from the team:
Hey everyone,
We are now able to share that Proton VPN has successfully passed its 4th consecutive independent audit of our strict no-logs policy, conducted by Securitum, a leading European security auditing company.
Key takeaways from the audit:
- No activity or metadata logs are kept anywhere on our servers.
- No inspection of user traffic occurs.
- Robust administrative and technical controls are in place, including automated configuration management and a dual-control change process.
- The no-logs policy is enforced uniformly across all servers, regions, and subscription tiers.
Don’t trust, verify is not just something we preach, but something we practice, so our no-logs policy has now been verified by independent experts; you don’t have to take our word for it.
📖 Read the full audit report here
Stay safe,
Proton Team
20 Comments
unexposedhazard@discuss.tchncs.de · -9 pts · 327d
Sorry to be a downer, but audits of software that isnt selfhosted are kinda useless. Unless they allow spontaneous unannounced inspection of their infrastructure, they can just do whatever they want after the audit.
akilou@sh.itjust.works · 55 pts · 327d
The only thing you can truly know is that you exist. Sorry to be a downer
Bahnd@lemmy.world · 23 pts · 327d
Descartes, chill.
lka1988@lemmy.dbzer0.com · 17 pts · 327d
I do not think, therefore I do not am
Observer@infosec.pub · 2 pts · 325d
Impronoucabl@lemmy.world · 18 pts · 327d
Well, would you trust the company that's actually gone through the audits, or the one that skips them to save money & be cheaper?
unexposedhazard@discuss.tchncs.de · -7 pts · 327d
Only the one that just open sources their code and encourages people to self host.
__Lost__@lemmy.dbzer0.com · 10 pts · 327d
You can't self host a VPN, what would be the point?
Magnum@lemmy.dbzer0.com · 3 pts · 327d
__Lost__@lemmy.dbzer0.com · 7 pts · 327d
Well, yes, you can self host a VPN to access your home network, I do that as well. That is not the context for proton et al though, and you can't self host a privacy VPN.
unexposedhazard@discuss.tchncs.de · 0 pts · 327d
Lemmy is "self hosted" that doesnt mean every user has their own instance...
onslaught545@lemmy.zip · 0 pts · 327d
That doesn't mean that instance owners can't do shady shit. Open source is meaningless when you're talking about a service provider.
onslaught545@lemmy.zip · -1 pts · 325d
To expand, you don't want your service provider to open source all of their configs. Audits like the one Proton went through require admin access to systems that you absolutely don't want the public to have.
This is just like Lemmy. The actual code is open sourced. But instance configs aren't (for good reason)
Proton isn't a developer when it comes to their VPN service. They most likely are utilizing open source solutions to run it, but they're not operating a code base for it.
Their clients are open source, though.
And I'm saying this as a cyber security expert who uses Proton for personal use.
Broken@lemmy.ml · 14 pts · 327d
So would you equate a company that doesn't do any audits as the same caliber?
ElectricWaterfall@lemmy.zip · 3 pts · 327d
I would trust some real court case where they end up turning up nothing because they have nothing.
Nelizea@lemmy.world · 2 pts · 326d
https://protonvpn.com/blog/transparency-report
artyom@piefed.social · 2 pts · 326d
The code is open source so feel free to audit it anytime you wish. But the audits are there for a third-party evaluation by actual experts.
lIlIlIlIlIlIl@lemmy.world · -35 pts · 327d
Red flags, red flags everywhere
incompetent@programming.dev · 23 pts · 327d
Such as?
circuscritic@lemmy.ca · 21 pts · 327d
Red flags, they're everywhere.
Was he not clear about that?
There's even some in the room with me right now.
DeathByBigSad@sh.itjust.works · 12 pts · 327d
Huge Red Flag:
