Is Proton Mail Really Private, Secure, and Anonymous?

Поділитися
Вставка
  • Опубліковано 14 лип 2024
  • In this video I tackle the topic of whether or not Proton mail is Really Private, Secure, and Anonymous
    Privacy Watchdogs article about Proton mail being a honey pot which covers some of the issues in this video in more details, plus other things I didn't talk about
    ₿💰💵💲Help Support the Channel by Donating Crypto💲💵💰₿
    Monero
    45F2bNHVcRzXVBsvZ5giyvKGAgm6LFhMsjUUVPTEtdgJJ5SNyxzSNUmFSBR5qCCWLpjiUjYMkmZoX9b3cChNjvxR7kvh436
    Bitcoin
    3MMKHXPQrGHEsmdHaAGD59FWhKFGeUsAxV
    Ethereum
    0xeA4DA3F9BAb091Eb86921CA6E41712438f4E5079
    Litecoin
    MBfrxLJMuw26hbVi2MjCVDFkkExz8rYvUF
    Dash
    Xh9PXPEy5RoLJgFDGYCDjrbXdjshMaYerz
    Zcash
    t1aWtU5SBpxuUWBSwDKy4gTkT2T1ZwtFvrr
    Chainlink
    0x0f7f21D267d2C9dbae17fd8c20012eFEA3678F14
    Bitcoin Cash
    qz2st00dtu9e79zrq5wshsgaxsjw299n7c69th8ryp
    Etherum Classic
    0xeA641e59913960f578ad39A6B4d02051A5556BfC
    USD Coin
    0x0B045f743A693b225630862a3464B52fefE79FdB
    Subscribe to my UA-cam channel goo.gl/9U10Wz
    and be sure to click that notification bell so you know when new videos are released.
  • Наука та технологія

КОМЕНТАРІ • 1 тис.

  • @N.S.A.
    @N.S.A. 3 роки тому +5341

    I use it. It's fast and secure.

    • @jorionedwards
      @jorionedwards 3 роки тому +549

      Seems sus.

    • @MentalOutlaw
      @MentalOutlaw  3 роки тому +4216

      Thank you for the clarification, I'll be deleting the video now to replenish my social credit score.

    • @looweegee252
      @looweegee252 3 роки тому +373

      @@MentalOutlaw lol it's going on your PERMANENT RECORD

    • @rabywastaken
      @rabywastaken 3 роки тому +78

      that's hilarious lmao

    • @N.S.A.
      @N.S.A. 3 роки тому +203

      @@MentalOutlaw As long as you understand.

  • @nothingiseverperfect
    @nothingiseverperfect 3 роки тому +1598

    *Looks at my carrier pigeon:*
    “You hear that little guy? I made the right choice!”

    • @nicholasbrooks7349
      @nicholasbrooks7349 3 роки тому +61

      What if the feds shoot it down? , ever thought about that!

    • @kashmirwillwin3124
      @kashmirwillwin3124 3 роки тому +99

      @@nicholasbrooks7349 And what if the birds being a government spy drones conspiracy theory is true. Time to learn telepathy

    • @GatoCoder
      @GatoCoder 3 роки тому +6

      @Mialisus I don't see why the choice is that bad in pfp

    • @franchufranchu119
      @franchufranchu119 3 роки тому +1

      Save-or Deez nuts lmao

    • @felipedaiber2991
      @felipedaiber2991 3 роки тому +5

      Me with a shotgun: no you didnt

  • @WahrerKuroKiba
    @WahrerKuroKiba 3 роки тому +1930

    Me: switches to Protonmail
    Kenny:

    • @xeome5596
      @xeome5596 3 роки тому +63

      exactly

    • @dadecountyboos
      @dadecountyboos 3 роки тому +29

      same

    • @daringcuteseal
      @daringcuteseal 3 роки тому +4

      lol

    • @grumpyspoder
      @grumpyspoder 3 роки тому +75

      same lol made the switch a week ago and then he decides to drop this lol

    • @bat4
      @bat4 3 роки тому +3

      @@grumpyspoder Yeah, ua-cam.com/video/Q30swyxHY0w/v-deo.html

  • @ghollisjr
    @ghollisjr 3 роки тому +1563

    If you want something done right, you gotta do it yourself. --The Feds.

  • @hedgeearthridge6807
    @hedgeearthridge6807 3 роки тому +1503

    Hopefully in the future we can completely re-invent email, with an open-source protocol that does center on privacy (and isn't a complete pain in the ass to use), because what we currently have is extremely outdated. The hardest part would be getting normies to accept it, and of course big tech wouldn't like it because they thrive on getting to process your emails for advertising data.

    • @Cookiekeks
      @Cookiekeks 3 роки тому +18

      Why is the email protocol outdated? Just curious to know.

    • @greenl7661
      @greenl7661 3 роки тому +25

      Zk proofs do that. No incentives for migration sadly

    • @wheezybackports6444
      @wheezybackports6444 3 роки тому +10

      OpenSMTP

    • @r05ejan8
      @r05ejan8 3 роки тому +98

      ​@@Cookiekeks Like the Big Man said... among other things... the inter-domain transfer protocols for email are incompatible with any sort of encryption... even if you go through the effort to PGP encrypt the body of your email... the header which includes info such as IP addresses and email addresses of the sender and receiver are in plaintext for ALL to see.... this stuff was standardized LONG ago when nobody cared about encryption... things have changed and for good reasons encryption is standard for many fundamental services we use everyday..... email is a leftover of times bygone.... much to our detriment.

