Is Proton Mail Really Private, Secure, and Anonymous?

Поделиться
HTML-код
  • Опубликовано: 12 июл 2024
  • In this video I tackle the topic of whether or not Proton mail is Really Private, Secure, and Anonymous
    Privacy Watchdogs article about Proton mail being a honey pot which covers some of the issues in this video in more details, plus other things I didn't talk about
    ₿💰💵💲Help Support the Channel by Donating Crypto💲💵💰₿
    Monero
    45F2bNHVcRzXVBsvZ5giyvKGAgm6LFhMsjUUVPTEtdgJJ5SNyxzSNUmFSBR5qCCWLpjiUjYMkmZoX9b3cChNjvxR7kvh436
    Bitcoin
    3MMKHXPQrGHEsmdHaAGD59FWhKFGeUsAxV
    Ethereum
    0xeA4DA3F9BAb091Eb86921CA6E41712438f4E5079
    Litecoin
    MBfrxLJMuw26hbVi2MjCVDFkkExz8rYvUF
    Dash
    Xh9PXPEy5RoLJgFDGYCDjrbXdjshMaYerz
    Zcash
    t1aWtU5SBpxuUWBSwDKy4gTkT2T1ZwtFvrr
    Chainlink
    0x0f7f21D267d2C9dbae17fd8c20012eFEA3678F14
    Bitcoin Cash
    qz2st00dtu9e79zrq5wshsgaxsjw299n7c69th8ryp
    Etherum Classic
    0xeA641e59913960f578ad39A6B4d02051A5556BfC
    USD Coin
    0x0B045f743A693b225630862a3464B52fefE79FdB
    Subscribe to my RUclips channel goo.gl/9U10Wz
    and be sure to click that notification bell so you know when new videos are released.
  • НаукаНаука

Комментарии • 1 тыс.

  • @N.S.A.
    @N.S.A. 3 года назад +5340

    I use it. It's fast and secure.

    • @jorionedwards
      @jorionedwards 3 года назад +549

      Seems sus.

    • @MentalOutlaw
      @MentalOutlaw  3 года назад +4215

      Thank you for the clarification, I'll be deleting the video now to replenish my social credit score.

    • @looweegee252
      @looweegee252 3 года назад +373

      @@MentalOutlaw lol it's going on your PERMANENT RECORD

    • @rabywastaken
      @rabywastaken 3 года назад +78

      that's hilarious lmao

    • @N.S.A.
      @N.S.A. 3 года назад +203

      @@MentalOutlaw As long as you understand.

  • @nothingiseverperfect
    @nothingiseverperfect 3 года назад +1597

    *Looks at my carrier pigeon:*
    “You hear that little guy? I made the right choice!”

    • @nicholasbrooks7349
      @nicholasbrooks7349 3 года назад +61

      What if the feds shoot it down? , ever thought about that!

    • @kashmirwillwin3124
      @kashmirwillwin3124 3 года назад +99

      @@nicholasbrooks7349 And what if the birds being a government spy drones conspiracy theory is true. Time to learn telepathy

    • @GatoCoder
      @GatoCoder 3 года назад +6

      @Mialisus I don't see why the choice is that bad in pfp

    • @franchufranchu119
      @franchufranchu119 3 года назад +1

      Save-or Deez nuts lmao

    • @felipedaiber2991
      @felipedaiber2991 3 года назад +5

      Me with a shotgun: no you didnt

  • @WahrerKuroKiba
    @WahrerKuroKiba 3 года назад +1929

    Me: switches to Protonmail
    Kenny:

    • @xeome5596
      @xeome5596 3 года назад +63

      exactly

    • @dadecountyboos
      @dadecountyboos 3 года назад +29

      same

    • @daringcuteseal
      @daringcuteseal 3 года назад +4

      lol

    • @grumpyspoder
      @grumpyspoder 3 года назад +75

      same lol made the switch a week ago and then he decides to drop this lol

    • @bat4
      @bat4 3 года назад +3

      @@grumpyspoder Yeah, ruclips.net/video/Q30swyxHY0w/видео.html

  • @ghollisjr
    @ghollisjr 3 года назад +1563

    If you want something done right, you gotta do it yourself. --The Feds.

  • @hedgeearthridge6807
    @hedgeearthridge6807 3 года назад +1502

    Hopefully in the future we can completely re-invent email, with an open-source protocol that does center on privacy (and isn't a complete pain in the ass to use), because what we currently have is extremely outdated. The hardest part would be getting normies to accept it, and of course big tech wouldn't like it because they thrive on getting to process your emails for advertising data.

    • @Cookiekeks
      @Cookiekeks 3 года назад +18

      Why is the email protocol outdated? Just curious to know.

    • @greenl7661
      @greenl7661 3 года назад +25

      Zk proofs do that. No incentives for migration sadly

    • @wheezybackports6444
      @wheezybackports6444 3 года назад +10

      OpenSMTP

    • @r05ejan8
      @r05ejan8 3 года назад +98

      ​@@Cookiekeks Like the Big Man said... among other things... the inter-domain transfer protocols for email are incompatible with any sort of encryption... even if you go through the effort to PGP encrypt the body of your email... the header which includes info such as IP addresses and email addresses of the sender and receiver are in plaintext for ALL to see.... this stuff was standardized LONG ago when nobody cared about encryption... things have changed and for good reasons encryption is standard for many fundamental services we use everyday..... email is a leftover of times bygone.... much to our detriment.

