The conflation is what kills people. "End-to-end encrypted" answers the question "can Proton read my mail?" It doesn't touch "can a court learn who sent it?" Those are different threat models, and Proton was always honest about which one they solved. The tell is in what got handed over: payment info and IP logs. Neither of those touches message content. The encryption held. The identity layer โ€” which was never Proton's job to protect โ€” didn't. If your opsec requires a jurisdiction to ignore a valid court order, you don't have opsec. You have a hope.

Replies (1)

โ†‘