    • @jan_harald
      @jan_harald 3 роки тому +32

      email works perfectly well for what it was invented for, just like regular mail... and the hardest part is not only getting people to switch, but also getting half a century worth of programs to ALSO switch... there's a *LOT* of mail integrations going around...
      not to mention it's easy to just use something like gpg or s/mime to establish secure connections (and you can secure even metadata if the other side knows how to decrypt it, which isn't standard), so instead of "fixing" the protocol with something that will probably take 5 years to stabilize in the first place (c'mon, rust doesn't even have a spec, while being all the rage, and Go's moving at a pretty fast pace, also, just to name a few "modern" things), instead the effort should be focused on overlaying on top of it, and making the secure layer as easy to use as possible, so instead of "go run this command to generate keys and then make an email subkey and then download that extention to your mail client, and then tell it to use that subkey and then figure out the recipient's key" etc it would instead automatically generate you a key and publish it somewhere (possibly on a regular keyserver), and automatically fetch the recipient's key based on their email with the user merely needing to press a button, if even that, and to back up their key (doable automatically, but everyone shouldn't send their private keys to any singular location, so would need additional questions about that)

  • @MrYAMAHA32177
    @MrYAMAHA32177 2 роки тому +519

    I have developed, (through mainline breeds) a new hybrid carrier pigeon for inner city communication within a 40 mile radius. Should be rolling out the first adults by the end of the second quarter and very excited with the testing so far.

    • @heidiho7314
      @heidiho7314 2 роки тому +34

      Finally! Fully compliant with RFC 1149, I assume?

    • @sirpretzel822
      @sirpretzel822 2 роки тому +36

      Are there any plans on making the genetic sequence open source?

    • @harrygarry2637
      @harrygarry2637 2 роки тому +20

      @@heidiho7314 government already has robot birds for this exact reason.
      Minus 70 social credit points

    • @johnarnold893
      @johnarnold893 Рік тому

      🤣🤣🤣🤣🤣

    • @frwystr
      @frwystr Рік тому

      bro let’s get one pigeon and maybe a uhhhhh chicken?

  • @Crypdography
    @Crypdography 3 роки тому +324

    Pro-tip:
    If you need to encrypt a message do it yourself.

    • @cahallo5964
      @cahallo5964 2 роки тому +7

      how would the other end get the key if communication is only through the internet

    • @Gurkewasser22
      @Gurkewasser22 2 роки тому +52

      @@cahallo5964 guess

    • @cahallo5964
      @cahallo5964 2 роки тому +9

      @@Gurkewasser22 that makes no fucking sense

    • @Gurkewasser22
      @Gurkewasser22 2 роки тому +47

      Day 8455 explaining jokes to strangers

    • @cahallo5964
      @cahallo5964 2 роки тому +23

      @@Gurkewasser22 I have autism you have to explain the joke to me so I can steal it and tell it in several diferent places until it stops being funny to me

  • @wclifton968gameplaystutorials
    @wclifton968gameplaystutorials 3 роки тому +503

    If they really wanted privacy or security then they should've opened up shop in Liechtenstien since they don't work with the US Government or the Chinese Government unlike the Swiss government which works with both

    • @steffeneilers8530
      @steffeneilers8530 3 роки тому +43

      Liechtenstien is probably too small for that, don't they follow the Swiss in most decisions? Also, I find this thing of thinking that countries won't bend over for Uncle Sam so dumb. It's understandable from their perspectives.

    • @nootics
      @nootics 3 роки тому +69

      @@steffeneilers8530 i like to call liechtenstein the 27th canton ("state") of Switzerland that likes to act as their own monarchy lmao

    • @lennykump8396
      @lennykump8396 3 роки тому +25

      Tutanota didn't give personal information of their customers away even though a court of the FRG tried to force them to. That's not a good point in my opinion. Also Liechtenstein probably doesn't care about some Chinese company just because the company could gain something from it.

    • @survivor303
      @survivor303 3 роки тому +24

      The swiss thing with their laws was a real thing back in the 90's. Now they are as corrupted as everyone else :)

    • @MrEdrftgyuji
      @MrEdrftgyuji 3 роки тому +7

      They also work closely with the EU, despite not being a EU member.

  • @asosa9502
    @asosa9502 3 роки тому +652

    I use Proton Mail and I don't really care if it's a honeypot. My reason for switching to Proton Mail is that I didn't want Google having all of my emails. The feds are going to have my emails whether I'm on gmail or on Proton Mail, so I might as well make sure Google doesn't have them too. And yes, I did consider self-hosting, but self-hosted emails are blocked by a large number of email providers because they are a huge source of spam. Just assume that everything you do over email is completely public and you'll be fine.

    • @Nash_Nismo
      @Nash_Nismo 2 роки тому +79

      Yep, screw Google

    • @companymen42
      @companymen42 2 роки тому +4

      Yea its kinda like the government is the devil you know vs corporations are the devil you dont.

    • @fearsomefoursome4
      @fearsomefoursome4 2 роки тому +6

      @@computerdores You mean the data that google gives the NSA willy nilly even without the rubber stamp of FISA courts. Did you not watch snowden?

