ProtonMail deletes 'we don't log your IP' boast from website after French climate activist reportedly arrested

Cops can read the SMTP spec too, y'know


Encrypted email service ProtonMail has become embroiled in a minor scandal after responding to a legal request to hand over to Swiss police a user's IP address and details of the devices he used to access his mailbox – resulting in the netizen's arrest.

Police were executing a warrant obtained by French authorities and served on their Swiss counterparts through Interpol, according to social media rumours that ProtonMail chief exec Andy Yen acknowledged to The Register.

At the time of writing, the company's website said: "We believe privacy and security are universal values which cross borders."

After data from ProtonMail was handed to the Swiss and then French police, the author of a left-wing political activists' blog in France wrote (en français) that a group called Youth for Climate had been targeted:

The police also noticed that the collective communicated via a ProtonMail email address. They therefore sent a requisition (via EUROPOL) to the Swiss company managing the messaging system in order to find out the identity of the creator of the address. ProtonMail responded to this request by providing the IP address and the fingerprint of the browser used by the collective. It is therefore imperative to go through the tor network (or at least a VPN) when using a ProtonMail mailbox (or another secure mailbox) if you want to guarantee sufficient security.

ProtonMail has said in the past that it does not collect user data and implements end-to-end encryption, and repeated that over the weekend, saying: "Under no circumstances however, can our encryption be bypassed, meaning emails, attachments, calendars, files, etc, cannot be compromised by legal orders."

This statement, while bold, seems to be borne out by the service's privacy policy which states that it can access the following user information:

  • Sender and recipient email addresses
  • The IP address incoming messages originated from
  • Message subject
  • Message sent and received times

These are all standard unencrypted information from email headers, inherent to the SMTP email specification, though it appears that ProtonMail's previous promises about user information logging were a bit over-generous. Back in January this year, the company's homepage stated: "No personal information is required to create your secure email account. By default, we do not keep any IP logs which can be linked to your anonymous email account. Your privacy comes first."

Today that boast has been replaced with a mealy-mouthed version: "ProtonMail is email that respects privacy and puts people (not advertisers) first. Your data belongs to you, and our encryption ensures that. We also provide an anonymous email gateway."

The firm's privacy policy, which was updated yesterday, now says: "If you are breaking Swiss law, ProtonMail can be legally compelled to log your IP address as part of a Swiss criminal investigation."

In a statement posted to Reddit, which Yen forwarded to El Reg in lieu of making a statement of his own, ProtonMail said:

In this case, Proton received a legally binding order from the Swiss Federal Department of Justice which we are obligated to comply with. There was no possibility to appeal or fight this particular request because an act contrary to Swiss law did in fact take place (and this was also the final determination of the Federal Department of Justice which does a legal review of each case).

As a Swiss company, ProtonMail is obliged to obey Swiss law and comply with Swiss legal demands, though it's unclear why the company was logging user-agent strings and IP addresses of client logins. An option exists in ProtonMail's user interface to enable access logging, though there is no information in public to suggest whether or not the French environmental protestor had enabled that.

In a followup clarification, ProtonMail insisted: "ProtonMail does not give data to foreign governments; that’s illegal under Article 271 of the Swiss Criminal code. We only comply with legally binding orders from Swiss authorities.

"Swiss authorities will only approve requests which meet Swiss legal standards (the only law that matters is Swiss law)."

It reiterated: "There was no legal possibility to resist or fight this particular request." ®

Similar topics


Other stories you might like

  • Amazon India accused of copying merchant products and juicing search results to sell its own knockoffs

    Report claims documents show employees abusing access

    When asked in July, 2020, by US Representative Pramila Jayapal (D-WA) whether Amazon ever mined data from its third-party vendors to launch competing products, founder and then CEO Jeff Bezos said he couldn't answer "yes" or "no," but insisted Amazon had rules disallowing the practice.

    "What I can tell you is we have a policy against using seller-specific data to aid our private label business but I can’t guarantee that policy has never been violated," Bezos said.

    According to documents obtained by Reuters, Amazon's employees in India flouted that policy by copying the products of Amazon marketplace sellers for its in-house brands and then manipulating search results on Amazon's website to place its knockoffs at the top of search results lists.

    Continue reading
  • AlmaLinux Foundation chair says he stepped down to highlight value of community status

    Close ties with CloudLinux remain, including former chair as 'guest attendee' at board meetings

    Igor Seletskiy, the founder of the AlmaLinux distro created in December 2020 as an alternative to CentOS, has explained that he stepped down as chair of the AlmaLinux Foundation in an effort to strengthen its community status - though his company still dominates the board.

