Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. It feels like Proton are being intentionally misleading in their statements.

It feels like Proton are being intentionally misleading in their statements.

Scheduled Pinned Locked Moved Uncategorized
80 Posts 44 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • malwaretech@infosec.exchangeM This user is from outside of this forum
    malwaretech@infosec.exchangeM This user is from outside of this forum
    malwaretech@infosec.exchange
    wrote last edited by
    #1

    It feels like Proton are being intentionally misleading in their statements. They know that most of their customers aren't familiar with how legal process actually works, so are happy to spread half-truths.

    Under US law, a US law enforcement agency (LEA) typically has to apply for a subpoena or search warrant with a US court. The court is then responsible for deciding if the legal bar for search a request has been met, then either grants or denies it.

    The problem is, if a company has no real US footprint (no US corporate entity, offices, servers, etc.), then a US court typically doesn't have the jurisdiction to compel the company to hand over customer data (except in some rare circumstances). Even if the court approved the warrant anyway, it wouldn't really be legally binding.

    Which is why the Mutual Legal Assistance Treaty (MLAT) exists. MLAT enables law enforcement agencies in one company to send requests for information to law enforcement agencies in another. Switzerland has such a treaty with the US. This means that the FBI can request that Swiss authorities hand over a Swiss company's data on their behalf.

    Any country requesting information held by a company in a foreign jurisdiction would typically do so via MLAT. Which means from Proton's perspective, the legal request would appear to originate from their local law enforcement, not the FBI. Which they clearly understand based on their Reddit post.

    Saying "we don't respond to legal requests from anywhere other than Swiss authorities" seems very intentionally worded to give the impression that the company does not cooperate with foreign law enforcement. But since it'd be the Swiss authorities handling any such requests, they'd have to comply, since as they admitted, they have to comply with local laws.

    There is, however, some useful (but more nuanced) information here:

    Firstly, MLAT requests are handled by local law enforcement according to local law. So if there is a difference between the law of the sending and recipient country, that might mean the MLAT request is denied. That probably doesn't mean much, because if you're on the FBI's radar, the chances are you did something that is also massively illegal in Switzerland too.

    Secondly, they are 100% correct in saying that no other service provider is going to do any better. They're all beholden to local laws, and the ones that think they're not tend to get their doors blown off by SWAT like CyberBunker did. The only exception is if the company resides in a country which does not cooperate with US law enforcement (which Proton does not).

    But the part that's extremely disingenuous is that the "we only respond to requests from the Swiss authorities". That statement is likely intended to imply they don't cooperate with law enforcement in any other countries, which is simply not true. Switzerland has MLAT agreements with over 30 counties.

    People really need to understand that no company is going to shield you from the FBI (or any reputable law enforcement agency). They'll use misleading statements to make it sounds like they don't cooperate with law enforcement, but they do. They have to.

    silhouette@dumbfuckingweb.siteS at1st@mstdn.caA randamumaki@mstdn.socialR can@haz.pinkC james@bne.socialJ 26 Replies Last reply
    1
    0
    • malwaretech@infosec.exchangeM malwaretech@infosec.exchange

      It feels like Proton are being intentionally misleading in their statements. They know that most of their customers aren't familiar with how legal process actually works, so are happy to spread half-truths.

      Under US law, a US law enforcement agency (LEA) typically has to apply for a subpoena or search warrant with a US court. The court is then responsible for deciding if the legal bar for search a request has been met, then either grants or denies it.

      The problem is, if a company has no real US footprint (no US corporate entity, offices, servers, etc.), then a US court typically doesn't have the jurisdiction to compel the company to hand over customer data (except in some rare circumstances). Even if the court approved the warrant anyway, it wouldn't really be legally binding.

      Which is why the Mutual Legal Assistance Treaty (MLAT) exists. MLAT enables law enforcement agencies in one company to send requests for information to law enforcement agencies in another. Switzerland has such a treaty with the US. This means that the FBI can request that Swiss authorities hand over a Swiss company's data on their behalf.

      Any country requesting information held by a company in a foreign jurisdiction would typically do so via MLAT. Which means from Proton's perspective, the legal request would appear to originate from their local law enforcement, not the FBI. Which they clearly understand based on their Reddit post.

      Saying "we don't respond to legal requests from anywhere other than Swiss authorities" seems very intentionally worded to give the impression that the company does not cooperate with foreign law enforcement. But since it'd be the Swiss authorities handling any such requests, they'd have to comply, since as they admitted, they have to comply with local laws.

      There is, however, some useful (but more nuanced) information here:

      Firstly, MLAT requests are handled by local law enforcement according to local law. So if there is a difference between the law of the sending and recipient country, that might mean the MLAT request is denied. That probably doesn't mean much, because if you're on the FBI's radar, the chances are you did something that is also massively illegal in Switzerland too.

