10 ms·
Proton spam and the AI consent problem
- Terr_ 8mo ago> Has anyone else noticed that the AI industry can’t take “no” for an answer? AI is being force-fed into every corner of tech. It’s unfathomable to them that some of us aren’t interested. The entire AI industry is built upon a common principle of non-consent. I can't help but see the spam as more circumstantial evidence of a bubble, where top-down "pump those numbers" priorities overrides regular process.
- hsbauauvhabzb 8mo agoAgree. The number of services i use where the apps continually add new marketing preferences which are defaulted to ‘enabled’ despite the fact that all other preferences are disabled is disgusting and clearly used by some companies to ignore people’s actual preferences. LinkedIn is one of the worst offenders.
- duskdozer 8mo agoHave you noticed certain financial providers sending blatant marketing emails with no unsubscribe option and a comment along the lines of "these emails are not marketing"
- pil0u 8mo agoThis is illegal practice in the EU
- duskdozer 8mo agoIt's illegal in the US too as far as I'm aware. But you missed the part where they clearly stated "it's not marketing" ;)
- nkrisc 8mo agoThey go in the junk folder and then get marked and reported as spam.
- chrisjj 8mo agoDangerous, since this invites genuine service emails to be junked.
- MiddleEndian 8mo agoI think that's fine. If 20% of the emails from some company (let's say Paypal) are spam, then all email providers (especially Gmail, the largest provider) should mark ALL of their emails as spam by default until they stop spending spam. If they want to keep spamming, they can at least humiliate themselves by telling people to check their spam folders for their emails.
- chrisjj 8mo agoIt proved not fine for me on an occasion of missing a service email and losing an account as a result.
- MiddleEndian 8mo agoI would say the base problem is that said organization sent you spam and then disconnected you, rather than the spam filter.
- chrisjj 8mo agoThe disconnection was the fault only of the spam filter hiding the service mail.
- MiddleEndian 8mo agoI mean if said company first spammed you and you marked them as spam, then it is on them. No different than if someone sent you a bunch of unwanted letters and you threw them out, but one of them happened to be relevant. It's on the organization sending you junk.
- chrisjj 8mo agoYet rife. My complaint to a major UK provide was rebuffed with the blatently false assertion that the email promoting a website refresh was an essential service email.
- hsbauauvhabzb 8mo agoYes, but not anywhere near as annoying for me at least.
- vee-kay 8mo agoThe trick is create a filter to weed out such junk. And if a company sends me marketing fluff without unsubscribe option, then it goes in the junk/spam folder, and I may eventually discontinue my account with that service provider altogether. Because I periodically check my sp/junk folder to see if legitimate emails got dumped there, so I eventually know who's a spammer and who's not.
- genewitch 8mo agocontrol+alt+shift+Win+L
- junon 8mo agoThis never stops annoying me that it exists.
- duskdozer 8mo agoWhat the fuck lmao
- MiddleEndian 8mo agoIn Windows 10, they added a shortcut Ctrl+Win+Alt+Shift to open Microsoft Office 365 (or whatever they call(ed) it). Caused me a ton of confusion and annoyance when I picked up my laptop by the corner of the keyboard.
- genewitch 8mo agodon't do that, that made me wince a bit, toughbooks from yesteryear aside.
- dwedge 8mo agoWhenever I login to LinkedIn I get "emails aren't getting through to your main email address". 1. That's by design, because you spammed the shit out of it. 2. Given that all I do is send them to /dev/null, HOW DO YOU KNOW?
- mnw21cam 8mo agoThey're checking to see whether any of the links they put in the emails are being fetched from their servers. It's stupid, but it works for most people. I had a similar situation with SMS messages that were being sent to me with links informing me of status updates. These texts were useful, and I would go over to my real computer to check the web site. Then after a few days the text messages said "It looks like these messages aren't getting through to you, so we'll stop sending them." Which is also stupid, but it works for most people that load the web site on their phone from the SMS link. God help you if you have a dumb-phone.
- Sharlin 8mo agoYou don't need the recipient to actually click on any visible link. Tracking pixels are the oldest trick in the book.
- pluralmonad 8mo agoOnly if people naively automatically load remote content. My inbox receives the bits that actually come in the email and nothing else. If you send an empty email with all images, you sent an empty email...
- direwolf20 8mo agoProbably tracking pixels in the emails
- dwedge 8mo agoSo they'd miss it anyway, my mail client is firewalled to only be able to access the mailserver. I've been unsubscribed from a handful of newsletters because I don't read them. I replied to one and told them I did, even reached out on Twitter, but they still deleted me.
- hattmall 8mo agoThe really strange thing is that so much of it doesn't work. Like I get that the SOTA models perform some tasks quite well and have some real value. But the AI being implemented in every corner creates a lot of really bad results. The Shopify code assistant will completely wreck your site and basically gets nothing correct. It will write 100 lines to change a color of a single DIV. The Amazon product Q&A will give you wrong information more frequently than not. In what mind frame is it logical or necessary to put these extremely poorly functioning products in to the wild?
- TeMPOraL 8mo agoIt's a desperate attempt at staying relevant, even if most of those companies don't realize it yet. Because of its general-purpose nature, AI subsumes products. Most software products that try to "implement AI in every corner" would, from the user's POV, be more useful if they became tools for ChatGPT/Claude/Gemini. People's goals are rarely limited to just one software product, and products are basically defined as a bag of tools glued with UI, that work together but don't interoperate much with anything else. That boundary drawn around a bunch of software utilities, is given a name and a fancy logo, and sold or used to charge people rent. That's software products. But LLMs want to flip that around - they're good at gluing things, so embedding one within a product is just a waste of model capabilities, and actually makes the product boundary more apparent and annoying. Or in short: consider Copilot in Microsoft Word, vs. "Generate Word Document" plugin/tool for a general LLM interface (whether Gemini webapp or Claude Code or something like TypingMind). The former is just an LLM locked in a box, barely able to output some text without refusing or claiming it can't do it. The latter is a general-purpose tool that can search the web for you, scrap some sites and run data analysis on results (writing its own code for this), talk results over with you, cross-reference with other sources, and then generate you a pretty Word document with formatting and images. This is, btw., a real example. I used a Word document generator with TypingMind and GPT-4 via API, and it was more usable over a year ago than Copilot is even now. Partly because Copilot is just broken, but mostly because the LLM can do lots of things other than writing text in Word. Point being, AI is eroding the notion of software product as something you sell/rent, which threatens just about the entire software industry :).
