients, should also have immutable by design logs of file/account access that do not violate owner privacy.

Search engines and online services are easier since you can get away with using better access methods and maintaining anonymity.

Offline tools are easier, since you can just warn user to sandbox/VM/restrict them to contain damage if malicious. Reproducible preferred of course.

Browsers and operating systems are the hardest to check (although Debian recently became reproducible). I do not have an approach outside of extensive efforts by vendors for reproducibility (which is not even that useful given the amount of code to be reviewed making it easier to slip in things).

This is all very optimistic to the point of delusion I know, but projects are taking steps in the right direction. I think PG should also follow by keeping the recommendation a moving target as threats evolve. Don’t recommend things that half ass stuff they claim to protect against in threat models. Only show projects as harm reduction if they are not worth recommending. The less spaces like PG legitimize half baked solution, the more user pressure can be built to work on these features.

---

## Post 11 by @ignoramous — 2025-03-27T10:46:00Z

> [@anon6884803](#):
>
> I think excluding all tools based on legislation made in origin country would mean no tool will pass the criteria

For VPNs, in face of secret govt mandates, lot of guarantees simply fall apart. There’s no need for PG to continue to sell VPNs as things they are not. There isn’t any need to relax the criteria just to recommend encryption products whose cornerstone is … encryption. Ditto for identity masking services.

> [@anon6884803](#):
>
> excluding all tools based on legislation made in origin country would mean no tool will pass the

My point was specifically for e2ee email providers, messengers, & VPNs. And the clients folks use to access them (like Web Browsers).

> [@anon6884803](#):
>
> Email clients should be reproducible. VPNs should have verifiable servers, and/or multi provider mixnet/hops, and/or protocols that preserve privacy/security by design. Reproducible clients and use of common protocol implementations instead of custom ones.

:100: Should be adopted by PG as min criteria (which I don’t think _most_ PG recommended VPNs / e2ee Messengers / Email providers currently meet).

> [@anon6884803](#):
>
> The less spaces like PG legitimize half baked solution, the more user pressure can be built to work on these features.

Hear, hear.

---

## Post 12 by @anon6884803 — 2025-03-27T12:30:38Z

> [@ignoramous](#):
>
> For VPNs, in face of secret govt mandates, lot of guarantees simply fall apart.

I agree. Most commercial VPNs only have policy level protections right now, and act as your ISP. Depending on threat model, you might wish your government ISP to have/not have your data and prefer/not prefer VPN provider.

> [@ignoramous](#):
>
> My point was specifically for e2ee email providers, messengers, & VPNs.

I was more thinking out loud. I agree, at least services which have more policy based trust [VPN (trusted to not log), encrypted email (trusted to not read plaintext emails), messaging (trusted to not aggregate metadata)] should be the first movers on this.

---

## Post 13 by @jonah — 2025-03-27T14:02:45Z

> [@ignoramous](#):
>
> There’s no need for PG to continue to sell VPNs as things they are not.

How is our current approach in any way misleading? :thinking: This is **exactly** how we “sell VPNs” currently:

> [@anon6884803](#):
>
> Most commercial VPNs only have policy level protections right now, and act as your ISP.

> **[How Do VPNs Protect Your Privacy? Our VPN Overview - Privacy Guides](https://www.privacyguides.org/en/basics/vpn-overview/)**
>
> Virtual Private Networks shift risk away from your ISP to a third-party you trust. You should keep these things in mind.

---

## Post 14 by @anon6884803 — 2025-03-27T14:03:33Z

Can you quote where I said PG is misleading?

I was just suggesting that PG act less as a list and more as a catalyst. By clearly showing that no VPN passes the bar right now, you can create a positive pressure on companies to be the first mover.

This is again my vision of how privacy advocacy should work, the site is free to not do it.

---

## Post 15 by @jonah — 2025-03-27T14:06:00Z

Sorry, I was only replying to @ignoramous, who seems to agree with you but also thinks PG is falsely advertising VPN features.

---

## Post 16 by @anon6884803 — 2025-03-27T14:07:28Z

Ah, my misinterpretation then.

---

## Post 17 by @anon29374801 — 2025-03-27T14:15:08Z

> [@ignoramous](#):
>
> PG for “secret backdoor mandates” for encryption software like Messengers?

I am a bit confused about how a criteria like this could even be evaluated. If its a secret backdoor PG won’t know about it and, I am not sure there is any value in PG explicitly saying they would not recommend software with known back doors.

