• Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
Blog - Creative Collaboration
No Result
View All Result
Home Internet

Privacy-focused ProtonMail provided a user’s IP address to authorities

September 7, 2021
Share on FacebookShare on Twitter

Enlarge / ProtonMail offers end-to-end encryption and a stated focus on privacy for its email service—which offers a user interface quite similar to those of more mainstream services such as Gmail.

This weekend, news broke that security/privacy-focused anonymous email service ProtonMail turned over a French climate activist’s IP address and browser fingerprint to Swiss authorities. This is seemingly in contradiction to the well-known service’s policies, which as recently as last week stated “by default, we do not keep any IP logs which can be linked to your anonymous email account.”

After providing the activist’s metadata to Swiss authorities, ProtonMail removed the section which had promised no IP logs entirely, replacing it with one saying “ProtonMail is an email that respects privacy and puts people (not advertisers) first.”

No logging “by default”

  • The phrase “by default” did a lot of heavy lifting in ProtonMail’s old front page.

  • The new “your data your rules” snippet offers much less concrete guarantee of privacy, and emphasizes ProtonMail’s optional Tor onion network service.

As usual, the devil is in the details—ProtonMail’s original policy simply said that the service does not keep IP logs “by default.” However, as a Swiss company itself, ProtonMail was obliged to comply with a Swiss court’s injunction demanding that it begin logging IP address and browser fingerprint information for a particular ProtonMail account.

That account was operated by the Parisian chapter of Youth for Climate, which Wikipedia describes as a Greta Thunberg-inspired movement focused on school students who skip Friday classes in order to attend protests.

According to multiple statements ProtonMail issued on Monday, it was unable to appeal the Swiss demand for IP logging on that account. The service could not appeal both because a Swiss law had actually been broken and because “legal tools for serious crimes” were used—tools which ProtonMail does not believe were appropriate to the case at hand, but is legally responsible to comply with nonetheless.

Break out your Tor browser

In addition to removing the misleading if technically correct reference to “default” logging policy, ProtonMail pledged to emphasize the use of the Tor network to activists. The new “your data, your rules” section on ProtonMail’s front page directly links to a landing page aggregating information about using Tor to access ProtonMail.

Advertisement

Using Tor to access ProtonMail may accomplish what ProtonMail itself legally cannot: the obfuscation of its users’ IP addresses. Since the Tor network itself hides users’ network origin prior to packets ever reaching ProtonMail, even a valid subpoena can’t get that information out of ProtonMail—because it never receives it in the first place.

It’s worth noting that the anonymity offered by Tor relies on technical means, not policies—which could serve as a textbook example of a double-edged sword. If a government agency or other threat can compromise Tor nodes your traffic passes through in a way that offers it a way to track origins, there is no policy preventing said government from doing so—or from using that data for law enforcement purposes.

ProtonMail also operates a VPN service called ProtonVPN and points out that Swiss law prohibits the country’s courts from compelling a VPN service to log IP addresses. In theory, if Youth for Climate had used ProtonVPN to access ProtonMail, the Swiss court could not have compelled the service to expose its “real” IP address. However, the company seems to be leaning more heavily toward recommending Tor for this particular purpose.

There’s only so much an email service can encrypt

ProtonMail is also careful to point out that, although its user’s IP address and browser fingerprint were collected by Swiss authorities acting on behalf of Interpol, the company’s guarantees of email content privacy were not breached.

The service uses end-to-end encryption and deliberately does not possess the key necessary to decrypt a user’s email body or attachments. Unlike the source IP address and browser fingerprint, collecting that data is not possible simply by changing a configuration on the company’s own servers as demanded by a court order.

Although ProtonMail can and does encrypt the email body itself with keys unavailable to the servers processing them, the SMTP protocol requires the email sender, email recipient, and message timestamps to be server-accessible. Accessing the service via Tor or a VPN may help obscure IP addresses and browser fingerprints, but the service can still be legally compelled to provide any of those fields to Swiss law enforcement.

In addition, email subject lines could also be encrypted without breaking the SMTP protocol—but in practice, ProtonMail’s service does not, which means the relevant courts may compel the service to provide that data also.

Listing image by ProtonMail

Next Post

Apple's new iPhone event invite has a secret augmented reality message

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

No Result
View All Result

Recent Posts

  • I tested the Moto G Stylus 2026, and it’s finally starting to feel like an affordable alternative to the Galaxy S26 Ultra, but the price tag makes it a tougher sell
  • Amazon launches AI Bio platform to accelerate early-stage drug discovery
  • Is Bluesky down? Here’s what we know.
  • Netgear routers seemingly won’t be banned in the US after all – and this just proves the ban was never about security
  • Steam spotted cooking up a game price tracker to save patient souls a few dollars

Recent Comments

    No Result
    View All Result

    Categories

    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi
    • Home
    • Shop
    • Privacy Policy
    • Terms and Conditions

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    No Result
    View All Result
    • Home
    • Blog
    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    Get more stuff like this
    in your inbox

    Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

    Thank you for subscribing.

    Something went wrong.

    We respect your privacy and take protecting it seriously