soc.octade.net is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
My custom ecosystem for watching #Dexter on a laptop while saving battery:
1️⃣ Thermal Physics: Designed a 3D-printed case for a #Raspberry #Pi 4 #VPN #gateway (WireGuard + ProtonVPN). Passive cooling via chimney effect clears heat with a 2-3 cm/s airflow (Bernoulli).
2️⃣ Client Side: Booting BashCoreGee live in RAM. Privacy via Mullvad Browser, zero local crypto overhead, massive battery life.
Built step by step 👊🦾
Restic is a fast, secure, and open-source backup tool for Linux, macOS, Windows, and BSD systems.
It supports encrypted backups, deduplication, snapshot versioning, and storage on local drives, SSH servers, S3, Backblaze B2, Azure, Google Cloud, rclone, and more.
Designed to make backups simple, efficient, and verifiable while keeping your data protected.
More details: https://digitalescapetools.com/tools/tool.html?id=restic
#OpenSource #Backup #Privacy #SelfHosted #Linux #Windows #macOS #DataBackup
#UK to ban #SocialMedia for kids under 16, may impose overnight curfews
#privacy #cybersecurity #politics #AgeVerification #SocialMediaBan
Zerion 2.0.3 is now live on F-Droid, Play Store and GitHub. This is our most stable release yet.
What’s in it: reliable voice calls in both directions, video calls as opt-in beta, faster startup, and lower battery use during sync.
F-Droid: https://f-droid.org/packages/com.professor.zerion
GitHub: https://github.com/zerionproject/Zerion/releases/latest
Play Store: https://play.google.com/store/apps/details?id=com.professor.zerion
#fdroid #foss #privacy #tor #android #encryption #p2p #opensource #infosec #grapheneos
Most people don't know Google has a free tool to remove your home address, phone number, and email from Search results. It's called Results About You (myaccount.google.com/results-about-you). It monitors for new matches and lets you request removal with one click. #privacy #Google #databrokers #infosec #indigoprivacy
#UK’s #SocialMediaBan for children: the #privacy problems #Australia already exposed
If you don't want unknown entities spying on your emails, setting up email encryption is a great way to protect your #privacy and use your #UserFredom: u.fsf.org/1bq #surveillance #FSF #FreeSoftware #GNU
Ugh. Apple is about to make Hide My Email useless. Now both Sign in with Apple and Hide My Email aliases are going to be issued on the "@private.icloud.com" subdomain. This makes it much easier to ban all aliases without affecting non-relay mailboxes on iCloud mail
Why the Inquisition Built the Surveillance State
https://clairesalerno.substack.com/p/why-the-inquisition-built-the-surveillance
The real motive behind web 2.0, web 3.0, the cloud, AI, and panopticon nonsense is to identify and isolate heretics.
"They began with the network. If you can find one suspected heretic and interrogate them about their associations, who they speak to, who they share meals with, whose homes they visit and which neighbours are sympathetic, you can build a list of names."
"Then, you visit each of those people on the list and ask them the same questions. From this you can build a map of the entire community, identifying relationships and flagging suspects."[. . . . .]
"They used the social fabric of communities and rewarded those who denounced others. They reduced penalties for cooperation, and built the assumption that staying silent is itself suspicious."
"They made it so the rational choice for any individual in the community is to inform on neighbours before neighbours inform on them. This creates a self-policing community. The community does the work, with the institution as the receiving authority."
"Think about that for a moment, because it describes the current digital surveillance apparatus exactly."This is exactly how the bulk of social media and online platforms work to maintain thought control and censorship. It is following the Roman model of fascism, while pretending to denounce fascism, or vocally denouncing socialism, while supporting socialism for the rich. The people screaming the loudest about 'fascists' or 'socialists' or 'communists' or 'liberals' or 'nationalists' or 'racists' are in fact the imperial collaborators, the turncoats, the snitches, the sellouts, the shills, etc.
#Inquisition #Surveillance #Panopticon #Privacy #Cathars #Censorship
🖼️ Squoosh — Open-Source Image Compression in Your Browser
Squoosh is a free, open-source image compression tool that runs entirely in your browser. Your images stay on your device and are never sent to a server.
Supports modern formats like WebP and AVIF, helping reduce file sizes while maintaining image quality.
More details: https://digitalescapetools.com/tools/tool.html?id=squoosh
#OpenSource #Privacy #ImageCompression #WebP #AVIF #Photography #WebDevelopment #Squoosh
boostedTry Runbox for 60 days. If it's not for you, we'll refund your subscription in full. No questions asked. 🤝
No risk, no small print. Just a straightforward guarantee from a Norwegian company that's been doing this for 25 years.
👉 https://runbox.com/price-plans/
#Runbox #Privacy #Sustainability #GreenTech #DeGoogle #Email #Alternative #Europe #Norway
No, #Google isn’t killing ad blockers: #AdGuard's CTO Andrey Meshkov on the #ManifestV2 panic
#AdBlocker #advertising #Chrome #ManifestV3 #manifest #privacy #cybersecurity
Apps for encryption, comms, Usenet, remailers ...
Ch1ffr3punk: https://github.com/Ch1ffr3punk
The owner is a denizen of the OG #Usenet scene.
#cypherpunk #cryptography #crypto #encryption #privacy #github #freesoftware
@cypherpunk@soc.octade.net @cryptography@soc.octade.net @usenet@soc.octade.net
Fitness trackers sell aggregate workout and location data to insurance companies and real estate firms in some markets. #privacy #fitness #healthdata #indigoprivacy
Massachusetts just voted 146-0 to ban the sale of precise location data. Brokers sell it to advertisers, stalkers, and agencies — no warrant. States are doing what the federal government won’t.
#privacy #locationdata #databrokers #legislation #indigoprivacy
#Privacy #services by https://nadeko.net/
#Invidious
https://inv.nadeko.net
#Matrix (Synapse) https://matrix.nadeko.net
Privatebin
https://pbin.nadeko.net
Redlib
https://redlib.nadeko.net
#Phantom
https://phantom.nadeko.net
#Breezewiki
https://breezewiki.nadeko.net
#Forgejo
https://git.nadeko.
