• ChristerMLB@piefed.social
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    1
    ·
    edit-2
    3 days ago

    Expecting everyone to be good at opsec is not a practical solution - making it the problem of the company that can and should hire people to be good at opsec, is.

    • stoy@lemmy.zip
      link
      fedilink
      English
      arrow-up
      2
      ·
      3 days ago

      Well, not everyone needs to be good at opsec, most people are fine as is.

      Most people are not working against the government either.

      But if you are going against the government, or any large and powerful entity, you absolutely need good, reliable opsec.

      When the police comes knocking on your door, you can’t just blame Proton for not informing you about not using your own CC to sign up for your service.

      This isn’t a playground, you are dealing with the big boys now, and they have far more tools than you have, unless you learn and adapt, you will get burnt.

      So while you are right that bot everyone can be expected to be good at opsec, that isn’t the issue.

      The issue is that this was an opsec failure of the guy, it wasn’t Proton messing up.

      • ChristerMLB@piefed.social
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        3 days ago

        “When the police comes knocking on your door, you can’t just blame Proton”

        obviously, but the ideal we should be working towards is that privacy is the default, right? The more normal it is to have this kind of privacy, the less suspicious it is.

        are they legally required to store the credit card information?

        • stoy@lemmy.zip
          link
          fedilink
          English
          arrow-up
          1
          ·
          3 days ago

          I agree that we should work toward a more private society, but we are not there yet.

          And to answer your question, yes, Proton is required to store the CC info.

          • ChristerMLB@piefed.social
            link
            fedilink
            English
            arrow-up
            1
            ·
            edit-2
            3 days ago

            Reply

            oh, well in that case I’m not sure what they could have done, aside from being clearer that this was a threat that users had to be aware of