    • @AR15ORIGINAL
      @AR15ORIGINAL 2 роки тому

      @@computerdores If your threat model includes feds, you shouldn't use email at all. We're talking STRICTLY about corporate tracking on this context.
      Also, google literally cooperated with the feds in the past. In all likelihood, they are already secretly sharing the plaintext contents of everybody's gmails. Why pretend otherwise?

    • @jorgesandoval4602
      @jorgesandoval4602 Рік тому +9

      Agreed, I'll do it exactly for the same reason

  • @coffeebean4529
    @coffeebean4529 3 роки тому +311

    I swear to God, it's like you're in my head. I was litteraly thinking about this yesterday.

    • @shadowbannedneet
      @shadowbannedneet 3 роки тому +9

      maybe he is

    • @8w73
      @8w73 3 роки тому +55

      take your meds

    • @ungureanucalin3293
      @ungureanucalin3293 3 роки тому +3

      BRUH I WAS THINKING ABOUT THE SAME THING 2 DAYS AGO

    • @geestwagen4614
      @geestwagen4614 3 роки тому +2

      Same bro. Yesterday, the radio was
      talking to me

    • @DenartMeyer
      @DenartMeyer 3 роки тому

      Didn’t he lowkey take a jab at protonmail in one of his other videos?

  • @ns-yz1hj
    @ns-yz1hj 3 роки тому +56

    *sadly looks at protonmail account
    "You aren't who I thought you were..."

  • @skeilnet
    @skeilnet 3 роки тому +198

    The thing is Proton mail is not designed for this level of security, it still need to comply with Swiss law. As always you’re never better served than by yourself. There is no easy route.

    • @bennihtm
      @bennihtm 3 роки тому +14

      Does Swiss law state, that they have to de-anonymize Tor traffic?

    • @electric26
      @electric26 5 місяців тому +1

      ​@@bennihtm redirecting to a clearnet site doesn't de-anonymize Tor users unless the government or entity(s) you're attempting to remain anonymous to run the exit node being used. It is pretty much just a benefit for servers unless you're at a high enough threat levels for governments to contact each other/collaborate.
      TLDR: it's probably good enough for most users.
      P.S. they don't redirect to the clearnet version anymore (you can do everything through Tor as far as I can tell)

  • @sgill4833
    @sgill4833 3 роки тому +69

    Very eye opening, all emails are essentially insecure.

    • @anneonymous4884
      @anneonymous4884 Рік тому +11

      Oddly enough, the only secure way to send messages is probably physical mail.

    • @Normal_Boii
      @Normal_Boii Рік тому +4

      Carrier pidgeon it is, then

  • @Marco-yk8kp
    @Marco-yk8kp 3 роки тому +353

    Day 5 of asking Kenny to make a video on "Mozzilla is made by the feds" situation.

    • @Jorgeee
      @Jorgeee 3 роки тому +49

      He won’t do that video because Mozilla is obviously not made by the feds.

    • @jan_harald
      @jan_harald 3 роки тому +50

      "made by"...yeah...totally...
      just like chrome isn't made by the feds, but a company which is very willingly handing over data, and also loves to get ALL the data it can out of everyone...
      mozilla's on real rough times due to chrome monopoly, and are 1) doing just telemetry, which is disable-able (just use a fork like idk, GNU IceCat, if you're paranoid, lol) and 2) trying to appeal to as many people as they can to attempt to make more normies use it (believe it or not, you can't really live a company off of purely linux geeks who use your software for free), which explains why they're changing the UI, and why they're moving along with chrome's extentions and ideas
      and other than firefox, they can't even afford any long-living projects, FirefoxOS was a great idea, only to be killed and turned proprietary by KaiOS, while ChromeOS is still a thing, and only non-browser things they have are lockwise (pretty much just standalone version of the password manager in the browser, for phones, so not that significant) and thunderbird, which actually has a surprisingly considerable amount of "web browser" as part of it, iirc...

    • @vijaysridhar351
      @vijaysridhar351 3 роки тому +3

      What about brave ??

    • @IWILL360URMOM
      @IWILL360URMOM 3 роки тому

      Doesn’t use librewolf... NGMI.

    • @Marco-yk8kp
      @Marco-yk8kp 3 роки тому

      @@Jorgeee he literally said it in a video, and he even said people asked him to expland and make a vid on it.

  • @PinakiGupta82Appu
    @PinakiGupta82Appu 2 роки тому +480

    You predicted, and it turned out to be true today, on 14th September 2021. The French government issued a gag order that was forwarded to Interpol and the Interpol rushed to The Honourable Swiss Federal Tribunal. Ironically, that order got passed and the French government forced ProtonMali to log IP addresses of users (mass surveillance) to crack down on an environmental activist. Drug dealers, traffickers, pirates, firearm brokers, virus crystal suppliers are freely roaming around. Protestors, dissenters, activists and journalists are considered to be the heftiest criminals nowadays. Anonymous throwaway type email providers over TOR networks with PGP encryption may be a better choice unless there are some decentralised TOR type chat clients. Though most (not all) TOR clients are also honeypots. Being rational and neutral is regarded as the most dangerous form of extremism these days. You'll be shunned for having an opinion. You own nothing. You don't have any choice. The mighty earl is always right. Might is right.

    • @e99g
      @e99g 2 роки тому +7

      So which Email provider (even in Tor) has the most privacy

    • @tomtravis858
      @tomtravis858 2 роки тому +86

      They were forced under law to do it, they were even transparent and changed their claims after it happened, it's not like they wanted to comply.