Monero Node
xmr.nadeko.net:18081
Jitsi (New)
https://meet.nadeko.net
I’ve been paying for a Proton account for years. I’ve also spent the last several months reading every word of their privacy policy, terms of service, transparency report, data processing agreement, and the Wayback Machine archives of pages they quietly deleted. This isn’t a “switch to Gmail” post. Gmail reads everything you send and builds ad profiles from it. Proton doesn’t do that. But Proton markets itself as a mathematical privacy guarantee, and that claim doesn’t hold up when you go through the actual documents they publish.
Here’s what I found.
Let’s start with Proton’s own transparency report, because the headline number gets buried.
From 2017 to 2025, Proton received 45,667 legal orders for user data. They complied with 40,389 of them. Do the math: that’s a 94% compliance rate, or a 6% contest rate, depending on which way you want to frame it.
Proton Mail legal orders by year: 2017 received 26, complied 23, rate 88%. 2018 received 340, complied 336, rate 99%. 2019 received 1594, complied 1484, rate 93%. 2020 received 3767, complied 3017, rate 80%. 2021 received 6243, complied 4920, rate 79%. 2022 received 6995, complied 5957, rate 85%. 2023 received 6378, complied 5971, rate 94%. 2024 received 11023, complied 10368, rate 94%. 2025 received 9301, complied 8313, rate 89%.
Orders received Orders complied with Compliance rate (% of orders complied with)
In 2017 they got 26 orders. By 2024 that number was 11,023, of which they complied with 10,368. That’s a 423x increase in seven years. The contest rate peaked at 21.2% in 2021, which is interesting because 2021 was when the French climate activist case became public and put them under scrutiny. After the spotlight moved, the contest rate dropped. By 2024 it was 5.9%, while order volume nearly doubled year-over-year.
Martin Steiger, a Swiss attorney who tracks Proton’s transparency data, attributes part of the 2024 jump to Switzerland switching from per-request billing to a flat-rate compensation model for law enforcement data requests at the start of that year. When filing a request costs less friction, more requests get filed. Proton got bigger, the government made the paperwork cheaper, and the fight rate cratered.
The thing people usually say here is “they have to comply, it’s the law.” But if that were true, the rate would be 100%. The 6% they do contest proves fighting is legally available. OVPN beat a Swedish court order in 2021 and got zero data handed over. Mullvad got raided by Swedish police who left empty-handed because the architecture genuinely held nothing. The “resistance is impossible” argument is cope for companies that choose cooperation.
Now compare Proton Mail’s numbers to Proton’s own VPN product. Proton VPN denied 100% of all legal orders from 2020 to 2025. Every year. Every order. Not because they’re braver than the mail team because the VPN architecture holds no logs to hand over. Compliance is technically impossible.
Proton Mail
6%
contested rate
Mail: architecture allows compliance
Proton VPN
100%
contested rate
VPN: no-log architecture, nothing to hand over
And compare to Tuta, which operates under German law, not Switzerland, not some privacy utopia. Germany. Tuta’s transparency report for the second half of 2025 shows 220 requests received, 58 complied with. That’s roughly a 75% rejection rate. First half of 2025: 227 requests, 54 complied with. Tuta fights three out of four requests by lodging objections based on the argument that they’re a telecommunications service (the CJEU ruled they’re not, but Tuta uses the legal angle anyway because it works some of the time). Proton hasn’t found a comparable angle, or hasn’t looked.
Proton’s marketing page, verbatim: “Proton Mail’s zero-access architecture means we can never access your emails. As a result, we cannot hand your emails over to anyone.”
Their homepage: “Our end-to-end encryption and zero-access encryption mean that no one (not even Proton) has the technical means to access your data without your permission. At Proton, privacy isn’t a promise, it’s mathematically ensured.”
Now their own privacy policy, also verbatim: “unencrypted messages sent from external providers to your Account, or from Proton Mail to external unencrypted email services, are scanned for spam and viruses… Such inbound messages are scanned for spam in memory, and then encrypted and written to disk.”

A diagram of the Proton inbound email flow for non-Proton senders
To understand why this matters technically, you need to understand how email works.
When someone sends you an email from Gmail, that message arrives at Proton’s SMTP gateway in plaintext (or TLS-encrypted transport, which Proton decrypts at the edge since they’re the TLS endpoint). Before Proton can encrypt that message with your public key and write it to disk under zero-access encryption, their servers have to see the plaintext. That’s not a flaw. It’s a fundamental constraint of how SMTP email interoperates with encryption systems. You can’t encrypt something for someone without a brief moment where you hold the plaintext and the recipient’s public key simultaneously.
The technical path goes:
Steps 3 through 4 are the window where Proton’s systems hold your plaintext. That window is brief. It is also real. Their own X account confirmed this: “we briefly see the contents of the email before immediately and automatically encrypting it without ever being able to access it again.” They called it a “limitation imposed upon us by providers like Gmail who do not use PGP encryption by default.”
That’s technically accurate. It’s also a direct contradiction of “not even Proton” can see your data. You can’t run body-level spam filtering without reading the body. That’s how reading works.
chompie, who runs IBM X-Force Offensive Research, posted about this and got 1.1 million views: “Not only can Proton Mail read your emails, but they’re subject to the same subpoenas and lawful government requests as Google. Real privacy requires end-to-end encryption, which users have to actively adopt, and most don’t because it’s hard and annoying.”
The only case where Proton genuinely can’t read your message content is Proton-to-Proton email, because both sender and recipient have keys managed by the Proton system, and E2E encryption can be applied before the message ever leaves the sender’s device (via the web crypto API or the mobile clients). The moment one party is on Gmail or Outlook, which is most of the email most people receive, that guarantee goes away.
Even setting aside the inbound email scanning, the metadata picture is worse than most people realize.