      Secondly, they are 100% correct in saying that no other service provider is going to do any better. They're all beholden to local laws, and the ones that think they're not tend to get their doors blown off by SWAT like CyberBunker did. The only exception is if the company resides in a country which does not cooperate with US law enforcement (which Proton does not).

      But the part that's extremely disingenuous is that the "we only respond to requests from the Swiss authorities". That statement is likely intended to imply they don't cooperate with law enforcement in any other countries, which is simply not true. Switzerland has MLAT agreements with over 30 counties.

      People really need to understand that no company is going to shield you from the FBI (or any reputable law enforcement agency). They'll use misleading statements to make it sounds like they don't cooperate with law enforcement, but they do. They have to.

      silhouette@dumbfuckingweb.siteS This user is from outside of this forum
      silhouette@dumbfuckingweb.siteS This user is from outside of this forum
      silhouette@dumbfuckingweb.site
      wrote last edited by
      #2

      @malwaretech well you convinced me, time to give all my data to an Indonesian bulletproof hoster

      kallisti@infosec.exchangeK _hic_haec_hoc@fosstodon.org_ 2 Replies Last reply
      0
      • silhouette@dumbfuckingweb.siteS silhouette@dumbfuckingweb.site

        @malwaretech well you convinced me, time to give all my data to an Indonesian bulletproof hoster

        kallisti@infosec.exchangeK This user is from outside of this forum
        kallisti@infosec.exchangeK This user is from outside of this forum
        kallisti@infosec.exchange
        wrote last edited by
        #3

        @silhouette @malwaretech
        I wonder if ocean floor datacenters could take advantage of laws on international waters

        dave_cochran@infosec.exchangeD jnk@masto.esJ oldoldcojote@climatejustice.socialO bruce@darkmoon.socialB 4 Replies Last reply
        0
        • malwaretech@infosec.exchangeM malwaretech@infosec.exchange

          It feels like Proton are being intentionally misleading in their statements. They know that most of their customers aren't familiar with how legal process actually works, so are happy to spread half-truths.

          Under US law, a US law enforcement agency (LEA) typically has to apply for a subpoena or search warrant with a US court. The court is then responsible for deciding if the legal bar for search a request has been met, then either grants or denies it.

          The problem is, if a company has no real US footprint (no US corporate entity, offices, servers, etc.), then a US court typically doesn't have the jurisdiction to compel the company to hand over customer data (except in some rare circumstances). Even if the court approved the warrant anyway, it wouldn't really be legally binding.

          Which is why the Mutual Legal Assistance Treaty (MLAT) exists. MLAT enables law enforcement agencies in one company to send requests for information to law enforcement agencies in another. Switzerland has such a treaty with the US. This means that the FBI can request that Swiss authorities hand over a Swiss company's data on their behalf.

          Any country requesting information held by a company in a foreign jurisdiction would typically do so via MLAT. Which means from Proton's perspective, the legal request would appear to originate from their local law enforcement, not the FBI. Which they clearly understand based on their Reddit post.

          Saying "we don't respond to legal requests from anywhere other than Swiss authorities" seems very intentionally worded to give the impression that the company does not cooperate with foreign law enforcement. But since it'd be the Swiss authorities handling any such requests, they'd have to comply, since as they admitted, they have to comply with local laws.

          There is, however, some useful (but more nuanced) information here:

          Firstly, MLAT requests are handled by local law enforcement according to local law. So if there is a difference between the law of the sending and recipient country, that might mean the MLAT request is denied. That probably doesn't mean much, because if you're on the FBI's radar, the chances are you did something that is also massively illegal in Switzerland too.

          Secondly, they are 100% correct in saying that no other service provider is going to do any better. They're all beholden to local laws, and the ones that think they're not tend to get their doors blown off by SWAT like CyberBunker did. The only exception is if the company resides in a country which does not cooperate with US law enforcement (which Proton does not).

          But the part that's extremely disingenuous is that the "we only respond to requests from the Swiss authorities". That statement is likely intended to imply they don't cooperate with law enforcement in any other countries, which is simply not true. Switzerland has MLAT agreements with over 30 counties.

          People really need to understand that no company is going to shield you from the FBI (or any reputable law enforcement agency). They'll use misleading statements to make it sounds like they don't cooperate with law enforcement, but they do. They have to.

          at1st@mstdn.caA This user is from outside of this forum
          at1st@mstdn.caA This user is from outside of this forum
          at1st@mstdn.ca
          wrote last edited by
          #4

          @malwaretech The thing that gets me is - is the company being requested by the MLAT allowed to challenge their local government on the legality of the request?

          Like how Apple famously refused to make a program to automatically decrypt their iPhones to federal, state, or municipal authorities to be able to decrypt a terrorist's phone, and as I recall, that actually went to court on that?

          Could Proton not do the same with the request made of them?

          can@haz.pinkC malwaretech@infosec.exchangeM saupreiss@pfalz.socialS ohir@social.vivaldi.netO iampytest1@infosec.exchangeI 5 Replies Last reply
          0
          • malwaretech@infosec.exchangeM malwaretech@infosec.exchange

            It feels like Proton are being intentionally misleading in their statements. They know that most of their customers aren't familiar with how legal process actually works, so are happy to spread half-truths.

