this post was submitted on 09 Oct 2026
91 points (89.6% liked)

Privacy

51363 readers
423 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 7 years ago
MODERATORS
 

I keep hearing bad stuff about proton, but I don’t really get most of it. Could someone please explain all of the controversy to me. Lastly, what are the best alternatives to all of their services?

you are viewing a single comment's thread
view the rest of the comments
[–] M1k3y@discuss.tchncs.de 8 points 20 hours ago (3 children)

Its crypto from the 90s and email is not meant to be secure. Some examples:

Only the mail body is protected, headers and metadata arent, so an attacker still knows with who you are talking about what.

Replies contain the full thread, if one person messes up once, the entire chain is unencrypted.

No ephemeral keys, no cleanly defined rotation mechanism. If someone gets your key, all past messages are also accessible.

[–] jabberwock@lemmy.dbzer0.com 5 points 18 hours ago

It depends on your threat model. The actual crypto portion of it holds up, at least until we have crypto-relevant quantum computers.

If you want anonymization and PFS for basic messaging, yeah PGP + email isn't going to cut it. But if you're sending documents, for example, with financial or health data tied to my identity anyway, I'd take PGP with my own email provider over TLS to some tech company servers where it sits unencrypted any day.

[–] manuallybreathing@lemmy.ml 2 points 18 hours ago* (last edited 18 hours ago)

so an attacker still knows with who you are talking about what.

>implying i fill out the subject box with anything meaningful 🤪

[–] bleustenns@lemmy.ml 1 points 20 hours ago (1 children)

TY for informing me. Is there a better alternative to PGP even with the other downsides of email you listed?

[–] Ohh@lemmy.ml 2 points 19 hours ago (1 children)

Signal is probably best, since it has volume to hide in, and it's difficult/ impossible to screw up. Partly because it's centralized. Which is the problem with e.g mateix protocol - each node can configure thi gs a bit differently. Also why you should use the official app imo.

This is a decent walk through: https://www.privacyguides.org/en/basics/email-security/

But simple duckduckgoing can provide much more

https://5blockchains.com/posts/pgp-vs-signal/

https://ubos.tech/news/pgp-encryption-security-crisis-why-cryptography-needs-modern-alternatives/ (feels a bit clanker like - but info is legit)

[–] XiJinpingStanAccount@lemmy.ml 2 points 10 hours ago

I would say Signal is the best like mainstream normie friendly option but if you want the most reliable privacy imo your better off with Briar. It's less convenient for sure, but it requires no phone number, has no centralized servers, can route messages over TOR, Bluetooth, LAN, etc. Messages are end to end encrypted peer to peer. And even when stored on your device are encrypted. Downside is you need the other person to have an android there is no iOS app. But upside is it has a flatpak!