• RBG@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    128
    arrow-down
    2
    ·
    8 months ago

    They provided the backup e-mail address

    Upon receiving the recovery email from Proton Mail, Spanish authorities further requested Apple to provide additional details linked to that email, leading to the identification of the individual.

    Just in case anyone thinks they decrypted mails and handed them over, nope. I hadn’t thought about that “settings” are not encrypted. Guess if you want to stay anonymous you shouldn’t add your private mail address in there as a backup.

      • BlushedPotatoPlayers@sopuli.xyz
        link
        fedilink
        English
        arrow-up
        7
        ·
        8 months ago

        But what do you do if that field is needed? A throwaway address won’t work as it’s easy to recreate. Buy your own domain and run a server?

          • shortwavesurfer@monero.town
            link
            fedilink
            English
            arrow-up
            5
            ·
            8 months ago

            It wasn’t a requirement when I signed up several years ago, and to my knowledge, it’s still not required now. Just as long as you keep your email and password in something like a password manager and don’t fuck it up, you’re fine.

        • /home/pineapplelover@lemm.ee
          link
          fedilink
          English
          arrow-up
          10
          ·
          8 months ago

          I put the Simplelogin email alias as my backup mail. Which forwards mail to my proton, so I guess it isn’t really a backup. Even more so if you realize I need to sign into simplelogin with my protonmail account and protonmail owns Simplelogin.

        • Scrollone
          link
          fedilink
          English
          arrow-up
          8
          ·
          8 months ago

          No, domain names are tied to a person and, even if that person register the domain with fake person details, there will be a digital payment associated with the purchase.

            • asdfasdfasdf@lemmy.world
              link
              fedilink
              English
              arrow-up
              6
              ·
              8 months ago

              Which also isn’t private. In fact, it’s the opposite of private since it’s a public blockchain.

              • EngineerGaming@feddit.nl
                link
                fedilink
                English
                arrow-up
                1
                ·
                edit-2
                8 months ago

                Yes, I am aware. But nonetheless it is far easier to use anonymously/pseudonymously than “traditional” payment. Like, exchanging BTC/LTC from Monero, and buying said Monero via a non-kyc method as well. And whatever protections you want to layer, depending on how much effort you think “they” would spend on you.

        • WaliBoi@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          8 months ago

          Proton doesn’t require recovery. But if you want recovery without email addresses, there’re multiple different ways from recovery phases to recovery phone number to even an encrypted recovery file you download onto a local device.