- njhnjhnjh 8mo ago[flagged]
- brauhaus 8mo agoThis is not an AI problem, it's an "data privacy + lack of consequences problem". It happens everywhere. I mean, have you ever tried making an airline company to stop sending their shitty miles newsletters? Only way to stop is to start fining these companies.
- ozlikethewizard 8mo agoNot sure where you live, but inside the EU / UK this is rarely a problem because the companies do get fined. If youre having problems like this report them to your relevant authority. But as another commentor noted, AI bubble makes paying spam fines more worthwhile than bubble popping.
- brauhaus 8mo agoOnly if the company is headquartered in EU/UK, right? Proton, for example, is headquartered in Switzerland. Even if it wanted, there would be no legal entity in EU to be fined.
- toby- 8mo agoMy understanding is that a company's location is largely irrelevant; a company becomes subject to the GDPR when they handle EU citizens' data (or UK GDPR when it's UK citizens), and the EU/UK will still try to fine companies that aren't resident in the EU/UK - enforceability is a different question, although non-payment of fines opens the door to other remedies e.g. blocking access, seizing assets, etc.
- chrisjj 8mo ago> Not sure where you live, but inside the EU / UK this is rarely a problem because the companies do get fined. Here in UK is is a frequent problem and companies rarely get fined e.g. MS never.
- weedhopper 8mo agoTrue, microslop has a record of breaking GDPR and changing ToS without notifying users and looks like they are free to do so.
- cwillu 8mo agoImplementing this sort of “functionality” is always the department of a junior team, so that the obvious sorts of questions about defaults can be answered with “a junior dev was responsible for the implementation and messed up”, even though the mess up was by design.
- RayVR 8mo agoI have often found proton’s intrusive marketing campaigns annoying. I use them for email and that’s all I want. Every time they market some new product to me, I get closer to moving to a new provider.
- deleted 8mo ago[deleted]
- chc4 8mo agoI saw a Mastodon tweet a while ago, which went something like: Do tech companies understand consent?: - [ ] Yes - [ ] Ask me again in a few days
- littlecranky67 8mo agoThis. We must change laws that the above field is not considered as given consent. And while we are at it, we must change "silence is agreement" to "silence is disagreement". This applies to change of ToS, price increases etc. That means if I don't click a link with a button "I agree", the ToS change is not accepted - that means they have to cancel/delete my account.
- bayindirh 8mo agoDidn't FCC remove "1-click unsubscribe" requirement since it can "provide more choice and lower prices to all users across the board" (since the companies can rip off more users and create pseudo-lower prices)? EU has its GPDR and it has some teeth, but US is currently hopeless on that front, for now, from my vantage point. I'd love to be stand corrected though.
- SpicyLemonZest 8mo agoThe FTC established a "click-to-cancel" rule, but (as with just so many regulations in the US) it was blocked by an appeals court. Federal law says there's a hoop they have to jump through for rules with an impact of more than $100 million, and they didn't jump through the hoop because they didn't think the impact was that high.
- lelanthran 8mo ago> And while we are at it, we must change "silence is agreement" to "silence is disagreement". Maybe we should reframe their "silence is agreement" message as "silence is consent".
- pluralmonad 8mo ago
- Quothling 8mo agoLumo will likely be the thing that moves me away from Proton. I've been pretty happy with it, ever since they made the photo's app actually have shareable libraries it's been just as good as any other Google Mail/Photos/Files thing I've used. The password manager plugin for firefox isn't as good as bitwarden, but when you're paying it's part of the package so... If I have to encrypt my files before I use the drive, and they continue to build their AI spy into everything, though, then what is the point really? Anyway, it is sort of hilarious to report Proton as spam to Proton.
- TonyStr 8mo agoIt's bewildering to see privacy-focused companies like Proton and DDG jump on the AI train. I guess privacy is just a vehicle for attracting early adopters, and all those principles fall apart once their user base becomes large enough.
- fundatus 8mo agoWhat's the issue with a privacy-focused AI assistant that doesn't store all your data?
- direwolf20 8mo agoAnd completely optional.
- xigoi 8mo agoThe marketing spam, as mentioned in the article.
- neobrain 8mo ago> I've been pretty happy with it, ever since they made the photo's app actually have shareable libraries it's been just as good as any other Google Mail/Photos/Files thing I've used. Glad to hear you found a service that's useful to you! > If I have to encrypt my files before I use the drive, and they continue to build their AI spy into everything, though, then what is the point really? That would be concerning indeed, but there is no such integration today and it seems unlikely they would integrate non-local models into drive. Even on the mail side, any use of LLMs is optional, opt-in, and limited to text production (i.e. no training on your inbox).
- perching_aix 8mo agoI have a Proton mailbox I specifically keep around to serve as a honeypot, for tracking when one of the many annoying little services will inevitably mishandle the contact address I hand them. Over the years, the only spam I ever received there was from Proton. Quite the way to recalibrate my expectations, eh?
- genewitch 8mo agoi think i have a proton email address, but i never used it. i wonder. but i pay fastmail a whopping $15/yr to give me mailboxes on my domain, which i have always heard is a good way to track who's selling your data. So far, nothing has made it past the spam filter, and i don't check spam (how many valid emails have you found in spam in the last 5 years?); that being said apparently no one is selling my email address anymore. or, and this is a significant possibility: when i tell them companynickname@mydomain.li they just ignore the domain and put in gmail? For instance i gave Take5 "take5@" as my email and i never received anything from them. The guy even said "No; your email address" with a weird half smile; then i explained it's my own website and email, i can use any email address i want; that it will alert me if someone sells my email address. I doubt there's a flag on the auto oil shop's CRM or POS or whatever for "customer states they're proactive about email spam and their privacy"
- dwedge 8mo ago> (how many valid emails have you found in spam in the last 5 years?) Personally, running SpamAssassin, zero. However, this seems to be getting worse with the big providers deciding to drop domains they don't like from time to time. Selfhosted email will work for 4 years and then Google or Microsoft will spam them for a month for no reason. It always starts working again because I assume that what they are doing is technically anti-trust and running it for too long would make it obvious.
