Difference between revisions of "ProtonMail"

From Wikispooks
Jump to navigation Jump to search
(email company)
 
(tidy+ misc)
Line 11: Line 11:
 
'''ProtonMail''' is an [[End-to-end encryption|end-to-end encrypted]] [[email]] service founded in 2013 in Geneva, Switzerland by scientists who spent time at the [[CERN]] research facility.<ref>https://home.cern/news/news/computing/cern-inspires-entrepreneurs-email-encryption</ref>
 
'''ProtonMail''' is an [[End-to-end encryption|end-to-end encrypted]] [[email]] service founded in 2013 in Geneva, Switzerland by scientists who spent time at the [[CERN]] research facility.<ref>https://home.cern/news/news/computing/cern-inspires-entrepreneurs-email-encryption</ref>
  
Originally an [[Alt Tech]] company located in formally neutral [[Switzerland]] to avoid any [[surveillance]] or information requests from countries under the [[Fourteen Eyes]], and/or under other government surveillance laws, like the United States' [[Patriot Act]] or covert surveillance, by 2021 there had been several revelations of its cooperation with US authorities.
+
Originally an [[Alt Tech]] company located in formally neutral [[Switzerland]] to avoid any [[surveillance]] or information requests from countries under the [[Fourteen Eyes]], and/or under other government surveillance laws, like the United States' [[Patriot Act]] or covert surveillance, by [[2021]] there had been several exposures of cooperation with US authorities.  
 +
 
 +
Also, there's a precedent of privacy-focused communications groups (especially those based in Switzerland), such as [[Anom]]<ref>https://www.justice.gov/usao-sdca/pr/fbi-s-encrypted-phone-platform-infiltrated-hundreds-criminal-syndicates-result-massive</ref> and [[Crypto AG]]<ref>https://www.justice.gov/usao-sdca/pr/fbi-s-encrypted-phone-platform-infiltrated-hundreds-criminal-syndicates-result-massive</ref> actually being [[intelligence fronts]] used to collect data on users en masse.<ref>https://propagandainfocus.com/proton-mail-imperialist-stooge/</ref>
  
 
==Encryption==
 
==Encryption==
Line 22: Line 24:
 
Email messages sent from ProtonMail to non-ProtonMail email addresses may optionally be sent in [[plain text]] or with end-to-end encryption. With encryption, the message is encrypted with AES under a user-supplied password. The recipient receives a link to the ProtonMail website on which they can enter the password and read the decrypted message. ProtonMail assumes that the sender and the recipient have exchanged this password through a [[backchannel]].<ref name=back>https://security.stackexchange.com/questions/58541/how-are-protonmail-keys-distributed/58552#58552</ref> Such email messages can be set to self-destruct after a period of time.<ref name="security-details">https://protonmail.com/security-details</ref>
 
Email messages sent from ProtonMail to non-ProtonMail email addresses may optionally be sent in [[plain text]] or with end-to-end encryption. With encryption, the message is encrypted with AES under a user-supplied password. The recipient receives a link to the ProtonMail website on which they can enter the password and read the decrypted message. ProtonMail assumes that the sender and the recipient have exchanged this password through a [[backchannel]].<ref name=back>https://security.stackexchange.com/questions/58541/how-are-protonmail-keys-distributed/58552#58552</ref> Such email messages can be set to self-destruct after a period of time.<ref name="security-details">https://protonmail.com/security-details</ref>
  
==Official Story==
+
==Surveillance laws==
[[image:Proton1-s.jpg|thumb|300px]]
+
[[image:Proton1-s.jpg|thumb|400px]]
Both ProtonMail and [[ProtonVPN]] are located in Switzerland to avoid any [[Global surveillance disclosures (2013–present)|surveillance]] or information requests from countries under the [[Five Eyes#Fourteen%20Eyes|Fourteen Eyes]], and/or under [[Edward Snowden disclosures|government surveillance laws]] like the United States' [[Patriot Act]] or outside the bounds of law.
+
Both ProtonMail and [[ProtonVPN]] are located in Switzerland to avoid any [[Global surveillance disclosures (2013–present)|surveillance]] or information requests from countries under the [[Five Eyes#Fourteen%20Eyes|Fourteen Eyes]], and/or under [[Edward Snowden disclosures|government surveillance laws]] like the United States' [[Patriot Act]]. The company also states that it is located in Switzerland because of its strict [[Privacy law|privacy laws]].<ref>https://protonvpn.com/about</ref>
  
