Due to the recent announcement of Proton moving to a non-profit structure (although not becoming fully non-profit) I’ve decided to take another look at them and really, Proton Unlimited is an enticing offer. However, the fact of everything from mail, to accounts, to storage being in one place is somewhat disconcerting. Also I recall them being decent, but not particularly outstanding at refusing to provide data to outside sources, there was a situation a while back where they handed over information of a climate activist.
To be fair, mail is insecure by default and if you’re going so far as to write to another Protonmail user you might as well use something actually secure and I am not exactly planning on breaking the law so I’m not too worried about data being handed over to authorities, yet it still leaves a bitter taste in my mouth and with the state of politics where I live there certainly is a concern that, being queer, I should also be a bit weary of governing bodies as well, as laws may change in the future.
Basically, by switching to Proton I’d be putting a lot of trust in them, instead of splitting it up between things like Mullvad, Bitwarden, etc. and besides a password manager (and to some extent my email provider), while dramatic, a single failure at any point wouldn’t be a total disaster. Are they trustworthy enough for the convenience benefits to be worth it to any of you?
I use Proton services (among others) since years and i think that they are pretty trustworth with stable services and fair conditions.
Personally I would split them so they are not all in the same place. So for email use something like proton or tuta, vpn could be mullvad and a local password manager such as keepass xc synced with syncthing.
Well, I just got blocked for replying all to an email with two recipients and now I can’t access my email, calendar, passwords, or VPN, so that’s great.
I agree with what others have already said about Proton being “good enough” for some threat models. And I second the argument about other options – such as Tuta for email, Mullvad for VPN, etc.
I’d just add one more thing. Once a company offers me to “handle” my digital privacy toolkit, I loose trust. Because a) it’s less resilient b) less secure c) less private. I would think twice before trusting emails, calendars, contacts, passwords and network security — to a single company.
The climate activist thing they did pursuant to a warrant, which every company will do, and the only thing of interest they turned over was the person’s recovery email…which was personally identifiable. From there the authorities got everything else. IIRC, they got access to the person’s iCloud. None of the person’s emails or anything like that was given out. If you are strictly concerned about privacy you shouldn’t use a recovery email so that your login can’t be tied back to you.
As far as the service, I am using Mail and Pass daily and like both. I use the VPN and Drive sparingly, but I have enough space on it to stop using my Google Drive. Calendar is useless for me because of the lack of CalDAV support… and also because I can’t have many calendars on the free plan.
It hits the sweet spot between privacy and ease of use for me. YMMV.
it’s funny when they are all about privacy and then when I register it immediately asked me about my other emails to verify me with NO OPTION TO SKIP IT… now think about how the climate activist got caught… yea proton is a textbook definition of honeypot.
I think their services are generally pretty good, yes.
But their frontends really aren’t. Their web apps are serviceable for desktop use. The Proton Mail desktop app is essentially the web app in an Electron or CEF wrapper. But on the desktop you can at least use Proton Bridge to then use whatever IMAP mail client you want.
On mobile, you can’t. You have to use their services with the corresponding app they provide on Android and iOS. I moved from iCloud Mail to Proton just a few weeks ago (and I also had Proton a few years ago), which meant I had to switch from the default iOS “Mail” app to the Proton Mail app, as Proton doesn’t support IMAP without a bridge (naturally, as IMAP doesn’t support end-to-end encryption).
Unfortunately the Proton Mail app is not a fully native app but instead it must be using React Native or something similar. It’s a low effort port of the web app, meaning very few integrations with iOS were actually done. For example, Apple Mail can show the email content in the notification, Proton Mail doesn’t. At least you can mark mails as read in the notification, but you can only see the subject line without opening the app. Offline functionality is very limited as mail contents aren’t cached on device, which can also make opening specific mails very slow (comparatively at least), and overall the app just feels less responsive compared to a native Swift UI app. UI animations aren’t “attached to your finger”, instead they just fully play once triggered no matter what. Calendar attachments just show up as an .ics file that you then have to download and open to add them to your calendar instead of just having a simple “Add to calendar” button.
But the worst part is that the iPad version is basically just the iPhone version blown up to fill the screen. It doesn’t have a multi-column layout with your inbox on the left and the selected mail on the right. Nope, just like on the phone app, you open a single mail, it takes over the whole screen and you have to go back to your inbox again.
For that reason I didn’t even bother with their calendar service.
The VPN app is fine. The iPad app is the same blown up iPhone app as well, but you don’t actively use the app for more than a few seconds to pick and connect to a server, so I don’t care.
Proton Pass is a little bit better (it’s also newer I think), it does have a separate iPad layout. It also integrates well with their email alias service (SimpleLogin, although the SimpleLogin service standalone is a bit different still). I still use 1Password though because of the SSH Agent integration on desktop and it also comes with a Safari iOS browser extension for additional convenience features over just the native OS integration for password managers.
I actually use SimpleLogin and while it’s technically not an OG Proton service, you do get their Premium service included with your Proton subscription (Proton owns SimpleLogin now). Very good service and hey, it has a pretty solid iOS app.
I didn’t really use Proton Drive yet, but I’ll probably use it for archiving some stuff by just uploading it through the web interface. Last time I checked they didn’t have a native Linux client yet (for Dropbox-like folder sync), but somebody hacked support into rclone I think, although the API isn’t documented on Proton’s part, so it’s probably not super-reliable.
That’s it, right? Apparently Proton might acquire Simple Notes, and I’d sure take that included in my subscription, although I feel like Proton should focus on vastly improving their existing services first before they broaden their portfolio.