Proton’s privacy policy lists what they hold as standard account data:
Email metadata (always accessible to Proton):
Privacy analysis
End-to-end encryption protects content — but the envelope is always visible
🔒
Proton can’t read this
End-to-end encrypted
Message content
Message body
Proton-to-Proton only. Encrypted before leaving your device with keys Proton never holds. Proton → Proton
Message body — non-Proton
After a short delivery window, Proton encrypts the stored copy at rest. The delivery window itself is unencrypted. At rest only
Attachments
Proton-to-Proton messages. Encrypted alongside the message body.
Password-protected messages
Replies from non-Proton users via the encrypted reply link are also E2EE.
Other data
Contacts — display names and notes
Stored with zero-knowledge encryption on Proton servers.
Calendar event details
Event titles, descriptions, and locations in Proton Calendar are E2EE.
Your private key
Encrypted with your login password before storage. Proton cannot decrypt it.
👁
Proton can read this
Metadata and envelope
Message envelope
Sender address
The From field is visible to Proton and required for routing. Always unencrypted.
Recipient address(es)
To, Cc, and Bcc fields. Bcc is hidden from other recipients but visible to Proton. Including Bcc
Subject line
Proton stores subject lines in plaintext. They are searchable server-side. A significant content leak. Plaintext on server
Timestamps
When you sent and received each message. Reveals communication patterns over time.
Message size
Approximate size of each message, which can hint at content type such as text or attachment.
Metadata and communication graph
Who you communicate with
The social graph of senders and recipients across your account history.
Frequency of communication
How often you email specific people. Reveals relationship strength and patterns.
Folder and label structure
Names of folders and which messages you’ve filed where. Organizational metadata is not E2EE.
Account and network data
IP address
Your originating IP may be logged unless you use Proton VPN or Tor. It can reveal rough location and ISP. Unless VPN / Tor used
Login times and session data
When you access your account, from which clients, and session duration.
Device and browser identifiers
User-agent strings and device identifiers from web and app sessions.
Message body — non-Proton, during delivery
When routing to Gmail, Outlook, or other providers, the body can pass through Proton’s servers unencrypted before SMTP delivery. During delivery only
Recovery email or phone number
If provided for account recovery, this data is account metadata and is not end-to-end encrypted.
Payment information
For paid plans. Processed by Proton and/or payment processors. Not E2EE by nature.
Proton’s legal privacy policy says it does not sell this metadata — but the metadata can still exist and may be subject to lawful Swiss orders. Subject lines remain one of the biggest content exposures for normal email use.
Subject lines deserve special attention. “Your prescription refill from CVS.” “Whistleblower submission received.” “Re: meeting with immigration attorney.” “Termination notice.” Subjects often carry the most information-dense summary of what an email is about, and Proton has them all, for every email you’ve ever sent or received, unencrypted.
Ask any intelligence analyst whether they’d rather have message content or metadata – sender, recipient, subject, timestamp, frequency, attachment names and they’ll say metadata. Metadata is structured. You can run pattern analysis on it. You can build a social graph from it. Content requires reading. Metadata requires a database query.
The account-level data Proton holds also includes recovery email or phone number you provided during signup, account creation date, and device identifiers.
Calendar metadata (stored unencrypted): event start and end times, time zones, recurrence rules, event creation and update times, event status. Your entire schedule.
Drive metadata: file and folder creation and modification times, permissions, the username that created or uploaded files, and for shared URLs, creation time, last access time, and number of accesses.
That’s what 40,389 orders have been requesting.
In January 2021, Proton’s homepage said, and I have the Wayback Machine archive to prove it: “No personal information is required to create your secure email account. By default, we do not keep any IP logs which can be linked to your anonymous email account. Your privacy comes first.”

http://web.archive.org/web/20210104131534/https://protonmail.com/

http://web.archive.org/web/20210930230626/https://protonmail.com/
Then, in September 2021, it came out that Proton had logged and handed over the IP address of a French climate activist to French authorities via Europol and Swiss MLAT channels. The technical specifics matter here.
The activist was part of Youth for Climate, an environmental group occupying buildings in Paris. Swiss authorities received an MLAT request, approved it, and Proton was compelled to begin IP logging on that specific account going forward (Proton doesn’t log IPs by default, but they can be ordered to start for a specific account). The IP they collected, combined with a recovery email address also handed over, led investigators to an Apple ID, which led to the activist’s identification and arrest.
The forensic chain here is a useful illustration of how metadata compounds. Proton provided two data points: an IP address and a recovery email. The IP resolved to an ISP subnet. The recovery email was tied to an Apple account. Apple, served with its own request or through iCloud, produced account details. The target was identified. None of this required anyone to read their emails.
After this went public, Proton quietly updated their homepage. The “we do not keep any IP logs” language disappeared. The Register documented the before and after with Wayback Machine screenshots. Bruce Schneier wrote about it. Proton’s current privacy policy now says: “If you are breaking Swiss law, ProtonMail can be legally compelled to log your IP address as part of a Swiss criminal investigation.”
More telling is a disclosure buried on a Proton VPN support page (not the main privacy policy, not the marketing pages but a VPN support article): email “is generally not no-logs and can require IP disclosure in the event of a Swiss criminal investigation. That’s why if your threat model requires hiding your IP from Swiss authorities when using Proton Mail, we recommend using a VPN or Tor.”
The privacy product has a gap, and Proton’s documented solution is to buy their other privacy product.
In September 2025, Proton suspended the accounts of Phrack Zine. If you’re not familiar with Phrack, it’s been publishing since 1985 — before Google, before most of Proton’s employees were born. It’s one of the foundational texts of security research, the kind of publication that DEFCON speakers cite in their acknowledgments.

A timeline graphic showing the Phrack incident
Two journalists publishing under pseudonyms Saber and cyb0rg had been doing responsible disclosure on a sophisticated intrusion into South Korean government systems — the Ministry of Foreign Affairs and the military’s Defense Counterintelligence Command — attributed to Kimsuky, a North Korean state-sponsored threat actor that CISA and the NSA have both published advisories about. They notified KrCERT/CC, South Korea’s national CERT, before publishing. They were using Proton specifically because they’re journalists working on sensitive national security material.
