• BladeFederation@piefed.social
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    23 hours ago

    For what to look for, sometimes people’s priorities will be different, and unfortunately sometimes you may need to sacrifice usability to meet all your personal criteria. But this is what I look for.

    FOSS (free open source software). The source code is open for everyone to read, and therefore you know exactly what the application is going, and security flaws will be noticed and fixed more quickly. There are sometimes exceptions for infrastructure. Back end software for services like email or cloud providers will not generally be open source for various reasons. E2EE (end to end encryption, it is encrypted from the moment it leaves my device and decrypted on your device). ZAE (zero access encryption) for services that store my info on a server, such as email or cloud storage. This means that the data is encrypted on the provider’s server, and they do not hold the encryption keys. Independent 3rd part audits. Privacy enthusiasts whose job it is to suss out problems are given free reign to inspect every part of the provider and see if they are really doing what they claim with privacy and security. Further proof may be shown by ethical hackers posting results of what they were able to do. Location: the Dev/provider has to obey local laws, so I trust if they are based somewhere that respects data privacy and are not authoritarian. If the company still seems a bit shady (certainly if they are closed source) but I want to use their product, I will carefully read their privacy policy. Sure, they may be lying, but you’ll be surprised at what some companies openly admit to. And if you’re not comfortable with what they state publicly, you should probably move on. To a lesser extent, I also prefer seeing open standards instead of proprietary ones (like PGP for encryption for example) and a strong choice for encryption because I know a little bit about that. No ads: self explanatory. Is the company/devs shady seeming in general? Also fairly self explanatory but more arguable.

    Proton meets all of these requirements for all their products, with the slight exception that not every part of every project is fully open source. If it was, you could hijack their email or cloud servers and use their infrastructure with any amount of storage for free, for example. This is pretty common for service providers. No idea what you’re on about with the last part. They specifically have a no logs policy for their VPN that has been “battle tested” by governments subpoenaeing info. They don’t have that info, so they were unable to give it.