For my threat model, yes they are trustworthy enough. I am not concerned about concealing my identity from a government investigating me for some alleged crime, but rather just transitioning away from Google and investing my time and money into a company that better respects my privacy. As a result, the centralisation doesn’t concern me as much as it does others and I am fine using Proton for VPN, email, calendar and storage. I also use SimpleLogin, which is now owned by Proton. All their applications are well designed and reliable for basic use in my experience, and it is more affordable for me to bundle these services together. I would definitely recommend them to people like myself, but your threat model sounds a little more complicated so you might want to do some further research and see what else is out there.
Been using Proton stuff for years. Some things are super annoying and just don‘t work. Their software engineers are mediocre at best. This made me move everything away from Proton a couple of years ago. Funny enough, all the other privacy focused providers annoyed me even more. So after 1-2 years without Proton, I moved everything back :D
Don‘t expect too much and you will be fine. Simple features you know from other services might be missing. Support is meh, but you rarely have to use it.
claims to be secure
closed source
total snakeoil
Man, would taking a few seconds to verify stuff kill you? All Proton applications are open source.
cool can you point me at the repo for their server software then? and the f-droid reproducible build of their android app, or the sideloadable iOS app?
Self hosting
You don’t have to use all services. I have the Unlimited plan and use mail with custom domains (+ the included SimpleLogin account) and VPN mostly, and Drive for backup (no Linux client yet makes it a no-go for daily use, but I have my own Nextcloud server that serves my purpose fine). Pass I have not tried (I use another manager), and Calendar I also don’t use.
I still feel I am getting my money’s worth.
https://flathub.org/apps/com.hunterwittenborn.Celeste
Pass is awesome
Calendar is good but can’t speak caldav which makes it useless for android and linux.
Nice, didn’t know about Celeste. Will check it out :)
Use it but don’t rely on it. Celeste uses rclone. The rclone support was temporarily disabled from Proton’s end a while back and also, the rclone backend still has a bunch of bugs and the developer seems to have gone missing
Why does the lack of CalDAV make it useless for Android? The app works just the same as Google Calendar on my phone.
They’re referring to the quality of integrations with third-party systems, like the built-in CalDAV support basically every OS has. For some people, using just the calendar app is fine, but others want that deeper integration so they don’t have to rely entirely on Proton to provide features in their frontends that OS apps might already handle.
For example, on Android I might want to let other apps access information from my calendar (e.g. my launcher so it can show me events from within its built-in schedule widget). Same goes for my Thunderbird client on Linux, it’d be nice to have the calendar events be integrated there too. Unfortunately, they currently only support a mail bridge, but the official Proton account on Reddit has made a few comments stating that they’re “looking into” adding CalDAV support to Bridge, but there’s no official timeline on when or if that’ll actually happen. I’m willing to bet it eventually will, but I’ll say I’d definitely appreciate it if they did.
It doesn’t integrate with android or linux. You are vendor locked in. You can only use proton’s app. Usually carddav and caldav go together, my tasks (and now kanban board. thank you jtx) and my calendar are very well integrated.
Wait, it doesn’t support caldav? That really kills the appeal of the convenience they provide as a one-stop-shop, as I’d have to deal with hosting my calendars in another way. I guess at that point I could just get SimpleLogin and use the rest as I have it, even if that gets close to proton unlimited price-wise…
Yes. I host my own nextcloud, I don’t need their calendar. But that also means I don’t need their drive. I only need the VPN and the mail and simplelogin is a nice bonus.
I’m pretty much in the same boat, you think it’s worth subscribing only for the vpn and email?
Tough question, but I guess yes. It’s 10 bucks a motnh iirc, and I don’t pay for streaming services
Yeah I suppose that’s not too expensive, although it feels like a waste when I’m not using all the services provided
Their changing their business structure (or just changed it). I guess you could say now that it’s also a donation to the whole system itself. Like donations to EEF or so. The more (financial) power proton has the better compared to other services.
I really love Proton, but I’m only using Mail, VPN, and Calendar. I kept BitWarden - already had it for a bit before Pass came about.
Oh: I’m also using SimpleLogin. Love that.
FYI: Bitwarden has integrations for SimpleLogin, Addy.io, FastMail, etc. for their username generator, so you can easily generate aliases for every site, regardless of what alias provider you use.
I’ve been using Proton for several years now, and paying for their Mail and VPN features. Proton Mail is definitely better than Gmail, but other than the privacy features, it’s just a basic email service. Their VPN also is just a basic service. If that’s what you need, then by all means, I’ve always had a good experience with them.
That being said, I do run a competing email service called Port87 that (IMHO) has better features for organization and spam protection, so take what I say with the knowledge that I am technically their competitor (although my user base is tiny compared to them). Really, I see them more as an ally against Gmail and MS Exchange, because I’ve never experienced any sort of anti-competitive behavior from them like I have with both Google and Microsoft.
Supporting smaller players in the email space is what keeps email open, so the more people move away from Gmail and Exchange/MS 365, the better.
One service provider, single point of failure. After google bullshit and how long it took me to get away, i aint cornering myself again. I will pay for the extra fee for mobility and choice.
You don’t have to use all the services, most of them have an excellent free tier. My setup is paying for VPN, using the free tier of pass and self hosting my email and cloud storage.
Legally they (and every other company) are required to hand over data to the police, however they can try to have as little data as possible. While Proton doesn’t take as extreme measures to protect your privacy as for example mullvad, they have no log policy and such. I believe the case where they had to collect data (IP address, which they normally don’t collect) they received a legally binding order from the Swiss government which normally is used for serious crimes. Every company has to follow these orders, so this isn’t a proton thing but rather a Swiss law thing.