I keep hearing bad stuff about proton, but I don’t really get most of it. Could someone please explain all of the controversy to me. Lastly, what are the best alternatives to all of their services?

  • NGC2346@sh.itjust.works
    link
    fedilink
    arrow-up
    5
    arrow-down
    4
    ·
    7 hours ago

    Nothing, people just hold on to the CEO bullshit take on US politics, which was said in early 2025, which is almost 2 years ago at this point.

    Tldr: emotion-driven incels making a scene for a non-issue, but i can understand why bcuz USA republicans are a cancer to the world like Israel.

    • AntiOutsideAktion@lemmy.ml
      link
      fedilink
      English
      arrow-up
      3
      ·
      6 hours ago

      which is almost 2 years ago at this point

      The last time I thought this was a long duration my mom made my lunches for me

      • NGC2346@sh.itjust.works
        link
        fedilink
        arrow-up
        1
        arrow-down
        1
        ·
        2 hours ago

        Valid for certain things, but holding on to things of lesser importance doesnt make you an adult, it makes you resentful

        • I_Has_A_Hat@lemmy.world
          link
          fedilink
          arrow-up
          1
          ·
          1 hour ago

          Ok, but you realize that 2025 was already post-election, and Trump started doing horrible shit from day 1. So if someone supported him in 2025, odds are their opinion hasn’t changed much. Which makes them garbage.

  • Zerush@lemmy.ml
    link
    fedilink
    arrow-up
    5
    arrow-down
    1
    ·
    12 hours ago

    Murena (Mail, Cloud, Workspace, Vault, Galery, Office suite, Tasks, Calendar, Notes, Phones (FairPhone), e/OS, e/Os for kids), OpenSource, encrypted, made in the EU (France)

  • nkk@programming.dev
    link
    fedilink
    arrow-up
    12
    ·
    edit-2
    8 hours ago

    Mail - Tuta Mail

    VPN - IVPN or AirVPN (Never been independently audited but cheaper and has port forwarding)

    Drive - Selfhost Nextcloud or Tuta Drive

    Calendar - Selfhost Nextcloud or Tuta Calendar

    Docs/Sheets - Selfhost Nextcloud or LibreOffice (offline)

    Pass - Bitwarden or KeePassXC (offline)

    Authenticator - 2FA or Aegis (both are offline but that’s a good thing with 2FA)

    Meet - Jitsi

    Lumo - Local AI or Kagi Assistant (paid, comes with privacy-focused search engine) or Duck.ai (free)

      • nkk@programming.dev
        link
        fedilink
        arrow-up
        4
        ·
        8 hours ago

        NymVPN is too new for me to feel comfortable using personally. Also it seems that they worked with Brave which I’m certainly not a fan of.

        I wouldn’t recommend Jottacloud as their privacy policy seems iffy and they don’t have e2ee.

        Filen’s privacy policy seems better, although they do say they do analytics. They do have e2ee though. Definitely much closer to Tuta than Jottacloud.

    • sumsinj@lemmy.world
      link
      fedilink
      arrow-up
      2
      ·
      13 hours ago

      I once saw people also recommend airvpn in the same context as ivpn, do they also have some issues or are they just too unknown?

      • nkk@programming.dev
        link
        fedilink
        arrow-up
        1
        ·
        8 hours ago

        I like IVPN because it feels like a pretty drop-in replacement for Mullvad. It’s also available on Accrescent which is great for anyone using GrapheneOS.

        As for AirVPN, I thought you needed an email to sign up but after checking their sign up page, it seems you can enter whatever string you want for your email.

        They also support port forwarding unlike IVPN so if that’s super important to you maybe AirVPN is the way to go.

        It also seems AirVPN is slightly cheaper year by year and significantly cheaper if you buy 3 years at a time.

        AirVPN has never had an independent security audit though, so if that concerns you IVPN is the way to go.

        Otherwise, it seems like AirVPN is a real contender if you’re worried about price and/or port forwarding. Maybe I’ll give both of them a try before I commit to one (still waiting for my Mullvad days to run out).

  • Ohh@lemmy.ml
    link
    fedilink
    arrow-up
    13
    ·
    23 hours ago

    Yes. There is controversy about the CEO. But mostly for me: is security theater. And in don’t trust them. Email will never work as a secure communication layer. Stop pretending it will. There a reasons which is tied to the protocol level, that make pgp non sufficient. There are also the pgp technology it self (no forward secrecy, no deniability, key management etc). Then there is the obvious fact about an email from proton to gmail, and 99% of other email providers, simply not being secure/encrypted. So you buy a privacy tool, which neglects to tell you: we actually don’t provide privacy at all - unless you treat proton emails as proton chat - strictly proton to proton… at which point youd be better of with e g signal.

