protonprivacy,
@protonprivacy@mastodon.social avatar

deleted_by_author

  • Loading...
    doomy,
    @doomy@mastodon.social avatar

    @protonprivacy proton unlimited subscriber here 👋 is there a reason the recovery email address was not hashed?

    jonah,
    @jonah@neat.computer avatar

    @doomy how would @protonprivacy “un-hash” it if they needed to send you a recovery email? A hash is one way.

    All they can do is encrypt it (which I’m sure they do), but in that case they’ll have the keys to decrypt it like they did here.

    AIBrain,

    @jonah @doomy @protonprivacy Not all hashes are one-way.

    jik,
    @jik@federate.social avatar

    @AIBrain @jonah @doomy @protonprivacy 1) If the hash isn't one-way then Proton can be compelled to unhash it so there's no point.
    2) They could require the user to reenter the recovery address if it's needed for recovery, confirm that it matches the hash, send the recovery message to the address, and then discard the unhashed address.
    If they're not doing it that way then they screwed up, or they decided convenience outweighs privacy, or they want to be able to cough it up if asked legally. 🤷

    jonah,
    @jonah@neat.computer avatar

    @jik asking people who’ve forgotten their password to remember their recovery email seems like a very bad move.

    @AIBrain @doomy @protonprivacy

    jik,
    @jik@federate.social avatar

    @jonah @AIBrain @doomy @protonprivacy In fact, people are significantly more likely to forget a password than to forget their email address.
    And if they have multiple addresses and don't remember which they used, they can try all of them.
    As I said, this is a privacy vs. convenience trade-off.
    Other apps do this (require recovery email to be verified by user before it can be used for recovery). Proton would not be breaking new ground here.

    protonprivacy,
    @protonprivacy@mastodon.social avatar

    @jik @jonah @AIBrain @doomy Setting a recovery email is also optional, more info here: https://proton.me/support/set-account-recovery-methods

    jik,
    @jik@federate.social avatar

    @protonprivacy @jonah @AIBrain @doomy I don't understand why you keep making excuses instead of at least acknowledging that you could choose to handle recovery emails in a way that keeps them private.

    protonprivacy,
    @protonprivacy@mastodon.social avatar

    @jik @jonah @AIBrain @doomy Hi Jonathan, email is just one of several recovery options, rest assured your feedback has been passed along to the team.

    protonprivacy,
    @protonprivacy@mastodon.social avatar

    @doomy From a technical perspective, one can't end-to-end encrypt or hash a recovery email as it needs to be accessible to send the recovery email, which is typically initiated by an unauthenticated user who has lost their password. In brief, if we did that, one wouldn't be able to use the recovery address for its intended purpose.

    doomy,
    @doomy@mastodon.social avatar

    @protonprivacy Thank you for the response, but I don't think that is correct. You can still store only the hash of the email.

    For example: If a user requests recovery, they must input their recovery email. The server would then check that the hash of the user provided email matches the stored hash. If it does, the server sends the recovery email to the provided address (or keeps the email for as long as needed for operations before scrubbing).

    protonprivacy, (edited )
    @protonprivacy@mastodon.social avatar

    @doomy Recovery addresses are also used to inform users in case suspicious login attempts or something of that sort has occurred, and for that we need to have access to the address itself.

    leberschnitzel,
    @leberschnitzel@existiert.ch avatar

    @protonprivacy maybe instead of a list what you can't give out you should publish a list of what you have to hand out if requested by court

    protonprivacy,
    @protonprivacy@mastodon.social avatar

    @leberschnitzel Proton stores minimal data and almost all data is end to end encrypted. You can find details in our privacy policy: https://proton.me/legal/privacy You can also check this article to see which data is stored encrypted and which cannot be: https://proton.me/support/proton-mail-encryption-explained

    leberschnitzel,
    @leberschnitzel@existiert.ch avatar

    @protonprivacy from what I'm reading there it means that ALL data that you log will be handed over if account information is legally requested? And the Sentinal Program means that your IP gets logged and also handed over to authorities, if requested (which seems counterintuitive)? Also support tickets get stored and will be handed out if requested?

    protonprivacy,
    @protonprivacy@mastodon.social avatar

    @leberschnitzel The swiss law has limits which are quite strict, especially after our 2021 court victory: https://proton.me/blog/court-strengthens-email-privacy. We limit data retention, so support tickets are not stored forever, either. They have also never been requested.

    myrix,

    @protonprivacy "but in terror cases Swiss courts can obtain recovery email"

    Also from users own domains? (Ask for a friend)

    protonprivacy,
    @protonprivacy@mastodon.social avatar

    @myrix A recovery email is optional and not required for a Proton account, more here: https://proton.me/support/set-account-recovery-methods

    pacogens,

    @protonprivacy can you tell us what other information can you provide so easy from our accounts? Or what is not encrypted?

    Now I know I need to delete my recovery mail.
    My phone number?
    If I use the easy switch option I am exposed?
    What about the new security options like proton sentinel or the dark web monitoring?

    protonprivacy,
    @protonprivacy@mastodon.social avatar

    @pacogens Hi there, setting a recovery method is optional, more on this here: https://proton.me/support/set-account-recovery-methods

    pacogens,

    @protonprivacy that's not what I asked.

    I want to know what other personal information you deliver so easy to authorities.

    protonprivacy, (edited )
    @protonprivacy@mastodon.social avatar

    @pacogens Thanks for clarifying! We outline this in the first paragraph here: https://proton.me/mail/privacy-policy

    Note that It’s also important to differentiate that VPN is not classified as a communication tool in Switzerland — Proton VPN does not log IPs and there are no existing Swiss laws that can compel us to do so.

    Also, nothing is delivered easily: Swiss law is very restrictive, and there are many hurdles to jump through to get a court order.

    martijn,
    @martijn@ieji.de avatar

    @protonprivacy seems like you're getting all the heat. So thanks for providing your services, still a happy customer 🩷

    lx,
    @lx@swiss.social avatar

    @protonprivacy Do you also store IP addresses? Can’t they be linked to real identities as well?

    protonprivacy,
    @protonprivacy@mastodon.social avatar

    @lx We provide an official Proton Mail onion site for use with the Tor network for those seeking anonymity.

    It’s also important to differentiate that VPN is not classified as a communication tool in Switzerland — Proton VPN does not log IPs and there are no existing Swiss laws that can compel us to do so.

    cyastis,
    @cyastis@mastodon.social avatar

    @protonprivacy Thanks for the very specific information on what information you may or may not be compelled to provide here. Let us know if anything changes!

    lx,
    @lx@swiss.social avatar

    @protonprivacy I thought I read somewhere in Proton’s docs that the last seen IP address is logged? Does that only apply to Proton Mail but not VPN?

    protonprivacy,
    @protonprivacy@mastodon.social avatar

    @lx We provide an official Proton Mail onion site for use with the Tor network for those seeking anonymity.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • DreamBathrooms
  • everett
  • InstantRegret
  • magazineikmin
  • thenastyranch
  • rosin
  • GTA5RPClips
  • Durango
  • Youngstown
  • slotface
  • khanakhh
  • kavyap
  • ngwrru68w68
  • tacticalgear
  • JUstTest
  • osvaldo12
  • tester
  • cubers
  • cisconetworking
  • mdbf
  • ethstaker
  • modclub
  • Leos
  • anitta
  • normalnudes
  • megavids
  • provamag3
  • lostlight
  • All magazines