            Under US law, a US law enforcement agency (LEA) typically has to apply for a subpoena or search warrant with a US court. The court is then responsible for deciding if the legal bar for search a request has been met, then either grants or denies it.

            The problem is, if a company has no real US footprint (no US corporate entity, offices, servers, etc.), then a US court typically doesn't have the jurisdiction to compel the company to hand over customer data (except in some rare circumstances). Even if the court approved the warrant anyway, it wouldn't really be legally binding.

            Which is why the Mutual Legal Assistance Treaty (MLAT) exists. MLAT enables law enforcement agencies in one company to send requests for information to law enforcement agencies in another. Switzerland has such a treaty with the US. This means that the FBI can request that Swiss authorities hand over a Swiss company's data on their behalf.

            Any country requesting information held by a company in a foreign jurisdiction would typically do so via MLAT. Which means from Proton's perspective, the legal request would appear to originate from their local law enforcement, not the FBI. Which they clearly understand based on their Reddit post.

            Saying "we don't respond to legal requests from anywhere other than Swiss authorities" seems very intentionally worded to give the impression that the company does not cooperate with foreign law enforcement. But since it'd be the Swiss authorities handling any such requests, they'd have to comply, since as they admitted, they have to comply with local laws.

            There is, however, some useful (but more nuanced) information here:

            Firstly, MLAT requests are handled by local law enforcement according to local law. So if there is a difference between the law of the sending and recipient country, that might mean the MLAT request is denied. That probably doesn't mean much, because if you're on the FBI's radar, the chances are you did something that is also massively illegal in Switzerland too.

            Secondly, they are 100% correct in saying that no other service provider is going to do any better. They're all beholden to local laws, and the ones that think they're not tend to get their doors blown off by SWAT like CyberBunker did. The only exception is if the company resides in a country which does not cooperate with US law enforcement (which Proton does not).

            But the part that's extremely disingenuous is that the "we only respond to requests from the Swiss authorities". That statement is likely intended to imply they don't cooperate with law enforcement in any other countries, which is simply not true. Switzerland has MLAT agreements with over 30 counties.

            People really need to understand that no company is going to shield you from the FBI (or any reputable law enforcement agency). They'll use misleading statements to make it sounds like they don't cooperate with law enforcement, but they do. They have to.

            randamumaki@mstdn.socialR This user is from outside of this forum
            randamumaki@mstdn.socialR This user is from outside of this forum
            randamumaki@mstdn.social
            wrote last edited by
            #5

            @malwaretech The MLAT request may originate from a country other than Switzerland, but it is still brought to Proton from the Swiss authorities in accordance to Swiss law, which makes it a legal request from Swiss authorities. Proton is not misleading in this.

            derekheld@infosec.exchangeD amd@gts.amd.imA 2 Replies Last reply
            0
            • malwaretech@infosec.exchangeM malwaretech@infosec.exchange

              It feels like Proton are being intentionally misleading in their statements. They know that most of their customers aren't familiar with how legal process actually works, so are happy to spread half-truths.

              Under US law, a US law enforcement agency (LEA) typically has to apply for a subpoena or search warrant with a US court. The court is then responsible for deciding if the legal bar for search a request has been met, then either grants or denies it.

              The problem is, if a company has no real US footprint (no US corporate entity, offices, servers, etc.), then a US court typically doesn't have the jurisdiction to compel the company to hand over customer data (except in some rare circumstances). Even if the court approved the warrant anyway, it wouldn't really be legally binding.

              Which is why the Mutual Legal Assistance Treaty (MLAT) exists. MLAT enables law enforcement agencies in one company to send requests for information to law enforcement agencies in another. Switzerland has such a treaty with the US. This means that the FBI can request that Swiss authorities hand over a Swiss company's data on their behalf.

              Any country requesting information held by a company in a foreign jurisdiction would typically do so via MLAT. Which means from Proton's perspective, the legal request would appear to originate from their local law enforcement, not the FBI. Which they clearly understand based on their Reddit post.

              Saying "we don't respond to legal requests from anywhere other than Swiss authorities" seems very intentionally worded to give the impression that the company does not cooperate with foreign law enforcement. But since it'd be the Swiss authorities handling any such requests, they'd have to comply, since as they admitted, they have to comply with local laws.

              There is, however, some useful (but more nuanced) information here:

              Firstly, MLAT requests are handled by local law enforcement according to local law. So if there is a difference between the law of the sending and recipient country, that might mean the MLAT request is denied. That probably doesn't mean much, because if you're on the FBI's radar, the chances are you did something that is also massively illegal in Switzerland too.

              Secondly, they are 100% correct in saying that no other service provider is going to do any better. They're all beholden to local laws, and the ones that think they're not tend to get their doors blown off by SWAT like CyberBunker did. The only exception is if the company resides in a country which does not cooperate with US law enforcement (which Proton does not).

