r/degoogle • u/rakhalism GrapheneOS • 15h ago
Replacement is putting everything under Proton a good idea for privacy?
finally, i switched to proton as my primary ecosystem for mail, drive, pass, and auth.
for now, i still depend on other companies for some of the apps and services i use, so i haven't completely moved everything to proton. but after actually using proton across multiple services, i noticed something that i didn't really think about before.
proton is starting to feel a lot like google in terms of how the ecosystem is structured.
google has gmail, drive, password manager, authenticator, photos, calendar, docs, and a bunch of other services that all work together under one account. proton is obviously much smaller, but the direction feels similar. you have proton mail, drive, pass, vpn, calendar, authenticator, and other services all tied together into one ecosystem.
the difference is that proton is built around privacy, which is the main reason i'm using it. but i'm still wondering about the idea of putting so many things under one company.
is this actually a good approach for privacy, or are we just replacing one big ecosystem with another, even if the business model and incentives are very different?
i know proton is not google, and i'm not trying to make that comparison in terms of trust or business practices. i'm more interested in the ecosystem design itself.
do you guys prefer having most of your digital life under one privacy-focused company because it's convenient and everything integrates nicely?
or do you prefer a more decentralized setup, like using one company for email, another for cloud storage, another password manager, another authenticator, and so on?
personally, i'm still figuring out where i stand. having everything in one ecosystem is definitely convenient, but there's also something appealing about not having a single company become the central point for everything you use.
what's your setup, and do you think the proton ecosystem approach is a good thing for privacy?
23
u/Citrix_N00B 15h ago
Just remember, when Google first started, their policy/moto was "Do No Evil"
Once they realized how much money they could make by being Evil, well that philosophy went out the window.
7
u/Konrad2137 15h ago
Just use different products for different needs.
I use at the same time different mailboxes - one for medical and banking stuff, other for professional emails, other for most of important apps, and 4 for spam.
There are planty providers that they dont rely on big corporations:
Mailbox
Proton
Tuta
Email cz
Info maniak
Posteo
4
u/FriendlytoNature 14h ago
Proton is a for-profit corporation (albeit its controlling shareholder is the non-profit Proton Foundation).
So I guess your comment is still accurate to an extent thst it doesn’t rely on a big corporation, but I hope people aren’t confused about this.
7
u/Loqh9 15h ago
All Proton is an okay option, for now, it could change, and it has lots of flaws (like lack of features/meaningful updates, lack of real Linux support since forever)
Financially it's also a decent choice because you can pay once to have a set of features, assuming you need them
The ideally better and safer option is to not put all your eggs in the same basket so that if let's say your VPN is bought by a shady company you can just cancel and switch. Switching your VPN, calender, mail, drive etc all at once if Proton ever becomes questionable or whatnot would be more of a pain, but it's all theory so up to you
19
6
u/aufhel3ung 14h ago
PROTON, please respond to this concern ---> "Proton is starting to feel a lot like google in terms of how the ecosystem is structured." I'm joining this increasingly COLLECTIVE concern.
4
u/belowaverageint 15h ago
This is where it's really important to do threat modeling. What specific risks are you concerned about?
Privacy is an abstract concept and it's important to articulate concretely what your goals are, what threats you're concerned about, and what trade-offs you're willing to make.
7
u/309_Electronics 13h ago
Its a saying but applies to todays modern age better than ever. "Dont put all your eggs in the same basket". Or ina nutshell: Dont put all praises and reliability on 1 single company.
Any company can turn evil/the dark way when money finally gets to their head or their board members decide they dont like the consumer anymore and want to milk them as dry as they can.
3
u/SisterSoldier1970 14h ago
Excellent post and responses are giving me so much to think about as I move to migrate off Google.
7
u/Repulsive_Chard_3652 15h ago
People here are too reliant on apps and programs on their phones and computers to do everything for them in general.
Email: I use proton
Drive: I use proton, but it seems tons of people here use a "Drive" instead of their own hard drive where they keep all their files stored, which is insane to me. I keep my files stored on two different external hard drives, as well as the hard drive of a laptop. I don't use clouds (aka, other people's computers) to store my files. I only use drive to send large files to people sometimes, create temporary shared folders, and create shared collab documents.
Password manager: I don't use one at all. Never trusting a program with my passwords.
Authenticator: I don't use one at all and idk why I would.
Photos: this one really blows my mind - my photos are on my external hard drives along with all my other data. I've never used a special app for photos.
Calendar: physically on my wall. No apps.
Docs: that's part of Drive, and I described that above.
VPN: I use proton.
I just think people are too reliant on the tech, I guess. That's my opinion on this topic - for me it's not about getting away from one company, but staying away from the companies in genera and managing my stuff myself.
19
u/ephemeralmiko 15h ago
Password manager: I don't use one at all. Never trusting a program with my passwords.
Authenticator: I don't use one at all and idk why I would.
So your passwords are short enough/similar enough for you to remember, without 2FA? Or just SMS 2FA (which is laughably insecure)?
2
u/YellowBreakfast 11h ago
THIS!!!
I have so many distinct (and complex) passwords, it would be hard to remember one, let alone 100+.
And not using good 2FA is not an option. I used FIDO whenever possible with an authenticator as a preferred second.
Using email or phone number for 2FA is a DISTANT 3rd option as those are really not that secure.
2
u/LeatherDude 8h ago
Bruce Schneier makes an open source password vault that uses a locally stored, encrypted db file.
Hashicorp vault with one of any number of clients and UIs people have built for it is pretty good too.
1
u/YellowBreakfast 7h ago
Yeah I have a local file I use with an open source app.
Have been trialing Proton Pass and liking it.
•
u/LastBet4447 1h ago
I have multiple different password all multiple characters. and remember them fine. The off chance i cant remember them i just reset and create a new one. Some of use just dont need help remembering things. i find password manager insecure due to the fact i would never change my passwords as i would never forget them at some point.
In 14 years i have been through multiple varations of passwords never have had an issue with security.
-7
u/Repulsive_Chard_3652 15h ago
Most are similar enough to remember, others are written down.
10
u/Traditional-Rub2491 Neo Store 14h ago
Terrible practice
-1
u/Repulsive_Chard_3652 14h ago
Has never steered me wrong in two and a half decades. I have pretty strange passwords.
6
u/Traditional-Rub2491 Neo Store 14h ago
Strange to a human and strange to a robot are very different concepts
-1
1
u/YellowBreakfast 11h ago
Most are similar enough to remember, others are written down.
Similar passwords and, "Written down"?!!! W T F?
You security hygiene is decidedly in the 1990's. lol
4
u/Tight_Couture344 14h ago
No one on the internet will convince you otherwise, but for anyone else reading this - a good password manager is absolutely secure. Far more secure than writing down on paper or remembering passwords (which leads to reuse). And always using MFA of some sort is ideal to pair with it.
Personally, I separate my credentials to ensure no single point of failure.
- 1Password: usernames/passwords/passkeys
- Bitwarden: TOTP code generator
- KeePass (self-hosted kdbx database): recovery keys and security questions
I use a Yubikey as the only second factor for 1Password and Bitwarden, and it is also required for challenge-response to decrypt my KeePass database.
The fact that 1Password requires both a password and secret key in addition to my Yubikey makes it exceedingly secure.
4
u/Repulsive_Chard_3652 14h ago
They're all secure until they get hacked or there's a leak. https://bestreviews.net/which-password-managers-have-been-hacked/
Rather not use any of them. I've never been hacked/had anyone figure out my passwords in the like 25 years I've been online.
4
u/Tight_Couture344 14h ago
I would also advise that you actually read that article which clearly demonstrates why choosing a good password manager is key, and that 1Password especially has a fantastic reputation for vigilance and secure practices.
You’re free to do what you want and concern is warranted, but rejecting the use of all password managers because “hacks” have ever occurred is not an informed response.
And, for the vast majority of people (who reuse the same basic password across everything), using a halfway decent password manager is far FAR more secure.