    • @jan_harald
      @jan_harald 3 года назад +32

      email works perfectly well for what it was invented for, just like regular mail... and the hardest part is not only getting people to switch, but also getting half a century worth of programs to ALSO switch... there's a *LOT* of mail integrations going around...
      not to mention it's easy to just use something like gpg or s/mime to establish secure connections (and you can secure even metadata if the other side knows how to decrypt it, which isn't standard), so instead of "fixing" the protocol with something that will probably take 5 years to stabilize in the first place (c'mon, rust doesn't even have a spec, while being all the rage, and Go's moving at a pretty fast pace, also, just to name a few "modern" things), instead the effort should be focused on overlaying on top of it, and making the secure layer as easy to use as possible, so instead of "go run this command to generate keys and then make an email subkey and then download that extention to your mail client, and then tell it to use that subkey and then figure out the recipient's key" etc it would instead automatically generate you a key and publish it somewhere (possibly on a regular keyserver), and automatically fetch the recipient's key based on their email with the user merely needing to press a button, if even that, and to back up their key (doable automatically, but everyone shouldn't send their private keys to any singular location, so would need additional questions about that)

  • @MrYAMAHA32177
    @MrYAMAHA32177 2 года назад +519

    I have developed, (through mainline breeds) a new hybrid carrier pigeon for inner city communication within a 40 mile radius. Should be rolling out the first adults by the end of the second quarter and very excited with the testing so far.

    • @heidiho7314
      @heidiho7314 2 года назад +34

      Finally! Fully compliant with RFC 1149, I assume?

    • @sirpretzel822
      @sirpretzel822 2 года назад +36

      Are there any plans on making the genetic sequence open source?

    • @harrygarry2637
      @harrygarry2637 2 года назад +20

      @@heidiho7314 government already has robot birds for this exact reason.
      Minus 70 social credit points

    • @johnarnold893
      @johnarnold893 Год назад

      🤣🤣🤣🤣🤣

    • @frwystr
      @frwystr Год назад

      bro let’s get one pigeon and maybe a uhhhhh chicken?

  • @asosa9502
    @asosa9502 3 года назад +652

    I use Proton Mail and I don't really care if it's a honeypot. My reason for switching to Proton Mail is that I didn't want Google having all of my emails. The feds are going to have my emails whether I'm on gmail or on Proton Mail, so I might as well make sure Google doesn't have them too. And yes, I did consider self-hosting, but self-hosted emails are blocked by a large number of email providers because they are a huge source of spam. Just assume that everything you do over email is completely public and you'll be fine.

    • @Nash_Nismo
      @Nash_Nismo 2 года назад +79

      Yep, screw Google

    • @companymen42
      @companymen42 2 года назад +4

      Yea its kinda like the government is the devil you know vs corporations are the devil you dont.

    • @fearsomefoursome4
      @fearsomefoursome4 2 года назад +6

      @@computerdores You mean the data that google gives the NSA willy nilly even without the rubber stamp of FISA courts. Did you not watch snowden?

    • @AR15ORIGINAL
      @AR15ORIGINAL 2 года назад

      @@computerdores If your threat model includes feds, you shouldn't use email at all. We're talking STRICTLY about corporate tracking on this context.
      Also, google literally cooperated with the feds in the past. In all likelihood, they are already secretly sharing the plaintext contents of everybody's gmails. Why pretend otherwise?

    • @jorgesandoval4602
      @jorgesandoval4602 Год назад +9

      Agreed, I'll do it exactly for the same reason

  • @Crypdography
    @Crypdography 3 года назад +324

    Pro-tip:
    If you need to encrypt a message do it yourself.

    • @cahallo5964
      @cahallo5964 2 года назад +7

      how would the other end get the key if communication is only through the internet

    • @Gurkewasser22
      @Gurkewasser22 2 года назад +52

      @@cahallo5964 guess

    • @cahallo5964
      @cahallo5964 2 года назад +9

      @@Gurkewasser22 that makes no fucking sense

    • @Gurkewasser22
      @Gurkewasser22 2 года назад +47

      Day 8455 explaining jokes to strangers

    • @cahallo5964
      @cahallo5964 2 года назад +23

      @@Gurkewasser22 I have autism you have to explain the joke to me so I can steal it and tell it in several diferent places until it stops being funny to me

  • @wclifton968gameplaystutorials
    @wclifton968gameplaystutorials 3 года назад +503

    If they really wanted privacy or security then they should've opened up shop in Liechtenstien since they don't work with the US Government or the Chinese Government unlike the Swiss government which works with both

    • @steffeneilers8530
      @steffeneilers8530 3 года назад +43

      Liechtenstien is probably too small for that, don't they follow the Swiss in most decisions? Also, I find this thing of thinking that countries won't bend over for Uncle Sam so dumb. It's understandable from their perspectives.

    • @nootics
      @nootics 3 года назад +69

      @@steffeneilers8530 i like to call liechtenstein the 27th canton ("state") of Switzerland that likes to act as their own monarchy lmao

    • @lennykump8396
      @lennykump8396 3 года назад +25

      Tutanota didn't give personal information of their customers away even though a court of the FRG tried to force them to. That's not a good point in my opinion. Also Liechtenstein probably doesn't care about some Chinese company just because the company could gain something from it.

    • @survivor303
      @survivor303 3 года назад +24

      The swiss thing with their laws was a real thing back in the 90's. Now they are as corrupted as everyone else :)

    • @MrEdrftgyuji
      @MrEdrftgyuji 3 года назад +7

      They also work closely with the EU, despite not being a EU member.