              But the part that's extremely disingenuous is that the "we only respond to requests from the Swiss authorities". That statement is likely intended to imply they don't cooperate with law enforcement in any other countries, which is simply not true. Switzerland has MLAT agreements with over 30 counties.

              People really need to understand that no company is going to shield you from the FBI (or any reputable law enforcement agency). They'll use misleading statements to make it sounds like they don't cooperate with law enforcement, but they do. They have to.

              can@haz.pinkC This user is from outside of this forum
              can@haz.pinkC This user is from outside of this forum
              can@haz.pink
              wrote last edited by
              #6

              @malwaretech the trick is to not have that data accessible in the first place. Like Mullvad back when they were forced to give out data.

              qgustavor@urusai.socialQ 1 Reply Last reply
              0
              • at1st@mstdn.caA at1st@mstdn.ca

                @malwaretech The thing that gets me is - is the company being requested by the MLAT allowed to challenge their local government on the legality of the request?

                Like how Apple famously refused to make a program to automatically decrypt their iPhones to federal, state, or municipal authorities to be able to decrypt a terrorist's phone, and as I recall, that actually went to court on that?

                Could Proton not do the same with the request made of them?

                can@haz.pinkC This user is from outside of this forum
                can@haz.pinkC This user is from outside of this forum
                can@haz.pink
                wrote last edited by
                #7

                @AT1ST @malwaretech does Proton have Apple money?

                at1st@mstdn.caA 1 Reply Last reply
                0
                • malwaretech@infosec.exchangeM malwaretech@infosec.exchange

                  It feels like Proton are being intentionally misleading in their statements. They know that most of their customers aren't familiar with how legal process actually works, so are happy to spread half-truths.

                  Under US law, a US law enforcement agency (LEA) typically has to apply for a subpoena or search warrant with a US court. The court is then responsible for deciding if the legal bar for search a request has been met, then either grants or denies it.

                  The problem is, if a company has no real US footprint (no US corporate entity, offices, servers, etc.), then a US court typically doesn't have the jurisdiction to compel the company to hand over customer data (except in some rare circumstances). Even if the court approved the warrant anyway, it wouldn't really be legally binding.

                  Which is why the Mutual Legal Assistance Treaty (MLAT) exists. MLAT enables law enforcement agencies in one company to send requests for information to law enforcement agencies in another. Switzerland has such a treaty with the US. This means that the FBI can request that Swiss authorities hand over a Swiss company's data on their behalf.

                  Any country requesting information held by a company in a foreign jurisdiction would typically do so via MLAT. Which means from Proton's perspective, the legal request would appear to originate from their local law enforcement, not the FBI. Which they clearly understand based on their Reddit post.

                  Saying "we don't respond to legal requests from anywhere other than Swiss authorities" seems very intentionally worded to give the impression that the company does not cooperate with foreign law enforcement. But since it'd be the Swiss authorities handling any such requests, they'd have to comply, since as they admitted, they have to comply with local laws.

                  There is, however, some useful (but more nuanced) information here:

                  Firstly, MLAT requests are handled by local law enforcement according to local law. So if there is a difference between the law of the sending and recipient country, that might mean the MLAT request is denied. That probably doesn't mean much, because if you're on the FBI's radar, the chances are you did something that is also massively illegal in Switzerland too.

                  Secondly, they are 100% correct in saying that no other service provider is going to do any better. They're all beholden to local laws, and the ones that think they're not tend to get their doors blown off by SWAT like CyberBunker did. The only exception is if the company resides in a country which does not cooperate with US law enforcement (which Proton does not).

                  But the part that's extremely disingenuous is that the "we only respond to requests from the Swiss authorities". That statement is likely intended to imply they don't cooperate with law enforcement in any other countries, which is simply not true. Switzerland has MLAT agreements with over 30 counties.

                  People really need to understand that no company is going to shield you from the FBI (or any reputable law enforcement agency). They'll use misleading statements to make it sounds like they don't cooperate with law enforcement, but they do. They have to.

                  james@bne.socialJ This user is from outside of this forum
                  james@bne.socialJ This user is from outside of this forum
                  james@bne.social
                  wrote last edited by
                  #8

                  @malwaretech

                  Not sure that Proton’s 100% true statement - that they only respond to requests from the Swiss authorities - is “intentionally misleading”. As you have outlined, it is literally the truth.

                  We’re all aware that international treaties exist. But, as you also outline, they are subject to domestic law. And that isn’t a given - breaking US tax law is unlikely to have any impact on Swiss authorities, who would likely deny requests for assistance before it ever reaches Proton.

                  I don’t like Proton much as a company - they do too many things, for one. I don’t use them (any more). But I don’t think your attempt to deliberately stir up FUD about them is warranted here.

                  james@bne.socialJ malwaretech@infosec.exchangeM 2 Replies Last reply
                  0
                  • malwaretech@infosec.exchangeM malwaretech@infosec.exchange

                    It feels like Proton are being intentionally misleading in their statements. They know that most of their customers aren't familiar with how legal process actually works, so are happy to spread half-truths.

