You are viewing a single thread.
View all comments
30 points
*

Proton a few years ago disclosed the IP address of the user of a certain mailbox upon request by LEA. That was enough to get the person found and arrested (I don’t remember what the case was about). They HAVE to comply with these requests, but they DON’T need to log/retain those info ETA: and I was wrong, thanks @Cheradenine@sh.itjust.works to set me straight. But I think the point still stands. I don’t want to be ALWAYS be tied to a VPN, there are some scenarios where I can’t use a VPN.

That was the moment I decided to selfhost my email server.

permalink
report
reply
28 points

In that particular case they did need to log the ip because they were compelled to do so by a Swiss court.

That was an opsec failure on the user, if they used a VPN or Tor they would not have been caught.

permalink
report
parent
reply
7 points

A VPN would’ve only shifted the “blame” unless it was a decent one like IVPN.

Tor would’ve been much better, especially considering Proton has an .onion address.

permalink
report
parent
reply
13 points

Yes, by VPN I meant something decent. Not whatever spyware is top on the Play Store for circumventing geoblocks.

They were already using Proton Mail, they just were probably thinking that was enough. It would have been if the French had not been able to convince a Swiss court that their request was valid.

permalink
report
parent
reply
2 points

So couldn’t a court compel the VPN to log all IPs and then use some FISA level shit to prevent the VPN from alerting users?

There’s been a handful of VPN cases taken to court where they have proved, at that moment in time, that they had no logs to hand over. But why not take it that last step and compel the change then?

permalink
report
parent
reply
3 points

That’s a good question. I know good vpns like mullvad do not and can not log ips/traffic without changes to their backend, I wonder if they could claim “it’s impossible” or something (clearly bogus, but the argument could be “with our current infrastructure, I.e. We can’t afford to redo our systems to comply”)

permalink
report
parent
reply
16 points

Posteo doesn’t have to retain IPs and doesn’t, it also doesn’t retain payment info (though if you transfer by wire there’s still a window where a payment can be traced AFAIU).

They will also absolutely forward any and all traffic for a particular account to law enforcement when given a court order. What’s it with criminals thinking that they can outsource opsec to legitimate businesses. Defending against a state-level actor actively hunting you down, watching closely and pouncing on any and every mistake, is a vastly different beast than making sure google doesn’t know about the butt plug you just bought.

permalink
report
parent
reply
3 points

Agree with you, that’s why I buy my butt plugs (and similar toys) with my gmail account! 😁

permalink
report
parent
reply
3 points

“If law enforcement is going to look at my data, I’ll give them something to look at” lmao

permalink
report
parent
reply
5 points

That was the moment I decided to selfhost my email server.

So now the hosting you use will share the same(or likely much more) data if some government requests it.

permalink
report
parent
reply
1 point

They can get my encrypted drive. My domain name is registered to me so that’s clear it’s my email. But no content.

permalink
report
parent
reply

Technology

!technology@lemmy.world

Create post

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


Community stats

  • 18K

    Monthly active users

  • 11K

    Posts

  • 505K

    Comments