> [@anon6884803](#):
>
> I think excluding all tools based on legislation made in origin country would mean no tool will pass the criteria.

This is way to broad of a characterization.

> [@anon6884803](#):
>
> A solution can be to rethink recommendations from scratch and only suggest the ones that have taken precautions to mitigate legislative threats, keeping in mind practicality.

This solution is already there via people using the tool suggestion to recommend removing tools that no longer fit the criteria.

* * *

This topic seems to be getting off course and has become a bunch of criteria suggestions for all manner of categories.

---

## Post 18 by @anon6884803 — 2025-03-27T14:31:28Z

I disagree. The issue is about switzerland trying to making privacy invasive state surveillance laws, the response from me is about how this is becoming common and why I think PG should evolve its criteria with this in mind, especially since PG has ditched five eyes ideas without good reasons.

> [@anon29374801](#):
>
> This is way to broad of a characterization.

Name a country any of the Pg recs are based in, I can point to surveillance and gag order laws that are there or in the pipeline. I do not think the ostrich approach is good here. Most major privacy and security vendors agree and are actively working on mitigations.

So I am not sure what is “too broad” about saying “no tool will be left if PG only considers country of origin”. There are legitimate issues with US, France, Sweden, India, China, etc. all extending their hands to try to break legal and/or technical protections (with technical protections harder to modify compared to policy based protections).

> [@anon29374801](#):
>
> This solution is already there

No, it is actively blocked by PG not considering jurisdiction relevant as of now. Again, using a related discussion to talk about a meta change is not anything out of ordinary in a forum where topics do not exist in isolation. When news about “XYX country breaking privsec” comes out, it will lead to discussions about should countries be relevant and not just discussions about “XYZ is bad, hope they don’t pass the bill”. Otherwise all these topics can just be a RSS feed instead of a discussion.

---

## Post 25 by @KevPham — 2025-03-27T15:06:59Z

I’m sorry if you felt that your opinions aren’t being heard in any previous post.

We don’t a specific policy against including jurisdiction as a criteria for VPNs. Most of how we build our criteria is based on community consensus, so naturally there will be a lot of opposition or support depending on the topic itself. Feel free to DM me if there is a particular issue you noticed about forum discussion quality. I’ll take a look into any past discussions accordingly.

Anyways, this discussion is getting off-topic. I’ll delete most of the ad-homenien arguments here but keep the discussion open to on-topic discussion.

---

## Post 26 by @privacyisconsent — 2025-03-27T15:10:12Z

@ignoramous @anon6884803

The solutions here (leaning toward open-source, reproducibility) do not seem to fit the threat (legislative harms & access or compromise requests). Just so anyone might be able to help me understand: the threat example here is that the state (presiding over where the project’s representing organisation is located) passes a law that disallows registration to an online service without certain personal information.

How does an organisation like the Signal Foundation mitigate this?

---

## Post 27 by @anon6884803 — 2025-03-27T15:13:31Z

Having open source reproducible and verifiable systems protects against secret surveillance orders and gag orders, not active legislative harms.

It will not protect against “VPNs are illegal” but will protect against “We can secretly force VPNs to serve malicious clients to log all data” type of laws.

---

## Post 28 by @ignoramous — 2025-03-27T15:21:24Z

> [@jonah](#):
>
> How is our current approach in any way misleading? :thinking:

I didn’t mean it _is_ misleading; I meant it shouldn’t _continue_ to be misleading in face of UK/Swedish/Swiss laws etc; if and when they come to pass (if they aren’t being enforced already). UK’s IPA has been in force since 2016!

If I am allowed to be critical (and pedantic):

> - Hiding your downloads (such as torrents) from your ISP and anti-piracy organizations.

Can they in face of govt letters the providers or their partners (co-hoster, for example) are subject to?

> - Allowing you to bypass geo-restrictions on certain content.

Mostly true for VPNs with residential IPs. Not _generally_ true and hence there’s no need to mention it.

> good VPN providers will not cooperate with e.g. legal authorities from oppressive regimes

For sake of neutrality, must also include that the VPN providers themselves could be subject to draconian surveillance. “Oppressive regimes” sounds way too convenient (making folks reading it think … (Western) “democracies” must be fine).

> Another common reason encrypted DNS is recommended is that it prevents DNS spoofing.

Standardized encrypted DNS transport protocols offer no such protection.

> Other MPRs run by different companies like Google

Google has sunset their “One” VPN, afaik.

> protection by segmentation only exists if you trust the two companies to not collude with each other to deanonymize you

Don’t believe this is true for Apple Private Relay. The guarantees are baked into the protocol/cryptography itself? Which is what MPRs at minimum should be, imo.

> If you’re looking for additional _privacy_ from your ISP, on a public Wi-Fi network, or while torrenting files, a **VPN** may be the solution for you.

May be not? Such reasoning implies ISPs are less trustworthy than VPNs because of government letters … but we now know govt letters are expanding to cover VPNs just the same?

> We also think it’s better for the security of the VPN provider’s private keys if they use [dedicated servers](https://en.wikipedia.org/wiki/Dedicated_hosting_service), instead of cheaper shared solutions (with other customers) such as [virtual private servers](https://en.wikipedia.org/wiki/Virtual_private_server).

Why is this sentence repeated on that page? “also think” can be removed as it is _true_ that VPS’ slice of RAM is under the full control of the underlying Host OS (in _most_ setups).

> **Mullvad** is a fast and inexpensive VPN … **IVPN** is another premium VPN provider …

Premium? Inexpensive? Sounds sales-speak to me.

> **Bridges and proxies** : Mullvad also allows you to use bridges or proxies to reach their API (needed for authentication), which can help bypass censorship attempts that block access to the API itself.

Also true for Proton… I hit their APIs from virtually any which place and it almost always has worked.

> Mullvad is very transparent

Mullvad is transparent\*

> - Censorship resistance features designed to bypass firewalls without DPI.

Moot. All censors running a “firewall”, as they mature, eventually will employ DPI. That’s how this goes.

> - VPN servers that use full-disk encryption or are RAM-only.

Won’t matter on a VPS.

> While not strictly requirements, there are some factors we looked into when determining which providers to recommend. These include content blocking functionality, warrant canaries,

VPN providers subject to secret mandates can’t post canaries …

---

## Post 29 by @privacyisconsent — 2025-03-27T15:27:58Z

OK. So, the developer provides reproducible builds of their client, and presumably there are independent parties doing reproducible build verification to verify successful builds, maintain a transparency log of all production builds and also external and inbuilt infra for end users to counter-check that the builds they are receiving match those in the transparency logs.

This would remove the vendors ability to serve **targeted** updates, right? They are not prevented from serving malicious updates (through malicious code), but of course there is a reliance on the non-vendor parties involved to try and catch anything foul. As another criterion or bonus, would a rich variety of reproducible third-party clients also help here? Then the vendor has potentially no control over the client at all potentially (beyond spec and how the client needs to communicate with the server).

---

## Post 30 by @ignoramous — 2025-03-27T15:33:12Z

> [@privacyisconsent](#):
>
> Then the vendor has potentially no control over the client at all potentially (beyond spec and how the client needs to communicate with the server).

As a service provider or app developer, remote attestation and reproducible builds are a pretty _good_ defence against powerful 3p adversaries (like, govts). It is a bit like Certificate Transparency, in a sense; in that, you place your _trust_ in the service provider / app developer and no one else. Attestation and Reproducibility are keystones atop which that trust can be anchored _cryptographically_ (see also: Secure/Trusted/Verified Boot).

---

## Post 31 by @PurpleDime — 2025-03-27T15:34:47Z

The is why I think it’s wrong to believe that encryption solves everything when it comes to online privacy, which I think Naomi Brockwell (lover her!) sometimes leans too hard on.

---

## Post 32 by @jonah — 2025-03-27T15:42:56Z

> [@ignoramous](#):
>
> Don’t believe this is true for Apple Private Relay. The guarantees are baked into the protocol/cryptography itself? Which is what MPRs at minimum should be, imo.

If it were true that it is impossible for the server providers working together to deanonymize someone, there would be no need for two different server providers at all. Apple could simply run two different servers on their own and say the protocol between them protects users (which isn’t true).

> [@ignoramous](#):
>
> Google has sunset their “One” VPN, afaik.

So has INVISV. [update: Remove mention of specific MPRs by jonaharagon · Pull Request #2981 · privacyguides/privacyguides.org · GitHub](https://github.com/privacyguides/privacyguides.org/pull/2981)

> [@ignoramous](#):
>
> VPN providers subject to secret mandates can’t post canaries …

As far as I know this has never actually been tested, so you can’t say this with confidence. Warrant canaries are an _attempt_ to defend against secret mandates, and such attempts are still worthwhile until it is proven that they are ineffective.

