WEBVTT
Kind: captions
Language: en

00:00:00.040 --> 00:00:07.580
Welcome everybody to my Proton Hardening Tutorial Part 2. The last video talked about Proton Mail

00:00:08.240 --> 00:00:13.380
as well as your Proton Account just on a meta level. It's important to watch that first because

00:00:13.540 --> 00:00:17.980
that Proton Account stuff is going to impact all the tools we covered today. This video we're going

00:00:17.980 --> 00:00:23.380
to touch on pretty much everything in the rest of the Proton Suite from ProtonVPN, ProtonPass,

00:00:23.600 --> 00:00:29.980
ProtonLumo, ProtonDrive, ProtonWallet, ProtonMeet. So I want to dive into the rest of the

00:00:30.000 --> 00:00:34.480
stuff, show you guys the things to enable, not enable, what each thing means. And again, this is

00:00:34.510 --> 00:00:39.040
a hardening guide, which means that this is for people who want to go above and beyond the already

00:00:39.220 --> 00:00:44.620
really good default settings that Proton offers. The goal isn't for you to enable everything 100%.

00:00:44.740 --> 00:00:48.680
It's to decide which of the tools make sense for your situation. And I'm going to do my best to

00:00:48.940 --> 00:00:53.980
educate you as I go. There will be timestamps for each tool in the suite. Go ahead and click around

00:00:54.170 --> 00:00:58.739
if you just want to look for a specific tool in the Proton ecosystem. The PGP guide should be the

00:00:58.760 --> 00:01:02.700
next video so we can talk about pretty good privacy and email encryption in the next video.

00:01:02.980 --> 00:01:08.680
Now let's get into ProtonVPN. So the first thing is picking a server. And this is a bit of a

00:01:08.900 --> 00:01:13.400
polarizing topic, but I think for most people, the right advice is to just pick a server that's

00:01:13.520 --> 00:01:16.500
closest to you. You're going to get the best feeds and you're going to get most of the benefits from

00:01:16.520 --> 00:01:21.380
your VPN. I think it's more about the company you're trusting. And as long as you're not picking

00:01:21.560 --> 00:01:26.920
a country that specifically is known to target VPN servers, you're probably still going to get very

00:01:26.940 --> 00:01:31.520
good benefits. But that is kind of a personal call. I think the universal advice I share with people

00:01:31.520 --> 00:01:36.940
is pick a server closest to you, unless you have a reason to not pick that server. Now port forwarding

00:01:37.080 --> 00:01:41.800
is a really good feature if you are torrenting or you have any games that go through P2P and you

00:01:41.940 --> 00:01:46.520
want the best speed. So if you are one of those people, you can definitely turn this feature on.

00:01:46.740 --> 00:01:51.440
Just keep in mind, it does create an inbound path to your device. So if you want to get very

00:01:51.640 --> 00:01:56.820
technical, that is opening up some attack surface, though I think a lot of that's speculative.

00:01:57.120 --> 00:02:02.620
But either way, if you're really going for the max hardening, I would definitely leave this off, especially if you have no reason to turn it on.

00:02:02.820 --> 00:02:05.300
The kill switch is one of the most important things of a VPN.

00:02:05.700 --> 00:02:10.080
It ensures that when you're connected to the VPN, all the traffic only goes through the VPN.

00:02:10.259 --> 00:02:13.920
And if you disconnect for whatever reason, all the traffic gets cut out.

00:02:14.100 --> 00:02:20.260
I do recommend for almost all situations, especially if you're watching this guy, to enable your kill switch, especially the one here.

00:02:20.360 --> 00:02:22.520
because this is their simple kill switch,

00:02:22.820 --> 00:02:27.620
which what it means is if you are actively connected to the VPN server,

00:02:28.120 --> 00:02:29.540
then the kill switch is enabled,

00:02:29.820 --> 00:02:32.780
which means if anything else tries to connect outside the VPN tunnel,

00:02:33.320 --> 00:02:34.400
then it won't go through,

00:02:34.460 --> 00:02:37.140
which I think for most people is exactly what they want.

00:02:37.540 --> 00:02:39.560
Now, they do technically have an advanced kill switch,

00:02:39.620 --> 00:02:43.300
which I believe is on Windows as well as Linux.

00:02:44.000 --> 00:02:47.080
And that one actually applies even when you click disconnect,

00:02:47.460 --> 00:02:48.800
which means that when you're disconnected

00:02:49.440 --> 00:02:50.900
and you have that one on,

00:02:51.020 --> 00:02:52.760
it literally just doesn't connect to anything.

