▲ | 0-_-0 3 days ago | ||||||||||||||||||||||||||||||||||
Proton's response copied from a Reddit thread: Hi everyone, No, Proton did not knowingly block journalists’ email accounts. Our support for journalists and those working in the public interest has been demonstrated time and again through actions, not just words. In this case, we were alerted by a CERT that certain accounts were being misused by hackers in violation of Proton’s Terms of Service. This led to a cluster of accounts being disabled. Because of our zero-access architecture, we cannot see the content of accounts and therefore cannot always know when anti-abuse measures may inadvertently affect legitimate activism. Our team has reviewed these cases individually to determine if any can be restored. We have now reinstated 2 accounts, but there are other accounts we cannot reinstate due to clear ToS violations. Regarding Phrack’s claim on contacting our legal team 8 times: this is not true. We have only received two emails to our legal team inbox, last one on Sep 6 with a 48-hour deadline. This is unrealistic for a company the size of Proton, especially since the message was sent to our legal team inbox on a Saturday, rather than through the proper customer support channels. The situation has unfortunately been blown out of proportion without giving us a fair chance to respond to the initial outreach. Thank you for your understanding, The Proton Team | |||||||||||||||||||||||||||||||||||
▲ | BoredPositron 3 days ago | parent | next [-] | ||||||||||||||||||||||||||||||||||
This makes the situation even worse for me. CERTs lack any legal authority to compel action or enforce compliance. Without a thorough and fast post mortem analysis, this incident is deeply concerning for anyone who relies on Proton as their primary email provider. I guess getting trigger happy just comes as soon as you get a bigger user base but that's exactly when you get caught slipping. Like they did with the false positives it honestly reads like: "We have good relationships and trust this CERT so we carpet bombed all accounts they send us without even looking at them." I wonder what would have happened to accounts or users without the reach on socials. | |||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||
▲ | IshKebab 3 days ago | parent | prev [-] | ||||||||||||||||||||||||||||||||||
I don't follow. They can't tell if their terms of service have been violated so they took CERT's word for it? How did they decide to restore two accounts then? | |||||||||||||||||||||||||||||||||||
|