All of this ignores the fact that recommending VPN providers in the face of potential secret government mandates still would not be misleading, because we don’t claim VPNs protect against government surveillance like this in the first place.

---

## Post 33 by @privacyisconsent — 2025-03-27T15:51:25Z

From my understanding Certificate Transparency is a reactive security measure. Both of you have taken the time to explain that the mentioned processes/techniques are “a pretty good defence” or “protection”, but just to be sure I am understanding correctly these measures _disincentivise_ by increasing the chance the chance of exposure, rather than prevent the problem we are talking about, right?

---

## Post 34 by @ignoramous — 2025-03-27T16:06:52Z

> [@jonah](#):
>
> If it were true that it is impossible for the server providers working together to deanonymize someone, there would be no need for two different server providers at all.

I meant, as far as I have looked at the spec (Privacy Pass, specifically), Apple has designed Private Relay in a way that despite collusion (network side; excluding clients), “anonymity” guarantees remain. Also a reason why (I think) Privacy Pass could potentially be adopted by the Tor community (if they haven’t). I hope I am not wrong, but I am also not a cryptographer…

> [@jonah](#):
>
> As far as I know this has never actually been tested, so you can’t say this with confidence.

From what I’ve seen, such mandates / laws usually literally spell it out that businesses/orgs cannot post alerts/canaries. Or: It wouldn’t be “secret” surveillance, no?

> [@jonah](#):
>
> update: Remove mention of specific MPRs by jonaharagon · Pull Request #2981 · privacyguides/privacyguides.org · GitHub

Ah. Might also want to remove non-neutral / weasel words / sales-speak (inexpensive, premium, very transparent etc).

---

## Post 35 by @ignoramous — 2025-03-27T16:13:04Z

> [@privacyisconsent](#):
>
> From my understanding Certificate Transparency is a reactive security measure.

Can’t speak for @privacybaddie (or whoever @anon6884803 is) but:

“Trust” is what I am after. If I can trust an app developer to only ever build, ship, deploy whatever was in the public code repository (reproducible builds / remote attestation), that’s enough. As once they pwn when no one is looking… that record would be public, and from then on, they’d have lost my “trust”, if no one else’s.

Without attestation / reproducibility, I have no way to base my trust on something concrete, and I’d rather not rely on pinky promises in EULAs / T&Cs (especially when govts are passing laws that require these developers / providers to never talk of backdoors / secret surveillance publicly).

---

## Post 36 by @privacyisconsent — 2025-03-27T16:36:05Z

> “Trust” is what I am after. If I can trust an app developer to only ever build, ship, deploy whatever was in the public code repository (reproducible builds / remote attestation), that’s enough. As once they pwn when no one is looking… that record would be public, and from then on, they’d have lost my “trust”, if no one else’s.

I very much agree with welcoming measures that significantly lower the barriers to exposing maliciousness. However, I notice here that you have talked about the app developers and the shipped client but not talked about the service provider. Am I right in understanding that the service provider is irrelevant in this case and as long as the app developer (third-party or not) employs those measures (publicly hosted code, verified reproducible builds, remote attestation) this would be acceptable?

---

## Post 37 by @fria — 2025-03-27T16:45:51Z

> [@ignoramous](#):
>
> I meant, as far as I have looked at the spec (Privacy Pass, specifically), Apple has designed Private Relay in a way that despite collusion (network side; excluding clients), “anonymity” guarantees remain. Also a reason why (I think) Privacy Pass could potentially be adopted by the Tor community (if they haven’t). I hope I am not wrong, but I am also not a cryptographer…

I’m not sure what Tor would need a blind signature system like this for since you don’t need to authenticate anything. Private Relay needs to authenticate you as an Apple user.

---

## Post 38 by @ignoramous — 2025-03-27T17:32:31Z

> [@fria](#):
>
> I’m not sure what Tor would need a blind signature system like this for since you don’t need to authenticate anything

Some ([only Cloudflare](https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/24321) & [hCaptcha](https://www.hcaptcha.com/privacy-pass)?) propose Privacy Pass as an alternative to endless captchas to prove one is a human and not a robot. For the Tor Browser specifically, I guess, the proposal went no where…

> [@privacyisconsent](#):
>
> However, I notice here that you have talked about the app developers and the shipped client but not talked about the service provider

The points should apply equally to both apps & services.

