ProtonMail deletes 'we don't log your IP' boast from website after French climate activist reportedly arrested (2024)

Encrypted email service ProtonMail has become embroiled in a minor scandal after responding to a legal request to hand over to Swiss police a user's IP address and details of the devices he used to access his mailbox – resulting in the netizen's arrest.

Police were executing a warrant obtained by French authorities and served on their Swiss counterparts through Interpol, according to social media rumours that ProtonMail chief exec Andy Yen acknowledged to The Register.

So @ProtonMail received a legal request from Europol through Swiss authorities to provide information about Youth for Climate action in Paris, they provided the IP address and information on the type of device used to the police https://t.co/KtKF4wn3wv

— Etienne - Tek (@tenacioustek) September 5, 2021

At the time of writing, the company's website said: "We believe privacy and security are universal values which cross borders."

After data from ProtonMail was handed to the Swiss and then French police, the author of a left-wing political activists' blog in France wrote (en français) that a group called Youth for Climate had been targeted:

The police also noticed that the collective communicated via a ProtonMail email address. They therefore sent a requisition (via EUROPOL) to the Swiss company managing the messaging system in order to find out the identity of the creator of the address. ProtonMail responded to this request by providing the IP address and the fingerprint of the browser used by the collective. It is therefore imperative to go through the tor network (or at least a VPN) when using a ProtonMail mailbox (or another secure mailbox) if you want to guarantee sufficient security.

ProtonMail has said in the past that it does not collect user data and implements end-to-end encryption, and repeated that over the weekend, saying: "Under no circ*mstances however, can our encryption be bypassed, meaning emails, attachments, calendars, files, etc, cannot be compromised by legal orders."

This statement, while bold, seems to be borne out by the service's privacy policy which states that it can access the following user information:

  • Sender and recipient email addresses
  • The IP address incoming messages originated from
  • Message subject
  • Message sent and received times

These are all standard unencrypted information from email headers, inherent to the SMTP email specification, though it appears that ProtonMail's previous promises about user information logging were a bit over-generous. Back in January this year, the company's homepage stated: "No personal information is required to create your secure email account. By default, we do not keep any IP logs which can be linked to your anonymous email account. Your privacy comes first."

Today that boast has been replaced with a mealy-mouthed version: "ProtonMail is email that respects privacy and puts people (not advertisers) first. Your data belongs to you, and our encryption ensures that. We also provide an anonymous email gateway."

  • Aussie telco Telstra says soz after accidentally diverting traffic meant for encrypted email biz through its servers
  • Epic, Spotify, ProtonMail and pals rise up as one against Apple's 30% cut, call for end to Cupertino-style markets
  • ProtonMail-run website boasting 'complete guide' to GDPR left credential-baring .git repo exposed online
  • Tutanota cries 'censorship!' after secure email biz blocked – for real this time – in Russia

The firm's privacy policy, which was updated yesterday, now says: "If you are breaking Swiss law, ProtonMail can be legally compelled to log your IP address as part of a Swiss criminal investigation."

In a statement posted to Reddit, which Yen forwarded to El Reg in lieu of making a statement of his own, ProtonMail said:

In this case, Proton received a legally binding order from the Swiss Federal Department of Justice which we are obligated to comply with. There was no possibility to appeal or fight this particular request because an act contrary to Swiss law did in fact take place (and this was also the final determination of the Federal Department of Justice which does a legal review of each case).

As a Swiss company, ProtonMail is obliged to obey Swiss law and comply with Swiss legal demands, though it's unclear why the company was logging user-agent strings and IP addresses of client logins. An option exists in ProtonMail's user interface to enable access logging, though there is no information in public to suggest whether or not the French environmental protestor had enabled that.

In a followup clarification, ProtonMail insisted: "ProtonMail does not give data to foreign governments; that’s illegal under Article 271 of the Swiss Criminal code. We only comply with legally binding orders from Swiss authorities.

"Swiss authorities will only approve requests which meet Swiss legal standards (the only law that matters is Swiss law)."

It reiterated: "There was no legal possibility to resist or fight this particular request." ®

ProtonMail deletes 'we don't log your IP' boast from website after French climate activist reportedly arrested (2024)

FAQs

ProtonMail deletes 'we don't log your IP' boast from website after French climate activist reportedly arrested? ›

ProtonMail deletes 'we don't log your IP' boast from website after French climate activist reportedly arrested. This is false, at least the "can't" part. Just like ProtonMail can be ordered to secretly record the IP, they can be ordered to read your e-mails.

Can my IP address be traced if I use Proton Mail? ›

Most popular web-based and mobile email apps don't include the public IP addresses assigned to individuals in email headers. The email headers of messages sent from Proton Mail web and mobile apps don't contain user IP addresses in the headers of sent mail.