    • @sanjacobs6261
      @sanjacobs6261 2 роки тому +12

      Protonmail shared what IPs connected. Not much of a big deal considering that Google would openly give away the content of every single email you've ever sent and received to any government that asks.

    • @MrR0flLol
      @MrR0flLol 2 роки тому +20

      @@sanjacobs6261 google never made privacy their main selling point. Not like protonmail.

    • @HarrisonMartinson
      @HarrisonMartinson 2 роки тому +1

      "most tor clients are honeypots"? Does that mean I should only download the official client unless I know what I'm doing?

  • @binarywoif2852
    @binarywoif2852 2 роки тому +103

    I mean, even the most suspicious things about ProtonMail are less suspicious than average email services.

    • @mansurtxafapapaias3517
      @mansurtxafapapaias3517 2 роки тому +2

      do not allow get into anyone?

    • @alonsoACR
      @alonsoACR Рік тому +4

      The most suspicious parts are the lies. Which you don't find elsewhere.

  • @TheStiepen
    @TheStiepen 2 роки тому +122

    Please note that traffic between mailservers can actually be encrypted, and will be if supported by both ends. It would however be possible for an attacker to block the encrypted connection, to force fallback to plaintext. To my knowledge something like hsts does not exist for SMTP

    • @vxicepickxv
      @vxicepickxv 2 роки тому +3

      Would attaching encrypted compressed file attachments work?

    • @TheStiepen
      @TheStiepen 2 роки тому +14

      @@vxicepickxv that's basically what pgp does. That also has the advantage that your mail provider cannot read your emails. It's main disadvantage is that it's annoying to use.

    • @ondrejsedlak4935
      @ondrejsedlak4935 11 місяців тому +1

      That is what is called the 'optional' ssl/tls flag, which most email servers set (including the one I run).
      You can set the encryption flag to 'enforce', but that will cause some emails to bounce as a few cheapo servers do not enforce encryption in transit.
      As for Proton mail being "encrypted", that is basically half bullshit. They use PGP which relies on the recipient using a private key for end to end encryption and is almost always an opt-in option for non-Proton users.
      Yes Proton mail won't canvass your emails but most of their claims are marketing bullshit. Gmail is more than welcome to canvass my emails as it's always used for non-essential stuff. My private email server however is never canvassed.

  • @GuardianofRoin
    @GuardianofRoin 2 роки тому +23

    Protonmail: It's not private, but it's about as close as you're gonna get with email.

  • @borntodie2071
    @borntodie2071 3 роки тому +55

    Me: makes a protonmail account and start using it for bussiness and shit
    MO: "It's all spookiness and glowies"
    Well fugg me i guess

  • @skyracer-mk8hg
    @skyracer-mk8hg 3 роки тому +105

    "We do not keep any IP logs which can be linked to your anonymous email account"
    That's where the catch is: They might keep logs of non anonymous email accounts (Which are all of them)

    • @MrEdrftgyuji
      @MrEdrftgyuji 3 роки тому +20

      They may not be telling the truth. It is a bit crazy to think, but government agencies have been known to bend the truth on occasions. All for your own good of course.

    • @Bond2025
      @Bond2025 9 місяців тому

      None of the accounts are anonymous, they are all linked to a phone number that gives a precise location and/or a payment method that is traced to you like a debit card, credit card or paypal.
      They also scan all your plain text emails as they leave and arrive at the servers before and after they encrypt and decrypt them.
      It's one massive honeypot - the next EncroChat.

  • @user-td6rb
    @user-td6rb 2 роки тому +28

    “there isn’t any hard evidence that protonmail is a honeypot, but protonmail is a honeypot”

    • @andalinta
      @andalinta 2 роки тому +2

      @DownloadPizza he literally said that in the video. What are you talking about?

    • @neoish
      @neoish 4 місяці тому

      The contradiction.

  • @chadkayser3691
    @chadkayser3691 2 роки тому +13

    3:30-3:45 Just a PSA they did use this approach through their newsletter if you had a free email with them. They provided candid dialogue about how no VPN or email encryption is 100% secure. They also explained pretty effectively why and then went into detail about what you're saying at 5:45. It made it clear (and they also said it meant) you had to put your trust in them. *Batman voice* _but you can't put your trust in anybody._
    Ok that may be excessive, but yeah thanks for this eye-opener. Also fantastic username 9:50
    Dangit that watchdog article is dead.

  • @zyansheep
    @zyansheep 3 роки тому +4

    I was literally wondering about this today, your timing is impeccable

    • @yes-ge4nm
      @yes-ge4nm 2 роки тому +1

      Hello fellow pirate

  • @Bagginsess
    @Bagginsess 3 роки тому +20

    If it's a honey pot at least the glowies have to pay the other glowies for the data instead having google directly feed it into their servers.