00:02:53.060 --> 00:02:55.880
There is a big gotcha with the advanced kill switch.

00:02:56.100 --> 00:02:57.800
The simple one is safe to use,

00:02:58.340 --> 00:03:00.020
but for the advanced kill switch,

00:03:00.200 --> 00:03:03.440
it can actually lock you out of your operating system itself.

00:03:03.820 --> 00:03:05.160
You could be in a situation

00:03:05.480 --> 00:03:06.820
where the kill switch is still activated,

00:03:06.980 --> 00:03:08.400
but you get logged out of ProtonVPN,

00:03:08.520 --> 00:03:09.340
so you can't connect,

00:03:09.600 --> 00:03:10.580
and now you're kind of stuck

00:03:10.740 --> 00:03:12.040
with broken internet on your system.

00:03:12.220 --> 00:03:13.820
The next feature is NetShield.

00:03:14.020 --> 00:03:15.820
This is a DNS feature.

00:03:15.920 --> 00:03:17.340
They don't really present it that way,

00:03:17.500 --> 00:03:18.760
but it is how it works.

00:03:18.960 --> 00:03:20.720
So when you connect to your VPN tunnel,

00:03:21.160 --> 00:03:22.720
oftentimes, especially the case with Proton,

00:03:23.080 --> 00:03:25.780
Proton then becomes your DNS provider as well,

00:03:26.080 --> 00:03:27.260
which means that they are the ones

00:03:27.290 --> 00:03:28.480
who are handling your queries.

00:03:28.920 --> 00:03:31.100
The cool thing is that they're able to do some filtering

00:03:31.320 --> 00:03:33.640
because they get access to those DNS queries.

00:03:34.160 --> 00:03:35.720
I always enable this

00:03:36.050 --> 00:03:38.060
because it means that anytime you access a website,

00:03:38.540 --> 00:03:40.300
it can block malware ads and trackers.

00:03:40.540 --> 00:03:41.940
You can also just block malware only,

00:03:42.220 --> 00:03:43.940
but I think for almost everyone out there,

00:03:44.020 --> 00:03:45.560
you want to do the most amount of filtering.

00:03:45.880 --> 00:03:51.700
If you're already trusting a provider with your DNS queries, there's no more trust required for them to filter those DNS queries.

00:03:51.870 --> 00:03:54.040
So this is no different from regular DNS filtering.

00:03:54.240 --> 00:03:56.460
It's just streamlined for you within the Proton ecosystem.

00:03:56.780 --> 00:03:58.620
We'll talk about custom DNS in a second here.

00:03:58.670 --> 00:04:03.340
But if you're not going to be touching custom DNS and you want to stick with just Proton stuff, enable this.

00:04:03.560 --> 00:04:05.520
SecureCore is a bit of an interesting feature.

00:04:05.650 --> 00:04:11.160
So if you turn SecureCore on, it's going to filter your traffic through more than one server.

00:04:11.250 --> 00:04:14.460
And they specifically have these servers with higher levels of security.

00:04:14.740 --> 00:04:22.380
If there's a malicious server, if there's something wrong with it, it's going to take you through a second server, which does have some potential privacy benefits there.

00:04:22.800 --> 00:04:25.500
But the caveat is you're still trusting two Proton servers.

00:04:25.680 --> 00:04:33.100
So it's not like you're trusting two different parties, which is a bit different from Apple's private relay or even Obscura's system with MulVad.

00:04:33.100 --> 00:04:38.220
Because in that situation, you have Obscura and MulVad, each of which are two different parties in the relay.

00:04:38.580 --> 00:04:40.600
This is also going to downgrade your speed.

00:04:40.940 --> 00:04:45.780
So I don't personally use SecureCore because for me, a VPN is very simple.

00:04:45.940 --> 00:04:48.460
I'm shifting trust away from my internet service provider,

00:04:49.020 --> 00:04:50.780
and I'm hiding my IP address from websites.

00:04:50.990 --> 00:04:52.860
Those are the two reasons why I'm using a VPN.

00:04:53.290 --> 00:04:56.320
The other feature that is actually a little bit hard to isolate here,

00:04:56.500 --> 00:05:00.220
but you're going to see an Onion logo here on Georgia, on Colorado.

00:05:00.700 --> 00:05:03.780
And if you pull up that server list specifically and you go to the bottom,

00:05:03.830 --> 00:05:06.080
you're going to see that there are these Onion servers.

00:05:06.600 --> 00:05:13.260
This is Proton essentially handling the Tor layer on the VPN server itself, which in some

00:05:13.400 --> 00:05:15.820
ways violates the whole trustless model of Tor.