  • @coffeebean4529
    @coffeebean4529 3 года назад +311

    I swear to God, it's like you're in my head. I was litteraly thinking about this yesterday.

    • @shadowbannedneet
      @shadowbannedneet 3 года назад +9

      maybe he is

    • @8w73
      @8w73 3 года назад +55

      take your meds

    • @ungureanucalin3293
      @ungureanucalin3293 3 года назад +3

      BRUH I WAS THINKING ABOUT THE SAME THING 2 DAYS AGO

    • @geestwagen4614
      @geestwagen4614 3 года назад +2

      Same bro. Yesterday, the radio was
      talking to me

    • @DenartMeyer
      @DenartMeyer 3 года назад

      Didn’t he lowkey take a jab at protonmail in one of his other videos?

  • @ns-yz1hj
    @ns-yz1hj 3 года назад +56

    *sadly looks at protonmail account
    "You aren't who I thought you were..."

    • @GabrielTobing
      @GabrielTobing 3 года назад +2

      Me: Well sht we got a problem.

  • @sgill4833
    @sgill4833 3 года назад +69

    Very eye opening, all emails are essentially insecure.

    • @anneonymous4884
      @anneonymous4884 Год назад +11

      Oddly enough, the only secure way to send messages is probably physical mail.

    • @Normal_Boii
      @Normal_Boii Год назад +4

      Carrier pidgeon it is, then

  • @PinakiGupta82Appu
    @PinakiGupta82Appu 2 года назад +480

    You predicted, and it turned out to be true today, on 14th September 2021. The French government issued a gag order that was forwarded to Interpol and the Interpol rushed to The Honourable Swiss Federal Tribunal. Ironically, that order got passed and the French government forced ProtonMali to log IP addresses of users (mass surveillance) to crack down on an environmental activist. Drug dealers, traffickers, pirates, firearm brokers, virus crystal suppliers are freely roaming around. Protestors, dissenters, activists and journalists are considered to be the heftiest criminals nowadays. Anonymous throwaway type email providers over TOR networks with PGP encryption may be a better choice unless there are some decentralised TOR type chat clients. Though most (not all) TOR clients are also honeypots. Being rational and neutral is regarded as the most dangerous form of extremism these days. You'll be shunned for having an opinion. You own nothing. You don't have any choice. The mighty earl is always right. Might is right.

    • @e99g
      @e99g 2 года назад +7

      So which Email provider (even in Tor) has the most privacy

    • @tomtravis858
      @tomtravis858 2 года назад +86

      They were forced under law to do it, they were even transparent and changed their claims after it happened, it's not like they wanted to comply.

    • @sanjacobs6261
      @sanjacobs6261 2 года назад +12

      Protonmail shared what IPs connected. Not much of a big deal considering that Google would openly give away the content of every single email you've ever sent and received to any government that asks.

    • @MrR0flLol
      @MrR0flLol 2 года назад +20

      @@sanjacobs6261 google never made privacy their main selling point. Not like protonmail.

    • @HarrisonMartinson
      @HarrisonMartinson 2 года назад +1

      "most tor clients are honeypots"? Does that mean I should only download the official client unless I know what I'm doing?

  • @Marco-yk8kp
    @Marco-yk8kp 3 года назад +353

    Day 5 of asking Kenny to make a video on "Mozzilla is made by the feds" situation.

    • @Jorgeee
      @Jorgeee 3 года назад +49

      He won’t do that video because Mozilla is obviously not made by the feds.

    • @jan_harald
      @jan_harald 3 года назад +50

      "made by"...yeah...totally...
      just like chrome isn't made by the feds, but a company which is very willingly handing over data, and also loves to get ALL the data it can out of everyone...
      mozilla's on real rough times due to chrome monopoly, and are 1) doing just telemetry, which is disable-able (just use a fork like idk, GNU IceCat, if you're paranoid, lol) and 2) trying to appeal to as many people as they can to attempt to make more normies use it (believe it or not, you can't really live a company off of purely linux geeks who use your software for free), which explains why they're changing the UI, and why they're moving along with chrome's extentions and ideas
      and other than firefox, they can't even afford any long-living projects, FirefoxOS was a great idea, only to be killed and turned proprietary by KaiOS, while ChromeOS is still a thing, and only non-browser things they have are lockwise (pretty much just standalone version of the password manager in the browser, for phones, so not that significant) and thunderbird, which actually has a surprisingly considerable amount of "web browser" as part of it, iirc...

    • @vijaysridhar351
      @vijaysridhar351 3 года назад +3

      What about brave ??

    • @IWILL360URMOM
      @IWILL360URMOM 3 года назад

      Doesn’t use librewolf... NGMI.

    • @Marco-yk8kp
      @Marco-yk8kp 3 года назад

      @@Jorgeee he literally said it in a video, and he even said people asked him to expland and make a vid on it.

  • @skeilnet
    @skeilnet 3 года назад +198

    The thing is Proton mail is not designed for this level of security, it still need to comply with Swiss law. As always you’re never better served than by yourself. There is no easy route.

    • @bennihtm
      @bennihtm 3 года назад +14

      Does Swiss law state, that they have to de-anonymize Tor traffic?