Proton suspended their dedicated disclosure email account after receiving a tip from a CERT. The next day, they suspended Saber’s personal Proton account too. Phrack emailed Proton on August 22nd requesting restoration. No response. September 6th, a follow-up. Still nothing. September 9th, Phrack went public on X. September 10th, Proton responded.
Proton’s official response: “We were alerted by a CERT that certain accounts were being misused by hackers in violation of Proton’s Terms of Service. This led to a cluster of accounts being disabled.”
A “cluster.” Proton cluster-banned accounts in the vicinity of the CERT tip without verifying which were legitimate. CERTs are advisory bodies. They have no legal enforcement authority. They issue recommendations. A CERT tip carries the same legal weight as an email from a stranger. Proton’s own terms of service say they act on “orders from the competent authorities” — a CERT is not a competent authority.
Andy Yen, Proton’s CEO, jumped in to defend it: “Honestly, this is a ridiculous take. We investigated, verified the tip, and enforced our ToS.”
But if the investigation verified the tip, why did they reinstate the accounts? If the accounts genuinely violated the ToS, restoring them makes no sense. If they didn’t, Proton suspended legitimate journalism accounts for weeks based on an unverified advisory from a non-legal body, ignored multiple appeals, and fixed it only when the internet started watching.
There’s also a technical contradiction here. Proton’s privacy marketing says they can’t see what’s in your account because of zero-access encryption. But they also claim they “investigated” account activity to enforce ToS. You can’t have both. Either you can see what users are doing, or you can’t. When Yen was asked directly whether the alleged violation was malware or hacking, he couldn’t answer. Because there was no real investigation.
On March 5, 2026, 404 Media published an FBI affidavit showing that Proton Mail handed over payment data that identified a Stop Cop City protester in Atlanta. The account was defendtheatlantaforest@protonmail.com, listed publicly on the Defend the Atlanta Forest Facebook page.
The FBI submitted a request through the US-Switzerland Mutual Legal Assistance Treaty. Swiss authorities approved it. Proton provided a credit card payment identifier — specifically, a Chargebee transaction ID, since Proton processes payments through Chargebee, a US-based subscription management platform. The FBI traced that identifier through Chargebee to the issuing bank, and the bank identified the cardholder. The person was arrested at Atlanta’s airport.

A flowchart of the MLAT data chain
A few things worth unpacking here.
The charge was trespassing. The investigating agent was from the FBI’s Domestic Terrorism squad. An international treaty request, routed through Swiss federal legal channels, was used to identify someone arrested for a misdemeanor-level offense. That’s the practical scope of “Swiss privacy protection” when a determined law enforcement agency decides it wants your data.
Proton’s X response is almost worth quoting in full because it contradicts itself within three paragraphs. Paragraph one: “Proton did not provide any information to the FBI.” Paragraph three: “only payment info was disclosed.” Edward Shone, Proton’s head of communications, told 404 Media: “We want to first clarify that Proton did not provide any information to the FBI, the information was obtained from the Swiss justice department via MLAT.” That distinction — whether Proton handed the data to the FBI or handed it to Swiss authorities who handed it to the FBI — is the kind of framing that looks like evasion when the outcome is the same.
Proton also characterized the underlying case as involving “a police officer was shot, and explosives were found.” The FBI’s own search warrant affidavit doesn’t mention a shooting. On X, @PplsCityCouncil called this out and noted that the officer involved was shot by another officer, and that the “explosives” appeared to be fireworks. Proton inflated the severity to justify the compliance. The actual charge was trespassing.
Separately: if this user had paid with Monero, there would have been no payment identifier to trace. Proton’s response noted they “accept cash and crypto.” They accept Bitcoin — the cryptocurrency with a public, permanent ledger that Chainalysis and Elliptic have built entire forensics businesses around tracing. Proton didn’t accept Monero at all until September 2025, and even then only through a third-party called ProxyStore, not natively. Their general manager promised direct Monero integration “by end of Summer 2025.” Missed that deadline.
This is the third time we’ve seen this pattern. French climate activist, 2021. Catalan independence activist, 2024. Stop Cop City protester, 2026. Three activists, three countries, three MLAT requests, three times Proton complied and someone got identified.
Proton’s marketing frames Swiss jurisdiction as a force field. Their blog says Switzerland is “outside of US and EU jurisdiction,” that Swiss companies “cannot be compelled to engage in bulk surveillance,” and that “the laws of mathematics cannot be changed or altered.”
The first two points are true in a limited sense. Foreign governments can’t directly subpoena Proton. Requests have to go through Swiss legal channels via MLAT or through the Swiss Federal Office of Justice. This adds a step.
That step has a 94% pass rate.
The MLAT mechanism is worth understanding in detail because it’s how almost all of the high-profile cases worked. A foreign law enforcement agency (FBI, Europol, French Interior Ministry, Spanish authorities) identifies a target and determines they’re using Proton. They draft an MLAT request to Swiss authorities, which goes to the Federal Department of Justice and Police and typically the Office of the Attorney General. Swiss prosecutors review the request, and if the underlying conduct would be illegal under Swiss law, they forward a legally binding order to Proton. Proton is then required to comply (or can contest, at their discretion).
The “underlying conduct must be illegal under Swiss law” requirement is the key process protection. This is why bulk surveillance requests don’t go through this channel easily — Swiss law has no equivalent of US national security letters or FISA requests. But trespassing is illegal in Switzerland. Climate protests can qualify as criminal damage. Independence movements can be framed as various offenses depending on what authorities want to argue.

A flowchart showing the MLAT request path
Proton also doesn’t notify users when their data gets requested. Steiger Legal flagged this: Proton’s position is that it’s Swiss authorities’ responsibility to inform targets, not Proton’s. So your data gets handed over and you don’t find out unless you get arrested or see a news story about it.
The Switzerland pitch also has some geographic inconsistencies. Your encrypted email sits on servers in Switzerland. But your support tickets route through Zendesk, a US company. Payment data goes through Chargebee, Stripe, and PayPal, all US companies. Customer support tickets also go through Atlassian tools. Sales data goes through HubSpot. Customer support subsidiaries exist in Macedonia and Taiwan. “Swiss privacy” has about six asterisks attached to it.