---

## Post 39 by @fria — 2025-03-27T17:37:19Z

> [@ignoramous](#):
>
> Some ([only Cloudflare](https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/24321) & [hCaptcha](https://www.hcaptcha.com/privacy-pass)?) propose Privacy Pass as an alternative to endless captchas to prove one is a human and not a robot. I guess that proposal went no where…

Ah right yeah that would be really cool. There’s a proposal for a browser API called [Private State Tokens](https://developers.google.com/privacy-sandbox/protections/private-state-tokens), that would essentially take care of the problem for all browsers. Cloudflare and Apple have [Private Access Tokens](https://blog.cloudflare.com/eliminating-captchas-on-iphones-and-macs-using-new-standard/) already. I guess the main thing holding it back is everyone has their own standard lol.

---

## Post 40 by @anon55464882 — 2025-03-27T20:24:22Z

> [@anon39279085](#):
>
> […] our last bastion of privacy friendly country. Now torn in pieces.

Despite its reputation, Switzerland has never truly been the ultimate haven for privacy that many believe it to be.

---

## Post 41 by @anon36940904 — 2025-03-27T20:27:09Z

Well that’s not true at all.

---

## Post 42 by @anon55464882 — 2025-03-27T20:28:52Z

In Swiss legislation, there have been and continue to be many ambiguities and gray areas regarding the handling of personal data and privacy rights, such as the legal classification of VPNs. In my opinion, it was only a matter of time before this topic would be addressed politically and judicially

---

## Post 43 by @Cyber-Typhoon — 2025-03-27T21:59:49Z

> **Offtopic**
>
> I don’t know why but I ended up remembering that the Session messenger app moved or are moving to Switzerland.
> 
> I wonder if they will need to move again. :sweat_smile:

---

## Post 44 by @RevealedInWords — 2025-03-27T23:14:50Z

Very true… Switzerland is not the privacy panacea many promote it to be.

New probe shows Switzerland’s involvement in “spectacular” international spy scandal—The Local: [https://archive.is/2A6lv](https://archive.is/2A6lv)

Swiss report reveals new details on CIA spying operation—Washington Post: [https://archive.is/S1qzE](https://archive.is/S1qzE)

CIA spying scandal in Switzerland shows the best way for intelligence services to read your messages is to OWN the platform—RT: [https://archive.is/oCJOn](https://archive.is/oCJOn)

[Note: Not sure why the actual archive.is links are changed to the name of each article, and if I post just the archive.is links (without the name of the article), just the arhive.is link appears and not the name of the article. Strange…]

---

## Post 45 by @anonymous309 — 2025-03-28T00:14:31Z

I am not sure the sources you posted mean that much in the context of Privacy Guides users. I don’t mean that to dismiss what you are saying. What I mean is that the first two sources seemed to be pretty clearly about governments, or at least government entities, coordinating to spy on other governments.

> [@RevealedInWords](#):
>
> CIA spying scandal in Switzerland shows the best way for intelligence services to read your messages is to OWN the platform—RT: [CIA spying scandal in Switzerland shows the best way for intelligence services to read your messages is to OWN the platform — RT Op-ed](https://archive.is/oCJOn)

While I think the idea that this op-ed promoted is reasonable, its nothing new to Switzerland or the privacy community. Privacy communities are constantly concerned about companies being honeypots.

The part I found most concerning was from the first article you linked where it talks about the Swiss intelligence service acting on its own without even informing the government.

> In a statement announcing the delegation’s findings Tuesday, parliament said the Swiss intelligence service had known “since 1993 that foreign intelligence services were hiding behind the company Crypto AG.”
> 
> The Swiss intelligence service had subsequently benefitted from an “information collaboration”, it said.
> 
> The Swiss government had meanwhile not been informed of the arrangement until late last year [2019], it said, warning that this raised concerns about gaps in the control over the intelligence service.

> [@RevealedInWords](#):
>
> Switzerland is not the privacy panacea many promote it to be.

While I agree with this, I think compared to most countries where its reasonable for users to find privacy tools, this jurisdiction is better then average. I do wonder why somewhere like Iceland, as an example, that has notable privacy protections does not produce more VPNs and other tools.

---

## Post 46 by @ignoramous — 2025-03-28T06:47:57Z

> [@jonah](#):
>
> ignores the fact that recommending VPN providers in the face of potential secret government mandates still would not be misleading, because we don’t claim VPNs protect against government surveillance like this in the first place

I missed this.