- genewitch 8mo agonot an issue for me in general. side channels for nearly everyone i'd need email-style communication with, especially if their primary contact method is handled by any FAANG. I send test emails manually; usually when a semiweekly newsletter sends a plaintext "apparently our newsletters are bouncing", which they detect by autoresponders autoresponding. they say it's been consistently 8 median autoresponses per newsletter for 18 years, so when they get zero...
- kenhwang 8mo agoOdd, I didn't even know Proton had an AI feature until I read this article. Didn't get an email or tooltip while using the app. Didn't previously explicitly opt-out either, and when I check my notification settings, Lumo product updates is set to disabled. Maybe someone's feature gate isn't working as intended? I did get the Github Copilot spam email today though.
- fergie 8mo ago> Proton for Business newsletter AFAIK you are legally allowed to spam businesses, but not individuals. A handy get-out clause for marketeers.
- robin_reala 8mo agoHow do you know the address you’re emailing belongs to a business? The head of A&A ISP in the UK used to regularly win ~£100 judgements in small claims from spammers because his personal email was leased for a nominal fee from aa.net.uk, the same domain as his business.
- ivan_gammel 8mo agoIf your email is used as a contact on Business subscription it is safe to assume that it is used for business purposes.
- fergie 8mo agoOP had checked that they would like to receive the "Proton for Business newsletter", and on that basis was deemed a "business".
- petesergeant 8mo agoI mean that's cute and all, but it's a party trick, and very unlikely it caused any actual behaviour to change.
- unethical_ban 8mo agoFile under "some business bro had this classified in the wrong newsletter". I don't see the big deal and I don't extrapolate this into some systemic disease with marketing emails.
- direwolf20 8mo agoThey do it every single newsletter?
- unethical_ban 8mo agoaaand I was right (allegedly). Account claiming to be Proton CTO says it was a technical screw-up.
- bflesch 8mo agoEver since my first interaction with their support is was clear that they DGAF about usability improvements that I'd care about. Time to build an alternative I guess.
- ivan_gammel 8mo agoI think we must make it clear that this is not related to AI at all, even if the product in question is AI-related. It is a very common problem with modern marketing teams, that have zero empathy for customers (even if they have one, they will never push back on whatever insane demands come from senior management). This is why any email subscription management interface now is as bloated as a dead whale. If too many users unsubscribe, they just add one more category and “accidentally” opt-in everyone. It’s a shame that Proton marketing team is just like every other one. Maybe it’s a curse of growing organization and middle management creep. The least we can do is push back as customers.
- bayindirh 8mo agoI believe this is combined with something I call "asymmetry blindness". They may say "but we send an single e-mail per month, this can't be bad". We the users get a barrage of e-mails everyday because every marketing team is thinking we only get their mail, and it makes our lonely and cold mailbox merrier. No, users are in constant "Tsunami warning!" mode and these teams are not helping.
- vintermann 8mo agoI'm pretty sure some people have performance metrics attached to their "newsletter".
- pseudalopex 8mo agoOur subscription product costs less than expensive coffee. Unused RAM is wasted.
- causalscience 8mo agoI only use Proton for the spam or temporary low value (and free) email accounts. Proton also tries to do everything, which I don't like. If I did I'd use Google. The thing I pay for is Tuta. The cheapest tier is way more generous than Proton and the product is simpler.
- guilhermesfc 8mo agoI have also been using Tuta for years. No complaints
- littlecranky67 8mo agoI have the exact opposite opinion. I use proton business together with their email, vpn, calendar, drive (on macOS), password manager etc. and switched specifically because of their encryption, data protection and fulls-size feature bundle. Plus, I migrated vom Office365 and it became a shitshow to manage and was full of bugs. And I had a separate bitwarden subscription, and a separate VPN subscription. Now it is one package, much preferred.
- causalscience 8mo agoOh yeah, having your passwords online is a great idea /s
- littlecranky67 8mo agoIt is, if they are encrypted. Without a password manager, I would inevitable have to reuse the same passwords over and over on my hundreds of different accounts. With a password manager, they are auto-generated random gibberish. And yes, even when using 2FA, you should have different passwords for all accounts. Bitwarden, OnePassword, LastPass, Proton Pass etc. are password managers with dozens of millions of users that agree.
- causalscience 8mo agoIt's not, because the world we live in isn't binary. It's not true that "it's encrypted therefore nothing can go wrong". Putting your password manager online increases the risk of an accident. And just because millions of people think this is a good idea, doesn't make it a good idea. Millions of people also reuse their passwords and that doesn't make it a good idea either.
- phacker007 8mo ago[flagged]
- LandenLove 8mo agoI also received the email from github about AI that the author mentioned. No matter what you do, they will keep pushing the AI slop onto you. For me, these kinds of emails especially stick out, because I like to keep my proton inbox clean and unsubscribe from everything I can.
- deleted 8mo ago[deleted]
- BrouteMinou 8mo agoI canceled my subscription, and deleted my account due to the nagging and promotional annoyances. I've contacted the support, but they basically don't care. There are not multiple ways to fight back against this behavior. I am now with mailfence until they start the same circus.
- unethical_ban 8mo agoY'all are wild. I have most of their emails turned on and barely think about Proton's comms. Rarely get one, briefly skim if I do.
- Night_Thastus 8mo agoYeah, I've always been surprised at how negative HN can get about Proton. They're not perfect, but man at least they're trying to fight the privacy fight. I've always had a very good experience with them. It's cheap, fast and their spam filter works well. Maybe 1x-2x a year I get an email from them about some promotion but that's it.
