I keep hearing bad stuff about proton, but I don’t really get most of it. Could someone please explain all of the controversy to me. Lastly, what are the best alternatives to all of their services?

  • LewdLemon@sh.itjust.works
    link
    fedilink
    arrow-up
    33
    arrow-down
    2
    ·
    2 days ago

    I’ll keep it short, but provide links for further reading. First off, I don’t think proton is “bad”, or anyone is trash-talking them legitimately. Both their jurisdiction (Switzerland), dedication to FOSS and good audit results make them a solid choice.

    Diversification is my main reason why I’d never go all-in on Proton. Over the years, they’ve grown an ever more complete suite of apps (e-mail, calendar, VPN, password manager, docs, AI) that does share some similarity with the Google app suite in that you’re essentially putting all eggs in one company’s basket - and a lot of trust with that. If Proton got hacked, got subverted by a three-letter agency, or just got taken advantage of by a rogue employee, the effects would be much more impactful than if it had just been your e-mail provider, just your VPN service, just your…

    Also, Proton’s official social media account echoing CEO Andy Yen’s private statements on U.S. politics haven’t helped convince people that the company is, indeed, politically neutral and solely focused on privacy.

    • NamelessDeity@lemmy.ml
      link
      fedilink
      English
      arrow-up
      1
      ·
      14 hours ago

      would self hosting be the way to go then in this case? also how good is using proton solely for mail and vpn? or should i diversify more?

      • LewdLemon@sh.itjust.works
        link
        fedilink
        arrow-up
        1
        ·
        5 hours ago

        would self hosting be the way to go then in this case?

        Absolutely. 👍 Running your own Nextcloud (+ calendar + contacts addons, + office if you like) gives you most of what Proton has to offer: docs/filehosting, calendar and contact sync (via calDAV/cardDAV). You can even tack on notes, photos, a password manager and more if you like, although I think there are better specialised tools for each of these. (For me, that’d be Joplin, immich and keepass + Syncthing.)

        also how good is using proton solely for mail and vpn? or should i diversify more?

        Personally, I would always separate my e-mail provider (which is prime real estate for identifying me personally) from my VPN (which is supposed to make me harder to identify). Whether that’s true for you (and worth the little bit of extra cost) is up to you.

    • nfreak@lemmy.ml
      link
      fedilink
      English
      arrow-up
      11
      arrow-down
      1
      ·
      2 days ago

      This sums it up well. Their products are fine, but putting everything into one company isn’t a good idea, and the political statements leave little faith.

      I use their free Drive for sharing files, but I’ve moved to Tuta for email and just about everything else selfhosted. I’m still running out a mullvad subscription but I’ll be switching that to IVPN when it expires.

      • LewdLemon@sh.itjust.works
        link
        fedilink
        arrow-up
        10
        ·
        2 days ago

        I’m still running out a mullvad subscription but I’ll be switching that to IVPN when it expires.

        I’m in the same boat: still on Mullvad, but eager to switch due to… things. May I ask what your main reason is to consider IVPN above all others? I’m still stuck choosing between IVPN, Proton and Nym.

          • LewdLemon@sh.itjust.works
            link
            fedilink
            arrow-up
            2
            arrow-down
            1
            ·
            5 hours ago

            If the CEO of a privacy company supports political forces that are deeply anti-liberty and anti-privacy, that does constitute a “need” to switch, don’t you think?

            • sompreno@lemmy.zip
              link
              fedilink
              English
              arrow-up
              1
              ·
              1 hour ago

              I don’t see how a ceo’s opinion matters if it does not impact the product. mullvad has the best privacy track record or any VPN I’ve looked into and is a better deal overall the ivpn in cost for what you get.

        • nfreak@lemmy.ml
          link
          fedilink
          English
          arrow-up
          3
          ·
          2 days ago

          It just seemed like the most similar choice that meets my needs. I looked at some of the other options - I’d go with Proton if it weren’t for the issues mentioned, I used them for a bit and the service works very well. Nym seemed interesting, but I don’t believe they offer Wireguard configs? I could be wrong.

          • LewdLemon@sh.itjust.works
            link
            fedilink
            arrow-up
            4
            ·
            2 days ago

            It [IVPN] just seemed like the most similar choice

            A lot of things are similar indeed, with one essential difference: the raid on Mullvad did prove their no-logs policy was no bullshit. I haven’t found anything similar on IVPN.

            Nym seemed interesting, but I don’t believe they offer Wireguard configs?

            Good call, they don’t. When is that relevant, though? When you want to connect a headless machine, such as a server?

            • Em Adespoton@lemmy.ca
              link
              fedilink
              arrow-up
              5
              ·
              2 days ago

              Wireguard is generally fast and secure. All the other transport options fail on at least one of those (OpenVPN is secure and slow, L2TP is slow and insecure, IPSec and IKEv2 are less secure and brittle).

              Essentially, the one downside to Wireguard is prevalence. So if you can find somewhere trustworthy that it IS an option, why not?

              That said, I do wonder why more people don’t turn to global Tailscale networks and bypass central control. Of course, you DO need some way to establish trust for your Tailscale network.

              If you’re willing to pay though, why not just spin up a VPS somewhere and run Tailscale on it? You control the logging, Your exit node is on a trusted netblock, and you can connect whatever you want to it over Wireguard.

              • milbyte@lemmy.ml
                link
                fedilink
                arrow-up
                2
                ·
                23 hours ago

                If you’re willing to pay though, why not just spin up a VPS somewhere and run Tailscale on it?

                It is some effort to set up, and VPS seems generally more expensive than a commercial VPN which has more nodes and other extra things. You’re moving your location which is cool, but multiple people use VPN nodes which serves as a mask because you can’t differentiate what traffic belongs to which user; You’re also still trusting whoever you rent your VPS from that they haven’t set up some sort of monitoring on a higher level before tailscale running on the machine can encrypt traffic.