Hacker News new | ask | show | jobs
by temp8964 1750 days ago
My understanding is that they will log you under specific law enforcement request. It’s very different from saying they automatically log everyone.
2 comments

In the discussion of their fulfilling the request, the data they provided was described as the IP during account creation. If that was accurate then it is a neat trick that law enforcement knew which accounts would eventually be of interest.
I dmed Andy Yen and he assured me they only start logging after requests, can you link me to your source?
TheRegister article quotes:

"They therefore sent a requisition (via EUROPOL) to the Swiss company managing the messaging system in order to find out the identity of the creator of the address. ProtonMail responded to this request by providing the IP address and the fingerprint of the browser used by the collective."

It looks like the Swiss police responded to a request that could not be fulfilled (creator's ip) by getting something ~equally good (most recent ip) through asking protonmail to enable IP monitoring and the resulting report shown redacted on TC looks like a normal subpoena response where the data was already available.

This does not really look like the back and forth seen with authorities first trying to request the impossible in a subpoena (i.e. famously from lavabit but also from any cloud provider) but that level of adversarial ~obstruction through precise compliance might not be possible in Swiss law.

If that's the case then my understanding of the event is wrong.
Not really different, since it's binary.

The message used to be "we don't keep IP logs" and now it's the opposite.

Not the opposite more a middleground "we don't keep IP logs unless (uncommonly) forced by law enforcement".