    • @electric26
      @electric26 5 месяцев назад +1

      ​@@bennihtm redirecting to a clearnet site doesn't de-anonymize Tor users unless the government or entity(s) you're attempting to remain anonymous to run the exit node being used. It is pretty much just a benefit for servers unless you're at a high enough threat levels for governments to contact each other/collaborate.
      TLDR: it's probably good enough for most users.
      P.S. they don't redirect to the clearnet version anymore (you can do everything through Tor as far as I can tell)

  • @binarywoif2852
    @binarywoif2852 2 года назад +103

    I mean, even the most suspicious things about ProtonMail are less suspicious than average email services.

    • @mansurtxafapapaias3517
      @mansurtxafapapaias3517 2 года назад +2

      do not allow get into anyone?

    • @alonsoACR
      @alonsoACR Год назад +4

      The most suspicious parts are the lies. Which you don't find elsewhere.

  • @GuardianofRoin
    @GuardianofRoin 2 года назад +23

    Protonmail: It's not private, but it's about as close as you're gonna get with email.

  • @borntodie2071
    @borntodie2071 3 года назад +55

    Me: makes a protonmail account and start using it for bussiness and shit
    MO: "It's all spookiness and glowies"
    Well fugg me i guess

  • @TheStiepen
    @TheStiepen 2 года назад +122

    Please note that traffic between mailservers can actually be encrypted, and will be if supported by both ends. It would however be possible for an attacker to block the encrypted connection, to force fallback to plaintext. To my knowledge something like hsts does not exist for SMTP

    • @vxicepickxv
      @vxicepickxv 2 года назад +3

      Would attaching encrypted compressed file attachments work?

    • @TheStiepen
      @TheStiepen 2 года назад +14

      @@vxicepickxv that's basically what pgp does. That also has the advantage that your mail provider cannot read your emails. It's main disadvantage is that it's annoying to use.

    • @ondrejsedlak4935
      @ondrejsedlak4935 11 месяцев назад +1

      That is what is called the 'optional' ssl/tls flag, which most email servers set (including the one I run).
      You can set the encryption flag to 'enforce', but that will cause some emails to bounce as a few cheapo servers do not enforce encryption in transit.
      As for Proton mail being "encrypted", that is basically half bullshit. They use PGP which relies on the recipient using a private key for end to end encryption and is almost always an opt-in option for non-Proton users.
      Yes Proton mail won't canvass your emails but most of their claims are marketing bullshit. Gmail is more than welcome to canvass my emails as it's always used for non-essential stuff. My private email server however is never canvassed.

  • @Bagginsess
    @Bagginsess 3 года назад +20

    If it's a honey pot at least the glowies have to pay the other glowies for the data instead having google directly feed it into their servers.

  • @skyracer-mk8hg
    @skyracer-mk8hg 3 года назад +105

    "We do not keep any IP logs which can be linked to your anonymous email account"
    That's where the catch is: They might keep logs of non anonymous email accounts (Which are all of them)

    • @MrEdrftgyuji
      @MrEdrftgyuji 3 года назад +20

      They may not be telling the truth. It is a bit crazy to think, but government agencies have been known to bend the truth on occasions. All for your own good of course.

    • @Bond2025
      @Bond2025 9 месяцев назад

      None of the accounts are anonymous, they are all linked to a phone number that gives a precise location and/or a payment method that is traced to you like a debit card, credit card or paypal.
      They also scan all your plain text emails as they leave and arrive at the servers before and after they encrypt and decrypt them.
      It's one massive honeypot - the next EncroChat.

  • @ScibbieGames
    @ScibbieGames 3 года назад +28

    The switch to the clearnet domain seems like a dumb oversight from the frontend developer.
    Maybe they will address it in the future.
    But these are fair concerns I suppose.

  • @atomick2398
    @atomick2398 3 года назад +44

    Your thumbnails are top tier Jesus Christ

  • @zyansheep
    @zyansheep 3 года назад +4

    I was literally wondering about this today, your timing is impeccable

    • @yes-ge4nm
      @yes-ge4nm 2 года назад +1

      Hello fellow pirate

  • @araa5184
    @araa5184 3 года назад +49

    Damn, wanted to know what you would rate it in terms of bio-illuminascent levels

  • @user-td6rb
    @user-td6rb 2 года назад +28

    “there isn’t any hard evidence that protonmail is a honeypot, but protonmail is a honeypot”

    • @andalinta
      @andalinta 2 года назад +2

      @DownloadPizza he literally said that in the video. What are you talking about?

    • @neoish
      @neoish 4 месяца назад

      The contradiction.

  • @chadkayser3691
    @chadkayser3691 2 года назад +13

    3:30-3:45 Just a PSA they did use this approach through their newsletter if you had a free email with them. They provided candid dialogue about how no VPN or email encryption is 100% secure. They also explained pretty effectively why and then went into detail about what you're saying at 5:45. It made it clear (and they also said it meant) you had to put your trust in them. *Batman voice* _but you can't put your trust in anybody._
    Ok that may be excessive, but yeah thanks for this eye-opener. Also fantastic username 9:50
    Dangit that watchdog article is dead.

  • @krissyramsey3934
    @krissyramsey3934 2 года назад +320

    Can we all just take a moment to consider how sad it is that we have to worry about things like cyber-security? What has this world come to?

    • @the9file
      @the9file 2 года назад +73

      security has mattered for the entire history of civilization. there are better uses of your time

    • @soulextracter
      @soulextracter 2 года назад +57

      if you really wanna worry, go watch a couple of videos from The Lockpicking Lawyer here on youtube. There isn't a lock he can't pick in like 30 seconds flat maximum lol. Granted not every home invader is going to have his skills, but still.

