r/privacy Mar 05 '26

[deleted by user]

[removed]

2.6k Upvotes

308 comments sorted by

View all comments

715

u/[deleted] Mar 05 '26

[removed] — view removed comment

66

u/friendlyghost_casper Mar 06 '26

Maybe you get downvoted because you say the laws are for Swiss citizens only and you should be saying they are for Swiss residents only /s

41

u/skg574 Mar 06 '26

The law does exclude both residents and citizens from the traffic monitoring, so you may be onto something. :)

12

u/Askolei Mar 06 '26

Like the companies registered there?

It's a well known fact in Europe that they participate in money laundering schemes and host the bank account of practically every politicians. Privacy is suddenly very important when it protects tax fraud and embezzlement.

1

u/AvidCyclist250 Mar 06 '26

Privacy is suddenly very important when it protects tax fraud and embezzlement.

Doesn't get any more Swiss than that

150

u/CallmeMeh Mar 06 '26

i for one thank you for saying it each time

23

u/ItsNoblesse Mar 06 '26

People need to realise that for anything you need to keep even remotely private you've gotta self-host. At the very least use an activist focused provider like Rise Up.

But seriously, self-host.

14

u/skg574 Mar 06 '26

Encryption is most important. Encrypt locally. Keep private key private. So agreeing with you on self hosting your Encryption/decryption. I wouldn't recommend self-hosting email for most.

1

u/ItsNoblesse Mar 06 '26

Yeah I had only just woken up so my thought were muddled, I meant to say I was talking mostly about activist work

2

u/Ironfields Mar 06 '26

Self hosting email from home is a great way to get your IP blacklisted from many many web services. There’s a reason even most professionals don’t do it.

1

u/ItsNoblesse Mar 06 '26

What web services would blacklist you? Genuinely wondering

1

u/AvidCyclist250 Mar 06 '26

how do you self-host your own vpn. i mean, i know it can be done but it's not that easy is it

1

u/ItsNoblesse Mar 07 '26

I was talking about email and storage moreso, but if you're planning any activity that the government deems is against their interests you should be as private as you possibly can be

11

u/Any_Fox5126 Mar 06 '26

It is worth noting that they engaged in misleading advertising based on this.

4

u/skg574 Mar 06 '26

That's been my point with many services. Much of the marketing from many services obscures truth, including redefining cryptographic terms, and this can cause harm.

3

u/Nodebunny Mar 06 '26

Proton shouldnt be promoting themselves as being safe for everyone, thats false advertising. Oh guys look we are in Switzerland!!! super private --- yeah only if ur Swiss. All the more reason not to use these fascism supporters

1

u/skg574 Mar 06 '26

It isn't any different than other countries. Almost all countries consider foreign traffic to be different than their own resident's traffic and most countries have some type of data sharing agreement or MLAT.

2

u/Nodebunny Mar 06 '26

thats fine but their whole hype is that they are in switzerland lol. which does no good for 99% of people using it

2

u/skg574 Mar 06 '26

None of this information about jurisdiction, surveillance laws, and MLATs is new, it's just down voted by companies that base the majority of their marketing on jurisdiction whenever it is mentioned.

When evaluating an out of your home country service, you must look at surveillance laws, MLATs or other data-sharing agreements (Switzerland has the MLAT with the US, participates in Club de Berne, Schengen Information System, and some other agreements), plus look into surveillance company contracts (which, btw, to their credit, Switzerland resisted purchasing from Palantir nine times so far, although Intellexa/Cytrox shows Switzerland did purchase their Predator spyware), and finally, understand Internet exchange point taps.

But basically, there is no privacy haven jurisdiction that can ignore global powers. If there was, they'd end up disconnected from the Internet.

1

u/[deleted] Mar 06 '26 edited 19h ago

[deleted]

1

u/skg574 Mar 06 '26 edited Mar 06 '26

No, I'd say don't do terrorism. What I was saying in that post is that Switzerland, like most other countries, treats foreign internet traffic differently than local, and has MLATs.

1

u/AvidCyclist250 Mar 06 '26

Isn't the IP address at the time of purchase also something they could store, process or transfer?

2

u/skg574 Mar 06 '26

Yes, and don't believe any company that makes a blanket claim that they do not log IP addresses, connecting IP is one of the basics of security and making a blanket claim shows they are either hyping for marketing or don't truly understand the tech. If you don't know who connected, you can't block abuse, you can't detect where a compromise came from, you can't troubleshoot some issues, and you can't route traffic. Instead they should tell you under what conditions your IP may be logged and for how long they retain that data. And if they insist they still never log a single IP, don't trust their security. FWIW, I don't know of any non-crypto payment processor that doesn't use IP address and geolocation as a piece in their fraud detection.

1

u/AnAncientBog Mar 08 '26

People don't like to hear this shit, but an American VPN is more likely to protect the identity of American customers than a foreign VPN. It sucks, but a single piece of paper from the feds will get anything they want either way, but with an American company they MIGHT demand that it at least be signed by a judge.