HN user

protonmail

836 karma

Official Proton team account

Posts0
Comments345
View on HN
No posts found.

There is no comparison between Crypto AG and us. Our encryption occurs client-side, our cryptographic code is open source ( https://proton.me/community/open-source ), and our tech can and has been independently verified. More about this here: https://proton.me/blog/is-protonmail-trustworthy.

In the case you shared, the name/address of the terrorism suspect was actually given to police by Apple, not Proton. The terror suspect added their real-life Apple email as an optional recovery address in Proton Mail. Proton can't decrypt data, but in terror cases Swiss courts can obtain recovery email. Moreover, the case concerns Proton Mail not Proton VPN, and Proton VPN's no-logs policy has been proven in both independent audits (https://protonvpn.com/blog/no-logs-audit) and in court (https://protonvpn.com/blog/transparency-report).

We most certainly are not a crypto company. We don't run a crypto exchange, didn't create a cryptocurrency, and don't speculate in crypto. We're an encryption company, but don't lump that in with crypto.

Recipients who do not have a Proton account need to create a free or paid Proton account to access the shared content. The email invitation includes a link to the Proton sign-up page.

Once account creation is successful, they will receive another email with the link that allows them to access the file.

This is pretty inaccurate. Proton's E2EE works by encrypting client side, and we can't just replace the GPG key because we have both key pinning and key transparency: https://proton.me/support/key-transparency

Proton does not claim no logs and has never claimed no logs. We do not retain logs by default, but our privacy policy has always been clear that we are legally obligated to follow Swiss court orders, which can ask for IP logging on specific accounts.

Proton's encryption provides privacy by default - we cannot access any of the email content, email attachments, calendars, files stored on Proton Drive or passwords, 2FA codes, notes etc. on Proton Pass, and therefore cannot share any of this with any third parties. We have also discussed such baseless claims of connections to NSA with our users on multiple occasions, including here: https://www.reddit.com/r/ProtonMail/comments/14demhj/debunki....

Verification emails are, as previously explained, hashed only, so we have no access to them. Additionally, they are not tied to a particular account.

Recovery emails are, on the other hand, only stored as long as the users themselves need them - as soon as you delete your recovery email from your account, it's deleted from our systems too.

There is no such requirement. You seem to be conflating a verification email address with the recovery one. The verification email address is sometimes required upon signup, but is not tied to the particular account, and also hashed so we don't have access to it: https://proton.me/support/human-verification. Therefore, we cannot share it with any third-parties (authorities included).

Recovery address (which is what this case is about), on the other hand, is completely optional, and it's not the only option we offer for account recovery: https://proton.me/support/set-account-recovery-methods. Also, it is removed from our systems as soon as you remove it from your account.