Remix.run Logo
trashburger 6 days ago

A lot of claims about being "privacy first", but is there any way to actually verify these claims? For example they claim "no logs", but unless I log into their servers and personally check there is no way I can be sure, right? Is there something I'm missing?

midtake 6 days ago | parent | next [-]

They have shared IP address information before [1]. They have also shared information about the owner of a Proton Mail account with the FBI before.

In my opinion, Proton glows. If you're a nobody, they will protect your privacy, but if you matter then it seems they won't stand up for you. I still use Proton, but it's mostly for registering on sites for which I don't want to burn a Gmail account. I wouldn't do anything sketchy on it.

[1] https://www.vice.com/en/article/protonmail-under-fire-for-sh...

Note: my post is about Proton Mail, I have no idea about Lumo but I imagine the same hypocrisy applies.

DaSHacka 5 days ago | parent [-]

> They have shared IP address information before [1]. They have also shared information about the owner of a Proton Mail account with the FBI before.

Any other mail provider can, and most certainly has, done the same thing when forced by a court order.

No one is going to go to prison for you because of your $5.

> In my opinion, Proton glows. If you're a nobody, they will protect your privacy, but if you matter then it seems they won't stand up for you.

How does this differ from any other SaaS service? Unless you specifically target "bulletproof" services, that are oftentimes blocked anyway due to facilitating fraud, scams, and other illegal tranactions (since the whole point is them not obeying the law while operating, until they inevitability get shut down).

wilsonnb3 6 days ago | parent | prev | next [-]

They've been audited by external organizations and had at least one legal request for log information where court was satisfied they couldn't comply due to their no log policy.

nicce 6 days ago | parent [-]

Even with external audits you need to trust them. Nothing prevents providing different software/configuration during audit.

mrcwinn 6 days ago | parent [-]

I’m not sure you’ll ever find what you’re looking for.

nicce 6 days ago | parent [-]

The point is that these kind of audits do not add similar value as security audits.

sephrenra 4 days ago | parent | prev [-]

Yes, compared to the other offerings this one just says "trust us" with no way to verify if those claims are actually true