Try creating a Proton account over Tor. Their “intelligent algorithm” — their own description — determines what verification method you get during signup based on signals from your connection. If you’re coming from a Tor exit node or a known VPN range, the escalation path goes: CAPTCHA → email verification → SMS phone number verification.
Security Architecture
Proton — Signup Verification Escalation
IP risk tier → verification requirement
ENTRY POINT Create Account Detect IP Type Normal Residential IP VPN IP Tor Exit Node STEP 1 CAPTCHA Challenge OUTCOME ✓ Access Granted RISK: LOW STEP 1 Email Verification OUTCOME ⚠ Sometimes Granted RISK: MEDIUM · MAY ESCALATE STEP 1 Phone SMS Verification OUTCOME ⛔ SMS Required to Proceed RISK: HIGH VERIFICATION TIER ── LOW MEDIUM HIGH
Entry Point
Create Account
Detect IP Type → Apply Verification Tier
Normal Residential IP
Step 1
CAPTCHA Challenge
✓ Access Granted
RISK: LOW
VPN IP
Step 1
Email Verification
⚠ Sometimes Granted
RISK: MEDIUM · MAY ESCALATE
Tor Exit Node
Step 1
Phone SMS Verification
⛔ SMS Required to Proceed
RISK: HIGH
🚫
VoIP Numbers Rejected — Approximately 60% of known VoIP number ranges are blocked. Disposable, virtual, and carrier-over-IP phone numbers, such as Google Voice, Skype, and Twilio-issued numbers, are flagged and rejected during SMS verification. A physical SIM-based mobile number is required to complete signup via the Tor path.
The people most likely to need phone verification are the people most likely to need anonymity — journalists, activists, people in countries with surveillance infrastructure, people who route through Tor specifically because they have something to protect.
Proton says this is to prevent spam bots from bulk account creation. That’s a real concern. If spammers create thousands of Proton accounts and use them to send spam, Gmail and Outlook will blacklist Proton’s mail servers, which breaks the product for everyone. Anti-abuse is a legitimate problem.
But compare to Mullvad: click “generate account,” get a random 16-digit number, done. No email, no phone, no name, no CAPTCHA. Or Tuta: CAPTCHA and you’re in. The idea that privacy-friendly signup and anti-spam are mutually exclusive is a design choice, not a technical constraint. Proton chose the design that requires identity information from the users most likely to need anonymity.
VoIP numbers are also blocked. Proton’s filters reject around 60% of traffic from known VoIP ranges. So burner numbers don’t work either. If you want a Proton account over Tor, you either give them a real phone number or you email their support team to beg for an exception.
Proton’s consumer VPN claims a strict no-logs policy, and their transparency report backs this up — 100% denial rate on all orders, 2020-2025. True. The architecture holds nothing.
But Proton’s Business VPN product, documented in their Business Privacy Policy, collects connection and disconnection timestamps, device type and operating system, and the IP address used to connect to VPN servers.
That’s the exact data their consumer VPN claims never to log. The existence of the Business VPN logging proves Proton built the logging infrastructure. They have the code. They deployed it for paying business customers. The consumer no-logs claim is a business decision about which customers get which configuration, not a statement about what’s technically possible.
In 2023, Proton launched Proton Wallet. A Bitcoin wallet. Bitcoin has a fully public blockchain. Every transaction is permanently visible to anyone who looks. Chainalysis and Elliptic built entire companies on tracing Bitcoin for law enforcement. The FBI has recovered millions from ransomware operations by following Bitcoin ledgers. This is common knowledge in the cryptocurrency space.
Meanwhile, Monero exists. Monero uses ring signatures, stealth addresses, and Confidential Transactions (specifically RingCT) to obscure sender, recipient, and transaction amounts by default. Mullvad accepts Monero. IVPN accepts Monero. Proton didn’t accept Monero at all until September 2025, and then only through ProxyStore as a third-party middleman — not natively, not directly on their payment page.
[IMAGE SUGGESTION: A two-column comparison of Bitcoin vs Monero privacy properties. Column 1 (Bitcoin): “Public ledger – all transactions visible. Sender address visible. Recipient address visible. Amount visible. Traceable by Chainalysis/Elliptic. FBI standard tool for crypto recovery.” Column 2 (Monero): “Ring signatures obscure sender. Stealth addresses protect recipient. RingCT hides transaction amounts. Not natively traceable by current blockchain analytics tools.” No promotional framing, just the technical properties.]
Proton’s own general manager promised direct Monero integration “by end of Summer 2025.” That deadline passed. Their UserVoice forum has had requests for Monero support for years. The company built an entire Bitcoin wallet product and dragged its feet on the privacy coin for years.
Proton brings in over $100 million annually. 585 employees. The primary shareholder is the Proton Foundation, a Swiss nonprofit endowed with Proton shares by Andy Yen and co-founders Jason Stockman and Dingchao Lu. This is marketed as a guarantee of mission integrity — no VC pressure to monetize users.
Andy Yen has a PhD in particle physics from Harvard and did research at CERN on the ATLAS experiment before founding Proton in 2014 in response to the Snowden revelations. That origin story is genuine.
A nonprofit shareholder structure and a CERN pedigree don’t change what the privacy policy says about scanning emails. They don’t change 40,389 complied orders.
Proton received €2 million in EU funding through Horizon 2020 and spends up to €100,000 per year lobbying the EU through APCO Worldwide, a Washington DC-based lobbying firm. Their lobbying focus includes the Digital Markets Act, encryption policy, cybersecurity frameworks, and data retention directives. In December 2022, they met with Commissioner Ylva Johansson’s cabinet about CSAM detection (the same policy area as the EU’s Chat Control proposal, which would mandate client-side scanning of encrypted messages). In March 2025, they met with EVP Stéphane Séjourné about AI competitiveness.
Lobbying on encryption policy isn’t inherently sinister — they may well be lobbying in favor of strong encryption. But “scrappy Swiss scientists fighting Big Tech” and “our lobbyist is APCO Worldwide out of DC” are two narratives that don’t coexist comfortably.
