this post was submitted on 27 Jul 2024
25 points (83.8% liked)

Proton

5065 readers
1 users here now

Empowering you to choose a better internet where privacy is the default. Protect yourself online with Proton Mail, Proton VPN, Proton Calendar, Proton Drive. Proton Pass and SimpleLogin.

Proton Mail is the world's largest secure email provider. Swiss, end-to-end encrypted, private, and free.

Proton VPN is the world’s only open-source, publicly audited, unlimited and free VPN. Swiss-based, no-ads, and no-logs.

Proton Calendar is the world's first end-to-end encrypted calendar that allows you to keep your life private.

Proton Drive is a free end-to-end encrypted cloud storage that allows you to securely backup and share your files. It's open source, publicly audited, and Swiss-based.

Proton Pass Proton Pass is a free and open-source password manager which brings a higher level of security with rigorous end-to-end encryption of all data (including usernames, URLs, notes, and more) and email alias support.

SimpleLogin lets you send and receive emails anonymously via easily-generated unique email aliases.

founded 1 year ago
MODERATORS
 
  • Proton VPN doesn't use RAM-only servers, arguing they offer no additional security over full-disk encryption on hard drives.
  • Full-disk encryption ensures data on hard drives is secure and inaccessible without proper authentication, even when servers are powered off.
  • Proton VPN prioritizes a strict no-logs policy, independent audits, and operating servers in privacy-friendly jurisdictions to protect user privacy.
you are viewing a single comment's thread
view the rest of the comments
[–] my_hat_stinks 23 points 3 months ago (1 children)

Very unconvincing. The only point they bring up which actually precludes RAM-only servers is hard drive encryption, which they only need to do because they store data on a hard drive. The whole article reads like them trying to justify a choice they've already made rather than a legitimate comparison RAM-only versus hard drives.

Their first point is literally that RAM-only doesn't help when the power's on. That's like saying you shouldn't wear a seatbelt because it doesn't protect against someone smashing your window. That's just not what it's for.

[–] Lodra 14 points 3 months ago

I largely agree. The title and opening words are misleading. The rest of the article is much more clear that they are defending their position of using VPN software that relies on storage and securing it with full disk encryption.

Also, full disk encryption doesn’t solve everything. If an attacker has access to the running server, the disk is unencrypted. At that point, reading files is much easier than reading RAM from a running process.