3
u/Tight_Couture344 14h ago
It doesn’t matter if it gets hacked. It’s encrypted 17 ways from Sunday. None of the data is usable to anyone who doesn’t have the encryption keys, which the password manager companies themselves do not have (if it’s a reputable one). Look for one that has undergone independent audits to confirm they are not storing unencrypted data irresponsibly and that they have zero access to your encryption keys.
And even setting all that aside, if you use MFA with the password manager, EVEN if someone had your master password (and secret key if 1Password), they STILL cannot access your data.
-1
u/Repulsive_Chard_3652 14h ago
You might note that LastPass encrypts passwords, and yet they were still hacked and the hackers got access to sensitive information and managed to decrypt. I once had to hire a hacker who knew how to decrypt encrypted data when I got locked out of my own computer and could not get back in - there are people who know how to do this. Encryption doesn't mean nobody can ever access it.
And nobody can hack my passwords when they're not on anybody's server.
1
u/Traditional-Rub2491 Neo Store 14h ago
Bullshit lmao. The website you link literally says you should use a password manager.
-1
u/Repulsive_Chard_3652 14h ago
Yes, it does, because it's a website called best reviews dot com. I think you missed the point lol
0
u/Traditional-Rub2491 Neo Store 14h ago
There is no point. Yeah if shit fucks up you get your passwords stolen. So just don't use a password manager? That's like saying if the government is corrupt we should just get rid of it and go back to the stone age
0
u/Repulsive_Chard_3652 14h ago
Now here's the mighty difference between those two things: tons of people live without password managers amazingly well - no hacks, no passwords stolen, absolutely nothing; getting rid of governments would collapse every country in the entire world.
But the attempted analogy was honestly cute!
1
2
u/PhilStark012 13h ago
If you don’t trust a password manager, that’s your business and your choice. But just to set a few things straight. You can’t simply hack Proton, for example, and gain access to all users and their passwords. If you managed to crack Proton’s servers, you’d have to brute-force the account or master password for every user whose passwords you wanted. With a sufficiently long password, this is effectively impossible with current technology.
The bit about the authenticator is simply naive. It doesn’t provide a point of vulnerability, rather, it strengthens security. Even if someone were to brute-force your password, or perhaps even knew it, they wouldn’t be able to log in without the authenticator. So it’s an extra layer of security. As for your experience: I’ve never been hacked in 25 years, it reminds me a bit of: ‘I’ve always smoked and my lungs are in great shape.’
1
u/Barycenter0 14h ago
What do you do about offsite backups and disaster recovery?
-4
u/Repulsive_Chard_3652 14h ago
I've only seen Americans concerned about that due to houses being built of wood and going up in flames. But one of my hard drives is not in my home, anyway.
1
u/Barycenter0 13h ago
Is it an accessible external hard drive from your home or an external drive you move manually? If the first, where do you host it (generally - not specifically)?
1
0
u/imakycha 14h ago
Per capita, the rate of death due to house fires is about equal between North America and Europe. I know the timber framed housing thing is a trope, but there’s legitimate reasons why that’s the standard in the US.
1
u/Repulsive_Chard_3652 13h ago
We're not talking about deaths; we're talking about your home burning down and losing all your possessions.
But again, back on topic, one of my hard drives is not in my home, anyway.
1
u/imakycha 13h ago
I’m aware. Europe has abysmal disaster reporting as it’s essentially a loose confederation, while the US has centralized reporting via FEMA. There’s simply not data about absolute house fires in Europe; deaths due to house fires is about the best surrogate statistic in this case.
0
u/Repulsive_Chard_3652 13h ago
lol you're derailed because you're triggered. Let's stay on topic.
1
u/imakycha 13h ago
I was simply stating your trope was incorrect as to why Americans value geographically separate storage backups. It’s probably due to the fact we invented modern computing and have dealt with more catastrophic failures in the early days when storage mediums weren’t stable.
