TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Is Protonmail logging my email content?

100 点作者 ppcelery超过 3 年前
evidences:<p>1. https:&#x2F;&#x2F;s3.laisky.com&#x2F;uploads&#x2F;2021&#x2F;12&#x2F;proton-1.jpg<p>2. https:&#x2F;&#x2F;s3.laisky.com&#x2F;uploads&#x2F;2021&#x2F;12&#x2F;proton-2.jpg<p>3. https:&#x2F;&#x2F;s3.laisky.com&#x2F;uploads&#x2F;2021&#x2F;12&#x2F;proton-3.jpg

15 条评论

ProtonTeam超过 3 年前
Please be aware that we don&#x27;t log email content (and we are also not vulnerable to Log4j). Our anti-spam systems do check for malicious links from third party email services so we can proactively warn users about phishing attempts.
评论 #29550199 未加载
评论 #29540322 未加载
评论 #29541686 未加载
1cvmask超过 3 年前
They have already being known to log emails when enforced by the Swiss authorities:<p><a href="https:&#x2F;&#x2F;techcrunch.com&#x2F;2021&#x2F;09&#x2F;06&#x2F;protonmail-logged-ip-address-of-french-activist-after-order-by-swiss-authorities&#x2F;" rel="nofollow">https:&#x2F;&#x2F;techcrunch.com&#x2F;2021&#x2F;09&#x2F;06&#x2F;protonmail-logged-ip-addre...</a><p><a href="https:&#x2F;&#x2F;protonmail.com&#x2F;blog&#x2F;transparency-report&#x2F;" rel="nofollow">https:&#x2F;&#x2F;protonmail.com&#x2F;blog&#x2F;transparency-report&#x2F;</a><p>——<p>In case you trust Swiss companies blindly:<p><a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Crypto_AG" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Crypto_AG</a><p><a href="https:&#x2F;&#x2F;www.thebureauinvestigates.com&#x2F;stories&#x2F;2021-12-06&#x2F;swiss-tech-company-boss-accused-of-selling-mobile-network-access-for-spying" rel="nofollow">https:&#x2F;&#x2F;www.thebureauinvestigates.com&#x2F;stories&#x2F;2021-12-06&#x2F;swi...</a>
评论 #29539442 未加载
评论 #29539629 未加载
评论 #29539673 未加载
评论 #29539774 未加载
speedgoose超过 3 年前
I&#x27;m not sure they are a Java company, they are more Python, PHP, Golang, and Node. At least Java is not described in their job offers, which are usually a very nice way to know about the company stacks by the way.<p><a href="https:&#x2F;&#x2F;careers.protonmail.com&#x2F;o&#x2F;devops-engineer-remote-europe-barcelona-london-vilnius-prague" rel="nofollow">https:&#x2F;&#x2F;careers.protonmail.com&#x2F;o&#x2F;devops-engineer-remote-euro...</a>
zaarn超过 3 年前
This is likely the spam filter scanning over the Links it finds in the E-Mail not actually something spitting the mail content into log4j (and I mean honestly, why would you even do that?)
评论 #29539214 未加载
评论 #29539182 未加载
md_超过 3 年前
It&#x27;s good to be cautious, but this is sort of a silly test.<p>Protonmail doesn&#x27;t have to &quot;log&quot; messages; <i>they have them already</i>. If I were Protonmail and I had to comply with lawful intercept requirements, I&#x27;d just:<p>a) make sure that message content isn&#x27;t deleted from the mailbox when the user thinks it is<p>b) make sure I retain access to server-managed PGP keys (by logging key material and user-supplied passphrases)<p>But I sure as hell would <i>not</i> call some Java logger.trace() on every goddamn email! That&#x27;s totally nonscalable and just silly.
INTPenis超过 3 年前
You should expect mail to be public. There&#x27;s no security at all in those protocols, by default.<p>Only encrypted e-mails are somewhat safe. So I just don&#x27;t understand who&#x27;s upvoting this. It&#x27;s a silly post.
rpadovani超过 3 年前
Was the email sent TO or FROM a protonmail address? Does it also happen if it is protonmail to protonmail?<p>Unrelated: what&#x27;s the name of the tool you use to &quot;listen&quot; to DNS calls?
评论 #29539129 未加载
gizdan超过 3 年前
Seems odd for PM to be vulnerable by the log4j CVE considering (from what I understand) they&#x27;re mostly Go house. Maybe in the Android app, but otherwise I&#x27;d be surprised.<p>Unrelated: I&#x27;ve been getting quite frustrated with some of the functionality and limitations of PM especially for the price I pay (I have 2 catch-all domains, 1 user for each, which requires 2 times pro accounts), so recently I&#x27;ve been trying to migrate away to mailbox.org. Mailbox allows for automatic PGP encryption when the emails come in which is great. However, there is no way to move all my PM emails onto my mailbox.org account while keeping the encryption (not via the original key set up in Protonmail, nor via new key set up in mailbox.org). Has anyone ever run into such a scenario, and what can be done in this scenario?
评论 #29541727 未加载
NabiDev超过 3 年前
Seems Proton scan the emails. Including domains in the body.
randy408超过 3 年前
This needs more detail, what is the body of the mail supposed to show?<p>Did you run an experiment? How was it run?<p>Is this between protonmail addresses?
ac130kz超过 3 年前
If I were you, I would not use any kind of non open source and non self-hosted email service pretending to be &quot;secret&quot;, in the best (!) case it has some sort of silent metadata&#x2F;access logging. While common shady services like Protonmail bluntly store plain text archives, and even if they claim they don&#x27;t, there&#x27;s no zero-knowledge proof on this highly sensitive topic.
polack超过 3 年前
Recipient or sender using Proton VPN?
Maro超过 3 年前
The screenshots are to show that that link is processed by log4j, because it exploits a log4j vulnerability and gets it to make a dns call, right?
elikoga超过 3 年前
This seems to me very worth looking into
评论 #29540528 未加载
tpoacher超过 3 年前
Hate to be that guy, but evidence has no plural.<p>Similar words often wrongly used in plural: - advices - feedbacks - codes (when referring to source code) - moneys - datas - syntaxes
评论 #29560479 未加载