A Proton Mail user was arrested in Spain because the service leaked his data

Proton Mail leaked user data

Before explaining the note, I would like to avoid the annoyance of many and above all so that it is understood that it is news of interest and not clickbait. To do this, I would like to explain a little about the Proton Mail service, which many will know and may even be users of.

For those who are unaware of the service, I can tell you that This is an email service, similar to Outlook, Gmail, Yahoo Mail (to mention the most popular), but unlike them is known for its strong focus on privacy through its end-to-end encryption and no-logs policy.

Another important fact about Proton Mail is that the service has its jurisdiction in Switzerland, That is to say that although the content of emails and files are always encrypted and are not accessible, for reasons of law in Switzerland, if cooperation is required with formal requests through appropriate legal channels, the service must cooperate and provide all necessary and requested information (as long as this is possible).

Now that this has been explained and understood, we can move on to the news, sincee the recent case involving the service with the Spanish police, has highlighted a wave of criticism because if "the supposed protection and privacy" actually exists and above all ifand with the "pretext" of national security, These must be violated.

This specific case, where Proton Mail gets involved, As such, the service had to cooperate due to this detail of its jurisdiction in Switzerland, a situation that cost the company to become embroiled in controversies due to its compliance with legal requests that resulted in arrests of individuals related to political activities.

“Proton Mail is aware of the case relating to alleged threats against the King of Spain, but we generally do not comment on specific cases. Importantly, Proton Mail provides privacy by default and not anonymity by default. Privacy means that the content of emails and files are always encrypted and cannot be read by Proton Mail. However, anonymity requires specific actions on the part of the user, such as not adding an optional recovery address like Apple's . It is important to note that Proton Mail does not require the addition of a recovery address, as this information could be disclosed by order of a Swiss court in cases involving illegal activities, such as terrorism, which is also illegal in Switzerland.

The controversy lies in the fact that Proton Mail provided the recovery email address associated with the account of "Xuxo Rondinaire" (pseudonym used by the individual), this era suspected of having links with the Catalan police and of supporting the Tsunami Democràtic movement.

It is worth mentioning that after this, the Spanish authorities, after receiving this information from Proton Mail, requested additional data related to the email from Apple, which finally led to the identification of the individual.

Betsy Jones, Proton spokesperson mentioned that illegal activities are not tolerated on ProtonMail platforms, as stipulated in its terms and conditions. The company has dedicated teams that handle cases of abuse of its terms and conditions, quickly and proactively disabling accounts that violate the rules. Although ProtonMail cooperates with authorities as required by law, emphasizes that the data provided is not of much use due to the encrypted nature of the emails, files and invitations, which cannot be decrypted by the company.

Personally, I can mention that Proton Mail's actions in the case were at all times in compliance with the stipulations of the territory where its services are located, whether it was in another country, such as Germany, the Netherlands, Japan, etc. The service must abide by the laws of the entity where it is located, given that it is a formally established company.

Previously In the rise of “warez”, many services direct downloads They protected themselves by having their servers in countries where their laws did not consider the activity “illegal.” or the type of content. On the other hand, things are very different now due to the great growth and demand for content services.

Another similar case is that of Apple, which Automatically scans photos to detect images of child abuse in the users' photo gallery. Something that worried many users at the time and not because they were going to have content of this type, but because of the same issue of privacy, and although in this case it may be more "understandable" and "acceptable", it is still one of the sides of the coin in the issue of privacy of user information.

Finally, all that remains is to raise a little awareness about how we deliver We store our information, since although it may not infringe anything, we are not exempt from data leaks or being victims of data theft.

Source: https://www.elnacional.cat