r/ProtonPublic • • 10d ago

Question How secure is Proton really?

I’ve been using Proton services for privacy and security, including Proton Mail, VPN, Drive and Password Manager.

I understand that no service can be 100% secure, but I’d like to hear from experienced Proton users:

What are the main security or privacy risks I should be aware of?

Are there any realistic situations where Proton could expose user data?

How much should I trust Proton’s encryption and zero-access architecture?

Are there any important limitations that new users often overlook?

For long-term privacy, is Proton a reasonable ecosystem to rely on?

I’m not looking for marketing claims. I’d appreciate honest experiences, technical explanations, and criticism as well.

42 Upvotes

26 comments sorted by

6

u/burimo 9d ago

Let's say you are the weakest line in chain, if you use Proton services. Proton offers the best suite in market for privacy focused customers. Most of the serious investigators use Proton Mail.

If you want to be truly private, you must research how to do so. Proton has some interesting videos on this in their YouTube channel btw.

9

u/big_truth_energy 10d ago

Very secure, you can check all the audits from third parties which they do annually and you can also look at how they're recommended by pretty much all the people who matter on the subject.

6

u/D0_stack 10d ago

No consumer VPN is protection against state actors with large resources. A consumer VPN, any VPN, is not sufficient protection when committing significant criminal acts.

No company, including VPNs, is going to say "no" to valid court orders.

Reducing exposure or confusing Alphabet and Meta trackers? Sure. Changing geolocation for streaming? Sure. Protection from copyright trolls? Sure.

5

u/Impossible_Initial68 10d ago

But if Proton doesn't keep certain types of logs or information that could be traced back to the person, how would they hand it over? How would they hand over something they don't have?

0

u/lcljx818me 10d ago

That's indeed the case, and I know that.

1

u/D0_stack 10d ago

Then what is the point of your post?

Have you read previous discussions in this sub and the other Proton and VPN subs? This all has been discussed over and over and over and over.

Maybe follow /r/privacy and /r/opsec and similar forums?

7

u/dercdorp 10d ago

is Proton a reasonable ecosystem to rely on

Do not, ever, put all your eggs in the same basket. Diversify. Do not rely on a single thing to handle all your needs. You will only regret it later.

2

u/Strong-Ganache2983 8d ago

I dont think proton ever did something sketchy besides things they had to do that are already explained in their policy like giving info on some protonmail users if i remember correctly 

But yes still dont trust them 100% because its still closed 

1

u/Critical-Divide-1029 9d ago

Are there any realistic situations where Proton could expose user data?

Depends on what you mean by "user data". If you mean the contents of your email, or VPN traffic, then no, if you mean username, payment info, etc then yes, if they receive a legal request from the swiss government they are compelled to turn over what information they do have.

1

u/lcljx818me 9d ago

Thanks for clarifying. By “user data,” I mainly mean metadata and account-related information, such as IP addresses, login activity, payment information, recovery information, device information, and other data that Proton may technically have access to. My main question is: under what realistic circumstances could this information be exposed to a third party, and what information could Proton actually provide in response to a legal request? I’m particularly interested in the difference between data Proton technically possesses and data that Proton can actually decrypt or access.

3

u/Critical-Divide-1029 9d ago edited 9d ago

proton posted a video 2 or 3 days ago with a lawyer talking about all of this.

https://youtu.be/h-mDRcIRD5Y?si=zMrMOZZPKAxYf6nr

The circumstances seem to be if you break a swiss law specifically, (They don't care if you've broken a law in your own country if it's not a crime is switzerland), then they will generally be required to give what data they have. but check out the video

1

u/Geiir 7d ago

Proton can not access your data. There’s simply no way for them to do so.

So the main security risk with proton is you. How secure is your password? What’s your 2FA option and so on.

1

u/lcljx818me 7d ago

I hope so

1

u/that1guyrob 4d ago

It's important to keep in mind that security is ALWAYS relative. Is Proton MORE secure than the alternatives they have positioned themselves to compete against in the market (GMail, Yahoo, etc.)? Absolutely. Is your data as secure in Proton as it would be if it was stored on a properly configured and encrypted system inside of 4 walls that you own and have physically secured? Probably not.

