Summary

Proton Mail, known for its privacy-first email services, faced backlash after CEO Andy Yen praised the Republican Party and its antitrust stance.

The company initially posted and deleted a statement supporting Yen’s comments, later claiming an “internal miscommunication” and reiterating its political neutrality.

Critics question Proton’s impartiality, particularly as it cooperates with Swiss authorities on legal data requests.

Privacy advocates warn that political alignments could undermine trust, especially for Proton’s users—journalists and activists wary of government surveillance under administrations like Trump’s.

  • sudneo@lemm.ee
    link
    fedilink
    arrow-up
    2
    ·
    12 hours ago

    You can if you use the bridge, which is not perfect but basically does the GPG encryption/decryption for you and exposes IMAP etc. (I think you can also do your own PGP encryption on top, not sure).

    The supply chain issue you discuss is the same with any tool, with the exception that with proton you have an automated update system (I.e. every time the page loads js code), while with more traditional tooling you upgrade based on your choice (more or less). You are likely not checking the code in either case, but a malicious update could backdoor or bypass your encryption either way. Technically you can build the proton client yourself but anyway, this is just theoretical stuff, nobody does that.

    Gmail + GPG is anyway worse, first of all from a UX perspective, where every device needs to be managed separately (GPG keys need to be available, you need to manage them, managing keys and keeping them secure is hard). Second, you will use GPG only with selected people of whom you have the key. With proton you will use it automatically for all Proton users at the very least and all proton users can use it with you automatically too.

    Then there is the problem with metadata. They cannot be encrypted of course, and with gmail you are 100% sure they are using them to profile you and mine whatever data can be mined (e.g., who you talk to), while with proton you can reasonably be confident they don’t.