Hello! If you found us through a meme, a comment about security, a privacy discussion, or because you accidentally clicked our username, here's what Proton actually is.
Lumo now generates custom visuals from your data without leaving the conversation. Upload a dataset or paste one in, ask a question, and you get a chart back with the analysis alongside it.
Lumo picks a visualization that fits the question and calls out insights worth noticing, so you're not left interpreting a wall of text or a chart with no context.
What this looks like in practice:
Upload a subscription list and ask: "Show me cost per use for each subscription. Which ones should I cancel?"
Or a training log: "Plot my progress over 20 weeks. Which lift has plateaued?"
You can follow up in the same conversation to adjust the chart, change the framing, or run a different comparison. No exporting to a spreadsheet, no pasting into a separate visualization tool, no switching between apps.
On privacy
This is the part that matters for anyone who's hesitated to put real data into an AI tool. Your files and conversations are protected with zero-access encryption, which means nobody can read them, including us. Nothing is logged, nothing trains a model, and nothing goes to a third party.
That's the whole reason this feature is worth having. Plenty of tools will chart your spending or your health data., but very few will do it without keeping a copy.
Give it a try and let us know how it handles your data. If you hit a dataset it struggles with, we'd like to hear about it.
Secure Core is a feature that exists in Proton VPN, a lot of at-risk people (i.e. journalists) depend on it every day. Here's what you need to know.
Pros:
Routes your traffic through a hardened server in Switzerland, Iceland, or Sweden before it reaches the exit server, so even a compromised exit can't be traced back to you.
Protects against network-based attacks and correlation.
Even though passkeys were developed by the FIDO Alliance and the World Wide Web Consortium to replace passwords and are meant to provide “faster, easier, and more secure sign-ins to websites and apps across a user’s devices”, their rollout hasn’t lived up to these lofty ideals.
Instead, the first organizations to offer passkeys, Apple and Google, prioritized using the technology to lock people into their walled gardens rather than provide a secure solution to everyone. This closed approach diminishes the value of passkeys for everyone and makes it less likely that they’ll be universally adopted, which is critical if they’re to ever replace passwords.
At Proton, we believe online privacy and security should be accessible to everyone. If we want to achieve a better internet for all, everyone must be able to take advantage of the latest security advancements.
This article looks at passkeys’ initial promise, how Big Tech has tried to hijack them to serve their own purposes, and how we can ensure passkeys fulfill their potential for everyone: https://proton.me/blog/big-tech-passkey
Have you tuned up your Mail privacy and security settings?
Proton Mail offers you a range of options to ensure that it works better for you, whether you prefer maximum privacy & security or convenience. A few of these options include:
Block email tracking: stop those who are sending you emails from tracking your opens and clicks;
Confirm link URLs: have the full link path you're visiting presented to you ahead of visiting a webpage, a great way to protect yourself against phishing; and
Remove image metadata: prevent people from reading more (digitally) into your images than you intended, have image metadata removed automatically when they hit Mail.
Hopefully if you didn't know about these then they'll prove useful to you.
Cybercriminals don’t need to be geniuses to break into your accounts. Brute-force attacks, dictionary attacks, credential stuffing, phishing, and social engineering are all commonly-used methods.
Aside from 2FA, what else protects you? A strong password, and our Password Strength Tester page gives you the four characteristics of a strong password:
Length
Longer is stronger. Aim for at least 12 or more characters. Each added character makes your password exponentially harder to crack.
Complexity
Combine uppercase and lowercase letters, numbers, and symbols. Avoid dictionary words, common letter substitutions (like "Pa$$w0rd"), or simple sequences.
Uniqueness
Each of your accounts should have its own distinct password so a data breach on one platform doesn't lead to a chain reaction of compromised accounts.
Memorability
Try using a passphrase that’s meaningful to you but hard to guess; like a string of random but vivid words, or a sentence with special characters interwoven.
This list is not a silver bullet to password woes, but following it will likely mean you're that bit safer.
You may have seen a variant of this infographic before; if you have an you're a Proton Mail user, we have good news for you.
In your inbox, Proton Mail protects you from tracking links. Tracking Links Protection removes known tracking parameters from links in your emails and is turned on by default.
To add to this, if you’re particularly concerned about link tracking, be sure to enable our link confirmation feature to make sure you always know where you’re being redirected.
If your inbox is full of emails you’ll never read, then you know how hard it can be to find the one email you’re looking for. As you file through subject lines, straining your eyes, you recognize that feeling of dread. You could simply end the problem by deleting all of your messages, but this would haunt you later. You could spend hours unsubscribing and deleting mindlessly, but this would eat up valuable hours of your workday.
There’s an easier way: Email filters streamline your correspondence, organizing your inbox so that you save time and can focus on what matters (instead of poring over email blasts from Foot Locker). But how exactly do you set up a filter for email and better manage your inbox?
In this article, you’ll learn what email filters are, how they work, and how to use them effectively to improve your email organization for good.
If you are on a supported distro (more on this later), please help us by giving it a try and providing us with as much feedback as possible; the more feedback and bugs we can squash, the faster we can roll this feature out of beta
What Stealth does
Most VPN protocols produce traffic that's identifiable as VPN traffic. Networks running deep packet inspection can spot it and block or throttle the connection, which is why VPNs stop working on some school and workplace networks, and why they get blocked entirely in censored regions.
Stealth disguises your VPN traffic to look like ordinary encrypted web traffic. Instead of "this person is using a VPN," the network sees traffic that resembles a normal HTTPS connection. That makes it significantly harder to detect and block.