In [my previous reply](https://discuss.privacyguides.net/t/secure-encryption-and-online-anonymity-are-now-at-risk-in-switzerland/26181/28), I point out that PG says VPNs can protect one from “anti-piracy orgs” and “oppressive regimes”. This is misleading:

1. Anti-piracy orgs, such as the MPAA, rely on govt legislatures & law enforcement? How can a VPN, under govt mandates, in a jurisdiction that cooperates with other govts, protect anyone?
2. Oppressive regimes sounds like a clever way to avoid mentioning there’s no such legal framework where PG recommend VPNs operate?

Both those points are misleading. Also, as @anon6848291 says, why do folks want to hide traffic from their ISP in the first place (torrenting for example)? In most, if not all regions, the govt mandates ISPs report illicit activity. If VPNs (or their partners worldwide) now are mandated to do the same thing … what’s the point of PG only going on and on about “protects you from ISPs”? I find it misleading.

If jurisdiction isn’t important, why mention “Proton is based in Switzerland” / “Mullvad is Swedish” / “iVPN is registered in Gibraltar”…? The fact that these providers have network partners worldwide subject to respective local laws, and the fact that there’s not much visibility into the agreements between them.

Also, the min criteria for VPNs explicitly calls out “secret logging”, as mentioned [before](https://discuss.privacyguides.net/t/clarification-on-the-swedish-covert-surveillance-act/23499).

 ![6bbc36cc-20c0-46c9-afd4-31bc7f4ab6a7](//forum-uploads.privacyguidesusercontent.com/original/2X/6/69297e2570105c6fbd86b94c1e97c3290a8d1abe.jpeg)

* * *

Edit: Are e2ee messengers, storage services, and email providers required to meet the “no secret backdoor” criteria? I don’t see such a requirement, presently. Better yet, as @anon6848291 says in this thread, reproducibility & attestation should be table stakes _if_ govt mandates are already in place (like in the UK).

---

## Post 47 by @anon80779245 — 2025-03-29T11:47:53Z

If any swiss citizen read here, make your voice heard by responding to the [public inquiry](https://www.admin.ch/gov/fr/accueil/documentation/communiques/communiques-conseil-federal.msg-id-103968.html) ;

> Adresse pour l’envoi de questions

> Jean-Louis Biberstein (responsable suppléant \>Service SCPT, responsable Droit et contrôle de gestion)  
> Service Surveillance de la correspondance par poste et télécommunication  
> T +41 58 462 26 27  
> jean-louis.biberstein@isc-ejpd.admin.ch

---

## Post 49 by @win11.shading291 — 2025-03-30T18:12:41Z

Do we have to be swiss? If someone makes a template, I’d be very willing to send it ;p

---

## Post 50 by @anon80779245 — 2025-03-31T00:50:21Z

Not sure, but forgeiners contacting them en masse might not be welcomed. Just to be clear I ain’t Swiss either I just speak French so I could read it. I believe you can also contact them in German.

---

## Post 51 by @overdrawn98901 — 2025-03-31T01:40:13Z

> [@ignoramous](#):
>
> what’s the point of PG only going on and on about “protects you from ISPs”?

I’m curious about what happens if illegal activity is detected from a VPN. If this results in a ban from a VPN provider, then for cases like Mullvad it’s simple: make a new account? If VPNs are required to trace it back to the original user and report them to authorities.. well I have no idea what it’s protecting against at that point. Seems dicey. I’d at least imagine if the threat model isn’t high tier, say your casual torrent user, it might be sufficient that it’s not worth the effort if the VPN is not in the same jurisdiction at the authorities in question? Lots of questions on my end about practical use of the VPN if said laws are passed in Switzerland.

---

## Post 53 by @null — 2025-03-31T18:39:59Z

This scary how much countrys in Europe is cracking down on basic freedom and privacy rights.

---

## Post 54 by @dumpster — 2025-03-31T21:33:50Z

> [@ignoramous](#):
>
> Anti-piracy orgs, such as the MPAA, rely on govt legislatures & law enforcement?

Not exclusively. Some ISPs enforce anti-piracy themself. They’ll respond to reports from anti-piracy orgs by warning their accused customers or even cutting off their internet access.

---

## Post 55 by @ignoramous — 2025-03-31T23:06:58Z

> [@overdrawn98901](#):
>
> If VPNs are required to trace it back to the original user and report them to authorities.. well I have no idea what it’s protecting against at that point

Zlich.

> [@overdrawn98901](#):
>
> Lots of questions on my end about practical use of the VPN

When you’ve got every mom & pop privacy blog _inventing_ usecases for VPNs … it tends to lead to confusion … unless you know exactly what questions to ask and where to find answers from. PG could be that place.

