Thinking of getting Proton and using it as my day-to-day email, but I have concerns
So I kind of want to get out of the Gmail ecosystem, and have been eyeing Proton as a good replacement, but I can't help but to think that nearly all of Proton's selling points and marketing...
So I kind of want to get out of the Gmail ecosystem, and have been eyeing Proton as a good replacement, but I can't help but to think that nearly all of Proton's selling points and marketing points are all smoke and mirrors.
And I don't know, maybe I'm looking at this entirely the wrong way, I am just really struggling to see the appeal of Proton.
First, I'll start with my "threat model".
In general I want to be more anonymous online and slip under the radar better.
I'm not planning on doing anything clandestine, but with the direction the US is going, I'd rather not be an easy target if I want to be active in activism spaces if you catch my drift.
And I'm also interested in staying off of databrokers radars, or obfuscate myself to prevent coherent tracking.
With that being said, it seems that even with a proton email if someone wanted to find my identity they could, data brokers or governments alike, even if I pay for my subscription with cash.
And not that I'm really worried about that, but to me that negates like the entirety of Proton's marketing gimmick.
And I'm failing to see what functional benefit Proton has when it comes to privacy outside of just being "aesthetically private".
Here are some of my concerns, please feel free to correct me if I'm completely offbase with any of the logic below, but this is just my initial thoughts, and I'd love to hear some feedback and/or be corrected or provided more context.
-
Why does the encryption of the message body matter if the envelope and address are is still exposed? If a government or data broker can get the sender/receiver info, timestamps, and my IP, they have a map of my life. Isn't the "private content" just a distraction from the real leak? Like other than not having my emails used to train AI or data being sold to data brokers, I can't find a functional improvement or benefit to my daily life to use Proton outside of thinking "Yeah, fuck The Man" every time I log in. Like I am more worried about governments and data brokers knowing who I'm sending/receiving things from than I am about the content of those messages being exposed since I'm not going to be monologuing evil plans over email, and I really don't care if the databroker tracking me knows that I bought a case of liquid death root beer 4 times in one month since they get that information from Amazon or whatever website anyways.
-
Everyone talks about "Swiss protection," but isn't that just a speed bump? If the U.S. government goes to Switzerland with an MLAT request, Proton has to comply. And even if I've payed with cash, they can still be compelled to log the IP logins and hand over the alias emails and primary mailbox used by that account and the metadata. So if I sign up for something using an alias, they can take that alias and file an MLAT request with Switzerland to get my main email, the metadata for my entire inbox(just not the body content) and the other aliases tied to that account, and then do a search for any services using those emails to find my identity. They could technically use an alias email I've made, send an information request to Switzerland/Proton, get back a list of aliases and email metadata, find that I used an alias to sign up to a pizza delivery service, then subpoena that pizza delivery service for my name, phone number, and address, at that point what's the point? Is the point just to make it harder for them? I'm not planning on doing anything that could get them to want to subpoena my emails ANYWAYS, but what's the point of making it harder for them outside of again, just thinking to myself "haha fuck you" every time I send an email?
-
Even if I use an alias, if the site I use the alias on gets tied to my online data/identity, then my privacy is broken, right? Like lets say I want to sign up for a new site called godotshaders.com, I use a proton alias to sign up. This site then collects that data, my IP, my cookie data, browser user agent string data, and that I'm logged into some account with my other non-proton email, etc, that gets tied to my browsing data they're collecting, and suddenly they've linked that alias email to my advertising profile and other browsing. Rinse & repeat. Now all the aliases are tied to me. I don't see how these emails help with online advertising tracking.
-
I have tons of accounts I use, my bitwarden login count sits at around 850 logins, but I probably only regularly use a small fraction of those. But if I end up changing my email on a lot of those accounts to the proton email, even a proton alias, all that does for data brokers is potentially tie every one of those new alias emails to me. And at that point there is no difference in my data broker information just that I have 850 different alias emails. But my data is still tied to those accounts. So AGAIN, what's the point of this? Do I need to sign up for everything from scratch in order to maybe have privacy?