Privacy: I have blinds on my windows. I control whether they are open or closed, but they aren’t secure. You could break a window and look inside if you really wanted to.
Security: my glass storm door has a lock. But privacy is only there when I close the front door.
There is overlap between these two concepts but one does not imply the other.
Companies have to comply with law enforcement. If anything, the little amount of data they were able to give after being forced is a good proof of their overall claim. If there is someone to blame here are courts using antiterrorism laws to catch environmental activists.
exactly if it’s a company they have to comply with laws. This is not a service to rely on if you doing espionage or something. It’s for people who want more privacy and choice.
I mean, if you want secure/private communication, email should not be your go-to. It’s a horrible platform by today’s standards. It was never designed to have any serious level of security. Once they have an unencrypted email on the target with timestamps and mail headers, all they need to do is see who was communicating with Proton at that point. I don’t know if anything has changed since the PRISM days, but back in the 2000s, they definitely had that level of insight into the web.
Not much has changed. It’s really only secure if you are sending emails between addresses within the same local network like gmail to gmail. Thankfull with end to end encryption it can be pretty safe just good luck finding someone that knows how to use it. but thankfully proton makes that pretty seamless.
That’s why I put “security and privacy” between quotes. I have absolutely Jo way to confirm if they are secure and private or if they’re not, other than all the contradicting mentions all over the internet. Also, while security and privacy may not be mutually dependent in the physical world, it stands to reason that something insecure cannot be private, and something not private is inherently insecure, as @pixelscript@lemmy.ml clearly pointed out.
As for controlling my own email infrastructure, I’d love to, as everything else I do self-host, and only with FOSS software. However, email hosting is a seriously complicated animal that requires too much effort and maintenance, and most of us dont have the knowledge and time to invest in that, so compromises need to be made. I am well aware that there’s always risk on using something I have no real control over, but the alternative meets the reason for the phrase “the treatment is worse than the decease”.
If you just did this little thing, you would convey your point very well. Proton is unfit for activist and journalist tier threat models. You could link Moon Of Alabama blog articles. Proton is better than Gmail and Outlook, but it is no saint. It is enough to achieve good basic privacy and security, but not bulletproof in worst cases.
deleted by creator
Are you confusing security and privacy?
I’m not, the comment I was replying to literally called proton a “security and privacy” company.
They mutually imply one another.
If something was private, but not secure, well, that implies there are ways to breach the privacy, which isn’t very private at all.
If it’s secure, but not private, that implies it’s readable by someone other than the consenting conversational parties, which makes it insecure.
Privacy: I have blinds on my windows. I control whether they are open or closed, but they aren’t secure. You could break a window and look inside if you really wanted to.
Security: my glass storm door has a lock. But privacy is only there when I close the front door.
There is overlap between these two concepts but one does not imply the other.
…and proton advertises as both, which as pointed out, isn’t true
Companies have to comply with law enforcement. If anything, the little amount of data they were able to give after being forced is a good proof of their overall claim. If there is someone to blame here are courts using antiterrorism laws to catch environmental activists.
exactly if it’s a company they have to comply with laws. This is not a service to rely on if you doing espionage or something. It’s for people who want more privacy and choice.
I mean, if you want secure/private communication, email should not be your go-to. It’s a horrible platform by today’s standards. It was never designed to have any serious level of security. Once they have an unencrypted email on the target with timestamps and mail headers, all they need to do is see who was communicating with Proton at that point. I don’t know if anything has changed since the PRISM days, but back in the 2000s, they definitely had that level of insight into the web.
Not much has changed. It’s really only secure if you are sending emails between addresses within the same local network like gmail to gmail. Thankfull with end to end encryption it can be pretty safe just good luck finding someone that knows how to use it. but thankfully proton makes that pretty seamless.
That’s why I put “security and privacy” between quotes. I have absolutely Jo way to confirm if they are secure and private or if they’re not, other than all the contradicting mentions all over the internet. Also, while security and privacy may not be mutually dependent in the physical world, it stands to reason that something insecure cannot be private, and something not private is inherently insecure, as @pixelscript@lemmy.ml clearly pointed out. As for controlling my own email infrastructure, I’d love to, as everything else I do self-host, and only with FOSS software. However, email hosting is a seriously complicated animal that requires too much effort and maintenance, and most of us dont have the knowledge and time to invest in that, so compromises need to be made. I am well aware that there’s always risk on using something I have no real control over, but the alternative meets the reason for the phrase “the treatment is worse than the decease”.
If you just did this little thing, you would convey your point very well. Proton is unfit for activist and journalist tier threat models. You could link Moon Of Alabama blog articles. Proton is better than Gmail and Outlook, but it is no saint. It is enough to achieve good basic privacy and security, but not bulletproof in worst cases.