> [@dumpster](#):
>
> Some ISPs enforce anti-piracy themself.

And why would that be? Any publicly available study/case on why ISPs don’t get dragged through the courts by customers fighting for their right to seed [aXXo](https://en.wikipedia.org/wiki/AXXo)’s RIPs?

---

## Post 56 by @ph00lt0 — 2025-04-04T06:48:56Z

Proton threatens to leave Switzerland upon passage of new surveillance law

> **[Bundesrat plant Gesetzesrevision: Chef von Schweizer Techfirma warnt vor...](https://www.derbund.ch/andy-yen-gegen-revisionsplan-des-bundesrats-mit-dieser-aggressiven-ueberwachung-muesste-proton-die-schweiz-verlassen-487339556764)**
>
> Proton-Chef Andy Yen sagt, Anbieter sicherer Mail- und Messenger­dienste wären vom neuen Überwachungsgesetz bedroht. Er erwägt einen Wegzug.

---

## Post 57 by @privacyisconsent — 2025-04-04T12:36:10Z

Leave Switzerland and go where exactly?

---

## Post 58 by @Eebzter — 2025-04-04T12:40:52Z

I would assume Iceland, Japan, and Norway could all be a viable option. Norway and Iceland still being within Europe but not part of the EU while still maintaining strong GDPR laws (or something similar).

---

## Post 60 by @RevealedInWords — 2025-04-07T00:47:23Z

Antarctica anyone?

---

## Post 61 by @Focus — 2025-04-21T18:17:03Z

Good Article by [kuketz-blog.de](http://kuketz-blog.de) about this.  
It’s in german, but you can use any translation tool recommended by privacyguides or just use an AI.

> **[Mythos Datenschutzparadies: Die Schweiz und ihr Nachrichtendienstgesetz](https://www.kuketz-blog.de/mythos-datenschutzparadies-die-schweiz-und-ihr-nachrichtendienstgesetz/)**
>
> Die Schweiz genießt international den Ruf, ein sicherer Hafen für Daten zu sein – außerhalb der EU, mit politischer Stabilität…

If you use a fully encrypted service like Signal the location of the server is still relevant, but not as relevant as if you use a trust me bro service.  
VPN’s are just based on Trust. For these services laws and countries are extremely important.  
My thoughts: If you use a VPN, you just acces the Internet from a different server which uses a different ISP then if you would acces the Internet directly via your home ISP. You just change the ISP with the advantage that you can defeat tracking methods which are just solely based on IP Adresses. Nowadays IP based tracking is just one of hundred methods, so a VPN doesn\*t help at all if you don’t do something against all the other tracking methods.

For someone living in the US it makes sense to VPN into a server in switzerland to use a swiss ISP instead of a american one. You don’t need to be an expert so know that US ISPs are tracking and surveilling way more then swiss ISPs.  
But from the perspective of a citizen in switzerland it doesn\*t make sense to use a VPN if you don’t select a swiss server or a server of a country where the ISP’s are as regulated as in switzerland or even more regulated. But if you choose a VPN server in romania or whatever, then you are decreasing your privacy. Yea, you are still getting a different IP adress, but overall it doesn’t make sense.

Am I right here?

I think many people don_t really understand VPNs and that you just switch the ISP which sees your traffic. Yea, your home ISP can_t see the traffic, but now ProtonVPN can see the traffic and the ISP from the datacenter server in say Romania can see the traffic too. Double hop makes sense if you for example choose a server in switzerland and one in iceland if you know that these countries are one of the best ones for privacy regulation.

---

## Post 62 by @anon21666177 — 2025-04-24T05:09:39Z

Most, but not all VPN servers are rented. For example, Mullvad owns servers in Denmark, Finland, France, Germany, Netherlands, Norway, Sweden, Switzerland, and the UK. Unfortunately, Iceland isn’t a country where Mullvad owns servers (they rent there). [Source](https://mullvad.net/en/servers?type=wireguard&ownership=true)

---

## Post 63 by @Focus — 2025-04-25T08:33:46Z

yea, that’s another big issue that if you just rent a cloud server you don’t have the same level of control as if you would own it yourself.

---

## Post 64 by @seuaaa — 2025-05-27T20:12:49Z

Has there been any news on the proposal? I cannot find anything recent.

---

## Post 65 by @mangomango — 2025-05-27T21:25:43Z

> [@anon36940904](#):
>
> We will still have to wait and see what actually happens.