  • @Atilolzz
    @Atilolzz 3 роки тому +12

    Its amazing how the costanza meme survived for a decade and is still very relateable

  • @jan_harald
    @jan_harald 3 роки тому +24

    email works perfectly well for what it was invented for, just like regular mail... and the hardest part is not only getting people to switch, but also getting half a century worth of programs to ALSO switch... there's a *LOT* of mail integrations going around...
    not to mention it's easy to just use something like gpg or s/mime to establish secure connections (and you can secure even metadata if the other side knows how to decrypt it, which isn't standard), so instead of "fixing" the protocol with something that will probably take 5 years to stabilize in the first place (c'mon, rust doesn't even have a spec, while being all the rage, and Go's moving at a pretty fast pace, also, just to name a few "modern" things), instead the effort should be focused on overlaying on top of it, and making the secure layer as easy to use as possible, so instead of "go run this command to generate keys and then make an email subkey and then download that extention to your mail client, and then tell it to use that subkey and then figure out the recipient's key" etc it would instead automatically generate you a key and publish it somewhere (possibly on a regular keyserver), and automatically fetch the recipient's key based on their email with the user merely needing to press a button, if even that, and to back up their key (doable automatically, but everyone shouldn't send their private keys to any singular location, so would need additional questions about that)

    • @normahostetler7859
      @normahostetler7859 2 роки тому +2

      Us, soccer moms, want to be able to freely post on social media and not be called domestic t.e.r.r.o.r.i.s.t.s. All social medias require an email and it ties it back to us.

  • @atomick2398
    @atomick2398 3 роки тому +44

    Your thumbnails are top tier Jesus Christ

  • @araa5184
    @araa5184 3 роки тому +49

    Damn, wanted to know what you would rate it in terms of bio-illuminascent levels

  • @krissyramsey3934
    @krissyramsey3934 2 роки тому +320

    Can we all just take a moment to consider how sad it is that we have to worry about things like cyber-security? What has this world come to?

    • @the9file
      @the9file 2 роки тому +73

      security has mattered for the entire history of civilization. there are better uses of your time

    • @soulextracter
      @soulextracter 2 роки тому +57

      if you really wanna worry, go watch a couple of videos from The Lockpicking Lawyer here on youtube. There isn't a lock he can't pick in like 30 seconds flat maximum lol. Granted not every home invader is going to have his skills, but still.

    • @finesseandstyle
      @finesseandstyle 2 роки тому +3

      cyber-security, laws and rules are made precisely because without them there would be chaos

    • @theunfortunatespectacle7381
      @theunfortunatespectacle7381 2 роки тому +17

      Back in the good old days, all we had to worry about was cholera, typhus or DDT. Good times

    • @skaruts
      @skaruts 2 роки тому +5

      @@finesseandstyle if there were no laws, then people would find ways to enforce order on their own. No one likes to live in chaos, therefore chaos is never the outcome. People solve problems on their own if a government isn't there to pretend to do it. Rules and security are two good examples of people doing just that. And they're more effective than any laws that exist, because laws are not preventive measures.

  • @evpowered6574
    @evpowered6574 3 роки тому +48

    When it comes to email the best you're going to get for privacy is your own domain and email hosting. Overall, consider what you send over email to be public.

    • @rampageviii7186
      @rampageviii7186 2 роки тому +2

      how do u buy a domain?
      there aint no monero offering registrars.
      with domain hosting still fucked tho

  • @ScibbieGames
    @ScibbieGames 3 роки тому +28

    The switch to the clearnet domain seems like a dumb oversight from the frontend developer.
    Maybe they will address it in the future.
    But these are fair concerns I suppose.

  • @zeeweenor
    @zeeweenor 3 роки тому +50

    ffs kenny i just switched to proton now you gotta do a followup on the best secure email service

    • @shrimp_on_internet
      @shrimp_on_internet 3 роки тому +4

      Self hosting is pretty secure

    • @imgladnotu9527
      @imgladnotu9527 3 роки тому +2

      @Big man pretty sure email hosting doesnt take much. All you need is a stable internet connection i suppose.

    • @tcideh4929
      @tcideh4929 3 роки тому +31

      @@shrimp_on_internet sef hosting just straight up not a option for 90% of people who use email.

    • @trik9464
      @trik9464 3 роки тому

      @Big man riseUp probably

    • @kekag
      @kekag 3 роки тому +7

      He answers your question directly in the video:
      14:18

  • @XaFFaX
    @XaFFaX 2 роки тому +10

    You can use any kind of throwaway email services as second email. I am almost sure they do not have filters for all of them. Hardly it will make you more "visible" if you are using a "common" service rather than setting up your own email server on a obscure VM somewhere in the middle of nowhere.

  • @Lystr0saur
    @Lystr0saur 3 роки тому +9

    I have absolutely 0 clue what the terms this guy uses in his videos mean, nor do I understand much of what's going on; yet these videos feel very informative and entertaining to me somehow.

  • @cherubin7th
    @cherubin7th 3 роки тому +12

    Biggest problem is that most of your emails will go to people with surveillance accounts on gmail or others like that anyway.

  • @rafnavi4500
    @rafnavi4500 3 роки тому

    Just saw an ad about proton on mooreslawisdead then the same day just hours apart, you upload this

  • @tac7826
    @tac7826 10 місяців тому +5

    It's not a US honeypot. It's probably a Swiss honeypot, maybe a WEF honeypot or Swiss intel.

    • @Bond2025
      @Bond2025 9 місяців тому

      With access granted to NSA and GCHQ.

