I think yours is the first comment I’ve read that has Proton hesitancy. I’m curious what your reservations are.
Yeah, I don’t trust proton mail.
First off, email is inherently insecure, trying to secure it is largely a waste of time.
Secondly, proton has complied with subpoenas in the past, revealing user messages to authorities/governments.
Finally, it’s just too centralized, with a single point of failure, why would you trust it?
Swiss laws aren’t as tight as a lot of people think.
I’d like for them to lean more heavily into open source
It’s probably tight enough for your needs. Unless you live in Switzerland or are breaking Swiss law, they’d need a really good reason to send your data anywhere.
That said, I use Tuta. They have a similar source model (open client, closed server) and are based in Germany, but since they’re an underdog, they have a bit more value and lower costs. I pay €3 and get 3 custom domains and 15 aliases, whereas w/ Proton I pay $4 and get just 1 custom domain and 10 aliases; I can also add people to my plan for €3, instead of upgrading to a Duo for $15 or family for $24. If Proton matched Tuta’s features, I’d probably pay slightly more for the better UX, but I use those features so I’m very hesitant to give that up. I don’t intend to use their VPN or other products, so I’m very much not interested in their higher tiers.
I do wish their server code was open source and self-hostable. I’d love to use my own storage, but still use their spam filtering and whatnot.
Not OP, I’ve heard criticism of their recent Duo subscription and their bitcoin wallet.
I use Proton services and my biggest gripe is their mediocre Linux VPN app. No binaries to download/Flatpak, advertised port-forwarding isn’t fully implemented and requires playing around in a terminal, and UI feels less polished than it’s Windows counterpart.
There’s a community made Flatpak of ProtonVPN though, in case it helps anyone
Honestly, I just use wg-quick to connect to VPNs, and I tested out ProtonVPN and it worked fine with it. I even set up my router to connect to ProtonVPN, so I could have a wifi network that’s always connected to their VPN.
But I’d really rather not have the same company host my VPN, email, and other stuff, I’d prefer to separate them a bit so no one company has a lot of my data. And something like a VPN really doesn’t benefit from bundling anyway, unless it’s bundled with a browser or something a la Mozilla VPN.
Not OP
There’s not a lot of negative press about them.
They complied with Swiss government requests to out the IP of a French activist.
It looks like they’re really doing the best they can.
Correct. They comply with court orders, its a business. People still need to be secure in how they use it, which that guy wasnt. So if you’re attempting to evade the government, use a vpn. All your data is encrypted, where you access it from and your billing information cannot be.
I actually don’t know what people’s hesitancy is, but I’ve seen numerous people say proton is not good, we’ll see if anybody chimes in with a reason.
The email service says it was unable to appeal a Swiss court’s demand to log the IP address of a French climate advocate.
This weekend, news broke that the anonymous email service ProtonMail turned over a French climate activist’s IP address and browser fingerprint to Swiss authorities. The move seemed to contradict the company’s own privacy-focused policies, which as recently as last week stated, “By default, we do not keep any IP logs which can be linked to your anonymous email account.”
Edit: formatting
I often figure it’s google bias and / or people trying to impose their threat models on other people.
Been using proton for quite a while with a few custom domains and am impressed with the service to price of their offerings.
We can one off use cases with any vendor, but at the end of the day, they offer a more secure out of the box experience than just about any other platform out there. If someone is doing illicit shit and gets popped, it’s not on the service provider to provide air cover for them. Improve your opsec or self host.
I’ve seen doubt of it’s push to pack products into it’s offering ala Google - however I don’t see that as enough to call it not good.
It’s also very easy (and suspicious imo) for anyone to call a service not good without any reason to back it up.