- cheschire 8mo agoI always wondered if it’s just a few actually upset customers mixed with a ton of astroturfing by competitors pretending to be outraged proton customers.
- cantalopes 8mo agoI also get pretty pissed of just ignoring gdpr, i just started to downright threaten them on support channels reminding that ignoring gdpr may cost them 2% of annual company turnover or 2 mil. eur, whichever is higher. You would be surprised how many ridiculous "oh sorry some error in system" excuses you're gonna get. Right, that email accidentally slipped INSERT INTO spam slop database on its own. And since i started to not explicitly opting in anywhere i know that when i receive a marketing email its abuse of my personal information. Under gdpr you need to explicitly consent to marketing communication. When you register to a service and receive spam you need to opt out from - that's an abuse. Some company try to argue they do so under "legitimate interest" clausule but that's bs and would not hold in court. For example, purchasing a product is not a valid legitimate interest for sending out eshop spam, they would lose. When the incident repeats or i just get really pissed i go full karen and report them to authorities. I know two busisses had legal troubles because of me because i received deeper follow up emails while solving the case and i am happy for it. One company that abused my personal data that i ended up not reporting was Telekom: when i contacted their support about spam incident and asked them for log of personal data and all of my consent logs and physical signatures to prove my consent, after which they said "it was a db error" (lol), and when the incident repeated i told them i am about to report them and they offered me 1 year of free internet - i said ok and never received a single spam from them ever again. Fight back, you have the screenshots, you have the logs, ask for proof, report.
- direwolf20 8mo agoYou can take the 1 year free internet, and then report them. It's not legal to commit a crime and then bribe someone not to report it.
- anigbrowl 8mo agoThis isn't an AI issue. Marketing departments have been like this forever, or at least since the infamous Canter & Siegel 'Green Card' email. https://en.wikipedia.org/wiki/Laurence_Canter_and_Martha_Siegel https://en.wikipedia.org/wiki/Laurence_Canter_and_Martha_Sie...
- prism56 8mo agoThe same reason I pay for proton and they insist on showing ads for upgrading my subscription. I click no don't show this and then a month later when there's a different promotion, there's another ad at the top
- LucaMo 8mo agoLegit point and agreed with everything, however wait until an email address of yours reaches the database of lead generation websites and you will see that you will never be able to keep count of the violations. Newsletter lists add your email in automatically and people sell you stuff without the unsubscribe button in the email, so no way to block them... I understand your concern but dealing with far worse
- dostick 8mo agoEven more hypocrisy:- if you have Proton Unlimited subscription, Lumo AI will be limited, not remembering conversations. And when it’s promoting you to upgrade, mentions in the same message that your Lumo is limited while you have Unlimited subscription.
- grub5000 8mo agoI’m not sure it’s quite fair to call this hypocrisy. Lumo was introduced separately after the Proton Unlimited subscription, and it was never claimed to be included in Unlimited (they also have a handful of other products like Standard Notes that are not included)
- danielhep 8mo agoThis problem, along with general annoyances at Proton’s lack of focus on a good email experience pushed me over the edge to move to Fastmail. I’m so much happier. Proton Mail Bridge would often pin one core of my laptop CPU, draining my battery, and it was still slow to sync new email. With Fastmail, incoming mail is so fast that the verification codes are already there before I can alt tab over.
- StrangeSound 8mo agoI'm in the same boat. I think part of that is Proton is spread across a huge suite of products and features, whereas Fastmail is specialised in one.
- Cthulhu_ 8mo agoIt feels like Proton is trying to build a solid Europe-based alternative to Microsoft 365, which is necessary but also very ambitious and expensive.
- throwaway173738 8mo agoProton’s pricing is really frustrating for me because I want to buy upgrades to only a few services like Pass and email. Your only option on their service is to select either Pass or Mail. You cannot buy both and you will be downgraded on one if you try to buy the other.
- jnurmine 8mo agoDoesn't Proton Unlimited have both?
- chrisjj 8mo ago> Fastmail is specialised in one. Sadly untrue since they added calendar. However I'd would say the email service and support remain excellent regardless.
- HackerThemAll 8mo agoI lost all respect for Proton. They've been running ragebait ad campaign on Facebook, maybe also on other media, I don't know that, with that rage especially targeted at Google, spreading fake information and hate.
- pelario 8mo agocould you tell more details or links about that ?
- HackerThemAll 8mo agoJust browse their Facebook profile. It's enough of an evidence. If that's not enough, just like couple of their posts and you're gonna witness the b.s. in their ads.
- osmsucks 8mo agoGreat timing: I just received a Copilot spam email from GitHub. I don't remember opting in to such marketing communications, instead I generally opt-out from such communications as soon as I sign up to a service...
- Tepix 8mo agoSame here. They created a new newsletter and added you to it without your consent.
- antonyh 8mo agoI got the same email on the same date. Unsubscribe told me it was from the 'important announcements' list - I fail to see how this could possibly fall into that category. I guess I can't have important announcements from Proton in the future if it's polluted with these low value messages.
- dwedge 8mo agoThere's one recruiting company I had contact with in 2017 (pre-GDPR, with no checked consent after) and they keep sending me marketing-disguised-as-GDPR emails. "Reply to tell us you want to keep hearing about our career insights newsletter that you never signed up for, or we'll delete your data in 30 days". In the end I got sick of them repeating this and never deleting the data, so I sent them a SAR. I don't care what data they have but if they want to play the GDPR game so do I.
- dwedge 8mo agoThis is good timing actually. I've been self-hosting SimpleLogin for a while but was considering the lifetime subscription to Proton to get it (it comes with ProtonPass but I selfhost VaultWarden). Last week I logged into my Proton mail that I'd used last year for some government contact to get the dates, and they'd deleted the account for inactivity. Ok, I don't pay, they're entitled. But now I see this and I think maybe I'll save the $150 or whatever it is.