Proton runs a partner and affiliate program paying up to 100% commission on referrals, with recurring revenue on renewals. They have a dedicated influencer contact at influencers@proton.ch. Their partner page: “Boost credibility and engage your privacy-conscious followers by endorsing secure digital solutions.”
A significant share of the “privacy recommendation” content on YouTube, Reddit, and newsletters that tells you to use Proton is financially incentivized to tell you to use Proton. They’re not lying about Proton being better than Gmail. They’re just leaving out everything covered in this article, because it’s hard to drive signups with “better than Gmail but the marketing overstates the privacy guarantees.”
If your threat model requires that no server anywhere sees your plaintext email, use PGP with a provider-agnostic setup. PGP encryption happens on your machine. The ciphertext is what hits any server. No provider sees plaintext, no matter who compels them. You can use PGP with any email provider, including self-hosted setups. The complexity is real — key management, distributing your public key, convincing the people you correspond with to use it — but it’s the only approach that removes the server from the trust chain entirely.
If you need a VPN with genuine no-knowledge architecture (not just a policy), Mullvad generates a random 16-digit account number with no email, username, or password. They accept Monero and cash sent in the mail. When Swedish police raided them in 2023, they found nothing, because there was nothing to find. If you lose your account number, your account is gone — because no identity information was ever collected to allow recovery.
Self-hosting the entire stack is also an option. Email server (Postfix/Dovecot), VPN (WireGuard), password management (Vaultwarden), file storage (Nextcloud). The infrastructure is free and open source. The operational burden is real — you’re responsible for updates, backups, deliverability, and your own security. But you’re not relying on any company’s policy or marketing.
Proton is better than Gmail for most people and that’s genuinely true. It’s worth using for exactly what it is: an email provider that doesn’t read your mail for advertising, that provides E2E encryption for Proton-to-Proton correspondence, that operates under Swiss law with some process protections that most email providers don’t have.
It is not a mathematical privacy guarantee. It is not untouchable by foreign governments. It doesn’t protect your metadata. And it hands over data in response to 94% of government requests it receives.
That’s what you’re buying. Use it with those facts in mind.
The French climate activist, 2021. The Catalan independence activist, 2024. The Stop Cop City protester, 2026. These aren’t edge cases or bad luck. They illustrate what happens when a company with 40,389 complied government orders gets a targeted MLAT request about a user whose security model assumed stronger protections than the product delivers.
HideMyAss went through this in 2011. They marketed anonymous VPN, kept connection logs the entire time, and handed over timestamps and IPs when the FBI came for a LulzSec member. After the story broke, they hired an auditor to verify a no-logs policy. By then the trust was gone. The pattern is: company markets absolute-sounding guarantees, users rely on those guarantees, legal pressure arrives, the architecture allows compliance, someone gets identified. The people who needed the guarantee most find out it had an asterisk after it was too late.
Proton is not HideMyAss. But they’re running the same gap between marketing language and architecture, and the transparency report shows the same 94% compliance dynamic. The difference is that Proton publishes the numbers and you can read them yourself.
So read them.
"Realizing your trove exists is terrifying. So is learning that it’s never been more vulnerable."
Bridget Read for New York/Intelligencer: https://nymag.com/intelligencer/article/your-digital-self-is-vulnerable.html
#Longreads #Privacy #Surveillance #Data #Technology #Internet
WhatsApp Clone, but Decentralized with P2P Messaging
"Secure and private" is the general goal.
This is a technical/concept demo of a fairly unique approach using a browser-based, local-first and webrtc.
This is intended to introduce a new paradigm in client-side managed secure cryptography. We can avoid registration of any sort.
Features:
* P2P
* End to end encryption
* Signal protocol
* Post-Quantum cryptography
* File transfer
* Local-first
* No registration
* No installation
* No database
* TURN server
Feel free to reach out for clarity instead of diving into the docs/code.
IMPORTANT: While this is aiming to provide a secure experience, it isnt audited or reviewed. **Shared for testing, feedback and demo purposes only.** Please use responsibly.
#Privacy #OpenSource #P2P #WebRTC #Decentralization #DigitalSovereignty #CyberSecurity #FOSS #SelfHosted #NoCloud #AntiCorp #Encryption #WebDev #TechLiberty #PrivateMessaging #Networking #DataPrivacy #InternetFreedom #LocalFirst #SoftwareEngineering #WebApps #ZeroKnowledge #PrivacyTech #IndieDev #NoSignup #NoInstall #DecentralizedWeb #SecureMessaging #BrowserApp #TechEthics #P2P #WebRTC #PeerJS #ZeroData #EphemeralData #Encryption #E2EE #BrowserToBrowser #NoInstall #Privacy #Security #Decentralized #Messaging #VideoCall #NoTracking #PrivateMessaging #Prototype #Demo #WorkInProgress #CloseSource #OpenSource #WebDev #GitHub #TechDevelopment #WhatsApp #ChatApp #InstantMessaging #PWA
#Meta Tapped a #Pentagon Supplier to Prototype Face Recognition for Its Glasses
https://www.wired.com/story/meta-rank-one-computing-face-recognition-smart-glasses/
#FRT #FacialRecognition #SmartGlasses #RayBan #Oakley #privacy #surveillance
Google Chrome update will close the door on ad blockers
#HackerNews #Google #Chrome #adblockers #update #adtech #privacy #changes
🚨 Chrome is closing the final loopholes that kept legacy ad blockers alive.
Starting with Chrome 150/151, Google is removing the remaining Manifest V2 workarounds, meaning extensions like uBlock Origin (MV2) will no longer function in Chrome. Users will be limited to Manifest V3-compatible blockers with reduced capabilities.
Read more: https://digitalescapetools.com/2026/06/chrome-150-ad-blocker-loopholes-closed.html
#Privacy #Chrome #AdBlockers #uBlockOrigin #ManifestV3 #OpenSource #DigitalEscapeTools
Most messengers can say “we can’t read your messages.” Almost none can say “we can’t see who you talk to, when, or how often.” That metadata lives on their servers.