    AlmaLinux is one of several distros to have sprung up, or demanded renewed attention, in the aftermath of Red Hat's decision to make CentOS a late preview of what will become Red Hat Enterprise Linux (RHEL) rather than a binary-compatible rebuild. Other contenders include Rocky Linux, founded by an original co-founder of CentOS, and Oracle Linux. AlmaLinux originated as a project of CloudLinux, a company and commercial distro which already tracked RHEL, and of which Seletskiy is CEO.

    At the end of March an AlmaLinux Foundation was formed to own the trademarks and, in the words of its bylaws, "to develop and maintain a no registration, ad free, stable, open source Linux distribution for the benefit of and free use by the general public."

    Continue reading
  • Shatner breaks the age barrier, goes where no nonagenarian has gone before with Blue Origin rocket trip

    Gives classic monologue upon landing

    Four travelers successfully flew to the edge of space and back on Blue Origin’s second commercial spaceflight including William Shatner, making the 90-year-old Star Trek actor the oldest person to leave Earth yet.

    The nonagenarian was joined by Audrey Powers, VP of Blue Origin’s New Shepard flight operations, Dr Chris Boshuizen, a former NASA engineer and co-founder of Earth-monitoring startup Planet Labs, and Glen de Vries, vice-chair of life Sciences & Healthcare, at Dassault Systèmes.

    Blue Origin’s capsule atop the New Shepard rocket launched near Van Horn, Texas, on Wednesday at 1449 UTC. The four-person crew was taken to the Kármán line, 100 kilometers or 330,000 feet above Earth’s mean sea level, a region where space officially begins. By 1459 UTC, they returned safely back on solid ground again. All in all, the journey only took about 10 minutes and 17 seconds.

    Continue reading
  • Judge in UK rules Amazon Ring doorbell audio recordings breach data protection laws

    Relax, this isn't a binding precedent - but it puts down a marker

    A judge in England has ruled that an Amazon Ring doorbell's functions broke the Data Protection Act after a neighbour dispute, over claims of a gang of armed robbers trying to steal an Audi, ended up in court.

    Dr Mary Fairhurst took her neighbour Jon Woodard to court after alleging that his mass of CCTV cameras, including an Amazon Ring doorbell camera, amounted to harassment, a nuisance and a breach of the Data Protection Act (DPA) 2018*.

    The case was sparked by audio-visual technician Woodard installing yet another camera on a neighbour's wall after falsely claiming an "armed criminal gang" tried to steal his car – putting a communal car park and its access road under full surveillance.

    Continue reading
  • Electric car makers ready to jump into battery recycling amid stuttering supply chains

    It's better to get lithium from used batteries than from the ground, says Elon Musk

    Car makers are electrifying fleets at such a pace that battery makers can't keep up. So Tesla, GM, Ford and others are investing in battery recycling to cut costs and mitigate risks posed by an erratic international supply chain.

    Batteries are basically high-grade ore and a cheaper and more environmentally friendly way for materials to be extracted and reused, said Elon Musk, CEO of Tesla, during a shareholder meeting last week.

    "It pays to do recycling of batteries," Musk said, adding: "You can either get your lithium and your nickel and various constituents from rocks, or from batteries. It's much better to get them from batteries."

    Continue reading
  • Lenovo Neptune makes weather supercomputers cool again

    KMA will generate over one million forecast maps each day

    Sponsored It is only natural the world’s top supercomputing sites in climate and weather modeling should be leading the charge for more efficient, sustainable, and green datacenter practices. With the right approaches, these centers can show that power and performance do not need to be a game of trade-offs and that systems can achieve radical performance with highly efficient cooling.

    While power and cooling are concerns at the facility level, the leading provider of supercomputers in the TOP500, Lenovo, and the Korean Meteorological Administration (KMA) are proving what server-level liquid cooling can do for cutting-edge HPC efficiency.

    KMA, South Korea’s national weather service, provides weather forecasting and issues warnings of adverse weather conditions across the region. The administration also conducts research on climate change to enable the Korean government to enact policies. To do this work, KMA operates the National Center for Metrological Supercomputer (NCMS), the largest supercomputer in Korea supporting vital weather and climate forecasting.

