Oddbean new post about | logout
 https://i.nostr.build/dwL2v.jpg 
 Hmmm I remembered they did the same but Saïd that they only Obey to swiss regulations and court. Is there any swiss accusations? 
 Swiss people are willing to throw you under the bus if it's in their interest.  
 They give that info when pressured but they limit the data they collect. Always use protonmail with a VPN that isnt proton and always give a recovery email not linked to you. Seems like the two weak points as far as I know. 
 Isn't this now multiple times of them doing this

What's a better alternative  
 Yea they gave away IP addresses and recovery email multiple times now. They are still good but wish they take away mandatory recovery email. 
 any better options for email  
 mailfence 
 I guess Tuta is the way to go.

nostr:nevent1qqs22qy3q0j78dpjulpgduf8c353kskx2nnfhnqcade9s37j7ltkqzgpz4mhxue69uhhyetvv9ujuerpd46hxtnfduhsygqpmhhz3xc696ggwn9rg2985s28vjnv45dtl25ctsspu74d59kn3spsgqqqqqqsjae2ph 
 Is there a better alternative? 
 I would ask @Ava . What alternative do you recommend for email?  
 I'd also recommend just giving protonmail a recovery email that doesn't link to you and always use it with a vpn. That's really the only two weak points that I see that can link to you. 
 Gotcha, thanks I appreciate the follow up 
 I think its sus the releases on GitHub are behind compared to the PlayStore  
 nostr:nevent1qqsfhm74zz3yme54rg5qwwmju6996tym4xnypqwpug0yhlzmm29shfsppamhxue69uhkummnw3ezumt0d5pzp5x7h70mzt00s86r6lrfg2dm0pyp9tq7f5k48gszmd42cl4yk3nvqvzqqqqqqyask03c 
 Here are the signup steps for creating a 2nd FREE account (over TOR). Notice the "maybe later" option under the phone/recovery email section.
 https://proton.me/support/create-a-free-email-account-address 
 Thanks 💜🫂 
 Ofc 🫂💜 
 What about totanuta? 
 Thanks 💜🫂 
 Ofc 🫂💜 
 What about totanuta? 
 What is the need to compartmentalise tor and vpn ? 

Is von not good on its own ? 
 Tor only or is VPN “good enough“? 
 “A VPN provider is not going to go to jail for your $5 a month subscription “ 
 a bitcoin paid mullvad VPN, hows that? 
 I recommend and use Mullvad as well. Paying with non KYC coin from a private wallet using a private server set up with good opsec is the way to go.

But again, it depends on your threat model and usecase. If you are using your identity associated paid Proton account, using the Proton VPN included with your subscription is fine. It's great for giving you privacy from your ISP, circumventing geographical limitations, and even torrenting, optiinally using another provider's VPN like Mullvad or IVPN or a Proton VPN plan not associated with your identity.

"Support for paying with Bitcoin when you first sign up is coming soon. Until then, you can sign up for a Free plan and then upgrade using Bitcoin"

Where you need more privacy, sign up and use a free nym Proton email account (not associated with your identity) optionally using another VPN provider like IVPN or Mullvad or a Proton VPN plan not associated with your identity.

Where you need as close to anonynity as possible,  sign up and use a free nym Proton email account (not associated with your identity) over Tor only. 
 Where you need even more privacy, don't use email. Even if you self-host with good OPSEC, use SimpleX instead.

Where it's mission critical, don't use the internet at all, use good OPSEC and communicate in person. 
 Thank you! Noted 🫡 
 Encrypted telepathy? 
 reading my mind 
 What’s wrong with an unsecured channel with strong cryptography, say GPG? 
 Of course metadata 
 One thing to add ava, communicate in rooms without electronic devices 🥸 
 💯 That falls under "good OPSEC" 
 I realize how often people (myself included) choose convenience over privacy, and I hate that. 
 It depends on your threat model in each area of your life. Tradeoffs are a natural occurance. The most important thing is to do the work and know your threat model.  
 🎯 
 Excellent. Thank you.  Already using nym protonmail account paid for with noKYC WP funds and using Mullvad VPN at all times… but it’s nice to have the confirmation 🙏🏼🫡 
 You can also buy a mulvad VPN voucher using lightning for addition peace of mind around privacy.

https://vpn.sovereign.engineering/ 
 that's a lot to not avoid IP address  
 Mulvad is too big, making it a target.  I use ivpn.  Smaller, under the radar. 
 Thanks for the feedback 
 Wouldn’t a larger VPN provider have more users, thus more obfuscation (a “larger crowd”) for the traffic coming from any one of the provider’s servers’ IP address?

If I’m the only person using the VPN provider, then all traffic from their server is the same individual (effectively as a pseudonymous user, until you log into your Facebook account 😉).