  • @Cookiekeks
    @Cookiekeks 3 роки тому +3

    12:05 now you sparked my interest. Hope a video on this thing without IPs follows

  • @ddicas
    @ddicas 3 роки тому +18

    What awesome coincidence: I'm right now creating a kind of "documentary + hands on" about privacy stuff for almost everything and all kinds of people and you upload this video :D
    (Seriosly, I just finished recording right now the desktop operating system security step and also installed gentoo on my laptop haha)
    I'm thinking about to invite some people (The Hated One, Newman) to this project and would like to invite you, Kenny, to participate (I've no idea when I'll finish the "hands on" video to start the documentary video, but anyway, I'll post a comment with this 2 video links when I finish everything)
    Anyway, again, great video and regards from Brazil o/

    • @baguettedad
      @baguettedad 3 роки тому +4

      r/suddenlycaralho

    • @ddicas
      @ddicas 3 роки тому +2

      Gostei da comunidade K
      se for tirar print, coloca o Genchu (do Gentoo) do lado huauhahua

  • @systemthirtytwo
    @systemthirtytwo 3 роки тому +47

    This is gonna be interesting.

  • @marknefedov
    @marknefedov 3 роки тому +9

    Hated and Mental, greatest crossover ever!

  • @iansmith8747
    @iansmith8747 2 роки тому +4

    As I recall you can use a disposable email account for verification (and therefore this is not a deanonymizing step), the goal being to add difficulty in setting up spam accounts.

  • @downrightlefthiill8081
    @downrightlefthiill8081 2 місяці тому +1

    Damn. Damn damn damn damn. I dodged a bullet here. Phew! You're a hero my guy. Idk what I'll do without you. ❤

  • @XZenon
    @XZenon 3 роки тому +7

    >melt the server with thermite
    I was about to comment that lmao
    I may not agree with you in every video but damn I love your sense of humour.

    • @MentalOutlaw
      @MentalOutlaw  3 роки тому +14

      Ya, the problem with thermite though is the ignition source has to be hot enough to get it going.

    • @XZenon
      @XZenon 3 роки тому +3

      @@MentalOutlaw Magnesium strip + Christmas lights

  • @Pro720HyperMaster720
    @Pro720HyperMaster720 3 роки тому +4

    I think the Onion domain was mainly intended for accessing the service, maybe someone should ask in their community pages for features and improvements that they extend it for registration

  • @johntr7565
    @johntr7565 3 роки тому +12

    Again: "If you want something done, do it yourself"
    Waiting for the video on self-hosted mail server :D

  • @sirajqazi2361
    @sirajqazi2361 2 роки тому +1

    Bro, you recommended Protonmail in your "Complete online privacy guide" video (2020)
    Better update that one
    Nice vid btw!

  • @romancvijanovic7130
    @romancvijanovic7130 Рік тому +2

    Some mail providers have starttls enabled on port 25. Thus making it possible to have an encryption connection between two MTAs. But the standard is for it to be transported in plaintext.

  • @v3eboy228
    @v3eboy228 3 роки тому +43

    Love it, you have a.. dare I say it?.... BASED way of presentation man. Been a longtime protonmail user, and the issues you're raising are alarming

  • @ronodipbasak4524
    @ronodipbasak4524 3 роки тому +16

    5:50 - "SMTP port 25 that can not be encrypted"
    Don't most providers use SSL encryption like on port 465 or 587?

    • @GlenMerlin
      @GlenMerlin 3 роки тому +6

      I know gmail allows port 25 but SSL encryption is the default

    • @auscompgeek
      @auscompgeek 2 роки тому +1

      Any and all mail going between providers always go over port 25. Ports 465 and 587 are only for submission.

  • @senorbill374
    @senorbill374 3 роки тому

    yo thanks this was super informative
    keep up the good work :^)

  • @xrichxlen
    @xrichxlen Рік тому +6

    Do NOT click the description link! The "privacy watchdog" link, now (May 2023), links to a dangerous page where suspicious animations occurred and I quickly received Trojan malware (HTML FakeAlert WRN). I tried to post a version of this comment this earlier, but YT did its comment-deletion thing - I am unsure of why. Perhaps this one is different enough to be allowed.

  • @DxBlack
    @DxBlack Рік тому +13

    You will note that nowhere on their website do they claim their service is for individuals who need the utmost high of privacy and anonymity...it's for secure white and grey activities, like businesses; not government whistleblower or drug dealers.

    • @ryannorthup3148
      @ryannorthup3148 Рік тому +2

      I doubt even greys would be safe & secure here.

  • @RyanRoadReaper
    @RyanRoadReaper 3 роки тому +32

    If it talks like a honeypot, and acts like a honeypot, it is a honeypot

  • @belliumm
    @belliumm 3 роки тому

    Thank you for posting this Kenny

  • @hannecart
    @hannecart 3 роки тому

    great summary at the end there

  • @Ultrajamz
    @Ultrajamz 3 роки тому +4

    Whats more interesting is if websites begin to not require emails but instead require a signal account or something.

    • @TheUnarch
      @TheUnarch Рік тому +2

      I second that thought!

  • @ItsOnlyLogixal
    @ItsOnlyLogixal 3 роки тому +6

    Ngl melting down the server with thermite when an intruder is detected was the funniest part of this video because who hasn't thought about that?

  • @notsam9528
    @notsam9528 3 роки тому

    Thanks I was waiting for this video

  • @toastybaconbus5737
    @toastybaconbus5737 3 роки тому +8

    What email service would you recommend to receive banking and insurance information. Main goal is to protect from identity theft, not hide from the gov or any such thing.