- mtlmtlmtlmtl 8mo agoI'm so fed up with Proton. I will be taking my business elsewhere. Instead of making a great product for X, they've decided to make a series of extremely mediocre products for P, Q, X, Y, Z and W, all of which are left missing the most basic features for years. Features which even the free alternatives already have. Things like supporting unicode in email headers without having to use punycode, creating mailboxes from sieve filters and a bunch of other sieve expansions, and decent, portable, non-bugridden integration with email clients. Protondrive has such dogshit speeds it's basically completely useless. The nat-pmp support on their vpn servers is very strange, and it took me a couple weeks to craft a script that could handle all of its idiosyncrasies, none of which are documented. I haven't even bothered trying their calendar, password manager, or the Yet Another AI Service they keep sending me upselling emails for. I don't need any of those things, but I'm sure they have similarly lacklustre feature parity. Doesn't help that when i notify them about these things, their support people just gaslight me. "I've notified our development team about this". Then nothing happens. I told them about the speed issue with protondrive when it was new, that was years ago now. Still not fixed, no updates, nada. I will be moving to something like fastmail, plus some other vpn service, since those are the only two products of theirs I'm actually using. It seems like I'll get a far better product in both cases for almost half the overall cost.
- deleted 8mo ago[deleted]
- gingerlime 8mo agoI’ve had a similar experience when signing up for Office365 and started getting promotional emails to CoPilot. These (2) emails were without an unsubscribe option. I contacted MS support and after some back n forth they claimed it was a transactional email that doesn’t require consent or opt out. Clearly promotional and not necessary but they won’t listen. I’m in the process of filing GDPR + ePrivacy complaints, but it’s a tedious process, unlikely to do anything.
- tmarice 8mo agoI've been using Fastmail for years now, and I'm completely satisfied. Custom domain + built-in masked email functionality works great.
- chrisjj 8mo agoThe FM Masked Email is insecure in that there is a circumstance under which it can leak your real email.
- tmarice 8mo agoDo elaborate.
- chrisjj 8mo ago"WARNING: Fastmail Masked Email insecurity" https://www.emaildiscussions.com/showthread.php?t=81287 https://www.emaildiscussions.com/showthread.php?t=81287
- tmarice 8mo agoOne concrete vulnerability is mentioned in a linked thread and described here https://news.ycombinator.com/item?id=37791500 https://news.ycombinator.com/item?id=37791500 I have created a ticket with the Fastmail support asking them more details about the vulnerability you mention in your thread, I’m curious to see their response.
- chrisjj 8mo agoThere FM said: > When forwarding an email as an attachment and later checking the headers of the attached email, I could not find the X-resolved-to header this is odd, no? This header field should remain. And regarding that FM Privacy First declaration, this is now 404.
- tmarice 8mo ago
- jofzar 8mo ago> I don’t know about you, but I think that’s baloney. Proton Support had five full business days to come up with a better excuse. Please tell me, how can I have been any more explicit about opting out of Lumo emails, only to receive “Try Lumo” “From Lumo”, and be told that is not actually a Lumo email? As someone who is in support in tech (not proton) I can tell you exactly what happened. Day 1 they already knew which email it was, they probably had other tickets about this, they probably had an open discussion about this with marketing/product team. Day 2-4 was the support agent arguing with marketing/product about how it's absolute bullshit to send out a AI newsletter when the user has it unticked and what they are going to do so it doesn't happen in the future. Day 5 is marketing/product telling them that this is Working as designed and theu aren't going to stop this in the future. This is the day the support person works on this email with their team and potentially their manager. It goes through a couple of "rewrites" for liability/protecting ass. The end result is the email you got, they know you are going to give a bad CSAT/NPS survey and it's going to kill their metrics. They want nothing more to write and email that says, "Sorry marketing and product are fucking idiots and can't read. I fought for this to be disabled, but told me it's not going to happen, sorry" but culture and then not wanting to lose their jobs is why they didn't send this. I really hope you didn't give them a bad survey.
- deleted 8mo ago[deleted]
- direwolf20 8mo agoI hope they sued
- redbell 8mo agoHere we are! Day after day, I realize that even smaller tech companies suffer from or could not resist the temptation of Enshittification[1] once they start gaining some momentum. I feel this path had became inevitable since everybody is doing this, at scale. I barely could recall some names that stuck to their original motto over time. ____________________ 1. https://en.wikipedia.org/wiki/Enshittification https://en.wikipedia.org/wiki/Enshittification
- direwolf20 8mo agoYou do what makes money, or you are eliminated from the game. Such is life in capitalism.
- dschuetz 8mo agoEvery company seems to scramble trying to sell AI based products they have invested in so heavily, disregarding whether anyone needed them at all in the first place. This AI thing is going to implode so hard.
- mark_l_watson 8mo agoI subscribed to Lumo for two months. Mistral models were good and I like the idea of a private version of GPT. However, if you only use it a few times a week, it’s not worth the money.
- bdbdbdb 8mo agoI'm with proton on this tbh. It's not a lumo update, it's an attempt to tell people who don't use lumo about it's existence. Maybe it's not something you want to read but an email saying "hey, have you heard of this thing called lumo" is not something you'd send out to existing lumo users
- fundatus 8mo agoOver in the Proton subreddit we've been wondering if there is currently some kind of Anti-Proton campaign going on. Constantly people will loudly complain about completely benign things and get lot's of people agreeing with them.
- this_user 8mo agoEvery time there is anything posted about Proton on HN, there is an immediate wave of super negative comments, none of which ever offer any arguments of substance. It's always just some vague allegations, and this has been the case for years. It's pretty obvious what is going on.
- anonymous908213 8mo agoThese vapid fanboy-esque comments make me significantly more likely to believe that Proton is astroturfing than the inverse that you are implying, that some unspecified actor is engaging in a conspiracy to impugn Proton's reputation. That said, if criticising Proton is indeed a paid vocation and you have some concrete details about where I can get paid for my comments daring to doubt the uncompromising holiness of Proton, I'm all ears.
- 7bit 8mo agoCalling it an "anti- Proton campaign" or "benign" is just rhetorical hand waving. Those words let you dismiss criticism without engaging with the substance. Proton did deliberately email people who opted out. That is a GDPR violation, full stop. They are a large, well resourced company; "oops" is not an excuse. Criticism over that is not hysteria or bandwagoning, and blaming people for speaking up instead of the company for breaking the rules is weak.