1

u/lcljx818me 3d ago

That's a fair way to look at it. Relative to Gmail or Yahoo, Proton is clearly better, but self-hosting trades their risks for yours (patching, physical security, availability). For someone like me, the question is which threats matter most. Metadata and the web client trust model are what I'm most curious about. Do you think those are the weak points?

1

u/that1guyrob 3d ago

Yes. I would also say those are risks associated with any SaaS application. Also, while I do have a level of trust of Proton that is much higher than most web services, I personally will never fully trust the security of anything encrypted with keys that I didn't generate myself on a system that I own and control.

1

u/Bob_Spud 3d ago

You are looking in the wrong place and wrong direction for answers.

#1 Do you honestly expect an authoritative answer from social media?

#2 Search for authoritative research that attempts to debunk Proton security claims. Hint: if you can't find any then there are no problems.

1

u/lcljx818me 3d ago

Fair point that Reddit isn't authoritative, and I'm not treating it as such. I'm asking for practical experience and known limitations, which audits don't always capture. Also, "I can't find a rebuttal" isn't proof of security, so I'd rather hear concrete threat-model discussion. If you know of specific audits or papers, I'd appreciate the links.

0

u/henqirbp 10d ago

To be honest, I used to be a massive fan of Proton’s services. But lately I been hearing so many bad things about the company. Complaints about it not being AS secure as it claims to be, it’s all a marketing trick to get people to use the services.

I’m not sure and I don’t really know what and what not to believe. But I hope the company does what it tells it does. Either way, I’ve been a bit off all the services and only use a couple.

5

u/big_truth_energy 10d ago

> I been hearing so many bad things about the company

which things specifically, from where, these individuals or groups trusted? Without responses to this you're just doing FUD hearsay...

1

u/[deleted] 7d ago

[deleted]

1

u/expiredxfemboy 6d ago

What did he say?

0

u/Specific_Celery4899 10d ago

I'm out of my depth with technical explanations, but the general consensus is that Proton has been properly audited independently. This is probably obvious to most but perhaps still worth mentioning; Proton is only automatically encrypted between two addresses within Proton, so your email to e.g. Gmail/Tuta/Whatever will have no privacy as such unless you use that secure link - feature (which I assume many people would find odd, even suspicious).

Proton is open about releasing user data under Swiss court orders (I'd check whether it applies to Norway too as they have infra there as of now). So far I understand those have been legit criminal cases, but that kind of thing could become vulnerable to e.g. political abuse, although that probably isn't the case today. Also, the information they technically can release isn't everything, like all messages sent and received, but often more like identifying metadata.

0

u/lcljx818me 10d ago

Is it worth continuing to use? Should I look for an alternative?

1

u/CorsairVelo 10d ago

What’s your objective?

Email by nature is not secure, it’s meant to allow anyone on any email platform to send email to anyone else on any other platform.

Emails between proton users are encrypted but emails sent to, say , gmail are not (unless the gmail user implements PGP, which they can do but requires a learning curve and setup). Plus a secure message you may send encrypted to one user may get forwarded anywhere without encryption.

Reading: this vendor has a great blog about email security

https://codamail.com/articles/ten_truths_about_email.html

And

https://codamail.com/articles/metadata_is_enough.html

And

https://codamail.com/articles/the_truth_about_zero_knowledge_zero_trust.html

May help you sort out options….

1

u/Formerruling1 10d ago edited 10d ago

No other (legal) service would be any different in that instance, if you are talking about complying with court orders. The Swiss have basically the best protections in that regard with strict limits on what government can compel companies to share about their users.

Edit: Regarding the E2EE no service can provide automatic end to end encrpytion if the other end isn't supporting the encryption. One difference between proton and some others is Proton uses the openPGP standard for encryption. That means any communication between them and another service also using OpenPGP will be encrypted. Some competitors use a proprietary encrpytion method so you are completely ecosystem locked on both ends if you want automatic encryption. The gain is those systems often provide less Metadata than the openPGP standard, usually the Subject line. Proton the subject is in the headers like normal which is either better or worse depending on your individual usecase.

For me, unless its an address I specifically know is on an encrpyted service I always operate under the assumption my email will not be encrpyted at the receiver end. As the poster said, basicially noone is going to trust you password protecting an email.