    • @finesseandstyle
      @finesseandstyle 2 года назад +3

      cyber-security, laws and rules are made precisely because without them there would be chaos

    • @theunfortunatespectacle7381
      @theunfortunatespectacle7381 2 года назад +17

      Back in the good old days, all we had to worry about was cholera, typhus or DDT. Good times

    • @skaruts
      @skaruts 2 года назад +5

      @@finesseandstyle if there were no laws, then people would find ways to enforce order on their own. No one likes to live in chaos, therefore chaos is never the outcome. People solve problems on their own if a government isn't there to pretend to do it. Rules and security are two good examples of people doing just that. And they're more effective than any laws that exist, because laws are not preventive measures.

  • @jan_harald
    @jan_harald 3 года назад +24

    email works perfectly well for what it was invented for, just like regular mail... and the hardest part is not only getting people to switch, but also getting half a century worth of programs to ALSO switch... there's a *LOT* of mail integrations going around...
    not to mention it's easy to just use something like gpg or s/mime to establish secure connections (and you can secure even metadata if the other side knows how to decrypt it, which isn't standard), so instead of "fixing" the protocol with something that will probably take 5 years to stabilize in the first place (c'mon, rust doesn't even have a spec, while being all the rage, and Go's moving at a pretty fast pace, also, just to name a few "modern" things), instead the effort should be focused on overlaying on top of it, and making the secure layer as easy to use as possible, so instead of "go run this command to generate keys and then make an email subkey and then download that extention to your mail client, and then tell it to use that subkey and then figure out the recipient's key" etc it would instead automatically generate you a key and publish it somewhere (possibly on a regular keyserver), and automatically fetch the recipient's key based on their email with the user merely needing to press a button, if even that, and to back up their key (doable automatically, but everyone shouldn't send their private keys to any singular location, so would need additional questions about that)

    • @normahostetler7859
      @normahostetler7859 2 года назад +2

      Us, soccer moms, want to be able to freely post on social media and not be called domestic t.e.r.r.o.r.i.s.t.s. All social medias require an email and it ties it back to us.

  • @Atilolzz
    @Atilolzz 3 года назад +12

    Its amazing how the costanza meme survived for a decade and is still very relateable

  • @tac7826
    @tac7826 10 месяцев назад +5

    It's not a US honeypot. It's probably a Swiss honeypot, maybe a WEF honeypot or Swiss intel.

    • @Bond2025
      @Bond2025 9 месяцев назад

      With access granted to NSA and GCHQ.

  • @evpowered6574
    @evpowered6574 3 года назад +48

    When it comes to email the best you're going to get for privacy is your own domain and email hosting. Overall, consider what you send over email to be public.

    • @rampageviii7186
      @rampageviii7186 2 года назад +2

      how do u buy a domain?
      there aint no monero offering registrars.
      with domain hosting still fucked tho

  • @cherubin7th
    @cherubin7th 3 года назад +12

    Biggest problem is that most of your emails will go to people with surveillance accounts on gmail or others like that anyway.

  • @zeeweenor
    @zeeweenor 3 года назад +50

    ffs kenny i just switched to proton now you gotta do a followup on the best secure email service

    • @shrimp_on_internet
      @shrimp_on_internet 3 года назад +4

      Self hosting is pretty secure

    • @imgladnotu9527
      @imgladnotu9527 3 года назад +2

      @Big man pretty sure email hosting doesnt take much. All you need is a stable internet connection i suppose.

    • @tcideh4929
      @tcideh4929 3 года назад +31

      @@shrimp_on_internet sef hosting just straight up not a option for 90% of people who use email.

    • @trik9464
      @trik9464 3 года назад

      @Big man riseUp probably

    • @kekag
      @kekag 3 года назад +7

      He answers your question directly in the video:
      14:18

  • @systemthirtytwo
    @systemthirtytwo 3 года назад +47

    This is gonna be interesting.

  • @XaFFaX
    @XaFFaX 2 года назад +10

    You can use any kind of throwaway email services as second email. I am almost sure they do not have filters for all of them. Hardly it will make you more "visible" if you are using a "common" service rather than setting up your own email server on a obscure VM somewhere in the middle of nowhere.

  • @xrichxlen
    @xrichxlen Год назад +6

    Do NOT click the description link! The "privacy watchdog" link, now (May 2023), links to a dangerous page where suspicious animations occurred and I quickly received Trojan malware (HTML FakeAlert WRN). I tried to post a version of this comment this earlier, but YT did its comment-deletion thing - I am unsure of why. Perhaps this one is different enough to be allowed.

  • @v3eboy228
    @v3eboy228 3 года назад +43

    Love it, you have a.. dare I say it?.... BASED way of presentation man. Been a longtime protonmail user, and the issues you're raising are alarming

  • @downrightlefthiill8081
    @downrightlefthiill8081 2 месяца назад +1

    Damn. Damn damn damn damn. I dodged a bullet here. Phew! You're a hero my guy. Idk what I'll do without you. ❤

  • @XZenon
    @XZenon 3 года назад +7

    >melt the server with thermite
    I was about to comment that lmao
    I may not agree with you in every video but damn I love your sense of humour.

    • @MentalOutlaw
      @MentalOutlaw  3 года назад +14

      Ya, the problem with thermite though is the ignition source has to be hot enough to get it going.