Zerion has no servers. Connections run device to device over Tor, contacts are keys instead of phone numbers, and the social graph exists nowhere but on your own phone.
Free, open source, GPL v3, on F-Droid:
https://zerion.chat
Signal warns UK plan to scan devices for nudes "endangers us all" — says client-side scanning risks mass surveillance & censorship, urges funding for education and child services instead. Read more: https://www.theregister.com/security/2026/06/09/signal-uks-child-nude-block-threat-wont-protect-children/5252761 🛡️🚨 #Privacy #Encryption
Voice Age Verification
#HackerNews #Voice #Age #Verification #technology #AI #age #verification #security #privacy
Around 52 percent of parents track their 18- to 25-year-old children using smartphone apps, according to a University of Michigan survey.
Is it healthy and the new normal or bordering on surveillance?
https://flip.it/jccv0M
With the worldwide wave of social media bans on major platforms aka digital verification, I wonder if we'll see an influx of people to the #fediverse
🤞🤞🤞 Here is hoping <3
#Meta Tapped a #Pentagon Supplier to #Prototype #FaceRecognition for Its Glasses
#RankOne , whose board includes a former #CIA deputy director and a former #FBI science chief, supplied face recognition to Meta for internal development of its smart glasses app.
#privacy #security
https://www.wired.com/story/meta-rank-one-computing-face-recognition-smart-glasses/
Last month I noted how the Trump FCC had unveiled a brand new plan to “stop robocalls.” As with most efforts the proposal doesn’t actually do much to stop robocalls because a well-lobbied U.S. government (1) refuses to hold big companies accountable or collect fines, (2) constantly embraces weak rules that make telemarketers and debt […]
In a parallel universe somewhere, all of the non-fascist-led Western nations conspired together behind the scenes to use the push for age verification as a way to free their citizens from all US platforms, and migrate them to the fediverse and FOSS en massé in a well conceived & perfectly executed stunning maneuver.
RE: https://hachyderm.io/@jbjrkng/116755393515371033
This goes for Canada, too. Carney wants to sell your data to his business pals, and you can't put that toothpaste back in the tube.
""Every failed attempt to make children safer online is followed by more surveillance and censorship," he said. "Children have rights too and these policies will harm their free expression and privacy rights, and push them into less regulated spaces. Meanwhile the business models driving harms are untouched."
Others questioned whether the measures can realistically be enforced. Mark Jones, an online harms specialist and partner at law firm Payne Hicks Beach, noted that the consultation closed only weeks ago and warned that determined teenagers have a habit of finding ways around restrictions.
"A social media ban only helps if it is genuinely enforceable," Jones said. "If large numbers of young people simply circumvent the restrictions, parents will just lose visibility into where their children are actually spending time online rather than reclaiming any control."
The political case for the crackdown appears relatively straightforward, but the practical one is less so. The government now has to persuade social media companies to enforce the rules and teenagers not to find ways around them."
#UK #AgeVerification #NannyState #Surveillance #Oligopolies #Censorship #BigBrother #BigTech #Privacy #Anonymity
Canadian Government Gears Up to Pretend to Care About Privacy
Reports are surfacing saying that privacy reform is going to be tabled soon. We've been through this song and dance before.
https://www.freezenet.ca/canadian-government-gears-up-to-pretend-to-care-about-privacy/
#News #Privacy #Security #Canada #legislation #PrivacyReform
Zerion 2.0.3 is out, earlier than planned.
Headline: voice calls now work reliably in both directions. Everything runs over Tor, no STUN, no TURN, no VoIP server — just two devices finding each other through onion services. Getting that stable took work. This is the release where it is.
Video calls landed as opt-in beta. Vault now has search and sort. Per-channel notification muting. Draft saving in channels.
APK and Play Store now, F-Droid pending:
https://github.com/zerionproject/Zerion/releases/latest
Meta benutzt Gesichtserkennungs-Software für US-Polizeibehörden #SmartGlasses
‚Meta soll mit einem Unternehmen kooperieren, das Gesichtserkennungs-Software für Polizeibehörden entwickelt. Wie Wired herausgefunden hat, ist das Rank One Computing (ROC), ein Anbieter für Gesichtserkennungs-Software. Einige Algorithmen sollen Gesichter in einer Entfernung von einem Kilometer erkennen….‘
#Gesichtserkennung #überwachung #Privacy #Polizei #Repression #Datenschutz
‚Bank details, sex and naked people who seem unaware they are being recorded. Behind Meta’s new smart glasses lies a hidden workforce, uneasy about peering into the most intimate parts of other people’s lives…..‘
#Meta #Surveillance #Privacy #RayBan #SmartGlasses #Data #Technology
Phone numbers as ids are not only bad for #privacy. They also make it hard to maintain multiple accounts for different areas of life.
E.g. I maintain four #chat accounts: One at work, one at my main #freeSoftware project, one for public #socialNetwork stuff, and of course a private one.
(In my case it's #Jabber/#XMPP, not Delta, but that doesn't matter in this context. Both do support multiple accounts.)
Thank you, #Massachusetts. This is a great start. This bill passed unanimously in the house, 146-0.
https://www.squaredtech.co/massachusetts-passes-major-new-privacy-law-banning-location-data-sales
The law prohibits companies that handle or process personal data of more than 100,000 consumers from selling or sharing sensitive personal data, including precise geolocation, biometrics, health data, genetic information, religion, immigration status, and sexual orientation, without a user’s explicit consent.
The location data ban applies to both residents and visitors across the state.
Do not provide your ID or facial scan to access social media.
I repeat, do NOT provide your ID or facial scan to access social media when requested.
This is not a drill.
If everyone refuse to comply, and let their accounts dormant instead, I promise you the platforms themselves, with their immense budget and network of lobbyists, are going to fight these absurd laws to recover their users.
They need you more than you need them.
Make them fight for your rights.
Do not comply.
Spread the word and boycott ID checks ✊
#StopIDSurveillance #AgeVerification #Privacy #HumanRights #Democracy #Safety #MassSurveillance #Authoritarianism
Palantir in Deutschland
Überwachung first, Bedenken second!
