ProtonMail Complied with 5,957 Data Requests in 2022 – Still Secure and Private?

Gandalf_The_Grey

Level 76
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,601
ProtonMail often touts its Swiss jurisdiction and privacy guarantees, but at the same time, it is complying with a record number of data request orders going through the Swiss legal system.

ProtonMail is one of the most popular secure email services in the world, having launched in 2014 via a crowdfunding campaign. It promises a higher level of privacy and security over other email platforms and frequently touts its Swiss jurisdiction.

While Switzerland is a good jurisdiction for privacy-conscious users, it’s certainly no guarantee for data security.

On the ProtonMail homepage, you can see references to “strict Swiss privacy laws” that should keep your data secure.
Proton provides data to the FBI and other police agencies

This past week Forbes ran an article on a case where the FBI was able to get data on a U.S. ProtonMail user who was being investigated for harassment (but not charged with any crime).

The warrant revealed that the FBI managed to acquire data from Proton Technologies, the owner of Proton Mail, to kick off the hunt for the anonymous emailer. It’s a rare example of a U.S. data request on Proton and shows how small pieces of metadata from encrypted software can prove hugely useful for cops trying to unmask users who expect strong privacy protections from such apps.
– Forbes
In this case, Proton Technologies provided the FBI with the “recovery and associated email addresses” of the user, which lead to his discovery.

Two years ago, RestorePrivacy ran an article on another ProtonMail logging case involving a French activist who was also a ProtonMail user. In that case, French police received the user’s IP address from Proton Technologies, leading to the arrest of the suspect.

This begs the question, how common are cases like these, particularly with cases that don’t end up in the news?
 

Digmor Crusher

Level 23
Verified
Top Poster
Well-known
Jan 27, 2018
1,265
At least their transparent and it looks like they were just responding to Swiss laws.
It's hard to offer any insightful comments on this unless we get factual numbers from every other VPN as to how many requests they fulfilled.
 

Arequire

Level 29
Verified
Top Poster
Content Creator
Feb 10, 2017
1,823
The important bits:
Proton Mail provided us with an explanation for the growing number of cases below.
The increase in cases reflects the increase in our user base. As Proton has scaled, and now has 100m sign ups to our services, it’s not surprising that these figures have risen. However, these cases have come through the Swiss authorities (which is a good sense check of their validity) and have also been reviewed by Proton to ensure they are reasonable for us to respond to (hence why there are also cases that we have not complied with mentioned on the transparency report). Please note that in all cases email content, attachments, files etc are always encrypted and cannot be read.
– Proton spokesperson
All businesses must comply with the laws in the countries where they are legally based. The only other option is to shut down, like we saw with CTemplar in 2022 and Lavabit back in 2013.
Is Proton Mail still secure and private?
In short, the answer is yes if you are looking for a secure, encrypted email service that does not have access to the contents of your inbox.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top