    Continue reading
  • James Webb Space Telescope completes its voyage to French Guiana

    Only a million or so miles to go

    The multinational James Webb Space Telescope – named after a former NASA administrator – has arrived in French Guiana, home to Europe's Spaceport, with launch finally in sight.

    An international collaboration (including contributions from NASA, ESA and the Canadian Space Agency), the long-in-gestation and eye-wateringly overbudget observatory is due for launch atop an Ariane 5 rocket on 18 December, just squeaking into 2021, if all goes well.

    Aside from the 16-day, 5,800-mile trip at sea from California, it has been quite the journey for the space telescope, on which work began in 1996 ahead of a 2007 launch date. Back then the budget was around $500m. These days it's nearer $10bn after repeated delays and a redesign. To be fair, however, nothing quite like the James Webb Space Telescope (JWST) has ever been built before. Then again, that is still quite the overrun and delay.

    Continue reading
  • Is that a meteor crashing to Earth? No, it's Chromebook makers coming back to reality

    US market – where 70% Chromies are sold – nears saturation

    The march of the Chromebook looks to be over for now, at least in the United States, as consumers and students had their fill during the pandemic and are now buying far fewer machines.

    Shipment data collated by Gartner shows that in a global PC market which grew 1 per cent year-on-year in Q3 to 84.147 million units, Chromebook models actually declined 17 per cent.

    This is the first time since their market debut in 2011 that double-digit declines were recorded for the form factor, the analyst told us.

    Continue reading
  • For Dell, being edgy now means single-node HCI without virtual storage, and rugged laptops

    Is it really hyperconverged if it has vSphere but not VSAN? Big Mike says 'yes'

    Dell has made a play for the edge, with pretty much the same stuff it offers in most other places.

    The centrepiece of the hardware giant's edge compute push, revealed today at the Dell Technologies Summit, is a "VxRail satellite node" – a 1U server that runs a subset of VMware's hyperconverged stack. The nodes are 1U servers, lightly ruggedised, and Dell assumes you'll run vSphere on 'em so that your edge servers behave the same way as the data centre servers you entrust to Virtzilla.

    Readers may recall, however, that VMware generally recommends its HCI stack runs on multiple nodes, and that doing so is necessary for resilience of the VSAN virtual storage array – also just for resilience in general.

    Continue reading
  • Soaring cloud division turns things around for SAP after annus horribilis that was 2020

    Remember those car-crash results in Q3 a year ago? No repeat collision this time round

    A year after outlining horrific calendar Q3 financials that caused the share price to crash by €28bn, SAP had no nasty surprises up its sleeves this time.

    In fact the company raised its full-year outlook for the third time in 2021, such is the confidence with which SAP now views its cloud biz. It is estimating sales to grow by up to 19 per cent year-on-year, and operating profit to be between flat to a decline of 2 per cent, better than the earlier projection of a 4 per cent drop.

    The preliminary results for the latest quarter ended 30 September show turnover of €6.84bn, up 5 per cent on the corresponding quarter of 2020. Among the highlights, cloud revenue jumped by a fifth to €2.39bn and software licences and support fell 1 per cent to €3.52bn, so lots of customer have migrations to do.

    Continue reading
  • Microsoft .NET updates include C and C++ code in Blazor WebAssembly, release date for Visual Studio 2022

    Just don't mention WPF

    Microsoft has come up with its usual monthly splurge of .NET news, including the ability to compile native dependencies into Blazor WebAssembly, and a release date of 8 November for Visual Studio 2022.

    The .NET 6 wave – significant since it is a long-term support release – is close to release, with the launch expected at the online .NET Conf 2021 on 9-11 November. The date for Visual Studio 2022 is therefore no surprise. Not everything will be ready, though, in particular the cross-platform MAUI (Multi-platform App UI) framework, based on Xamarin technology, which is scheduled for an RC release in early 2022 and general availability in the second quarter of 2022. Preview 9 of MAUI is now out, with updated controls and graphics API (Microsoft.Maui.Graphics).

    At this point in the release cycle new features give way to bug fixes, but a key new feature has arrived in the Blazor framework for browser applications. Principal program manager Daniel Roth described native dependencies for Blazor WebAssembly (Wasm) apps, which means that "any portable native code can be used as a native dependency." This in turn means that C code, for example, can be called from C# code running in the browser. Both the C# and the C code will be compiled to Wasm so technically it may seem just a small step, but it is nicely wrapped to work in the same way as native code interop for C# on the server or desktop.

    Continue reading

Biting the hand that feeds IT © 1998–2021