                    Under US law, a US law enforcement agency (LEA) typically has to apply for a subpoena or search warrant with a US court. The court is then responsible for deciding if the legal bar for search a request has been met, then either grants or denies it.

                    The problem is, if a company has no real US footprint (no US corporate entity, offices, servers, etc.), then a US court typically doesn't have the jurisdiction to compel the company to hand over customer data (except in some rare circumstances). Even if the court approved the warrant anyway, it wouldn't really be legally binding.

                    Which is why the Mutual Legal Assistance Treaty (MLAT) exists. MLAT enables law enforcement agencies in one company to send requests for information to law enforcement agencies in another. Switzerland has such a treaty with the US. This means that the FBI can request that Swiss authorities hand over a Swiss company's data on their behalf.

                    Any country requesting information held by a company in a foreign jurisdiction would typically do so via MLAT. Which means from Proton's perspective, the legal request would appear to originate from their local law enforcement, not the FBI. Which they clearly understand based on their Reddit post.

                    Saying "we don't respond to legal requests from anywhere other than Swiss authorities" seems very intentionally worded to give the impression that the company does not cooperate with foreign law enforcement. But since it'd be the Swiss authorities handling any such requests, they'd have to comply, since as they admitted, they have to comply with local laws.

                    There is, however, some useful (but more nuanced) information here:

                    Firstly, MLAT requests are handled by local law enforcement according to local law. So if there is a difference between the law of the sending and recipient country, that might mean the MLAT request is denied. That probably doesn't mean much, because if you're on the FBI's radar, the chances are you did something that is also massively illegal in Switzerland too.

                    Secondly, they are 100% correct in saying that no other service provider is going to do any better. They're all beholden to local laws, and the ones that think they're not tend to get their doors blown off by SWAT like CyberBunker did. The only exception is if the company resides in a country which does not cooperate with US law enforcement (which Proton does not).

                    But the part that's extremely disingenuous is that the "we only respond to requests from the Swiss authorities". That statement is likely intended to imply they don't cooperate with law enforcement in any other countries, which is simply not true. Switzerland has MLAT agreements with over 30 counties.

                    People really need to understand that no company is going to shield you from the FBI (or any reputable law enforcement agency). They'll use misleading statements to make it sounds like they don't cooperate with law enforcement, but they do. They have to.

                    stinerman@mastodon.socialS This user is from outside of this forum
                    stinerman@mastodon.socialS This user is from outside of this forum
                    stinerman@mastodon.social
                    wrote last edited by
                    #9

                    @malwaretech I think they should be more upfront about what they're selling. They sell security. They don't really sell anonymity. People think Proton is "I create an account and everything I do is anonymous." It isn't, Proton never said it was, but people make assumptions.

                    But let's not pretend that any other similar service (Tuta, etc.) wouldn't do the same thing.

                    ohir@social.vivaldi.netO 1 Reply Last reply
                    0
                    • silhouette@dumbfuckingweb.siteS silhouette@dumbfuckingweb.site

                      @malwaretech well you convinced me, time to give all my data to an Indonesian bulletproof hoster

                      _hic_haec_hoc@fosstodon.org_ This user is from outside of this forum
                      _hic_haec_hoc@fosstodon.org_ This user is from outside of this forum
                      _hic_haec_hoc@fosstodon.org
                      wrote last edited by
                      #10

                      @silhouette @malwaretech I hear there's a good one in the island of Kinakuta

                      1 Reply Last reply
                      0
                      • james@bne.socialJ james@bne.social

                        @malwaretech

                        Not sure that Proton’s 100% true statement - that they only respond to requests from the Swiss authorities - is “intentionally misleading”. As you have outlined, it is literally the truth.

                        We’re all aware that international treaties exist. But, as you also outline, they are subject to domestic law. And that isn’t a given - breaking US tax law is unlikely to have any impact on Swiss authorities, who would likely deny requests for assistance before it ever reaches Proton.

                        I don’t like Proton much as a company - they do too many things, for one. I don’t use them (any more). But I don’t think your attempt to deliberately stir up FUD about them is warranted here.

                        james@bne.socialJ This user is from outside of this forum
                        james@bne.socialJ This user is from outside of this forum
                        james@bne.social
                        wrote last edited by
                        #11

                        @malwaretech As for keeping your privacy…

                        Mullvad sells (tamper-proof) paper vouchers on Amazon.

                        I buy one with my credit card. Amazon ships it to me. They know I bought a Mullvad subscription, and my address and credit card. But they don’t know which Mullvad account it relates to.

                        Mullvad knows they shipped a bunch of paper vouchers to Amazon. They know this voucher came from there. But they don’t know who I am - they have none of my details other than the voucher information.