As s/he said, still nothing changed.  
The government (=executivr power) only launched a phase of multi-stakeholders consultation about a proposal of revision of the law. These stakeholders include Proton AG and NGOs for instance.

This period of consultation is over since the 6th of May so now we are only waiting for the final report about the consultation I guess.  
You can find all the details here [Fedlex](https://www.fedlex.admin.ch/fr/consultation-procedures/ended/2025#https://fedlex.data.admin.ch/eli/dl/proj/2022/21/cons_1)

---

## Post 66 by @anon80779245 — 2025-06-04T08:38:11Z

Interesting article [Switzerland plans to ban anonymity and data retention by decree | heise online](https://www.heise.de/en/news/Switzerland-plans-to-ban-anonymity-and-data-retention-by-decree-10377287.html)

> In the **future** , **online services** with a **t least 5,000 users** will have to **store metadata such as IP addresses and port numbers for six months** and **help** the police and **intelligence services to decrypt content**. According to the plan, there will also be a new **requirement** for such **operators to identify users.** They would have to present a **copy of their ID** or driving license **or at least** provide **a** tele **phone number**

> Article 50a of the VÜPF reform stipulates that providers with reduced and full obligations must remove “the encryption provided by them or on their behalf”. To achieve this, they are to “capture and decrypt the telecommunications traffic of the monitored person at suitable points” so that the desired data can be delivered in plain text. End-to-end encryption would not be affected by this. However, only if this takes place “between end customers”. The exception for end-to-end encryption would probably not apply at the provider level.

---

## Post 67 by @Blackbird — 2025-06-04T08:43:46Z

I’m pretty much speechless.

---

## Post 68 by @Regime6045 — 2025-06-04T13:09:50Z

I think this was rejected by all major parties, though I’m not sure what it means - is the law completely off the table or will they try it with an amended version? [https://www.inside-it.ch/vupf-revision-faellt-in-der-vernehmlassung-komplett-durch-20250507](https://www.inside-it.ch/vupf-revision-faellt-in-der-vernehmlassung-komplett-durch-20250507)

---

## Post 69 by @anon80779245 — 2025-06-04T15:11:07Z

AFAIK this isn’t a law per se, it is just a planned change to a government-level regulation, so it doesn’t need to pass trough the parliament. (That being said, normally Swiss politics are consensus-based, so they _might_ give up due to the pushback, but I am not sure)

Edit: read the article from Regime

---

## Post 70 by @PrivadoQ — 2025-07-15T16:26:07Z

I haven’t read anything from Proton discussing the proposed changes to Switzerland law, which will greatly impact their services. Is anyone familiar with this? Maybe I missed a thread on the forum?

> **[Switzerland’s Privacy and Encryption Under Attack: Proposed Surveillance Laws...](https://www.isoc.ch/swiss-surveillance-ordinance-encryption-threat-vupf-oscpt/)**
>
> Zurich, May 6, 2025 – A sweeping revision of he Ordinance on the Surveillance of Postal and Telecommunications Traffic (VÜPF/OSCPT) and the ordinance of the Federal Department of Justice and Police (VD-ÜPF/OME-SCPT) , concludes...

---

## Post 71 by @anonymous372 — 2025-07-24T17:35:28Z

> I haven’t read anything from Proton discussing the proposed changes to Switzerland law, which will greatly impact their services.

Well, now they’re moving out

> [@Proton is moving most of its physical infrastructure out of Switzerland](https://discuss.privacyguides.net/t/proton-is-moving-most-of-its-physical-infrastructure-out-of-switzerland/29398):
>
> Continuing the discussion from [Introducing Lumo, the AI where every conversation is confidential | Proton](https://discuss.privacyguides.net/t/introducing-lumo-the-ai-where-every-conversation-is-confidential-proton/29346) Yeah, that was surprising to me. Do we know where in the EU they are moving to? Do we know if their Swiss legal jurisdiction could still pose a problem even if the data itself is outside of Switzerland? Raises a lot of questions…

---

## Post 72 by @mangomango — 2025-08-21T12:57:43Z

> [@anon39279085](#):
>
> our last bastion of privacy friendly country

Not sure about where this idea that Switzerland is a privacy heaven comes from but it is not one. For instance, Internet service providers are mandated to record the deplacements and all the metadata of all the communicaton of all their users for 6 months. [Vorratsdatenspeicherung - Digitale Gesellschaft](https://www.digitale-gesellschaft.ch/dossier/vorratsdatenspeicherung/)
