I have been deep diving into internet privacy and cyber security for a while now. I’ve noticed that any popular privacy related product will get haters for some reason. Obviously I am not going to support a privacy related product “no matter what controversy surrounds it”, in fact I have VERY specific requirements for that. And I get people being paranoid in that specific community, and that maybe people will be on the lookout for controversy. But people will be like “you use PROTON products? What a basic entry level choice” and it’s like do you not know WHY they are so popular in this space? Because they hit all the check boxes and are easy to use. One time I mentioned Signal and someone was like “isn’t that a CIA honeypot?” No. No it is not. There is no evidence whatsoever. And the code is right there, you can just read it. Just because some “normies” like a product doesn’t mean it’s a trick.
And people don’t seem to understand that it is sometimes not wise to completely avoid controversy. Who do you trust more, a group of devs (or even gasp a company) who has been around for 15 years, had a security flaw 3 years ago and patched it after someone noticed and passed independent 3rd party audits since then, or a brand new 1 man project that has no controversy (yet)?
So while I absolutely disagree with blind loyalty to anything, people are sometimes too quick to jump ship and end up being like the “yet you participate in society. Interesting!” meme.
You need to teach the normies what to look for. I use Proton because it was the first one i tried and it did what I wanted to. I dont trust it though. I dont know what to look for for it to be trustworthy.
“You know the government and basically any corporation that wants it can have access to all of your activity and tie it to you? Send all your data through me first. Trust me bro. Totes secure dawg.” Just immediately triggers my suspicion, and it will be triggered on any service like that.
For what to look for, sometimes people’s priorities will be different, and unfortunately sometimes you may need to sacrifice usability to meet all your personal criteria. But this is what I look for.
FOSS (free open source software). The source code is open for everyone to read, and therefore you know exactly what the application is going, and security flaws will be noticed and fixed more quickly. There are sometimes exceptions for infrastructure. Back end software for services like email or cloud providers will not generally be open source for various reasons. E2EE (end to end encryption, it is encrypted from the moment it leaves my device and decrypted on your device). ZAE (zero access encryption) for services that store my info on a server, such as email or cloud storage. This means that the data is encrypted on the provider’s server, and they do not hold the encryption keys. Independent 3rd part audits. Privacy enthusiasts whose job it is to suss out problems are given free reign to inspect every part of the provider and see if they are really doing what they claim with privacy and security. Further proof may be shown by ethical hackers posting results of what they were able to do. Location: the Dev/provider has to obey local laws, so I trust if they are based somewhere that respects data privacy and are not authoritarian. If the company still seems a bit shady (certainly if they are closed source) but I want to use their product, I will carefully read their privacy policy. Sure, they may be lying, but you’ll be surprised at what some companies openly admit to. And if you’re not comfortable with what they state publicly, you should probably move on. To a lesser extent, I also prefer seeing open standards instead of proprietary ones (like PGP for encryption for example) and a strong choice for encryption because I know a little bit about that. No ads: self explanatory. Is the company/devs shady seeming in general? Also fairly self explanatory but more arguable.
Proton meets all of these requirements for all their products, with the slight exception that not every part of every project is fully open source. If it was, you could hijack their email or cloud servers and use their infrastructure with any amount of storage for free, for example. This is pretty common for service providers. No idea what you’re on about with the last part. They specifically have a no logs policy for their VPN that has been “battle tested” by governments subpoenaeing info. They don’t have that info, so they were unable to give it.
Yeah, that’s how I look at a lot of products. There will be faults and there are some red lines that I won’t cross, but I’d rather a company have done minor faults, be open about them, and fix them rather than be brand new and possibly hiding a lot worse.
I completely agree. Nearly every product, service, or company in the privacy sphere has some controversy. If I based my choices on the lack of shitty behaviour, I would have to give up on the internet completely.
I have been deep diving into internet privacy and cyber security for a while now. I’ve noticed that any popular privacy related product will get haters for some reason. Obviously I am not going to support a privacy related product “no matter what controversy surrounds it”, in fact I have VERY specific requirements for that. And I get people being paranoid in that specific community, and that maybe people will be on the lookout for controversy. But people will be like “you use PROTON products? What a basic entry level choice” and it’s like do you not know WHY they are so popular in this space? Because they hit all the check boxes and are easy to use. One time I mentioned Signal and someone was like “isn’t that a CIA honeypot?” No. No it is not. There is no evidence whatsoever. And the code is right there, you can just read it. Just because some “normies” like a product doesn’t mean it’s a trick.
And people don’t seem to understand that it is sometimes not wise to completely avoid controversy. Who do you trust more, a group of devs (or even gasp a company) who has been around for 15 years, had a security flaw 3 years ago and patched it after someone noticed and passed independent 3rd party audits since then, or a brand new 1 man project that has no controversy (yet)?
So while I absolutely disagree with blind loyalty to anything, people are sometimes too quick to jump ship and end up being like the “yet you participate in society. Interesting!” meme.
You need to teach the normies what to look for. I use Proton because it was the first one i tried and it did what I wanted to. I dont trust it though. I dont know what to look for for it to be trustworthy.
“You know the government and basically any corporation that wants it can have access to all of your activity and tie it to you? Send all your data through me first. Trust me bro. Totes secure dawg.” Just immediately triggers my suspicion, and it will be triggered on any service like that.
For what to look for, sometimes people’s priorities will be different, and unfortunately sometimes you may need to sacrifice usability to meet all your personal criteria. But this is what I look for.
FOSS (free open source software). The source code is open for everyone to read, and therefore you know exactly what the application is going, and security flaws will be noticed and fixed more quickly. There are sometimes exceptions for infrastructure. Back end software for services like email or cloud providers will not generally be open source for various reasons. E2EE (end to end encryption, it is encrypted from the moment it leaves my device and decrypted on your device). ZAE (zero access encryption) for services that store my info on a server, such as email or cloud storage. This means that the data is encrypted on the provider’s server, and they do not hold the encryption keys. Independent 3rd part audits. Privacy enthusiasts whose job it is to suss out problems are given free reign to inspect every part of the provider and see if they are really doing what they claim with privacy and security. Further proof may be shown by ethical hackers posting results of what they were able to do. Location: the Dev/provider has to obey local laws, so I trust if they are based somewhere that respects data privacy and are not authoritarian. If the company still seems a bit shady (certainly if they are closed source) but I want to use their product, I will carefully read their privacy policy. Sure, they may be lying, but you’ll be surprised at what some companies openly admit to. And if you’re not comfortable with what they state publicly, you should probably move on. To a lesser extent, I also prefer seeing open standards instead of proprietary ones (like PGP for encryption for example) and a strong choice for encryption because I know a little bit about that. No ads: self explanatory. Is the company/devs shady seeming in general? Also fairly self explanatory but more arguable.
Proton meets all of these requirements for all their products, with the slight exception that not every part of every project is fully open source. If it was, you could hijack their email or cloud servers and use their infrastructure with any amount of storage for free, for example. This is pretty common for service providers. No idea what you’re on about with the last part. They specifically have a no logs policy for their VPN that has been “battle tested” by governments subpoenaeing info. They don’t have that info, so they were unable to give it.
Yeah, that’s how I look at a lot of products. There will be faults and there are some red lines that I won’t cross, but I’d rather a company have done minor faults, be open about them, and fix them rather than be brand new and possibly hiding a lot worse.
I completely agree. Nearly every product, service, or company in the privacy sphere has some controversy. If I based my choices on the lack of shitty behaviour, I would have to give up on the internet completely.