The company claims that it is also located in Switzerland because of its strict [[Privacy law|privacy laws]].<ref>https://protonvpn.com/about|access-date=2021-07-16</ref>
+
But by law, Proton has to cooperate with Swiss security authorities. With the Swiss Surveillance Act (BÜPF) and the Intelligence Service Act (NDG), Switzerland is "a fully-fledged surveillance state"<ref name=steiger>https://steigerlegal.ch/2021/08/02/protonmail-daten-usa/</ref>. Switzerland provides mutual legal assistance to the [[United States]] on the basis a 1973 treaty; this way data also ends up with law enforcement agencies there.<ref name=steiger/>
  
By law, ProtonMail has to cooperate with Swiss security authorities. With the Swiss Surveillance Act (BÜPF) and the Intelligence Service Act (NDG), Switzerland is "a fully-fledged surveillance state"<ref name=steiger>https://steigerlegal.ch/2021/08/02/protonmail-daten-usa/</ref>. Switzerland provides mutual legal assistance to the United States on the basis of the Legal Assistance Treaty of 1973; this way data also ends up with law enforcement agencies there.<ref name=steiger/>
+
ProtonMail founder [[Andy Yen]] originally stated that the company would rather leave Switzerland than comply with the Swiss Surveillance Act. ProtonMail chose to stay in Switzerland, and thus has to comply with it<ref name=steiger/>.
  
ProtonMail founder [[Andy Yen]] originally stated that the company would rather leave Switzerland than comply with the BÜPF. ProtonMail chose to stay in Switzerland, and thus has to comply with Swiss surveillance law.<ref name=steiger/>
+
==Good cooperation with authoritites==
 +
In 2021, a company user was involved in threats against the health bureaucrat [[Anthony Fauci]]. In a series of emails, the sender threatened, among other things, to kill Fauci and his family. The [[DOJ|American Justice Department]] wrote<ref>https://www.justice.gov/usao-md/pr/man-facing-federal-charges-allegedly-sending-threatening-emails-dr-anthony-fauci-and-dr</ref> in an affidavit that the accused used "an email account from a provider of secure, encrypted email services based in Switzerland". According to the affidavit, the relevant e-mails end with "Sent with ProtonMail Secure Email"<ref name=steiger/>.
  
==Good cooperation with (US) authoritites==
+
Based on data from ProtonMail, it became apparent that the accused had used several ProtonMail user accounts at the same time. According to his own statements, the accused had switched to ProtonMail because he believed he was protected by Swiss data protection law and end-to-end encryption. Nevertheless, the sender could be identified by the interaction of data from ProtonMail with other online services such as Mail.com.<ref>https://www.justice.gov/usao-md/press-release/file/1416926/download</ref>
In 2021, the company was involved in threats against the well-known health bureaucrat [[Anthony Fauci]]. In a series of emails, the sender threatened, among other things, to kill Fauci and his family. As the [[DOJ|American Justice Department]] wrorte<ref>https://www.justice.gov/usao-md/pr/man-facing-federal-charges-allegedly-sending-threatening-emails-dr-anthony-fauci-and-dr</ref> in an affidavit that the accused used "an email account from a provider of secure, encrypted email services based in Switzerland". According to the affidavit, the relevant e-mails end with “Sent with ProtonMail Secure Email”<ref name=steiger/>.
 
  
Based on data from ProtonMail, it became apparent that the accused had used several ProtonMail user accounts at the same time. According to his own statements, the accused had switched to ProtonMail because he believed he was protected by Swiss data protection law and end-to-end encryption. Nevertheless, the sender could be identified in the interaction of data from ProtonMail and other online services such as Mail.com.<ref>https://www.justice.gov/usao-md/press-release/file/1416926/download</ref>
+
The Swiss [[Federal Office of Police]] (Fedpol) confirmed the exchange with the American authorities. At the same time, Fedpol said it was delighted to work with ProtonMail: "Protonmail is cooperating with the authorities. The cooperation is good."<ref>https://www.tagesanzeiger.ch/us-corona-papst-erhaelt-drohungen-ueber-schweizer-mail-dienst-964516231868</ref>
  
The Swiss [[Federal Office of Police]] (Fedpol) confirmed the exchange with the American authorities. At the same time, Fedpol said it was delighted to work with ProtonMail: «Protonmail is cooperating with the authorities. The cooperation is good."<ref>https://www.tagesanzeiger.ch/us-corona-papst-erhaelt-drohungen-ueber-schweizer-mail-dienst-964516231868</ref>
+
In 2021, ProtonMail also turned over a [[French]] climate activist's IP address and browser fingerprint to Swiss authorities. The company stated its guarantees of email content privacy were not breached.<ref>https://www.wired.com/story/protonmail-amends-policy-after-giving-up-activists-data/</ref>
  