    If you insist: mailfence.org allows you to upload and control you own pgp keys. That’s interoprational with proton. Simarly priced i think, also Schweiz, and a bit more honest and strict imap (no bridge). But honestly… stop treating email as secure.

      • M1k3y@discuss.tchncs.de
        link
        fedilink
        arrow-up
        8
        arrow-down
        1
        ·
        20 hours ago

        Its crypto from the 90s and email is not meant to be secure. Some examples:

        Only the mail body is protected, headers and metadata arent, so an attacker still knows with who you are talking about what.

        Replies contain the full thread, if one person messes up once, the entire chain is unencrypted.

        No ephemeral keys, no cleanly defined rotation mechanism. If someone gets your key, all past messages are also accessible.

        • jabberwock@lemmy.dbzer0.com
          link
          fedilink
          arrow-up
          5
          ·
          18 hours ago

          It depends on your threat model. The actual crypto portion of it holds up, at least until we have crypto-relevant quantum computers.

          If you want anonymization and PFS for basic messaging, yeah PGP + email isn’t going to cut it. But if you’re sending documents, for example, with financial or health data tied to my identity anyway, I’d take PGP with my own email provider over TLS to some tech company servers where it sits unencrypted any day.

        • manuallybreathing@lemmy.ml
          link
          fedilink
          arrow-up
          3
          arrow-down
          1
          ·
          18 hours ago

          so an attacker still knows with who you are talking about what.

          implying i fill out the subject box with anything meaningful 🤪

        • bleustenns@lemmy.ml
          link
          fedilink
          arrow-up
          1
          ·
          20 hours ago

          TY for informing me. Is there a better alternative to PGP even with the other downsides of email you listed?

      • bedwyr@piefed.ca
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        10 hours ago

        There are internet blacklists, several dozen, purportedly for scammers, and Israel is dropping their critics on them, and proton takes it at face value, with no appeal option.

        Plus the US gave them lists of accounts to deleted and they did. They are bitches.

  • PierceTheBubble@lemmy.ml
    link
    fedilink
    arrow-up
    30
    arrow-down
    5
    ·
    edit-2
    1 day ago

    For me it’s their ransomware-like business model of: attracting new users with free accounts, incentivizing them to migrate their Gmail inbox to Proton (Easy Switch), encrypting the content (“for security”), and then letting them find out that a paid feature (Bridge) is necessary to integrate the mailbox into a third-party client like Thunderbird (as a decryption layer in between); well, unless you want to manually export the mailbox using their Mail Export Tool. I’m not opposed to paying for a service (I also donate to Disroot), but I dropped them like a hot brick when I found out: thankfully not the hard way (I tested integration before migration).

  • cerement@slrpnk.net
    link
    fedilink
    arrow-up
    52
    arrow-down
    4
    ·
    1 day ago

    Andy Yen

    Known for: Proton founder (ProtonMail, Proton VPN, etc)

    Proton claims to be politically neutral, but in early 2025 Andy praised the Republican party on X, and Proton issued an “official response” on Mastodon and Reddit (later deleted as “not actually official”) re-enforcing that Proton and/or Andy threw their hat in with Trump and the Republican party.

    —Weird Little Guys

    Current best alternative if you want to stay in the cloud: Tuta

  • LewdLemon@sh.itjust.works
    link
    fedilink
    arrow-up
    30
    arrow-down
    2
    ·
    1 day ago

    I’ll keep it short, but provide links for further reading. First off, I don’t think proton is “bad”, or anyone is trash-talking them legitimately. Both their jurisdiction (Switzerland), dedication to FOSS and good audit results make them a solid choice.

    Diversification is my main reason why I’d never go all-in on Proton. Over the years, they’ve grown an ever more complete suite of apps (e-mail, calendar, VPN, password manager, docs, AI) that does share some similarity with the Google app suite in that you’re essentially putting all eggs in one company’s basket - and a lot of trust with that. If Proton got hacked, got subverted by a three-letter agency, or just got taken advantage of by a rogue employee, the effects would be much more impactful than if it had just been your e-mail provider, just your VPN service, just your…

    Also, Proton’s official social media account echoing CEO Andy Yen’s private statements on U.S. politics haven’t helped convince people that the company is, indeed, politically neutral and solely focused on privacy.

    • NamelessDeity@lemmy.ml
      link
      fedilink
      English
      arrow-up
      1
      ·
      7 hours ago

      would self hosting be the way to go then in this case? also how good is using proton solely for mail and vpn? or should i diversify more?

    • nfreak@lemmy.ml
      link
      fedilink
      English
      arrow-up
      11
      arrow-down
      1
      ·
      1 day ago

      This sums it up well. Their products are fine, but putting everything into one company isn’t a good idea, and the political statements leave little faith.