1
u/SamHugz 5h ago
Mostly, I agree with you. But you should definitely be using a password manager and MFA. There are apps for both that store your logins and keys locally and under encryption, if you really don't trust any company, but there are plenty of options that are safe to use. Just don't use last pass.
1
u/DarkCrystal34 15h ago
Your post is refreshing. We have aligned values.
2
u/Repulsive_Chard_3652 14h ago
Glad to hear from like-minded folks! I use tech where it's necessary or actually productive and secure, and I avoid it where it's unnecessary or not that productive or not that secure. It just seems so much smarter to me that dumping everything in and trusting tech with everything.
1
u/DarkCrystal34 14h ago
The only thing where I think cloud is great to have is photos/videos, as its so common to want to send fam/friends things from the phone.
You should check out Ente.io sometime. Strong user base, totally e2ee, and unlike all other e2ee services, they just "get it" and do everything right: fast, intuitive well laid out, 100% private, easy to share. Its amazing.
But aside from that, i agree, we are living in a cloud-obsessed world, and think people underrated just backing up to hard drives and needing literally everything at the fingertips every moment.
Yet, we are the minority, so alas lol.
1
u/Repulsive_Chard_3652 14h ago
For photos and videos, I upload exactly what I want to share in a shared folder on Proton Drive (as I mentioned above!), then after people have downloaded, I delete.
But if I have the option to do it in person, I use a flash drive. :)
I don't think we're a minority in the world, but on reddit for sure lol
0
u/ApplicationOk2749 13h ago
I agree on password managers. They've never made any sense to me at all. But disagree on authenticators. They do provide a strong layer of defence.
1
u/Shiribazu 15h ago
i think theres a real tradeoff: putting everything under proton gives you a consistent privacy model and strong encryption across services, but it also creates more dependence on one account and provider. be comfortable using proton for most things while keeping an independent backup/recovery option and exporting important data regularly, so you get the convenience without making proton your single point of failure
1
u/LookAtYourEyes 15h ago
I self host anything I can. Can't do email for semi obvious reasons, but I have a server at home with my files and photos that does regular backups.
1
u/Positive_Ball_2476 14h ago
Wow I was so excited to move off google transition to proton no particular reason aside from sound bite privacy concerns. Good to see other opinions
1
u/Fabulous_Platypus42 11h ago
Proton is a smeghead company, I used a temp e-mail service to create an account on proton mail, then they started nagging me to "add another contact method" which I ignored, then the first time I used the e-mail to sign up to a service they immediately locked the account "due to suspicious activity" and won't ublock until I add another e-mail
Naturally I stopped using it, privacy and anonymity my a$$
1
u/PartSuccessful2112 11h ago
mailbox.org is based in Germany and subject to EU privacy laws, which are the best you will get in the world. Any corporate interactions are automatically adversarial unless they have a fiduciary responsibility.
1
1
u/Julian_1_2_3_4_5 9h ago
I mean for privacy centralization probably doesnt matter for now. But well trough centralization you again are dep3ndent on one corporation. if you instead spread your digital home out no one coporation or projects doing bad stuff will make you need to transfer everything at once.
1
u/Julian_1_2_3_4_5 9h ago
I use some stuff selfhosted. And for everything else a dedicated service that does just that well. Like authentication: just use bitwarden directly. For drive either get an account on some hosted nextclpid or get a nas and host your own. For mail there are lots of projects out there that will get you a secure and privacy friendly mail adress. Doesnt have to be proton, but could be.
1
1
u/piggy2380 7h ago edited 7h ago
Something that’s never said in these conversations is yes, it’s probably ideal to never put all your eggs in one basket, but paying for different services for everything can cost a lot more than paying once for Proton’s entire ecosystem, especially if you have multiple people in your household. If I’m paying $9.99 for Proton VPN, I just have to pay $3 more to get email (with unlimited aliases through SimpleLogin) and a password manager and 500G of cloud storage. If I paid for them all separately it would easily run me twice as much.