    • @Bond2025
      @Bond2025 9 місяців тому

      UK Banks and financial people BLOCK ProtonMail. I found this when I tried using an account.

  • @fosres
    @fosres 2 роки тому +4

    Hi Mental Outlaw, may you do a video on Tutanota? Its also another end-to-end encrypted email service.

  • @vladislavkaras491
    @vladislavkaras491 Рік тому +1

    Thanks for the video!

  • @cyf3r867
    @cyf3r867 3 роки тому

    I love th end thanx buddy !

  • @justethical280
    @justethical280 3 роки тому +35

    Haha Mental Outlaw, even though i'm a person who is fairly good in security and IT , i still like the way you present this kind of news/information LoL. Stay safe man. Greetings from The Netherlands.

  • @jakedw25
    @jakedw25 3 роки тому +6

    "Email a known drug dealer on April, 20th"...😂😭😂👌

  • @drasticfred
    @drasticfred 2 роки тому +1

    "Encryption of email body/contents" is just a marketing/advertisement polishing feature by this company. Almost all email you receive in plaintext. Plus you can encrypt all your email body/contents by yourself without relying a third party, no hassle required.

  • @MusicToTheEars141
    @MusicToTheEars141 3 роки тому +1

    Yes! You gave THO some credit!

  • @rpeetz
    @rpeetz 3 роки тому +9

    As long as the feds dont steal my steam account it is fine

    • @egg5474
      @egg5474 3 роки тому +5

      The feds want to play yandere simulator give me your password

    • @rpeetz
      @rpeetz 3 роки тому

      @@egg5474 my password is **************

  • @teriyakipuppy
    @teriyakipuppy 3 роки тому +4

    There's a saying in the kitchen. "When in doubt, throw it out!"

  • @MA-naconitor
    @MA-naconitor Рік тому

    An improvement on their part is, that you can now use a recovery phrase instead, that you can store in plain-text. More vulnerable (they emphasise this), but much better than a recovery e-mail.

    • @seifshebl7404
      @seifshebl7404 11 місяців тому

      How to use it, please? I don't find that option when signing up. What country do you login from?

  • @waltz9230
    @waltz9230 2 роки тому +2

    Random but important question, why did Protonmail STOP asking what kind of encryption you wanna use upon account creation? I made a new account recently and this time it didn’t ask me if I wanted lighter or more robust (but slower) encryption. Granted, I creates my last account with the paid plan from the get-go where as with this new one I started with the free plan first. This is kind of odd.

    • @libertyworker5886
      @libertyworker5886 2 роки тому +1

      I've seen it on mobile and desktop, desktop no longer asks you but mobile(through a browser)asks you

  • @zacktrujillo3473
    @zacktrujillo3473 3 роки тому +3

    IVPN also makes some honest claims about VPN security and they also accept cash. IVPN is slightly cheaper, I'd stick with it.

  • @John_Gaye
    @John_Gaye 3 роки тому +4

    The phone verification is easy to bypass with a free sms site, still spooky tho

  • @user-en6mj2ck9v
    @user-en6mj2ck9v 2 роки тому

    Nice video, thanks for the details, any idea of what to use instead ?

    • @beybrain7896
      @beybrain7896 Рік тому

      He said at the end that a private email provider doesn't exist.

  • @snowblowerrr
    @snowblowerrr 3 роки тому +1

    Do a video next about how to anonymously communicate over the web.

  • @arbazna
    @arbazna 3 роки тому +7

    Regarding port 25, it could be encrypted via STARTTLS as far as I know.

    • @eDoc2020
      @eDoc2020 2 роки тому +1

      More importantly, there's also a new MTA-STS standard which turns STARTTLS from opportunistic to mandatory for supported servers.

  • @rallias1
    @rallias1 Рік тому +2

    Ok, I'm going to pick the same nit here that got me kicked out of DEF CON 30's Hacker Jeopardy.
    Port 25 has the ability to use STARTTLS. If a mail server refuses to send a message to a server without STARTTLS, then no man in the middle is able to intercept the contents of that email, only the two MTA's at either side.

  • @throwaway9911
    @throwaway9911 Рік тому +2

    Also, I would like to point out that feds buy for something like 60% of TOR networks development.
    Kenny you should make a video on that...

  • @kon81996
    @kon81996 3 роки тому

    Caught me off guard with the "Arbiter Of Truth"

  • @uKhyta
    @uKhyta 2 роки тому +9

    How relevant the Video has become again... ironic

  • @AshishKumar-tg6zh
    @AshishKumar-tg6zh 3 роки тому +3

    I am proud of you because the only person who can guide us in the right direction is you.

    • @andalinta
      @andalinta 2 роки тому +1

      What?? Noo, do your own research. I only agree to half the stuff he says in this video and that is because I'm informed and I understand MY needs aro not those of everyone. You should strive for the same.

  • @OblateSpheroid
    @OblateSpheroid Рік тому

    Thank you for your work.

  • @gizka6816
    @gizka6816 3 роки тому

    you really are doing god's work out here

  • @hof_prod
    @hof_prod 3 роки тому +11

    but what about some 10minmail for the Recovery E-Mail?

    • @zimboiii9025
      @zimboiii9025 3 роки тому

      why do they make it so difficult?