- Tepix 8mo agoI had a similar issue with Microsoft today. They obviously invented a new "Copilot Newsletter" and subscribed my address to it, without my consent. I wonder what the legislation says (I'm in Germany). I know that some business related mails are deemed legal, but this seems to clearly cross the line.
- user34283 8mo ago[flagged]
- direwolf20 8mo agoOf course it appears repeatedly. It occurs every single time they run a new marketing campaign.
- gingerlime 8mo agono unsubscribe button in this MS Copilot campaign. And they’re trying to gaslight like it’s some essential notification when it’s clearly and blatantly unnecessary marketing spam.
- chrisjj 8mo agoUK legislation says it is illegal. MS are serial offenders and the UK regulator has charged them not once.
- gingerlime 8mo agoSame. Posted a comment about it [0]. I already filed a GDPR and ePrivacy compliants. Happy to share notes. Contact details in my profile. [0] https://news.ycombinator.com/item?id=46730206 https://news.ycombinator.com/item?id=46730206
- weedhopper 8mo agoHere is an interesting case of a failure of the regulations, I’m curious how this goes https://www.gofundme.com/f/hold-mojang-accountable-for-their-unlawful-behaviour https://www.gofundme.com/f/hold-mojang-accountable-for-their...
- nkmnz 8mo agoProton should pay that guy for his rage post. First time I’ve heard about Lumo, will certainly try it out!
- alphadelphi 8mo ago"Never attribute to malice that which is adequately explained by stupidity" - Robert J. Hanlon If you ever tried to setup a martech stack you konw what a PITA is to comply GDPR without any error
- tsylba 8mo agoThis make me think of the GitHub spamming issue. See, my GitHub email is not my main address, and when I got some it's either from a user of one of my repository or from a marketing team that extracted thousand of address from starred repositories to fake genuine email with my name and all. The things is, it's always a less than stellar product. It started with NFTs, calm down for a bit and now came back with a vengeance with AI startups. I guess it's a number game for them but I can't comprehend their lack of value, same for those peoples that subscribes to everyone just to gain a sub back (and judging by the number, a lot of people sub back without thinking about it, so it works). Damn I despise that marketing-bussiness hellscape that the internet slowly morphed into along the years. We can't have nice things because there will always be a prominent proportion of us that would exploit it for personal gain and we would do collectively nothing against it, for the name of liberal economic or something. And forward the enshitification goes.
- aborsy 8mo agoLumo is not end to end encrypted. The model is in some kind HSM? Are those trusted? If they are, I see some people might be interested.
- lighthouse1212 8mo ago[dead]
- g947o 8mo agoWhen I migrated my email from Gmail, I took a careful look at Proton and Fastmail. Proton's very questionable design and claims around encrypted emails and their service offerings made me concerned, which were the main reasons I went with Fastmail. So far it has worked well, and I hope it stays that way.
- heikkilevanto 8mo agoSame here. Tried out Proton and Fastmail, and chose Fastmail. Been happy with it for a few months so far.
- alex1138 8mo agoProton's UX just subjectively FEELS bad
- MrFinch 8mo agoI dislike Proton's excessive marketing on privacy and encryption topics, especially in their posts on X, where they always claim that accessing the internet without a VPN is a bad thing. It reminds me of Crypto AG. Everyone would be happier if they just focused on good products instead of excessive marketing. I'm tired of seeing their privacy slop all the time.
- bartbutler 8mo agoHey, Proton CTO here. There was a bug, and we fucked up. Support should have reported it up the chain and acknowledged this. Things happen, especially at scale, but we take comms consent seriously and will fix it.
- ivan_gammel 8mo agoThanks for acknowledging it. Your support team misattributed the email to Business category. It may help to have the exact name of subscription category in the footer of the message.
- bartbutler 8mo agoThat's not a bad idea, I'll see what people think. Note that clicking on the unsubscribe link will unsubscribe you to whatever comms preference was specified in the sending and tell you what it was.
- chrisjj 8mo agoThanks. Well done.
- Washuu 8mo agoCan you fix the fact that this new email spam category was added and that I was automatically opted into receiving it without my consent? That's fucked. I'm a paying customer and I keep getting advertisements in the Proton desktop applications for various things.(Black Friday deals, other stuff.) I should never see these advertisements if I'm paying you.
- devnullbrain 8mo agoI have the desktop app open right now. In the top-right corner is a nag saying 'Share your plan'. It's an ad for Proton Duo. I just clicked 'Don't show again'. I get a toast saying you won't show me that offer again and it's immediately replaced with a nag saying 'Refer friends'. It has its own 'Don't show again'. In August 2024 I sent Proton support an email with this text: >I pay 95.88 € a year for Proton and every time I open the webapp or the desktop program, I see this: >https://imgur.com/a/3kE6zJI https://imgur.com/a/3kE6zJI >Is there a tier of Proton that doesn't have ads? The support reply told me I can remove the button by clicking on it, then "Don't show again". If I was frustrated enough to email you about it, I'm guessing I clicked it. I have expressly opted out of ads for Proton Duo. You're interpreting this as me opting out of a single ad for Proton Duo. Changing the copy doesn't mean I have opted into comms about it. So I disagree you take this seriously.
- catoc 8mo agoTrust is maybe the most valuable commodity for a VPN provider… And I have the feeling Proton is gambling it away. It made me move to Mullvad. Despite the fact that in terms of performance Proton is slightly better. (underscoring just *how* crucial ‘trust’ is)
- alex1138 8mo agoFunnily, Proton was supposed to be the anti-Google, wasn't it? Maybe some of "Proton's not in the US, so not subject to scary NSA warrant canaries" Except... Gmail has handled spam pretty well? And at least if you do get Spam they actually tell you: https://news.ycombinator.com/item?id=6090712 https://news.ycombinator.com/item?id=6090712
- Cyan488 8mo agoFunny they mentioned the GitHub email. I got the same one and unsubscribed from every GitHub email immediately. I wonder if they track how fast people unsubscribe after opening particular emails.