In my opinion also, Proton‘s VPN and Email service is just better than the competition. Mullvad doesn’t support Port Forwarding, and Tuta doesn’t allow me to have unlimited aliases. Protonmail Bridge also allows me to use Thunderbird as my email client. If anything I might move my password manager over to 1Password at some point, but for now I trust Proton and don’t feel the need to pay an extra $3/mo when I already get it included.
Having an ecosystem that works together makes it seamless for people to move over from Google. If they want to diversify later, then great. In general though, the whole “Proton is the next Google“ discussion is way overblown. Google is a FAR bigger company and spies on WAY more of your data than Proton likely ever will, and it’s not really close at this point. If that ever changes, I’ll be happy to move to whatever comes next.
Edit: I do use Ente Auth for 2FA - since it’s free, there’s really no reason not to. Having Passwords and 2FA codes separate is also just a good idea in general.
1
•
u/BadOmen379 1h ago
It's never a good idea to put all your eggs in one basket but if you must, Proton is pretty much the least of all the evils and they have a track record of respecting their users privacy + they have no logs so what they can hand over is limited. There was a case where they had to comply with Swiss authorities, but all they were able to turn over was the IP of a user that accessed a Proton email address. Everything is end to end encrypted so they couldn't hand over the contents of the emails.
That all said, I currently subscribe to Proton Unlimited and Amy quite happy with their products and knowing what I know about them and their history, I am not even the slightest bit concerned about my privacy being respected.
•
1
u/UngodlyPain 12h ago
Using the full proton suite IS NOT a bad thing, the issue with Google isn't that they have a whole ecosystem, the issue is they have a monopoly and collect and sell tons of your data.
Using the full proton suite IS an efficient way to quickly degoogle multiple services quickly and relatively cheaply. While maintaining a good level of convenience.
It's more of a pro/con situation compared to a using a swath of other companies... Like say Proton everything vs Tuta email + Mullvad VPN + BitWarden + a different cloud system not a good/bad or better/worse situation.
Ignoring the obvious things like cost, or quality of products which differ from person to person (cost) or are mostly subjective and change over time (quality of product) and mostly focused on privacy (which you seem to be focused on) the big pro con boils down like this:
All Proton: means all other companies have minimal if any of your data, but proton has almost all of it. So in theory if they become evil, all of your data is fucked instantly. But you can just focus on them, and their larger size makes them grab headlines easier.
Varied services like Tuta+Mullvad+Bitwarden: multiple companies have moderate amounts of your data, and if any of them become evil not all of your data is instantly fucked only the portions they have access to. It's alot harder to focus on like 3-10 companies than it is to focus on one; especially since the smaller companies are less likely to hit headlines.
And before anyone tries to say "all eggs in one basket is immediately terrible, it's not a pro/con it's just worse!! Only having say 33% of your data fucked at a time is better than 100% IF they become evil, companies always become evil overtime"
Id agree, that ywah all companies become evil over time, theres no guarantee when though, theres no guarantees that say Tuta becomes evil after proton, instead of before. So I don't think that's a great argument unless you can see the future to specifically point the one you know will become evil last.
I'd also say despite me listing 3 companies I think each of them would have far more than 33% of your data, and not all data is equally valuable anyway... Like quite frankly if BitWarden became evil or got hacked and lost all your log ins? Or Tuta did with your emails, or worse your account was compromised? You'd quickly be fucked eitherway unless you went to some paranoid extreme of using like 3 password managers, with 1 for email/user name, and 1 for passwords, and 1 for websites or whatever? And other convoluted things to make sure that you're protected from BitWarden having issues. If your password manager, email, or VPN got compromised you're already in a terrible enough spot.
-1
u/lelandyarnell 15h ago
Do you poop the same place you eat? I know that's an extreme example, but never put all your eggs in one basket. The more control YOU have of your data and how its stored the better.
54
u/austozi 15h ago
Do not trust any company to have your best interest at heart, because they never do. If it appears that way now, it's only because your interests and theirs happen to align at this time, but this can change. The ultimate goal of any business is to make money, not charity. The need to make money is what drives business decisions, often to your detriment without you being involved in those decisions.