                        This seems a simple method of firewalling the purchase information from the service to which it relates. Given Proton’s size, and its professed security credentials, it’s curious why they don’t do similar.

                        1 Reply Last reply
                        0
                        • james@bne.socialJ james@bne.social

                          @malwaretech

                          Not sure that Proton’s 100% true statement - that they only respond to requests from the Swiss authorities - is “intentionally misleading”. As you have outlined, it is literally the truth.

                          We’re all aware that international treaties exist. But, as you also outline, they are subject to domestic law. And that isn’t a given - breaking US tax law is unlikely to have any impact on Swiss authorities, who would likely deny requests for assistance before it ever reaches Proton.

                          I don’t like Proton much as a company - they do too many things, for one. I don’t use them (any more). But I don’t think your attempt to deliberately stir up FUD about them is warranted here.

                          malwaretech@infosec.exchangeM This user is from outside of this forum
                          malwaretech@infosec.exchangeM This user is from outside of this forum
                          malwaretech@infosec.exchange
                          wrote last edited by
                          #12

                          @james Each sentence of your comment is increasingly dumber than the last. "We’re all aware that international treaties exist" yeah, your average internet user definitely understands international legal assistance processes.

                          There's nothing "FUD" about my statement. It contains only facts which enable users to better inform their decisions.

                          "breaking US tax law is unlikely to have any impact on Swiss authorities" Is an extremely funny statement given it was the US who forced Switzerland to roll back some of it's bank secrecy laws so the US could go after tax evaders.

                          If you're gonna accuse me of spreading FUD, at least put in a modicum of effort.

                          1 Reply Last reply
                          0
                          • at1st@mstdn.caA at1st@mstdn.ca

                            @malwaretech The thing that gets me is - is the company being requested by the MLAT allowed to challenge their local government on the legality of the request?

                            Like how Apple famously refused to make a program to automatically decrypt their iPhones to federal, state, or municipal authorities to be able to decrypt a terrorist's phone, and as I recall, that actually went to court on that?

                            Could Proton not do the same with the request made of them?

                            malwaretech@infosec.exchangeM This user is from outside of this forum
                            malwaretech@infosec.exchangeM This user is from outside of this forum
                            malwaretech@infosec.exchange
                            wrote last edited by
                            #13

                            @AT1ST No, Apple just outright refused and has enough money to tie most of the federal government lawyers up in court for the rest of their careers

                            at1st@mstdn.caA 1 Reply Last reply
                            0
                            • can@haz.pinkC can@haz.pink

                              @AT1ST @malwaretech does Proton have Apple money?

                              at1st@mstdn.caA This user is from outside of this forum
                              at1st@mstdn.caA This user is from outside of this forum
                              at1st@mstdn.ca
                              wrote last edited by
                              #14

                              @can @malwaretech Do they *need* Apple money to challenge the Swedish legal system? Justice should not just be for the rich; the Swedish government should have a vested interest in their own companies being able to challenge an MLAT request so it is not just a "Did they cross their 'i's and dot their 't's?" system of justice.

                              stefan_hessbrueggen@fedihum.orgS 1 Reply Last reply
                              0
                              • malwaretech@infosec.exchangeM malwaretech@infosec.exchange

                                It feels like Proton are being intentionally misleading in their statements. They know that most of their customers aren't familiar with how legal process actually works, so are happy to spread half-truths.

                                Under US law, a US law enforcement agency (LEA) typically has to apply for a subpoena or search warrant with a US court. The court is then responsible for deciding if the legal bar for search a request has been met, then either grants or denies it.

                                The problem is, if a company has no real US footprint (no US corporate entity, offices, servers, etc.), then a US court typically doesn't have the jurisdiction to compel the company to hand over customer data (except in some rare circumstances). Even if the court approved the warrant anyway, it wouldn't really be legally binding.

                                Which is why the Mutual Legal Assistance Treaty (MLAT) exists. MLAT enables law enforcement agencies in one company to send requests for information to law enforcement agencies in another. Switzerland has such a treaty with the US. This means that the FBI can request that Swiss authorities hand over a Swiss company's data on their behalf.

                                Any country requesting information held by a company in a foreign jurisdiction would typically do so via MLAT. Which means from Proton's perspective, the legal request would appear to originate from their local law enforcement, not the FBI. Which they clearly understand based on their Reddit post.

                                Saying "we don't respond to legal requests from anywhere other than Swiss authorities" seems very intentionally worded to give the impression that the company does not cooperate with foreign law enforcement. But since it'd be the Swiss authorities handling any such requests, they'd have to comply, since as they admitted, they have to comply with local laws.

                                There is, however, some useful (but more nuanced) information here:

                                Firstly, MLAT requests are handled by local law enforcement according to local law. So if there is a difference between the law of the sending and recipient country, that might mean the MLAT request is denied. That probably doesn't mean much, because if you're on the FBI's radar, the chances are you did something that is also massively illegal in Switzerland too.