    • @XZenon
      @XZenon 3 года назад +3

      @@MentalOutlaw Magnesium strip + Christmas lights

  • @Lystr0saur
    @Lystr0saur 3 года назад +9

    I have absolutely 0 clue what the terms this guy uses in his videos mean, nor do I understand much of what's going on; yet these videos feel very informative and entertaining to me somehow.

  • @Cookiekeks
    @Cookiekeks 3 года назад +3

    12:05 now you sparked my interest. Hope a video on this thing without IPs follows

  • @ronodipbasak4524
    @ronodipbasak4524 3 года назад +16

    5:50 - "SMTP port 25 that can not be encrypted"
    Don't most providers use SSL encryption like on port 465 or 587?

    • @GlenMerlin
      @GlenMerlin 3 года назад +6

      I know gmail allows port 25 but SSL encryption is the default

    • @auscompgeek
      @auscompgeek 2 года назад +1

      Any and all mail going between providers always go over port 25. Ports 465 and 587 are only for submission.

  • @johntr7565
    @johntr7565 3 года назад +12

    Again: "If you want something done, do it yourself"
    Waiting for the video on self-hosted mail server :D

  • @marknefedov
    @marknefedov 3 года назад +9

    Hated and Mental, greatest crossover ever!

  • @ddicas
    @ddicas 3 года назад +18

    What awesome coincidence: I'm right now creating a kind of "documentary + hands on" about privacy stuff for almost everything and all kinds of people and you upload this video :D
    (Seriosly, I just finished recording right now the desktop operating system security step and also installed gentoo on my laptop haha)
    I'm thinking about to invite some people (The Hated One, Newman) to this project and would like to invite you, Kenny, to participate (I've no idea when I'll finish the "hands on" video to start the documentary video, but anyway, I'll post a comment with this 2 video links when I finish everything)
    Anyway, again, great video and regards from Brazil o/

    • @baguettedad
      @baguettedad 3 года назад +4

      r/suddenlycaralho

    • @ddicas
      @ddicas 3 года назад +2

      Gostei da comunidade K
      se for tirar print, coloca o Genchu (do Gentoo) do lado huauhahua

  • @rafnavi4500
    @rafnavi4500 3 года назад

    Just saw an ad about proton on mooreslawisdead then the same day just hours apart, you upload this

  • @senorbill374
    @senorbill374 3 года назад

    yo thanks this was super informative
    keep up the good work :^)

  • @rpeetz
    @rpeetz 3 года назад +9

    As long as the feds dont steal my steam account it is fine

    • @egg5474
      @egg5474 3 года назад +5

      The feds want to play yandere simulator give me your password

    • @rpeetz
      @rpeetz 3 года назад

      @@egg5474 my password is **************

  • @jakedw25
    @jakedw25 3 года назад +6

    "Email a known drug dealer on April, 20th"...😂😭😂👌

  • @belliumm
    @belliumm 3 года назад

    Thank you for posting this Kenny

  • @iansmith8747
    @iansmith8747 2 года назад +4

    As I recall you can use a disposable email account for verification (and therefore this is not a deanonymizing step), the goal being to add difficulty in setting up spam accounts.

  • @RyanRoadReaper
    @RyanRoadReaper 3 года назад +32

    If it talks like a honeypot, and acts like a honeypot, it is a honeypot

  • @DxBlack
    @DxBlack Год назад +13

    You will note that nowhere on their website do they claim their service is for individuals who need the utmost high of privacy and anonymity...it's for secure white and grey activities, like businesses; not government whistleblower or drug dealers.

    • @ryannorthup3148
      @ryannorthup3148 Год назад +2

      I doubt even greys would be safe & secure here.

  • @notsam9528
    @notsam9528 3 года назад

    Thanks I was waiting for this video

  • @ItsOnlyLogixal
    @ItsOnlyLogixal 3 года назад +6

    Ngl melting down the server with thermite when an intruder is detected was the funniest part of this video because who hasn't thought about that?

  • @Pro720HyperMaster720
    @Pro720HyperMaster720 3 года назад +4

    I think the Onion domain was mainly intended for accessing the service, maybe someone should ask in their community pages for features and improvements that they extend it for registration

  • @uKhyta
    @uKhyta 2 года назад +9

    How relevant the Video has become again... ironic

  • @romancvijanovic7130
    @romancvijanovic7130 Год назад +2

    Some mail providers have starttls enabled on port 25. Thus making it possible to have an encryption connection between two MTAs. But the standard is for it to be transported in plaintext.

  • @sirajqazi2361
    @sirajqazi2361 2 года назад +1

    Bro, you recommended Protonmail in your "Complete online privacy guide" video (2020)
    Better update that one
    Nice vid btw!

  • @toastybaconbus5737
    @toastybaconbus5737 3 года назад +8

    What email service would you recommend to receive banking and insurance information. Main goal is to protect from identity theft, not hide from the gov or any such thing.

    • @Bond2025
      @Bond2025 9 месяцев назад

      UK Banks and financial people BLOCK ProtonMail. I found this when I tried using an account.

  • @justethical280
    @justethical280 3 года назад +35

    Haha Mental Outlaw, even though i'm a person who is fairly good in security and IT , i still like the way you present this kind of news/information LoL. Stay safe man. Greetings from The Netherlands.

  • @vladislavkaras491
    @vladislavkaras491 Год назад +1

    Thanks for the video!

  • @cyf3r867
    @cyf3r867 3 года назад

    I love th end thanx buddy !

  • @botowner8623
    @botowner8623 3 года назад +4

    yes but its 10000% still better than gmail

  • @fosres
    @fosres 2 года назад +4

    Hi Mental Outlaw, may you do a video on Tutanota? Its also another end-to-end encrypted email service.

