this post was submitted on 23 Apr 2026
2 points (75.0% liked)

Technology

42810 readers
212 users here now

A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.

Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.

Subcommunities on Beehaw:


This community's icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

founded 4 years ago
MODERATORS
 

I heard that they require plaintext data to work. What are the other factors to this?

you are viewing a single comment's thread
view the rest of the comments
[–] sanzky@beehaw.org 1 points 4 days ago* (last edited 4 days ago) (1 children)

there has been in the news several instances where proton has given to law enforcements information that have hold onto. in some cases regarding journalists.

their answer is always "ah, yeah. we do keep that one, but not the other data"

before you ask...an example https://privacyradar.com/news/privacy/proton-mail-payment-data-stop-cop-city-activist-identified/

[–] Steve@communick.news 1 points 4 days ago* (last edited 4 days ago) (1 children)

Of course they have to keep some basic account data. And I think the last IP you logged in from. Also email data outside the BODY can't be encrypted. That's just how email works. So law enforcement can get all of that if they convince a Swiss court to order Proton.

But no they don't keep or turn over anything that isn't technically required for the service to work. I don't know what you'd expect.

[–] sanzky@beehaw.org 0 points 3 days ago (1 children)

in that particular case the people involved were identified through their recovery email which they did not hash like 'safe' other providers do. they have positioned themselves as safe even for activist and journalists and have failed to deliver in that account consistently.

no surprise since their CEO is a MAGA guy

[–] TehPers@beehaw.org 0 points 3 days ago (1 children)

recovery email which they did not hash

How do you recover an account on the other providers? Do you have to provide the same recovery email you set before during account recovery? If you hash the email, you have no way of reading it anymore, so someone has to provide it to you again.

[–] sanzky@beehaw.org 1 points 3 days ago

you ask the user for it if they want to recover the account and hash it. if the hash matches your previously stored hash then you send the email

other providers that position themselves as secure for activists or journalists do exactly that and they cannot handle that information