                                Secondly, they are 100% correct in saying that no other service provider is going to do any better. They're all beholden to local laws, and the ones that think they're not tend to get their doors blown off by SWAT like CyberBunker did. The only exception is if the company resides in a country which does not cooperate with US law enforcement (which Proton does not).

                                But the part that's extremely disingenuous is that the "we only respond to requests from the Swiss authorities". That statement is likely intended to imply they don't cooperate with law enforcement in any other countries, which is simply not true. Switzerland has MLAT agreements with over 30 counties.

                                People really need to understand that no company is going to shield you from the FBI (or any reputable law enforcement agency). They'll use misleading statements to make it sounds like they don't cooperate with law enforcement, but they do. They have to.

                                saupreiss@pfalz.socialS This user is from outside of this forum
                                saupreiss@pfalz.socialS This user is from outside of this forum
                                saupreiss@pfalz.social
                                wrote last edited by
                                #15

                                @malwaretech

                                Thing is that these requests must still comply with Swiss law and can be challenged in Swiss courts. Which IS more restrictive on these matters than US law.

                                1 Reply Last reply
                                0
                                • at1st@mstdn.caA at1st@mstdn.ca

                                  @malwaretech The thing that gets me is - is the company being requested by the MLAT allowed to challenge their local government on the legality of the request?

                                  Like how Apple famously refused to make a program to automatically decrypt their iPhones to federal, state, or municipal authorities to be able to decrypt a terrorist's phone, and as I recall, that actually went to court on that?

                                  Could Proton not do the same with the request made of them?

                                  saupreiss@pfalz.socialS This user is from outside of this forum
                                  saupreiss@pfalz.socialS This user is from outside of this forum
                                  saupreiss@pfalz.social
                                  wrote last edited by
                                  #16

                                  @AT1ST

                                  Absolutely.
                                  Also, no such things as gag orders are known (yet…) on this continent.

                                  @malwaretech

                                  1 Reply Last reply
                                  0
                                  • R relay@relay.an.exchange shared this topic
                                  • malwaretech@infosec.exchangeM malwaretech@infosec.exchange

                                    It feels like Proton are being intentionally misleading in their statements. They know that most of their customers aren't familiar with how legal process actually works, so are happy to spread half-truths.

                                    Under US law, a US law enforcement agency (LEA) typically has to apply for a subpoena or search warrant with a US court. The court is then responsible for deciding if the legal bar for search a request has been met, then either grants or denies it.

                                    The problem is, if a company has no real US footprint (no US corporate entity, offices, servers, etc.), then a US court typically doesn't have the jurisdiction to compel the company to hand over customer data (except in some rare circumstances). Even if the court approved the warrant anyway, it wouldn't really be legally binding.

                                    Which is why the Mutual Legal Assistance Treaty (MLAT) exists. MLAT enables law enforcement agencies in one company to send requests for information to law enforcement agencies in another. Switzerland has such a treaty with the US. This means that the FBI can request that Swiss authorities hand over a Swiss company's data on their behalf.

                                    Any country requesting information held by a company in a foreign jurisdiction would typically do so via MLAT. Which means from Proton's perspective, the legal request would appear to originate from their local law enforcement, not the FBI. Which they clearly understand based on their Reddit post.

                                    Saying "we don't respond to legal requests from anywhere other than Swiss authorities" seems very intentionally worded to give the impression that the company does not cooperate with foreign law enforcement. But since it'd be the Swiss authorities handling any such requests, they'd have to comply, since as they admitted, they have to comply with local laws.

                                    There is, however, some useful (but more nuanced) information here:

                                    Firstly, MLAT requests are handled by local law enforcement according to local law. So if there is a difference between the law of the sending and recipient country, that might mean the MLAT request is denied. That probably doesn't mean much, because if you're on the FBI's radar, the chances are you did something that is also massively illegal in Switzerland too.

                                    Secondly, they are 100% correct in saying that no other service provider is going to do any better. They're all beholden to local laws, and the ones that think they're not tend to get their doors blown off by SWAT like CyberBunker did. The only exception is if the company resides in a country which does not cooperate with US law enforcement (which Proton does not).

                                    But the part that's extremely disingenuous is that the "we only respond to requests from the Swiss authorities". That statement is likely intended to imply they don't cooperate with law enforcement in any other countries, which is simply not true. Switzerland has MLAT agreements with over 30 counties.

                                    People really need to understand that no company is going to shield you from the FBI (or any reputable law enforcement agency). They'll use misleading statements to make it sounds like they don't cooperate with law enforcement, but they do. They have to.

                                    diogoconstantino@masto.ptD This user is from outside of this forum
                                    diogoconstantino@masto.ptD This user is from outside of this forum
                                    diogoconstantino@masto.pt
                                    wrote last edited by
                                    #17

                                    @malwaretech that's not misleading it's actual thruth. Italia the Switz authoroties that are collaborating with the foreign authorities under the MLAT.

