What is Proton's mission? Watch our new video | Proton

3 Likes

Did anyone tell Proton Youtube is big tech?

1 Like

https://knowyourmeme.com/memes/we-should-improve-society-somewhat

2 Likes

1:32, they show subject and email encrypted.

Pretty good video.

I would say more anonymity should be added when possible if they want to better protect their free users who rely on it for safety but at the same time, anonymity for users and fraud prevention and free services sound like a huge challenge.

It makes sense for Proton to advertise where the people are, and to use that on their page to push the view count. But its still funny. They have the resources to run a peertube channel.

2 Likes

It’s ironic because their blog constantly bashes big tech like a teenage boy.

Well, I guess it’s precisely where you need to convince people. Telling people in PeerTube they need to leave BigTech would be a waste of time.

5 Likes

They could do both, and use peertube for their blog. Reach the masses and promote the alternatives.

Let’s hope this supposed to be domains hosted by Proton (i.e. completely internal email), otherwise it looks like false advertising…

I’m also curious how they know how their service is being used when they supposedly can’t see any of the data (e.g. 2:50 where there were puportedly leaked lists of people who were going to be drafted in the Ukraine war – how do they know this?)

1 Like

Sorry to reply again @Mxyzptlk , but my comment decided to not like formatting anymore and freaked out, so I had it deleted to repost this. Anyway:

\

I decided to ask support about this yesterday, but did not hear back yet.

To me, this visualization does not sit right with me, but it may fall under the category “technically not incorrect”. It definitely is ambiguous at best.

  • It is false that they E2E-encrypt header information like sender, recipient, or subject line. They adhere to OpenPGP, which does not support it (yet™*). They state this on this support page.
  • This similarly structured and worded page puts the relevant part in a separate paragraph about what I understand as the state of at-rest, but not included in the “zero-access” criterion

Message storage

...
  • Password-protected Emails are also stored end-to-end encrypted.
  • Subject lines and recipient/sender email addresses are encrypted, but not end-to-end encrypted.

\

As far as I’m concerned, the last point makes the strongest argument for the visualization being technically not incorrect, albeit still misleading.

It is clear to me that it represents transit and not emails at-rest.

While Proton encrypts subjects and possibly the whole header at-rest (don’t confuse with zero-access**), they do not for sending.

\

*6 years ago, Proton said:

PGP is indeed quite old, but as we are now the biggest user of PGP, and the maintainers of some of the most popular PGP libraries out there, we are thoroughly modernizing PGP. If you look at the latest versions of OpenPGPjs, you can see many of those improvements (such as AEAD, etc), and it is only a matter of time before we can also add encrypted subject lines into the standard.

\

**It probably means Proton’s storage is encrypted against attackers, but Proton still can decrypt the metadata parts, whereas email bodies are zero-access to them.

1 Like

I lost access to edit the above comment, so I’ll leave this clarification about the asterisks here until I can re-add them:

and