 
==Participating in information war==
 
==Participating in information war==
In May 2021. during the aftermath of the [https://www.moonofalabama.org/2021/06/roman-protasevich-casualty-of-the-ryanair-incident-in-belarus-is-spilling-the-beans.html emergency landing in Minsk] of a [[Ryanair]] flight between [[Greece]] and [[Lithuania]]] ProtonMail provided fractional information about emails which delivered a bomb threat against the plane to several airports. As analyst [[Moon of Alabama]], the partial and seemingly willfully incomplete response by ProtonMail" about when and how many emails were sent, "has led to false claims by various media against the government of [[Belarus]], thus making it part of the Western "information war against Belarus."<ref>https://www.moonofalabama.org/2021/05/how-protonmail-lost-the-public-trust-it-needs-to-do-business.html</ref>
+
In May 2021, during the aftermath of an emergency landing in [[Minsk]] of a [[Ryanair]] flight between [[Greece]] and [[Lithuania]]<ref>https://www.moonofalabama.org/2021/06/roman-protasevich-casualty-of-the-ryanair-incident-in-belarus-is-spilling-the-beans.html</ref>, ProtonMail provided fractional information about emails which delivered a bomb threat against the plane to several airports. As analyst [[Moon of Alabama]] pointed out, "the partial and seemingly willfully incomplete response by ProtonMail about when and how many emails were sent...has led to false claims by various media against the government of [[Belarus]]", thus making it part of the Western information war against the country.<ref>https://www.moonofalabama.org/2021/05/how-protonmail-lost-the-public-trust-it-needs-to-do-business.html</ref>
 +
 
 +
Proton has financially supported<ref>https://proton.me/blog/lifetime-account-supporting-charter97</ref> Belarus-based [[Charter'97]], an "[[independent]]" media organization that Proton describes as one of "Belarus’s most trusted news sites,"<ref>https://proton.me/blog/lifetime-account-supporting-charter97</ref> but which in reality is backed by Western governments and adjacent organizations, including [[Open Society Foundations,]] and the [[German Marshall Fund of the United States]].
 +
 
 +
 
  
 
{{SMWDocs}}
 
{{SMWDocs}}
 
==References==
 
==References==
 
{{Reflist}}
 
{{Reflist}}

Revision as of 10:38, 8 February 2024

Group.png ProtonMail  
(Tech company, Alt Tech)Rdf-entity.pngRdf-icon.png
Protonmail logo.png
Formation16 May 2014
Founder• Jason Stockman
• Andy Yen
• Wei Sun
HeadquartersSwitzerland
Email and VPN server originally located in formally neutral Switzerland to avoid US/NATO surveillance or "information requests", but this has been hollowed out.

ProtonMail is an end-to-end encrypted email service founded in 2013 in Geneva, Switzerland by scientists who spent time at the CERN research facility.[1]

Originally an Alt Tech company located in formally neutral Switzerland to avoid any surveillance or information requests from countries under the Fourteen Eyes, and/or under other government surveillance laws, like the United States' Patriot Act or covert surveillance, by 2021 there had been several exposures of cooperation with US authorities.

Also, there's a precedent of privacy-focused communications groups (especially those based in Switzerland), such as Anom[2] and Crypto AG[3] actually being intelligence fronts used to collect data on users en masse.[4]

Encryption

ProtonMail uses client-side encryption to protect email content and user data before they are sent to ProtonMail servers, unlike other common email providers such as Gmail and Outlook.com. The service can be accessed through a webmail client, the Tor network, or dedicated iOS and Android apps.[5]

ProtonMail is run by its parent company Proton Technologies AG, which is based in the Canton of Geneva.[6] The company also operates ProtonVPN, a VPN service. ProtonMail received initial funding through a crowdfunding campaign. Initially invitation-only, ProtonMail opened up to the public in March 2016. In 2017, ProtonMail had over 2 million users,[7] and grew to over 5 million by September 2018,[8] 20 million by the end of 2019,[9] and over 50 million in 2020.[10]

An email message sent from one ProtonMail account to another is automatically encrypted with the public key of the recipient. Once encrypted, only the private key of the recipient can decrypt the message. When the recipient logs in, their mailbox password decrypts their private key and unlocks their inbox.

Email messages sent from ProtonMail to non-ProtonMail email addresses may optionally be sent in plain text or with end-to-end encryption. With encryption, the message is encrypted with AES under a user-supplied password. The recipient receives a link to the ProtonMail website on which they can enter the password and read the decrypted message. ProtonMail assumes that the sender and the recipient have exchanged this password through a backchannel.[11] Such email messages can be set to self-destruct after a period of time.[12]

Surveillance laws

Proton1-s.jpg

Both ProtonMail and ProtonVPN are located in Switzerland to avoid any surveillance or information requests from countries under the Fourteen Eyes, and/or under government surveillance laws like the United States' Patriot Act. The company also states that it is located in Switzerland because of its strict privacy laws.[13]

But by law, Proton has to cooperate with Swiss security authorities. With the Swiss Surveillance Act (BÜPF) and the Intelligence Service Act (NDG), Switzerland is "a fully-fledged surveillance state"[14]. Switzerland provides mutual legal assistance to the United States on the basis a 1973 treaty; this way data also ends up with law enforcement agencies there.[14]

ProtonMail founder Andy Yen originally stated that the company would rather leave Switzerland than comply with the Swiss Surveillance Act. ProtonMail chose to stay in Switzerland, and thus has to comply with it[14].

