Hacker News new | ask | show | jobs
by thumbuddy 1073 days ago
Wasn't there some article or something claiming that this company was a NSA honeypot or something? Or am I imagining that.
3 comments

You might be thinking of https://encryp.ch/blog/disturbing-facts-about-protonmail/

edit: I'd like to inject a reminder that protonmail doesn't encrypt all of your mailbox contents. From their privacy policy:

"we have access to the following email metadata: sender and recipient email addresses, the IP address incoming messages originated from, attachment name, message subject, and message sent and received times"

> "we have access to the following email metadata: sender and recipient email addresses, the IP address incoming messages originated from, attachment name, message subject, and message sent and received times"

Is there any of that that’s not basically required by the fact that they’re running an _email_ service?

Sure, for sending/receiving the email all of that is accessible/needed but some (all, even) of this could be stored encrypted by the user's password/mailbox-password.

If I remember correctly: one of the reasons they don't encrypt that metadata is so they can do the search box server-side.

The CIA/NSA claims are quite easily debunked: https://www.reddit.com/r/ProtonMail/comments/14demhj/debunki...
No. Nothing of the sort. They were forced by law to reveal IP addresses of some key individuals.

https://en.m.wikipedia.org/wiki/ProtonMail#Compliance_with_S...

https://proton.me/legal/transparency

If you can cite some sources, I will be very interested to read all about it. I trust Proton with most of my crucial e-mails(bank, insurance, govt services) and use a cheap alternative for personal things.

If it is really a NSA honeypot, I'd rather let M$ or GOOG have my e-mails anyways.

No real sources but hn comments, but hey if the river sounds..

https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

The NSA/CIA are just too good at hijacking swiss -neutral- companies for their own bidding

A circular reference to baseless conjecture is not a source.
Agreed. I'll look for where I read this... Maybe it was just a paranoid loon on the internet but for some reason I shelved it mentally as trustworthy... Bah don't trust me
Thus why I said not a source?
I guess you are referring to Crypto AG

https://en.wikipedia.org/wiki/Crypto_AG