- plagiarist 8mo agoThey do. Companies will track app uninstalls also.
- eightys3v3n 8mo agoI had a similar problem with SunLife marketing emails. I would unsubscribe from everything there was an option for, then a month later I would get another marketing email setting personal finance advisors. I spoke to support to be told how to unsubscribe, then that it "was an account information email not a marketing email so I cauld not unsubscribe". Eventually after escalating I was put on a do not email list and haven't received emails since; though they do still send crap to my work email.
- gampleman 8mo agoI tend to have a policy: I will click on your unsubscribe button once, after that it's straight to 'report spam'. If that sinks your domain ratings, that's on you.
- eightys3v3n 8mo agoYeah except once in a blue moon they send an email I do need that really is account information and all from the same SunLife email :/ Otherwise I have the same policy.
- njhnjhnjh 8mo ago[dead]
- blabla_bla 8mo ago[flagged]
- aprentic 8mo agoI really hope the Proton PMs are watching this. Their main business offerings are privacy and security. The fact that they were able to pull customers away from Google shows that switching costs are low. Your reputation is your moat. If you ruin it by acting like Google, you're filling your own moat.
- vee-kay 8mo ago[flagged]
- prussia 8mo agoTerrorist attacks and perverts are every government's excuse to crack down on freedom. Refusing to comply with an authoritarian government like India's is a plus in my book.
- vee-kay 8mo agoYour plus is someone else's minus. Of course, if you or your family are not the victim of a terror attack, you may not care if others are impacted by it. After 9/11, USA did the biggest crackdown on terror, including domestic security overhaul such as stringent security checks in airports, more pervasive surveillance, etc. Microsoft has recently given FBI recovery keys for Bitlocker to unlock a suspect's laptops: https://techcrunch.com/2026/01/23/microsoft-gave-fbi-a-set-of-bitlocker-encryption-keys-to-unlock-suspects-laptops-reports/ https://techcrunch.com/2026/01/23/microsoft-gave-fbi-a-set-o... And this was for fraud investigation, not even a terror investigation case. Every nation responds to repeated terror attacks in a similar way. Increased surveillance, increased scrutiny, increased vigilance, retaliatory strikes. What do you expect? Let terror attacks happen, try not to prevent them, try not to retaliate at terrorist networks and nests? You live in a cosy idealistic world, if you think that terrorism can be handled by ignoring it or its mechanisms of communication.
- pluralmonad 8mo ago"Every nation takes advantage of the opportunities that are terrorist attacks in a similar way" If you think these crackdowns are for your own good, then it is you that lives in an idealized world.
- crazygringo 8mo ago> Has anyone else noticed that the AI industry can’t take “no” for an answer? AI is being force-fed into every corner of tech. And yet this blog post is guilty of the exact same thing. It's just a complaint about which marketing messages get categorized as which newsletters you can opt in or out of (a valid complaint but pretty boring), but slaps "AI Consent" in the title to turn it into clickbait because the marketing message happens to be about an AI product. This spam has been a problem for decades. It didn't arise with AI. I haven't even noticed any uptick with AI.
- 0x1ch 8mo agoAbout six months ago I switched to completely self hosted email in Hetzner, waited the billing period to receive outbound access, but still use free forwarding for outbound by default. People always complain on forums about the struggles of self hosting, but outside of an occasional email I have to whitelist because of spam filters, it's nearly hands free (mailcow). I setup aliases for every single one of my existing protonmail and gmail accounts, and now have them forward to my aliases. I can still use my old accounts, but everything is now ran through my systems, my data that I control. I recommend others look at doing the same.
- r_lee 8mo agoIs anyone actually like super hyped about "Building AI Agents" with this and that? I wish I could get excited and just become a 100% AI Agwnt vibecoding all day and building AI agents to do AI stuff but like, I don't know? Is there a crowd that just drools whenever a new way to "Build AI Agwnts" or "Agentic Workflows" comes out or something?
- davidee 8mo agoI've been using proton for a year after migrating from Rackspace and I'm done. Not because of this article, but I might as well pile on: 1. I use a custom domain. Turns out that there are two competing features, not-at-all documented. If you use a catch-all, like I do, AND use specific addresses for sending, the two are incompatible to some degree. Which is bonkers. Example: with a catchall I can create any address I want (and I do). Some store wants an email for a big discount, cool, here's a throwaway. Buying something online, here's a throwaway. Now sometimes, I need to reply using that throwaway. Turns out in Proton, this triggers a gotcha. As soon as I add the throwaway email to my list of email addresses for sending, I enter a world with a limit of 10 max. That's fine, I can disable them right? Nope, it turns out if I disable them in order to add aothers, Proton blocks those addresses *even though I have a catch-all*. WHAT?? Worse, if I try to delete the addresses, Proton will also delete the associated messages in my Inbox/folders. Excuse me? 2. What really pushed me away: Search. Whatever proton is using under the hood is easily the worst search experience I've ever had from a mail product, and I use Thunderbird on my work machine. Notable: Proton Bridge. I get why, but it's just terrible. So many rough edges. Just not worth it.
- thejoeflow 8mo agoIsn't the search bad because they can't search email contents? As long as the term is somewhere in the metadata (title, sender email, sender name) it seems to work ok. I agree though that the user experience isn't great because of this limitation. You kind of have to remember what the title of the email was for what you're looking for. Searching for "flight ticket" results in mixed success
- sabellito 8mo agoThey can search contents. You have to activate local indexing in the search UI itself.
- devnullbrain 8mo agoThe indexing needs to be refreshed almost every time I use it.
- trvz 8mo agoProton is frankly a bad company and this is unsurprising.
- Insanity 8mo agoI think the last line is important. Proton isn’t perfect, neither are others. And proton is imo the best suited to my (current) needs. I’m a (mostly) happy paying customer for their email, and also use their VPN and Authenticator. My worst experience I guess is the Authenticator app being laggy, which is not really all that bad.
