Conversation

Charlotte lotteheartplural/Cinny cinny_heart_plural thetadelta ursaminor treblesand

we never have access to your data with Zero Access Encryption™, a custom term we invented to mean that “you can decrypt the data and we also see the data and by extension law enforcement can also intercept”

1
1
3

@charlotte you never have access to your data with "Zero Access Encryption", a custom term we invented to mean "we store the CRC32 of the file rather than the file oops"

1
0
1

@ben zero access encryption is a term that proton uses to describe their encrypted services which they pinkie-promise they can’t read the data of (even though by design they literally hold the plaintext at some point)

1
0
1

@charlotte ok so can you access it from a new browser

1
0
0

@ben i mean like

when you send an email with protonmail, they send off an unencrypted copy of the message
if you receive an email with protonmail, they have received an unencrypted copy of the message and then encrypt it before adding it to your mailbox

when you use their ai chatbot thing, the messages are encrypted between you and the chatbot (which is run by them)

in either case there is a point in time where the message is unencrypted and in their possession

1
0
1

@charlotte I'm asking because if there's any way to get the encryption key through protonmail then they can do that too

1
0
0

Charlotte lotteheartplural/Cinny cinny_heart_plural thetadelta ursaminor treblesand

Edited 4 days ago

@ben i am unsure but at the very least the encryption key would be some sort of file that is encrypted with your password

1
0
1

@charlotte is it symmetric or asymmetric encryption

1
0
0

@ben presumably asymmetric encryption

but the problem i am pointing at is that proton handles your inbound/outbound emails in plain text (this is a fundamental issue with email) where they could just

make a copy

and lumo, because of their choices put the messages through the LLM in plain text so like. they also got your messages there too. in plain text.

1
0
1

@ben so like it imo kinda doesn’t matter how they did or did not implement the actual cryptography because the wide open front door is to just look at the plain text messages directly that they do directly handle

1
0
1

@charlotte if there's a government request for your data, the government is probably fine with waiting until you next log in

1
0
0

@charlotte so like

completely useless across multiple vectors

0
0
0