Good cooperation with authoritites

In 2021, a company user was involved in threats against the health bureaucrat Anthony Fauci. In a series of emails, the sender threatened, among other things, to kill Fauci and his family. The American Justice Department wrote[15] in an affidavit that the accused used "an email account from a provider of secure, encrypted email services based in Switzerland". According to the affidavit, the relevant e-mails end with "Sent with ProtonMail Secure Email"[14].

Based on data from ProtonMail, it became apparent that the accused had used several ProtonMail user accounts at the same time. According to his own statements, the accused had switched to ProtonMail because he believed he was protected by Swiss data protection law and end-to-end encryption. Nevertheless, the sender could be identified by the interaction of data from ProtonMail with other online services such as Mail.com.[16]

The Swiss Federal Office of Police (Fedpol) confirmed the exchange with the American authorities. At the same time, Fedpol said it was delighted to work with ProtonMail: "Protonmail is cooperating with the authorities. The cooperation is good."[17]

In 2021, ProtonMail also turned over a French climate activist's IP address and browser fingerprint to Swiss authorities. The company stated its guarantees of email content privacy were not breached.[18]

Participating in information war

In May 2021, during the aftermath of an emergency landing in Minsk of a Ryanair flight between Greece and Lithuania[19], ProtonMail provided fractional information about emails which delivered a bomb threat against the plane to several airports. As analyst Moon of Alabama pointed out, "the partial and seemingly willfully incomplete response by ProtonMail about when and how many emails were sent...has led to false claims by various media against the government of Belarus", thus making it part of the Western information war against the country.[20]

Proton has financially supported[21] Belarus-based Charter'97, an "independent" media organization that Proton describes as one of "Belarus’s most trusted news sites,"[22] but which in reality is backed by Western governments and adjacent organizations, including Open Society Foundations, and the German Marshall Fund of the United States.



Many thanks to our Patrons who cover ~2/3 of our hosting bill. Please join them if you can.


References

  1. https://home.cern/news/news/computing/cern-inspires-entrepreneurs-email-encryption
  2. https://www.justice.gov/usao-sdca/pr/fbi-s-encrypted-phone-platform-infiltrated-hundreds-criminal-syndicates-result-massive
  3. https://www.justice.gov/usao-sdca/pr/fbi-s-encrypted-phone-platform-infiltrated-hundreds-criminal-syndicates-result-massive
  4. https://propagandainfocus.com/proton-mail-imperialist-stooge/
  5. http://motherboard.vice.com/en_ca/read/protonmail-the-easy-to-use-encrypted-email-service-opens-up-to-the-public
  6. https://ge.ch/hrcintapp/externalCompanyReport.action?companyOfrcId13=CH-660-1995014-1&ofrcLanguage=4
  7. https://protonmail.com/blog/tor-encrypted-email/
  8. https://www.inverse.com/article/49041-protonmail-ceo-andy-yen-interview
  9. https://aperture.co/changing-the-business-model-of-the-internet-12/
  10. https://www.theinformation.com/articles/how-protonmail-is-fighting-big-tech
  11. https://security.stackexchange.com/questions/58541/how-are-protonmail-keys-distributed/58552#58552
  12. https://protonmail.com/security-details
  13. https://protonvpn.com/about
  14. a b c d https://steigerlegal.ch/2021/08/02/protonmail-daten-usa/
  15. https://www.justice.gov/usao-md/pr/man-facing-federal-charges-allegedly-sending-threatening-emails-dr-anthony-fauci-and-dr
  16. https://www.justice.gov/usao-md/press-release/file/1416926/download
  17. https://www.tagesanzeiger.ch/us-corona-papst-erhaelt-drohungen-ueber-schweizer-mail-dienst-964516231868
  18. https://www.wired.com/story/protonmail-amends-policy-after-giving-up-activists-data/
  19. https://www.moonofalabama.org/2021/06/roman-protasevich-casualty-of-the-ryanair-incident-in-belarus-is-spilling-the-beans.html
  20. https://www.moonofalabama.org/2021/05/how-protonmail-lost-the-public-trust-it-needs-to-do-business.html
  21. https://proton.me/blog/lifetime-account-supporting-charter97
  22. https://proton.me/blog/lifetime-account-supporting-charter97