                                    amd@gts.amd.imA 1 Reply Last reply
                                    0
                                    • at1st@mstdn.caA at1st@mstdn.ca

                                      @can @malwaretech Do they *need* Apple money to challenge the Swedish legal system? Justice should not just be for the rich; the Swedish government should have a vested interest in their own companies being able to challenge an MLAT request so it is not just a "Did they cross their 'i's and dot their 't's?" system of justice.

                                      stefan_hessbrueggen@fedihum.orgS This user is from outside of this forum
                                      stefan_hessbrueggen@fedihum.orgS This user is from outside of this forum
                                      stefan_hessbrueggen@fedihum.org
                                      wrote last edited by
                                      #18

                                      @AT1ST Swiss. Not Swedish. Cuckoo clocks, not IKEA. *facepalm @can @malwaretech

                                      at1st@mstdn.caA 1 Reply Last reply
                                      0
                                      • malwaretech@infosec.exchangeM malwaretech@infosec.exchange

                                        @AT1ST No, Apple just outright refused and has enough money to tie most of the federal government lawyers up in court for the rest of their careers

                                        at1st@mstdn.caA This user is from outside of this forum
                                        at1st@mstdn.caA This user is from outside of this forum
                                        at1st@mstdn.ca
                                        wrote last edited by
                                        #19

                                        @malwaretech So they're skirting the government request *entirely* on money and lack of compliance?

                                        I am not saying that ProtonMail has to *win* their case, but it does feel like ProtonMail is just folding right out of the gate.

                                        Like how it has been pointed out that a Filibuster where you have to keep debating an issue in the House or the Senate to block it became suddenly a "If you threaten to filibuster it, then I guess we don't bother testing that you *can* filibuster this law - it's just dead.".

                                        lackthereof@beige.partyL 1 Reply Last reply
                                        0
                                        • malwaretech@infosec.exchangeM malwaretech@infosec.exchange

                                          It feels like Proton are being intentionally misleading in their statements. They know that most of their customers aren't familiar with how legal process actually works, so are happy to spread half-truths.

                                          Under US law, a US law enforcement agency (LEA) typically has to apply for a subpoena or search warrant with a US court. The court is then responsible for deciding if the legal bar for search a request has been met, then either grants or denies it.

                                          The problem is, if a company has no real US footprint (no US corporate entity, offices, servers, etc.), then a US court typically doesn't have the jurisdiction to compel the company to hand over customer data (except in some rare circumstances). Even if the court approved the warrant anyway, it wouldn't really be legally binding.

                                          Which is why the Mutual Legal Assistance Treaty (MLAT) exists. MLAT enables law enforcement agencies in one company to send requests for information to law enforcement agencies in another. Switzerland has such a treaty with the US. This means that the FBI can request that Swiss authorities hand over a Swiss company's data on their behalf.

                                          Any country requesting information held by a company in a foreign jurisdiction would typically do so via MLAT. Which means from Proton's perspective, the legal request would appear to originate from their local law enforcement, not the FBI. Which they clearly understand based on their Reddit post.

                                          Saying "we don't respond to legal requests from anywhere other than Swiss authorities" seems very intentionally worded to give the impression that the company does not cooperate with foreign law enforcement. But since it'd be the Swiss authorities handling any such requests, they'd have to comply, since as they admitted, they have to comply with local laws.

                                          There is, however, some useful (but more nuanced) information here:

                                          Firstly, MLAT requests are handled by local law enforcement according to local law. So if there is a difference between the law of the sending and recipient country, that might mean the MLAT request is denied. That probably doesn't mean much, because if you're on the FBI's radar, the chances are you did something that is also massively illegal in Switzerland too.

                                          Secondly, they are 100% correct in saying that no other service provider is going to do any better. They're all beholden to local laws, and the ones that think they're not tend to get their doors blown off by SWAT like CyberBunker did. The only exception is if the company resides in a country which does not cooperate with US law enforcement (which Proton does not).

                                          But the part that's extremely disingenuous is that the "we only respond to requests from the Swiss authorities". That statement is likely intended to imply they don't cooperate with law enforcement in any other countries, which is simply not true. Switzerland has MLAT agreements with over 30 counties.

                                          People really need to understand that no company is going to shield you from the FBI (or any reputable law enforcement agency). They'll use misleading statements to make it sounds like they don't cooperate with law enforcement, but they do. They have to.

                                          knowprose@mastodon.socialK This user is from outside of this forum
                                          knowprose@mastodon.socialK This user is from outside of this forum
                                          knowprose@mastodon.social
                                          wrote last edited by
                                          #20

                                          @malwaretech I don't see how dragging Proton through the mud helps privacy overall.

                                          The user paid for their email address with their credit card then posted it as a group contact on facebook.

                                          On Facebook.

                                          Going at Proton means they might lose business. Them losing business is not in the interests of smart US citizens who don't plaster their email address on a Meta platform after they pay for it with a credit card.

                                          c'mon.

                                          The user holds the majority of responsibility in this case, imho.

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups