News Feed
  • DrugHub has agreed to fully refund all users who lost money in the SuperMarket exit scam.  
  • Retro Market has gone offline. Circumstances of the closure unknown.  
  • SuperMarket has closed following an exit scam by one of the admins.  
  • The admin of Incognito Market, Pharoah, has been arrested by the FBI several months after exit scamming.  
  • Silk RoadTorhoo mini logo
  • darknet markets list
  • Popular P2P exchange LocalMonero has announced it is closing.  

Reasons not to use Protonmail? : OpSec | Torhoo darknet markets

I was wondering whether someone would be so kind as to provide clarification on some of the comments I've read telling people not to use protonmail? I was under the impression that it was one of the better email services out there.

I did do a search here but after 10-15 pages could only find people saying not to use it, however no proper explanation. I use pgp for sensitive communications regardless, but my curiosity is piqued as to the exact reasons (and have already created a secmail account).

Thank you in advance for taking the time to respond.
/u/bignose
2 points
5 years ago
last time I tried, it wanted me to enable javascript, which is a no-no
/u/[deleted]
2 points
5 years ago
Protonmail is owned by the feds.
/u/[deleted]
2 points
5 years ago*
They require javascript which is impractical but the reason why they really suck is because when you try to make an account with Tor they often want to send you an SMS for verification and you cant use a number which was already used once.

So for successfully making an anonymous account you need to use a VPN, then you maybe get the option shown to use another email address for verification so with your VPN you need to make another email address somewhere for getting the verification code.

So they claim privacy but dont really like it when you are anonymous.

And there are a lot of rumors or facts that they fucked users over not only once.

Tutanota or ctemplar are similar and also require javascript to work but i would say still better then sucking protonmail.
But they are also a bit newer so no one knows how they will develop in the future.

Edit:
There was a seller some time ago who said protonmail blocked his account after they found out that he used it for selling drugs.
/u/adversa 📢
1 points
5 years ago*
Thank you for taking the time to respond at length, I much appreciate it. I didn't realise they forced JS - I don't actually use the address for anything illicit, more along the lines of sensitive discusssions that could easily be used to build the wrong sort of profile on me were meta-analysis to be performed on them. The privacy vs. anonymity distinction is an important one - I'll stick with secmail from now on. Many thanks!

Edit: and the SMS verification thing seems to defeat the purpose of the service, as I know several journalists who use it who could easily become targets of state actors for their work...guess who would have the tools to access SMS logs?
/u/[deleted]
2 points
5 years ago
Tutanota, ctemplar and protonmail all require javascript.
For doing the crypto completely on your computer javascript is necessary and as long as the javascript gets served by a reputable legit institution there is not necessarily something bad with it.
Still it should be avoided because you'll never know who is on the other side of the screen.

Thats the reason why secmail or elude or TorBox all look shitty because they offer just plain-simple email solutions without big features so that they can work without javascript.

I think protonmail somewhere claims that the phone number is not linked to your account but they keep the number because you can not use a number more than once and i would say this is already bad enough.

Tutanota or ctemplar at least do not require an SMS verification so i would prefer them when you need an email service who works for clearnet too.
/u/PharmaSyndicate
1 points
5 years ago
javascript
/u/adversa 📢
1 points
5 years ago
Strange that this didn't come up in my search, although it was quite late last night so I may have just missed it. Much appreciated!
/u/tabbi2x0
1 points
5 years ago
i wouldnt use oroton mail

just use secmail or something like that

just go to their onion address and duckduckgo it

make sure its the onion one. they dont ask for any info and no java. easy to sign up and you can use it chronically or a simple throw away. almost literally untraceable long as you dont dox yourself

good luck
/u/adversa 📢
1 points
5 years ago
Thanks - yes, I made a secmail yesterday and will be using it from now on. As someone else mentioned above there's a difference between being "privacy-focused" service and allowing people to be truly anonymous and I would prefer to remain the latter.
/u/LPFJ2
1 points
5 years ago
I hers secmail is also compromised.
/u/adversa 📢
1 points
5 years ago
Source for this claim?
/u/LPFJ2
0 points
5 years ago
Dude aren't you defended?
/u/adversa 📢
1 points
5 years ago
My apologies, I'm not sure I understand your comment?