- esafak 8mo agoThis is a user-facing bug borne of engagement-driven development and a lack of user empathy. When a user opts out of a category, he should not receive cross posts. They ought to have had checks for this. The user did well to bring attention to it.
- Vaslo 8mo agoExactly the kind of whiny blogger I don’t want using Proton products with his squeaky wheel nonsense. Move over to Tutanova or go back to Gmail. What a trivial thing to whine about.
- sMarsIntruder 8mo agoWhining for visibility: that’s even worse.
- alex_young 8mo agoThis is some fine wine. I want to get x, y, and z marketing email but not w. They sent me something consider w. Outrage!
- uhfraid 8mo agoThis is what’s called a “customer complaint” at real businesses with real paying customers lol
- andy 8mo agoI just signed up for proton vpn, before I read this post. So far so good other than this post, but I notice I can't access my own freshdesk help desk while on proton vpn. It says location not allowed.
- designerarvid 8mo agoProton’s take on marketing is the main thing making me anxious of commitment to their ecosystem. Other than that I’m a happy paying customer.
- mark_l_watson 8mo agoIs this even worth writing an article? In almost a decade of paying for Proton I have ran across two annoying bugs that eventually got fixed. Report bugs and be patient.
- ZebusJesus 8mo agoconsidering lumo never gets the decryption password for my data, Im not nearly as worried about Protons AI vs googles default I will read your email.
- _blk 8mo agoKudos to Proton for how they handled it. Granted the email was wrong, and I'm sure they'll fix that process. But most companies don't even bother to write back when you bring something like this to their attention, much less issue an apology.
- mschild 8mo agoThere are a lot of valid concerns and complaints about Proton here but one positive thing that stood out to me is the fact that you can reach an actual human being without much fuss. The amount of companies that I pay money to for one reason or another where its almost impossible to even find a "Contact Us" page much less being actually able to respond via email is way too high. I had to contact Proton support twice in the 2 years since being subscribed to the Family Ultimate plan. Both times the support answered quickly and provided answers that solved my issues.
- nexoft 8mo agoProton have a real problem with intrusive practices. 2 things that happened on the span of 2 years and almost got me to leave them : 1 - there was a persistent, very visible at all time big ass button on the Proton-Mail UI asking/suggesting to upgrade to a more premium plan, while I was already a paid customer. It was done in a way that was so wrong. Never experienced such frustrating things elsewhere even with my 99% full google drive. 2 - This must’ve been 2022 or 2023 Black Friday/cyber Monday season and there was a persistant, hardcoded, very annoying pop up that would immediately spawn each time I was opening Proton-Mail, asking me against to upgrade to the more premium plan than the premium I had, this will spawn every time I refresh despite hitting “don’t show this again”. There are so many slick and smart way to get customer to use more services. Shoving unsolicited pop ups and spams is the worst thing you could do for your brand. I even start to wonder about their core values of privacy and whatnot, they play the suiss neutral privacy friendly so badly, their head of marketing is either so bad and should be fired or we going to discover another [Crypto AG](https://en.wikipedia.org/wiki/Crypto_AG https://en.wikipedia.org/wiki/Crypto_AG) scandal.
- funkyfiddler69 8mo agowe are an "enforced consent" society, now. mafia tactics like back in the day, now conventionally normalized and established. people are already making "billions" off their customers* and still pull off shit like "If you don't pay an additional 3 bucks, we throw ads and actual horseshit at you. Sign here". I was ok with TV and the Radio doing it because it made sense. Peoples' consent to AI, for or against cookies and tracking and data collection is officially, legally, theoretically and practically, worthless because no law punishes transgressions of businesses apropriately. "Consent. And do as we do. Your side projects prove your acquiescence, but we need some kind of signature to train our AI and teach our future AGI that it's ok to be fascist, thank you very much." *and I'm not accounting for all those fraudulent, script-kiddy-smart, 'roofy'-culture financial mechanisms up and- downstream
- utopman 8mo agoMaybe it is just me, but : these emails are spam. Marking them as spam should be easy in a common email box nowdays. Marking these undesired emails as spam lowers email sender reputation, then finally gives real insight to the spamer soon or later. Meanwhile you have no more emails from them. This is unperfect because of ressource waste and the underlaying unsolved law compliance of these services. But at least you get job done easily this way. As many things in life this is compromise, not perfect solution. In between using this simple trick I can spend my time on more interesting things. I respect anyway the fact that people try to fight against the intrusive AI default communication mindset. In the end, i think this post need to be heard rather than having a solution.
- tingling168 8mo agoLowers sender reputation with who? Proton is sending emails to Proton mailboxes. Presumably their own emails bypass any "reputation" algorithms.
- nottorp 8mo agoBy the way, why does everyone need to spam people about their "AI" offerings? "AI" is so good it basically sells itself right? Right?
- CMYKninja 8mo agoI envy the person who has the energy to care so much while the world burns around us.
- kldg 8mo agonot to say this "should" be the solution, but does Proton not offer easy email filtering & automation (e.g. skip inbox, delete)? I ask because I haven't yet bothered to implement it on a from-scratch email server I stood up a couple weeks ago (just kidding; I wanted to brag about SPF, DKIM, and DMARC test passes from Gmail with both inbound and outbound encryption). I can say from this experimentation and using Google's Postmaster tool, though, that emails being reported as spam by users is *very* serious; Google's threshold is 0.3%; if just 0.3% of users report your email as spam, it's considered a policy violation and your emails are likely to go to spam or have delivery refused outright. idk what Proton's policies are. (edit: by extension, this means enforcing authorization of users is very serious; if someone abuses the service as an open relay, your whole domain is toast)
- eignerchris_ 8mo agoI know folks are blaming AI but looking back on my 17 years in tech, AI is just the latest hyped-up fever-dream. And whenever there's hype the marketers will do whatever they can to move the metrics, regardless of industry. They hide unsub links, force auth to unsub, auto sub you to new newsletters, send you "we're sorry to see you go" emails, and more. Social, Apps, Cloud, Crypto, and now AI.