Why is Proton Mail banned? ›

In response to hoax bomb threats that were sent through Proton Mail, some members of the Indian government suggested taking the extreme measure of blocking Proton. At Proton, we are resolutely against the use of Proton services for purposes that are contrary to Swiss law (Proton is a Swiss company).

What is the controversy with Proton Mail? ›

In 2021 Nadim Kobeissi published an article arguing that as Proton Mail was generally accessed through a web client, "no end-to-end encryption guarantees have ever been provided by the Proton Mail service."

Can police track Proton Mail? ›

Law enforcement can additionally request the contents of unencrypted messages in the account, account profile information and assorted metadata, storage use and login times among other items. However, they cannot compel ProtonMail to attempt to decrypt any encrypted messages in the account.

Can Protonmail be subpoenaed? ›

The email provider only holds onto the encrypted gibberish, and in the event of a warrant or subpoena, this gibberish would be the only content it could hand over. (Metadata is another story, but that's a whole other post!) This seems like a perfect way to keep a message confidential, and it almost is!

Does Proton VPN protect your IP? ›

Protect your IP address at all times

Proton VPN is private by default. Our kill switch hides your device's IP address even if your VPN connection is disrupted, helping you stay secure no matter what.

Is Proton Mail safe anymore? ›

All ProtonMail data at rest and in transit is encrypted. However, subject lines in ProtonMail are not end-to-end encrypted, which means if served with a valid Swiss court order, we do have the ability to turn over the subjects of your messages. Your message content and attachments are end to end encrypted.

Where is Proton Mail banned? ›

Proton Mail to be banned in India

Section 69A empowers officers to issue orders for content blocking in the interest of national security and public order. The state's police had been facing challenges in tracing the sender's IP address in order to find the hoax bomb threat culprit.

Which is safer Gmail or Proton Mail? ›

Still deciding between Proton Mail vs. Gmail? While Gmail scans your emails and lets third parties into your inbox, Proton Mail blocks all trackers and encrypts your messages so only you can read them. We believe you should be the one who chooses what happens to your data.

What is the most hacked email provider? ›

What is the most hacked email provider? Historically, large providers like Yahoo have experienced significant breaches, making them among the most hacked email services.

Has Proton Mail been hacked? ›

The message was then followed by an attack (believed to be from the group called the Armada Collective, which has been responsible for extortion of several private email services), that flooded ProtonMail's IP addresses and knocking the service offline for approximately 15 minutes.

Can an email from Proton Mail be traced? ›

ProtonMail is encrypted, so you won't be able to track an email through ProtonMail, except through advanced methods which we will explain in this article. An IP (Internet Protocol) address is a set of rules that governs the format of data sent via a local network or the internet.

Can you trace an IP address from an email? ›

Typically, it is difficult to trace the personal IP address of someone using a browser-based email provider. However, sometimes an optional field, X-Originating-IP, is included in the email header which will reveal the originating IP address.

How do I get rid of Proton Mail? ›

Log in to your account at account.proton.me and go to Settings → All settings → Account → Account and password → Delete account and click the Delete your account button. 2. Please provide a reason why you're leaving us and confirm your Proton Mail username and password as a security precaution.

Can police track a deleted email account? ›

Yes. Very simply. The email comes from an email server, and it is very easy to determine which server from each email sent from the account. The server will have logs of that deleted account and its activity.

Can an email reveal an IP address? ›

Sending an email from a desktop client has the potential to reveal your originating IP address, meaning the one that is associated with your specific device. However, sending an email through a browser like Gmail will attach one of Google's IP addresses, which is much less specific.

Can email recipients see my IP address? ›

Access through email: Some email platforms include your IP address in the data sent with your emails. A recipient can then copy your address and use it to collect your data.

Can an IP address be untraceable? ›

Using a VPN not only hides your IP address but also encrypts all the data related to your internet browsing sessions. Some premium VPNs use advanced encryption protocols that make you nearly invisible to anyone else on the internet.

Does your IP address get tracked? ›

Can someone track my IP address' exact location? In short, no – you don't need to worry about your exact location being found through your IP address. Though IP addresses, by design, can be tracked, the purpose is to indicate your location to Internet providers and other devices when you're accessing the Internet.

Top Articles
Latest Posts
Article information

Author: Catherine Tremblay

Last Updated:

Views: 6208

Rating: 4.7 / 5 (67 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Catherine Tremblay

Birthday: 1999-09-23

Address: Suite 461 73643 Sherril Loaf, Dickinsonland, AZ 47941-2379

Phone: +2678139151039

Job: International Administration Supervisor

Hobby: Dowsing, Snowboarding, Rowing, Beekeeping, Calligraphy, Shooting, Air sports

Introduction: My name is Catherine Tremblay, I am a precious, perfect, tasty, enthusiastic, inexpensive, vast, kind person who loves writing and wants to share my knowledge and understanding with you.