The @protonmail sharing-IP-with-LEA situation is a good reminder that if, on the Internet, something is technically possible, it is practically unavoidable.


@rysiek @protonmail I don't think anybody "raising the alarm" actually read ProtonMail's threat model page.

@riseandfalloft2 absolutely. I'm not "raising the alarm", I am merely remarking that this was inevitable.

Now, could @protonmail have communicated better and made it more clear that metadata remains a problem? Probably.

There is also the open question of whether or not they notified the user about them starting to record the metadata on LEA's request. My understanding is that they have not, while nothing stopped them from issuing such a notification. I would love to get clear information about that.