  • @hannecart
    @hannecart 3 года назад

    great summary at the end there

  • @teriyakipuppy
    @teriyakipuppy 3 года назад +4

    There's a saying in the kitchen. "When in doubt, throw it out!"

  • @Ultrajamz
    @Ultrajamz 3 года назад +4

    Whats more interesting is if websites begin to not require emails but instead require a signal account or something.

    • @TheUnarch
      @TheUnarch Год назад +2

      I second that thought!

  • @hof_prod
    @hof_prod 3 года назад +11

    but what about some 10minmail for the Recovery E-Mail?

    • @zimboiii9025
      @zimboiii9025 3 года назад

      why do they make it so difficult?

    • @hof_prod
      @hof_prod 3 года назад +4

      @@zimboiii9025 if you really think about it, its okay how they do it. Companies that are not interested in your Privacy e.g. Google require you to use your phone number to create an account. They "just" force you to have an other mail, for which you easily can use gorillamail or 10minemail

  • @AshishKumar-tg6zh
    @AshishKumar-tg6zh 3 года назад +3

    I am proud of you because the only person who can guide us in the right direction is you.

    • @andalinta
      @andalinta 2 года назад +1

      What?? Noo, do your own research. I only agree to half the stuff he says in this video and that is because I'm informed and I understand MY needs aro not those of everyone. You should strive for the same.

  • @arbazna
    @arbazna 2 года назад +7

    Regarding port 25, it could be encrypted via STARTTLS as far as I know.

    • @eDoc2020
      @eDoc2020 2 года назад +1

      More importantly, there's also a new MTA-STS standard which turns STARTTLS from opportunistic to mandatory for supported servers.

  • @gizka6816
    @gizka6816 3 года назад

    you really are doing god's work out here

  • @OblateSpheroid
    @OblateSpheroid Год назад

    Thank you for your work.

  • @dayumnson9769
    @dayumnson9769 2 года назад +6

    Are you about clickbaiting or actually informing people? Did you even read their homepage?
    All their clients and bridges are e2e encrypted and open source.
    It seems that this is more "how you feel" than what it is.
    anyway, you do you.

  • @John_Gaye
    @John_Gaye 3 года назад +4

    The phone verification is easy to bypass with a free sms site, still spooky tho

  • @drasticfred
    @drasticfred 2 года назад +1

    "Encryption of email body/contents" is just a marketing/advertisement polishing feature by this company. Almost all email you receive in plaintext. Plus you can encrypt all your email body/contents by yourself without relying a third party, no hassle required.

  • @TIOLIOfficial
    @TIOLIOfficial 7 месяцев назад +2

    No, it's not. It gave some French dude's IP information to the Swiss government when ordered to track him. This was in 2021.

  • @zacktrujillo3473
    @zacktrujillo3473 3 года назад +3

    IVPN also makes some honest claims about VPN security and they also accept cash. IVPN is slightly cheaper, I'd stick with it.

  • @rallias1
    @rallias1 Год назад +2

    Ok, I'm going to pick the same nit here that got me kicked out of DEF CON 30's Hacker Jeopardy.
    Port 25 has the ability to use STARTTLS. If a mail server refuses to send a message to a server without STARTTLS, then no man in the middle is able to intercept the contents of that email, only the two MTA's at either side.

  • @MusicToTheEars141
    @MusicToTheEars141 3 года назад +1

    Yes! You gave THO some credit!

  • @throwaway9911
    @throwaway9911 Год назад +2

    Also, I would like to point out that feds buy for something like 60% of TOR networks development.
    Kenny you should make a video on that...

  • @JamesQHolden
    @JamesQHolden 3 года назад +11

    CERN uses it, I'd imagine they'd be uptight with security hiring one of the finest scientists out there

    • @imgladnotu9527
      @imgladnotu9527 3 года назад +8

      For a second there i mis-percieved CERN as SERN there.

    • @kashmirwillwin3124
      @kashmirwillwin3124 3 года назад +13

      @@imgladnotu9527 SERN sounds like a bootleg version of CERN some anime about time travel would come up with to bypass copyright. elpsykongru

    • @MrEdrftgyuji
      @MrEdrftgyuji 3 года назад +3

      They don't really care if US/Western government agencies spy on them. They only really care about the Chinese or private organisations / hackers.

    • @retroman7581
      @retroman7581 3 года назад +2

      @@kashmirwillwin3124 the organisation is near, we need to move!

  • @TheUnitedNations.
    @TheUnitedNations. 3 года назад +5

    Do these concerns extend to ProtonVPN?

    • @twei__
      @twei__ 2 года назад

      Not really afaik, but proton drive *could* be affected

  • @xastronix
    @xastronix Месяц назад +1

    The point is, is it better then Gmail or other big companies? Definitely YES!

  • @user-en6mj2ck9v
    @user-en6mj2ck9v 2 года назад

    Nice video, thanks for the details, any idea of what to use instead ?

    • @beybrain7896
      @beybrain7896 Год назад

      He said at the end that a private email provider doesn't exist.

  • @donaldalexandre2641
    @donaldalexandre2641 Год назад +4

    Heard A LOT misinformation and Red Herring arguments here. Creator needs to do more reading.