    • @hof_prod
      @hof_prod 3 роки тому +4

      @@zimboiii9025 if you really think about it, its okay how they do it. Companies that are not interested in your Privacy e.g. Google require you to use your phone number to create an account. They "just" force you to have an other mail, for which you easily can use gorillamail or 10minemail

  • @dayumnson9769
    @dayumnson9769 2 роки тому +6

    Are you about clickbaiting or actually informing people? Did you even read their homepage?
    All their clients and bridges are e2e encrypted and open source.
    It seems that this is more "how you feel" than what it is.
    anyway, you do you.

  • @InfernalMonsoon
    @InfernalMonsoon 3 роки тому

    You gonna do a video on the Steam Deck Kenny? Would love to hear your opinion on it with it since it's a Linux system.

  • @ddenobrega8298
    @ddenobrega8298 3 роки тому

    I was waiting for this one

  • @JamesQHolden
    @JamesQHolden 3 роки тому +11

    CERN uses it, I'd imagine they'd be uptight with security hiring one of the finest scientists out there

    • @imgladnotu9527
      @imgladnotu9527 3 роки тому +8

      For a second there i mis-percieved CERN as SERN there.

    • @kashmirwillwin3124
      @kashmirwillwin3124 3 роки тому +13

      @@imgladnotu9527 SERN sounds like a bootleg version of CERN some anime about time travel would come up with to bypass copyright. elpsykongru

    • @MrEdrftgyuji
      @MrEdrftgyuji 3 роки тому +3

      They don't really care if US/Western government agencies spy on them. They only really care about the Chinese or private organisations / hackers.

    • @retroman7581
      @retroman7581 3 роки тому +2

      @@kashmirwillwin3124 the organisation is near, we need to move!

  • @LennyG2006
    @LennyG2006 2 роки тому

    Fantastic, can you guess which ad I was served when the video ended? Yup, Protonmail. Own goal.

  • @suuuken4977
    @suuuken4977 2 роки тому

    At 10:20 when it required an email to authenticate you're a human, couldn''t you just use a temporary email service online via the tor network and then it will be untraceable? Am i missing some key detail?

  • @TheUnitedNations.
    @TheUnitedNations. 3 роки тому +5

    Do these concerns extend to ProtonVPN?

    • @twei__
      @twei__ 2 роки тому

      Not really afaik, but proton drive *could* be affected

  • @45678213914284289421
    @45678213914284289421 2 роки тому +3

    About secure payment: something its weird with this. Last month I bought their vpn by bitcoin and I was surprised that you can't do the same with email so I've checked it and now I didn't had that option either (neither in mail or vpn) but I still have option to extend account by bitcoin and cash. My transaction was after you published video, so probably they have weird payment policy or this is just a bug. You can pay anonymously if you're determined enough. :)
    Edit: and about encrypted emails - if you have more then two brain cells you should figure out that if you send encrypted email to provider that doesn't support it and your recipient didn't revived random gibberish it had to be decrypted at some point - read about service before you start using it.

    • @user-hq4jz6lc9d
      @user-hq4jz6lc9d 4 місяці тому

      Hmm. Would they accept payment with pre-paid credit cards, purchased with cash?

    • @45678213914284289421
      @45678213914284289421 3 місяці тому

      @@user-hq4jz6lc9d I don't know I don't use them.

  • @midimusicforever
    @midimusicforever 2 роки тому +1

    It depends on the use case.

  • @justanotherspy5636
    @justanotherspy5636 Рік тому +1

    I liked your example email address.

  • @botowner8623
    @botowner8623 3 роки тому +4

    yes but its 10000% still better than gmail

  • @tomt8709
    @tomt8709 3 роки тому +2

    Very interesting topics you mention here. I currently try their free email. However, even if it's not all perfect as promoted I would assume it's still much safer than Gmail. Agree?

  • @victorkorir18
    @victorkorir18 Рік тому

    What course should I purse to get a better understanding of snipping emails and meta data on a mail?

  • @rodiculous9464
    @rodiculous9464 Рік тому +1

    When you said "biggest pieces of" I was expecting something different than what you said next

  • @damnmodz5468
    @damnmodz5468 3 роки тому +3

    "Having multiple free accounts is not considered an acceptable use of our service (e.g. bulk-signups, large number of free accounts created by a single organization or individual). Free accounts can also only be created and maintained by their effective users (e.g. it is not acceptable to create accounts in anyone else’s name and later transfer credentials to that third party)."
    How can they enforce this if they do not keep log of IP addresses?

    • @moonlitee
      @moonlitee 3 роки тому +1

      trust me, they don't enforce it

    • @moonlitee
      @moonlitee 2 роки тому

      @@justacat.1428 oh maybe in that case, but i have like 20 accounts and they haven't done anything (doesn't mean they don't keep ip logs, they probably do)

  • @yuiooiuy2167
    @yuiooiuy2167 3 роки тому +8

    This video: "I'm going to take boiler plate snippets and make extrapolations for the entire company!"
    Also, Mental outlaw doesn't understand that https + onion are standard practice for orgs that understand encryption. I guess he was bored and needed a video with no real points or new information on his channel.

    • @joshuawlawson
      @joshuawlawson 3 роки тому +3

      Mental Outlaw and Techlore both spread a lot of FUD.

    • @wallegamecube
      @wallegamecube 3 роки тому +4

      Yeah I'm not too happy with this video either. His points about email being a horribly insecure protocol that anyone can spy on are valid, but I wish he clarified how Proton is still one of the best non-Google options that's actually user-friendly