Jump to content
  • ProtonMail deletes 'we don't log your IP' boast from website after French climate activist reportedly arrested

    aum

    • 1 comment
    • 562 views
    • 4 minutes
     Share


    • 1 comment
    • 562 views
    • 4 minutes

    Cops can read the SMTP spec too, y'know

     

    Encrypted email service ProtonMail has become embroiled in a minor scandal after responding to a legal request to hand over a user's IP address and details of the devices he used to access his mailbox to Swiss police – resulting in the user's arrest.

     

    Police were executing a warrant obtained by French authorities and served on their Swiss counterparts through Interpol, according to social media rumours that ProtonMail chief exec Andy Yen acknowledged to The Register.

     

    Etienne - Tek
    @tenacioustek

    So @ProtonMail received a legal request from Europol through Swiss authorities to provide information about Youth for Climate action in Paris, they provided the IP address and information on the type of device used to the police

     

    E-ijyHdXsAUQqek?format=png&name=360x360

     

    At the time of writing, the company's website said: "We believe privacy and security are universal values which cross borders."

     

    After data from ProtonMail was handed to the Swiss and then French police, the author of a left-wing political activists' blog in France wrote (en français) that a group called Youth for Climate had been targeted:

     

    The police also noticed that the collective communicated via a ProtonMail email address. They therefore sent a requisition (via EUROPOL) to the Swiss company managing the messaging system in order to find out the identity of the creator of the address. ProtonMail responded to this request by providing the IP address and the fingerprint of the browser used by the collective. It is therefore imperative to go through the tor network (or at least a VPN) when using a ProtonMail mailbox (or another secure mailbox) if you want to guarantee sufficient security.

     

    ProtonMail has said in the past that it does not collect user data and implements end-to-end encryption and repeated that over the weekend, saying: "Under no circumstances however, can our encryption be bypassed, meaning emails, attachments, calendars, files, etc, cannot be compromised by legal orders."

     

    This statement, while bold, seems to be borne out by the service's privacy policy which states that it can access the following user information:

     

    • Sender and recipient email addresses
    • The IP address incoming messages originated from
    • Message subject
    • Message sent and received times

     

    These are all standard unencrypted information from email headers, inherent to the SMTP email specification, though it appears that ProtonMail's previous promises about user information logging were a bit over-generous. Back in January this year, the company's homepage stated: "No personal information is required to create your secure email account. By default, we do not keep any IP logs which can be linked to your anonymous email account. Your privacy comes first."

     

    Today that boast has been replaced with a mealy-mouthed version: "ProtonMail is email that respects privacy and puts people (not advertisers) first. Your data belongs to you, and our encryption ensures that. We also provide an anonymous email gateway."

     

    The firm's privacy policy, which was updated yesterday, now says: "If you are breaking Swiss law, ProtonMail can be legally compelled to log your IP address as part of a Swiss criminal investigation."

     

    In a statement posted to Reddit, which Yen forwarded to El Reg in lieu of making a statement of his own, ProtonMail said: "In this case, Proton received a legally binding order from the Swiss Federal Department of Justice which we are obligated to comply with. There was no possibility to appeal or fight this particular request because an act contrary to Swiss law did in fact take place (and this was also the final determination of the Federal Department of Justice which does a legal review of each case)."

     

    As a Swiss company, ProtonMail is obliged to obey Swiss law and comply with Swiss legal demands, though it's unclear why the company was logging user-agent strings and IP addresses of client logins. An option exists in ProtonMail's user interface to enable access logging, though there is no information in public to suggest whether or not the French environmental protestor had enabled that. ®

     

    Source

    • Like 3

    User Feedback

    Recommended Comments

    As I mentioned on another topic about Proton, there was an anonymous mail server back in the late 80s and early 90s called anon.penet.fi.  It worked well and was free and maintained by a person in Finland.  But then people started to use it for illegal activities and the owner started getting requests from police for data he didn't have and after some time he decided it wasn't worth doing any more and shut it down.  It only takes a few bad apples to run something for literally millions of people and in the end they don't have it to use either.

    • Like 2
    Link to comment
    Share on other sites




    Join the conversation

    You can post now and register later. If you have an account, sign in now to post with your account.
    Note: Your post will require moderator approval before it will be visible.

    Guest
    Add a comment...

    ×   Pasted as rich text.   Paste as plain text instead

      Only 75 emoji are allowed.

    ×   Your link has been automatically embedded.   Display as a link instead

    ×   Your previous content has been restored.   Clear editor

    ×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...