      I use their free Drive for sharing files, but I’ve moved to Tuta for email and just about everything else selfhosted. I’m still running out a mullvad subscription but I’ll be switching that to IVPN when it expires.

      • LewdLemon@sh.itjust.works
        link
        fedilink
        arrow-up
        10
        ·
        1 day ago

        I’m still running out a mullvad subscription but I’ll be switching that to IVPN when it expires.

        I’m in the same boat: still on Mullvad, but eager to switch due to… things. May I ask what your main reason is to consider IVPN above all others? I’m still stuck choosing between IVPN, Proton and Nym.

        • nfreak@lemmy.ml
          link
          fedilink
          English
          arrow-up
          3
          ·
          1 day ago

          It just seemed like the most similar choice that meets my needs. I looked at some of the other options - I’d go with Proton if it weren’t for the issues mentioned, I used them for a bit and the service works very well. Nym seemed interesting, but I don’t believe they offer Wireguard configs? I could be wrong.

          • LewdLemon@sh.itjust.works
            link
            fedilink
            arrow-up
            3
            ·
            1 day ago

            It [IVPN] just seemed like the most similar choice

            A lot of things are similar indeed, with one essential difference: the raid on Mullvad did prove their no-logs policy was no bullshit. I haven’t found anything similar on IVPN.

            Nym seemed interesting, but I don’t believe they offer Wireguard configs?

            Good call, they don’t. When is that relevant, though? When you want to connect a headless machine, such as a server?

            • Em Adespoton@lemmy.ca
              link
              fedilink
              arrow-up
              5
              ·
              1 day ago

              Wireguard is generally fast and secure. All the other transport options fail on at least one of those (OpenVPN is secure and slow, L2TP is slow and insecure, IPSec and IKEv2 are less secure and brittle).

              Essentially, the one downside to Wireguard is prevalence. So if you can find somewhere trustworthy that it IS an option, why not?

              That said, I do wonder why more people don’t turn to global Tailscale networks and bypass central control. Of course, you DO need some way to establish trust for your Tailscale network.

              If you’re willing to pay though, why not just spin up a VPS somewhere and run Tailscale on it? You control the logging, Your exit node is on a trusted netblock, and you can connect whatever you want to it over Wireguard.

              • milbyte@lemmy.ml
                link
                fedilink
                arrow-up
                2
                ·
                15 hours ago

                If you’re willing to pay though, why not just spin up a VPS somewhere and run Tailscale on it?

                It is some effort to set up, and VPS seems generally more expensive than a commercial VPN which has more nodes and other extra things. You’re moving your location which is cool, but multiple people use VPN nodes which serves as a mask because you can’t differentiate what traffic belongs to which user; You’re also still trusting whoever you rent your VPS from that they haven’t set up some sort of monitoring on a higher level before tailscale running on the machine can encrypt traffic.

  • Pirate2377@lemmy.zip
    link
    fedilink
    English
    arrow-up
    16
    ·
    edit-2
    1 day ago

    From what I understand, Proton’s CEO has polarizing opinions to put it lightly. There’s other controversies than that, but that seems to be the main point of contention now in days.

    As for alternatives, you have 3. Tutanota, Mailbox.org, or using mainstream options and manually using OpenGPG encryption yourself.

    • Yeah, you can also host your own mail server or VPS and FDE (full disk encryption) the whole thing, which i have for some stuff, but generally it’s not great because cloud hosting service ip blocks are usually marked very low reputation by general mail providers, so your legitimate emails are very likely to go to spam even if you have spf, dkim, and the like all set up.

      Important to note, just like proton mail or competitors though, full disk encryption prevents anyone from getting into your mail, but it does not shield messages you send. For that you need something like openpgp to encrypt actual email content, like you said.

  • GreatWhiteBuffalo41@slrpnk.net
    link
    fedilink
    English
    arrow-up
    11
    arrow-down
    2
    ·
    1 day ago

    This is my personal opinion and only that, my opinion. If your options are proton or Google, proton. If you have the ability, technical ability (in some cases), and mental bandwidth to diversify those services, that’s even better. And if you want to securely and properly self host your own options that match your specific threat level, that’s the best.

    I personally use paid proton for my email. I occasionally use the free VPN, and I have several things in their drive as a backup to my backup of my backup. I personally would not put all my eggs in the proton basket because I did that in the past with Google and if we’re ignoring the privacy portion, they have discontinued so many things over the years that I learned not to put ALL my faith in ONE company.

    Edit to add, I also didn’t even touch the CEO thing but I see several others have. If we account for that, I’d still say it’s significantly better than Google.