    • @juliana1313
      @juliana1313 Год назад +1

      I like his videos about linux. but anything else he makes videos about is misinformation. I will never forget when this dude said twitter before elon musk was a safe space when in fact twitter had a cp problem kek

  • @da_cat
    @da_cat 2 года назад +3

    Me using the same Yahoo mail since i was a minor. Now i'm in my 30-ties Didn't even bother to change the password despite getting an email from Yahoo themselves telling me they have been data breached like 2 times 😂 Perks of being poor and having nothing to lose

  • @ddenobrega8298
    @ddenobrega8298 3 года назад

    I was waiting for this one

  • @MA-naconitor
    @MA-naconitor Год назад

    An improvement on their part is, that you can now use a recovery phrase instead, that you can store in plain-text. More vulnerable (they emphasise this), but much better than a recovery e-mail.

    • @seifshebl7404
      @seifshebl7404 11 месяцев назад

      How to use it, please? I don't find that option when signing up. What country do you login from?

  • @russellpearce3749
    @russellpearce3749 3 года назад +8

    I am not trying to hide from anyone or do anything illegal. I just like the fact that they don't sell data and I don't get hit with Annoying ads protonmail is fine for me

  • @yuiooiuy2167
    @yuiooiuy2167 3 года назад +8

    This video: "I'm going to take boiler plate snippets and make extrapolations for the entire company!"
    Also, Mental outlaw doesn't understand that https + onion are standard practice for orgs that understand encryption. I guess he was bored and needed a video with no real points or new information on his channel.

    • @joshuawlawson
      @joshuawlawson 3 года назад +3

      Mental Outlaw and Techlore both spread a lot of FUD.

    • @wallegamecube
      @wallegamecube 3 года назад +4

      Yeah I'm not too happy with this video either. His points about email being a horribly insecure protocol that anyone can spy on are valid, but I wish he clarified how Proton is still one of the best non-Google options that's actually user-friendly

  • @waltz9230
    @waltz9230 2 года назад +2

    Random but important question, why did Protonmail STOP asking what kind of encryption you wanna use upon account creation? I made a new account recently and this time it didn’t ask me if I wanted lighter or more robust (but slower) encryption. Granted, I creates my last account with the paid plan from the get-go where as with this new one I started with the free plan first. This is kind of odd.

    • @libertyworker5886
      @libertyworker5886 2 года назад +1

      I've seen it on mobile and desktop, desktop no longer asks you but mobile(through a browser)asks you

  • @suuuken4977
    @suuuken4977 2 года назад

    At 10:20 when it required an email to authenticate you're a human, couldn''t you just use a temporary email service online via the tor network and then it will be untraceable? Am i missing some key detail?

  • @45678213914284289421
    @45678213914284289421 2 года назад +3

    About secure payment: something its weird with this. Last month I bought their vpn by bitcoin and I was surprised that you can't do the same with email so I've checked it and now I didn't had that option either (neither in mail or vpn) but I still have option to extend account by bitcoin and cash. My transaction was after you published video, so probably they have weird payment policy or this is just a bug. You can pay anonymously if you're determined enough. :)
    Edit: and about encrypted emails - if you have more then two brain cells you should figure out that if you send encrypted email to provider that doesn't support it and your recipient didn't revived random gibberish it had to be decrypted at some point - read about service before you start using it.

    • @user-hq4jz6lc9d
      @user-hq4jz6lc9d 4 месяца назад

      Hmm. Would they accept payment with pre-paid credit cards, purchased with cash?

    • @45678213914284289421
      @45678213914284289421 3 месяца назад

      @@user-hq4jz6lc9d I don't know I don't use them.

  • @w3w3w3
    @w3w3w3 2 года назад +6

    this video was before its time =D they handed someones data over to the feds couple days agoooooooo =D

  • @rodiculous9464
    @rodiculous9464 Год назад +1

    When you said "biggest pieces of" I was expecting something different than what you said next

  • @snowblowerrr
    @snowblowerrr 3 года назад +1

    Do a video next about how to anonymously communicate over the web.

  • @ugly717
    @ugly717 3 года назад +53

    I only switched to Protonmail to get away from Google and it's funky service(and also i dislike Google) so this video didn't make me thunk too much. Good points though. Though might make a cock li account for the funny names

    • @someguy4853
      @someguy4853 3 года назад +1

      Seems you need to know someone who already has a cock.li email account in order to get your own.

    • @OVXX666
      @OVXX666 3 года назад +1

      you can't get a cock.li i tried :(

    • @someguy4853
      @someguy4853 3 года назад

      @@OVXX666 ya kind of sad would of been funny to have one.

    • @McSinyx
      @McSinyx 3 года назад +1

      There are other email provider like NixNet and Disroot, they do not offer extra privacy technically but they run on 100% FLOSS.

    • @ambivalentonion2620
      @ambivalentonion2620 3 года назад

      i want one for the domain but it needs invites :(

  • @damnmodz5468
    @damnmodz5468 3 года назад +3

    "Having multiple free accounts is not considered an acceptable use of our service (e.g. bulk-signups, large number of free accounts created by a single organization or individual). Free accounts can also only be created and maintained by their effective users (e.g. it is not acceptable to create accounts in anyone else’s name and later transfer credentials to that third party)."
    How can they enforce this if they do not keep log of IP addresses?

    • @moonlitee
      @moonlitee 3 года назад +1

      trust me, they don't enforce it

    • @moonlitee
      @moonlitee 2 года назад

      @@justacat.1428 oh maybe in that case, but i have like 20 accounts and they haven't done anything (doesn't mean they don't keep ip logs, they probably do)