‚Bundesinnenminister #Dobrindt hält an der Überwachungssoftware #Palantir fest. Eine taz-Recherche zeigt: Damit steht er fast alleine da. Ein Grund zur Entwarnung ist das nicht…..‘
#Überwachung #Bundesregierung #Datenschutz #Privacy #Antireport
📤 PairDrop — Open-Source Cross-Platform File Sharing (AirDrop alternative)
PairDrop lets you send files, photos, folders, and text directly between devices using peer-to-peer connections. No account required.
Works on Android, iPhone, Windows, Linux, and macOS right from your browser.
More details:
https://digitalescapetools.com/tools/tool.html?id=pairdrop
#OpenSource #Privacy #FileSharing #SelfHosted #AirDropAlternative #Android #Linux #Windows #iPhone
„Am Mittwoch will die grün-schwarze #Landesregierung in #Baden-Württemberg einen heftig umstrittenen Gesetzentwurf verabschieden. Er erlaubt dem Bundesland den Einsatz der Palantir-Software zur #Datenanalyse, die das Land für mehr als 25 Millionen Euro bereits eingekauft hat…..“
Palantir in Baden-Württemberg
Polizei soll mit deinen Daten Software trainieren dürfen
#Grüne #CDU #BaWü #Überwachung #Polizei #Daten #Datenschutz #Privacy
‚Heute wurde in #Berlin eine Novelle des Polizeigesetzes verabschiedet. Sie erlaubt so ziemlich alles, was an digitaler Überwachung möglich ist: Verhaltensscanner, Gesichtersuche, Palantir-artige Datenanalysen, Staatstrojaner….‘
https://netzpolitik.org/2025/neues-polizeigesetz-berlin-wirft-die-freiheit-weg/
#Netzpolitik #Überwachung #Deutschland #Palantir #Gesichtserkennung #Datenschutz #Daten #Privacy
‚Deutschlandweit sprechen sich Politiker*innen dafür aus, keine Software von Palantir zu verwenden. Stattdessen soll eine europäische Alternative eingesetzt werden. Die Verknüpfung und automatische Analyse möglichst vieler Daten bleibt aber ein totalitäres Konzept…..‘
Totalitäre Tendenzen - Palantir-Ersatz aus der #EU ist ein gefährlicher Wunsch
https://netzpolitik.org/2026/totalitaere-tendenzen-palantir-ersatz-aus-der-eu-ist-ein-gefaehrlicher-wunsch/
Sehr treffender Kommentar von @yoshiXYZ
#Überwachung #Datenschutz #Privacy #Palantir #Netzpolitik #Totalitarismus
American Express ordered to fix security gaps after a customer complained about improper employee access.
It seems that a customer reported a privacy concern and fought AmEx for 4 years to get them to implement stronger access controls or monitoring of employee access to data.
Now, the AU govt has ordered AmEx to rectify security flaws in five of its data systems to guard against “insider threats” and to restrict employee access to specific customer information to protect vulnerable and high-profile customers.
and:
https://www.oaic.gov.au/__data/assets/pdf_file/0031/264919/Report-of-investigation-into-AMEX.pdf
h/t, @TheAge (paywalled):
https://www.theage.com.au/business/banking-and-finance/american-express-ordered-to-fix-security-gaps-after-customer-was-spied-on-20260612-p606ei.html
#AmEx #AmericanExpress #insiderthreat #accesscontrols #logging #enforcement #privacy #FinSec #infosec
Last week W3C Privacy Lead Tara Whalen was at ICANN86 Policy Forum Seville.
She participated in the GNSO: ISPCP Outreach Session "Data Sharing for Abuse Mitigation: Balancing Privacy and Security"
https://icann86.sched.com/event/2NQOU/gnso-ispcp-outreach-session
Learn more about W3C's work on Privacy and how you can help shape the privacy-preserving Web as a W3C Member: https://www.w3.org/mission/privacy/
(photo credit: @icannphotos on Flickr https://www.flickr.com/photos/icann/55327133245/)
#ICANN86 #Privacy #Policy #JoinW3C
WIRED - The Latest in Technology, Science, Culture and Business [Unofficial] » 🌐
@wired.com@web.brid.gy
Rank One, whose board includes a former CIA deputy director and a former FBI science chief, supplied face recognition to Meta for internal development of its smart glasses app.
The UK government has adopted the Boris Johnson clown car. They've just announced a ban on under 16s accessing social media.
But, they have not first understood the implications of age verification on everyone else:
"The regulator #Ofcom has been asked to carry out a rapid study to identify the best ways to verify if someone is over 16. "https://www.bbc.co.uk/news/articles/ceqdny4l3jdo
What utter stupidity from #KeirStarmer #LisaNandy of #UKLabour. If only Ofcom regulated the companies.
Things that make me instantly happy: beautiful night sky, beautiful forests and nature (night or day), fireflies, aurora borealis, rain, the smell of rain, good food, good satire, good coffee, good movies, good music, good art, happy animals, Linux, privacy, security, human rights… etc. 🌌🐧🌲🌿🌧️ ✨
#instantlyhappy #beautifulNightsky #beautifulForests #nature #nightOrDay #fireflies #auroraborealis #rain #smellOfRain #goodFood #happyAnimals #Linux #privacy #security #humanRights
What makes you instantly happy… 🤔
Hejo, widzieliście już Verified Apps?
Projekt od @privacyguides to oficjalny fork dobrze znanego AppVerifiera. Ktoś z Was już używa? Co myślicie, ma szansę na stałe zastąpić oryginał?
Zaletą jest na pewno znacznie większa, rozwijana przez społeczność baza danych, która automatycznie agreguje skróty certyfikatów. Zostajecie przy rygorystycznym, ręcznym sprawdzaniu hashy w AppVerifierze czy wolicie automatyzację, w której aplikacja sama potwierdza kryptograficzną autentyczność pochodzenia pliku?
Link do repo: https://github.com/privacyguides/verified-apps-android
#GrapheneOS #PrivacyGuides #AppVerifier #VerifiedApps #Android #DeGoogle #Privacy #Cybersecurity