More users of the VPN would mean a larger pool of data that a malicious actor or advertiser (same difference) would be unable to distinguish the individual users’ traffic. Device fingerprinting and logins aside, of course.

Do I have this concept right? 
 I recommend and use Mullvad as well. Paying with non KYC coin from a private wallet using a private server set up with good opsec is the way to go.

But again, it depends on your threat model and usecase. If you are using your identity associated paid Proton account, using the Proton VPN included with your subscription is fine. It's great for giving you privacy from your ISP, circumventing geographical limitations, and even torrenting, optiinally using another provider's VPN like Mullvad or IVPN or a Proton VPN plan not associated with your identity.

"Support for paying with Bitcoin when you first sign up is coming soon. Until then, you can sign up for a Free plan and then upgrade using Bitcoin"

Where you need more privacy, sign up and use a free nym Proton email account (not associated with your identity) optionally using another VPN provider like IVPN or Mullvad or a Proton VPN plan not associated with your identity.

Where you need as close to anonynity as possible,  sign up and use a free nym Proton email account (not associated with your identity) over Tor only. 
 Where you need even more privacy, don't use email. Even if you self-host with good OPSEC, use SimpleX instead.

Where it's mission critical, don't use the internet at all, use good OPSEC and communicate in person. 
 Thank you! Noted 🫡 
 Encrypted telepathy? 
 reading my mind 
 What’s wrong with an unsecured channel with strong cryptography, say GPG? 
 Of course metadata 
 One thing to add ava, communicate in rooms without electronic devices 🥸 
 💯 That falls under "good OPSEC" 
 I realize how often people (myself included) choose convenience over privacy, and I hate that. 
 It depends on your threat model in each area of your life. Tradeoffs are a natural occurance. The most important thing is to do the work and know your threat model.  
 🎯 
 Excellent. Thank you.  Already using nym protonmail account paid for with noKYC WP funds and using Mullvad VPN at all times… but it’s nice to have the confirmation 🙏🏼🫡 
 You can also buy a mulvad VPN voucher using lightning for addition peace of mind around privacy.

https://vpn.sovereign.engineering/ 
 that's a lot to not avoid IP address  
 Mulvad is too big, making it a target.  I use ivpn.  Smaller, under the radar. 
 Thanks for the feedback 
 Wouldn’t a larger VPN provider have more users, thus more obfuscation (a “larger crowd”) for the traffic coming from any one of the provider’s servers’ IP address?

If I’m the only person using the VPN provider, then all traffic from their server is the same individual (effectively as a pseudonymous user, until you log into your Facebook account 😉).

More users of the VPN would mean a larger pool of data that a malicious actor or advertiser (same difference) would be unable to distinguish the individual users’ traffic. Device fingerprinting and logins aside, of course.

Do I have this concept right? 
 Excellent. Thank you.  Already using nym protonmail account paid for with noKYC WP funds and using Mullvad VPN at all times… but it’s nice to have the confirmation 🙏🏼🫡 
 You can also buy a mulvad VPN voucher using lightning for addition peace of mind around privacy.

https://vpn.sovereign.engineering/ 
 Encrypted telepathy? 
 Of course metadata 
 Thanks for this Ava! Appreciate it 🙏🏽 
 💜🔥💜 
 💜🔥💜 
 Mulvad is too big, making it a target.  I use ivpn.  Smaller, under the radar. 
 Thanks for the feedback 
 Wouldn’t a larger VPN provider have more users, thus more obfuscation (a “larger crowd”) for the traffic coming from any one of the provider’s servers’ IP address?

If I’m the only person using the VPN provider, then all traffic from their server is the same individual (effectively as a pseudonymous user, until you log into your Facebook account 😉).

More users of the VPN would mean a larger pool of data that a malicious actor or advertiser (same difference) would be unable to distinguish the individual users’ traffic. Device fingerprinting and logins aside, of course.

Do I have this concept right? 
 Yesterday i made an account at Mullvad and pay that with lightning. It is just awesome. No Mail Adress or Bank Account is needed for this. Mullvad just creat a random account number for you. It´s like the Npub on Nostr. 
 I realize how often people (myself included) choose convenience over privacy, and I hate that. 
 It depends on your threat model in each area of your life. Tradeoffs are a natural occurance. The most important thing is to do the work and know your threat model.  
 🎯 
 It depends on your threat model in each area of your life. Tradeoffs are a natural occurance. The most important thing is to do the work and know your threat model.  
 I would never use Proton. Also, email needs to go the way of the fax machine.

Mullavd only for VPN and if you must use email then use Startmail. Startmail has better privacy with their email accounts than Proton. 

All one has to do is read each service provider's terms and conditions and privacy statements. 
 Thanks for that! I’ll look into it 🫡 
 Thanks for that! I’ll look into it 🫡