• seathru@lemmy.sdf.org
    link
    fedilink
    English
    arrow-up
    166
    arrow-down
    6
    ·
    edit-2
    2 months ago

    No company is going to legally go to bat for you for $10/mo. I love how Proton nonchalantly calls out the user’s dumb move in the article:

    Proton provides privacy by default and not anonymity by default because anonymity requires certain user actions to ensure proper OpSec, such as not adding your Apple account as an optional recovery method. Note, Proton does not require adding a recovery address as this information can in theory be turned over under Swiss court order…

    • deweydecibel@lemmy.world
      link
      fedilink
      English
      arrow-up
      16
      ·
      edit-2
      2 months ago

      At any point in the process, does it warn you about setting up recovery with personal email addresses?

      Feels like with as much as Proton advertises nowadays as a privacy protecting service, they need to be taking into consideration that a lot of their customers now are going to be average users who don’t know anything about proper OpSec. They should be much clearer about what things they can’t protect you from.

      It shouldn’t be in a press release like this, they should be explaining the difference between privacy and anonymity to the customer. It’s not like their marketing team isn’t aware of the fact most people don’t know any better.

      It’s in their best interests, too, because it doesn’t matter how many times you say “we provide privacy not anonymity”, the headlines are a bad look.

      • Railcar8095@lemm.ee
        link
        fedilink
        arrow-up
        5
        ·
        2 months ago

        Unless you’re targeted by law enforcement, having a recovery email won’t be an issue. 99.99% of the userbase world never have a problem with this.

        I get what you say, but it’s really nitpicking at this point I think.

    • azalty@jlai.lu
      link
      fedilink
      arrow-up
      10
      arrow-down
      2
      ·
      2 months ago

      Proton does require a recovery email address if you sign up to a mail forwarding service or similar, right after creating the account. In that case the account remains locked if you don’t, so that’s just a lie

      • Setarkus.LW@lemmy.world
        link
        fedilink
        arrow-up
        15
        ·
        2 months ago

        In the article it says that that’s a one-time verification address. Though that leaves the question if/how long it’s stored

        • azalty@jlai.lu
          link
          fedilink
          arrow-up
          4
          arrow-down
          1
          ·
          edit-2
          2 months ago

          Still, it wasn’t optional for me, so I’m pretty annoyed that they’re saying it.

          You can remove the mail after but indeed, I won’t trust proton with not keeping that info. The mail has to be entered in the recovery email field, and then sends mail to the recovery email when you have unread mail. So it’s not a one-time mail sent with a code.

    • The Doctor@beehaw.org
      link
      fedilink
      English
      arrow-up
      7
      ·
      2 months ago

      Thing is, Protonmail has been telling people this from the very beginning. It’s like it gets rediscovered every year or so when somebody else gets busted.

    • classic@fedia.io
      link
      fedilink
      arrow-up
      8
      arrow-down
      1
      ·
      2 months ago

      What would be a more appropriate email address to use - or just no recovery email?

      • seathru@lemmy.sdf.org
        link
        fedilink
        English
        arrow-up
        19
        ·
        2 months ago

        It’s best for anonymity to not use one at all. Proton provides a recovery key to allow access to your account if you manage to lock yourself out. Keep that key somewhere safe/secure.