UK government is trying to get into iCloud end-to-end encryption. (Again?)

Makes me think about email servers too. Most of my private information is in emails, and not only I use a service where the host machines access the email, so do almost everyone I email to/from.

  • Telorand@reddthat.com
    link
    fedilink
    arrow-up
    2
    ·
    4 hours ago

    They’re not anonymous, contrary to common perception. They’re encrypted, but they know things like your IP address and which IP addresses you’re communicating with, even if they don’t know the content of your messages. Some of them explicitly state as much.

    Depending on the local laws of the company or servers, they might be compelled to share whatever data they do have, which could be enough info to assist law enforcement in making an arrest, even if they can’t see the message itself.

    If you want anonymous email use, you have to use a logless VPN at a minimum every time you access a third party encrypted email service. That way neither side of the email exchange can tie your IP address to you.

    • Gayhitler
      link
      fedilink
      English
      arrow-up
      2
      ·
      4 hours ago

      Of course, I only meant that unlike Gmail and such services like proton don’t actively impede your anonymity and build a profile on you as far as we know.

      • Pika@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        3
        ·
        edit-2
        3 hours ago

        Proton does require you to have a dedicated phone number or email to sign up though, like that was my main thing that swayed me away from making a protonmail account was when I went to sign up I was met with a phone number requirement and I’m like “oh well this isn’t going to be helpful”

        They claim it’s to prevent abuse of the service, and that it’s only the cryptographic hash which can be used to find out if the email has been used on an account before. But I dislike that it requires even going that info

        ammendum: apparently this restriction may be based off of your region used and browser. I was able to finally successfully create an account using Chrome, but Firefox exclusively gave me email or phone number requirements

        • Gayhitler
          link
          fedilink
          English
          arrow-up
          4
          ·
          3 hours ago

          I think I got in before they started doing that.

          Actually I don’t think they require that. I just set up a new proton account on a device with a fresh wipe from a vpn endpoint I never used before and they offered to record a phone number or recovery email but didn’t require it.

          • Pika@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            3
            ·
            edit-2
            3 hours ago

            Can you tell me which endpoint/region that you used? Cuz I just tried using a VPN endpoint from Switzerland Sweden and Ukraine and all three of them brought up a requirement to have a verification email

            edit: disregard apparently it was a browser issue, switched from Firefox to Chrome and reconnected to a Switzerland endpoint and it let me solve a captcha instead of using email verification system

            • Gayhitler
              link
              fedilink
              English
              arrow-up
              3
              ·
              3 hours ago

              Mullvad us Denver 205.

              I’m also using their encrypted dns though that shouldn’t matter. Recording an email might be a regulatory requirement of the intelligence sharing treaties of the eu and broader eurozone.

              Try an endpoint outside of the western world and see what happens!

              • Pika@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                1
                ·
                edit-2
                3 hours ago

                Yeah weirdly enough it ended up being a browser issue, Firefox wasn’t able to use anything but email verification/phone number verification but Chrome was able to offer a captcha in place of it