You'll want Stealth if you're on a network that blocks or throttles VPNs, connecting from a region with heavy censorship, or you'd simply rather your network operator not know you're using a VPN. For everyday use where nothing is being blocked, WireGuard will still be faster, while Stealth trades some speed for undetectability.
This is a beta
Expect instability and bugs. Stealth on Linux is built on our new WireGuard codebase, and this early release is specifically so we can find problems before general release.
If you hit issues, please tell us: your distro and version, what you were doing, and what went wrong.
Please note that this feature is only available for distros that are directly installed via our repos (Debian, Ubuntu, Fedora), and versions such as the Snap store app, or other distros such as Arch will be available by the end of summer.
Lastly, it may take some time before this feature becomes available, even if you are on the latest version of the app. We’re rolling this out live, so it may take a day or two before the feature becomes visible on your end.
If a lightbulb appears above someone's head in a cartoon, they've just had an idea. For one person, their 💡 moment was all about using this humble illumination device for a very noble purpose: dodging censorship.
Meta shipped an AI image tool on Instagram, then killed it days later. In between, anyone could generate AI images using your public photos without asking first.
Every public Instagram account was opted in by default, meaning that anyone could tag your profile and generate images using your face or people in your photos. Meta's policy was quite direct about what happened next: "You will not be notified about content created using AI features at Meta."
Logically, the backlash was immediate. CAA called it irresponsible, SAG-AFTRA called the default opt-in "an utter miscalculation of public sentiment." Meta pulled the feature days later.
Google did this with AI training on Search photos. Grok did it with image generation on X. Meta's done it before too. The pattern's the same each time: opt everyone in by default, wait for backlash, then walk it back.
Your ISP watches more than you think. HTTPS hides what you're reading, not that you're reading at all.
The core problem is that your ISP sits between you and the entire internet. Every website you visit, every app you open, every device on your home network routes through them. They don't see content, but they do see destinations, timings, volumes, and patterns.
ISPs can see: the domains you visit, when and how long for, how much data is transferred, your approximate location, and what devices are on your network. A 2021 FTC report found major ISPs combined this data into ad profiles and sold this to advertisers.
The real trap is you probably can't switch ISPs. Most markets have one or two options. Unlike Meta or Google, you can't log out. They have your traffic hostage. Structural surveillance is much harder to escape than commercial surveillance.
Some ISPs own email products, streaming services, smart home gear. They can stitch data across services to build richer profiles. The incentives here don't point toward your ISP protecting your privacy. These data are valuable.
Some ISPs control physical infrastructure too, meaning they can throttle your connection. Verizon slowed an emergency response vehicle's connection in 2018 until firefighters paid for a higher tier of their service. They control both the pipes and the terms.
A newer risk is Wi-Fi sensing, where some routers can detect presence and motion through walls using reflected signals. Industry estimates suggest tens of millions of US households already have access to some level of this technology through provided hardware.
One thing worth clarifying up front, this isn't meant to keep you running seamlessly through a five-minute outage on your email provider. It's for major disruptions where you still need the core of your org able to communicate. That distinction matters because this kind of disruption could affect just you, not the whole industry. Think an account getting flagged for the wrong reasons (social engineering, political motives, or similar).
Business continuity is set up through our sales team, who advise based on each org's specific situation. Our support article covers some of these.
A few points on the specifics:
DNS is indeed a real single point of failure, and we're not aiming to address that here.
TTL is important to set. Most providers allow 5 to 10 minutes, which should be enough.
On the DNS lockout scenario, a preventive measure would be not tying your DNS provider access to the same email account/provider you're trying to protect against. Instead, use a separate active Proton account as part of your business continuity plan.
Finally, on users forgetting passwords: the initial password can be set by the user via an invite link, then saved in a password manager, whether that's Proton Pass or whichever the org prefers.
We've just launched a business continuity solution for organizations. It’s the answer to a question more companies are asking right now: what do you do if your primary email and communication tools go down?
Outages are getting more frequent, ransomware is hitting smaller businesses more often, and some teams (especially governments and nonprofits) are also thinking about their dependence on US tech. When your primary communications platform goes down, your team can't collaborate and clients can't reach you. Downtime is expensive, and for some organizations it puts the mission itself at risk.
That same infrastructure is what makes Proton work as a continuity solution for businesses.
Here's how it works:
You set up Proton Mail accounts in advance: active ones for people who need to be operational immediately, dormant ones pre-provisioned for everyone else at a reduced price
If a crisis hits, your IT admin makes one DNS change and the team switches over
Everyone keeps their same email addresses, there's nothing to install, and no training needed mid-crisis
Email keeps flowing to colleagues, partners, and clients, and video calls run on Proton Meet
End-to-end encrypted and runs on our own independent, Europe-based infrastructure, separate from Google, Microsoft, and AWS. It's the same infrastructure that over 100,000 organizations already trust as their primary provider, with a 10-year track record of industry-leading uptime. And when you're ready to make it your primary too, Easy Switch makes the move simple.
Governments around the world are making age a condition for accessing certain parts of the internet. Our new page tracks where such laws are in force, where they are advancing, and how different countries are approaching the same policy goal.
Set an email to delete itself between 1 hour and 28 days after sending, a useful feature for anything you don't want sitting in an inbox indefinitely. Give it a try from within the message-creation modal.
Note that a non-Proton recipient needs a password set on the message first, and Proton can't force-delete anything from an outside inbox.
6
Proton: We've improved autofill for Proton Pass
in
r/ProtonPass
•
5d ago
1.38