00:05:16.120 --> 00:05:18.000
But I think it's all relative, right?

00:05:18.160 --> 00:05:22.420
So if you're comparing this to rolling your own Tor browser and, you know, doing that by

00:05:22.540 --> 00:05:25.100
yourself, I'm always going to say use Tor browser for that.

00:05:25.150 --> 00:05:26.880
This doesn't replace that use case.

00:05:27.220 --> 00:05:31.700
But if you want Tor system wide for whatever reason, or you just want something that adds

00:05:31.900 --> 00:05:36.560
more privacy than a regular Proton VPN connection for whatever reason, then you have the option

00:05:36.580 --> 00:05:40.900
use these onion servers. Now, if we go into the settings, we have a few features. Start on boot

00:05:41.060 --> 00:05:45.680
is really nice if you're someone who wants 24 seven VPN connections. So that way, like right when you

00:05:45.860 --> 00:05:50.300
start, boom, it starts and it just connects right away. Notify unprotected networks is just going to

00:05:50.560 --> 00:05:54.540
ping you and give you notification if you connect to a less secure network. So that way it's more

00:05:54.660 --> 00:05:58.640
like on demand. So that's maybe for someone who just wants to use a VPN when they're traveling or

00:05:58.740 --> 00:06:04.320
something like that. In terms of protocol, I, you know, they said they have smart. Personally, I'm a

00:06:04.340 --> 00:06:08.260
WireGuard kind of person. I like how it's a much smaller code base. They don't even have

00:06:08.600 --> 00:06:13.100
OpenVPN here as an option on the macOS client anymore. I think for most of you out there,

00:06:13.320 --> 00:06:17.700
WireGuard is pretty much what you should be using. The one thing to flag though is Stealth,

00:06:17.700 --> 00:06:22.180
which is WireGuard over TLS, which tries to obfuscate the fact that you're using WireGuard

00:06:22.220 --> 00:06:26.540
in the first place. It's important to understand what Stealth is doing. This is for censorship

00:06:27.000 --> 00:06:33.240
resistance. It's actually going to go through some bigger companies like AWS to try to obfuscate

00:06:33.260 --> 00:06:37.000
your traffic. That doesn't mean your web traffic is getting sent to those companies necessarily.

00:06:37.200 --> 00:06:40.920
It's just routing the encrypted tunnel through them. But again, it is actually adding a party.

00:06:41.040 --> 00:06:46.660
That is how the stealth functionality works. So only enable stealth if you need it in a region or

00:06:46.740 --> 00:06:51.880
a situation where your Wi-Fi or your region is blocking your VPN traffic. Split tunneling is

00:06:52.020 --> 00:06:56.240
interesting. It is, as it says, experimental on macOS. I don't think it's experimental on other

00:06:56.440 --> 00:07:01.000
platforms, though. What this is going to do is you can set it so, oh, hey, just these five apps go

00:07:01.020 --> 00:07:05.100
through the tunnel, the VPN tunnel, and these five don't. I think if you just want a system-wide

00:07:05.360 --> 00:07:08.780
VPN, you probably don't need to touch split tunneling. Split tunneling is very useful though

00:07:08.780 --> 00:07:15.080
in situations where, hey, you know, I need pretty much a full system-wide VPN, but there's this one

00:07:15.360 --> 00:07:19.880
program I absolutely need access to that doesn't work with the VPN. And if it wasn't for split

00:07:20.000 --> 00:07:23.640
tunneling, then I couldn't use the VPN at all and I have to turn it off system-wide. Allow LAN

00:07:23.900 --> 00:07:29.680
connections is the next thing. And definitely off is a good safe default. This is a situation where

00:07:29.700 --> 00:07:34.360
you have a local printer on your network. Or for me, I have my NAS behind me and I like to connect

00:07:34.410 --> 00:07:39.580
to that. So if you have a local machine on your network, you need to be able to access on a local

00:07:39.880 --> 00:07:44.360
IP address, then you have to enable allow LAN connections. And that's how you can still access

00:07:44.600 --> 00:07:50.660
it with the VPN still being enabled. Otherwise, if the VPN is enabled and allow LAN connections is

00:07:50.880 --> 00:07:54.600
off, you're not going to be able to access those devices. Alternative routing actually functions

00:07:54.620 --> 00:07:59.680
independent of this protocol. So they are both censorship resistant techniques. It actually

00:07:59.860 --> 00:08:04.220
comes enabled by default. I don't see a reason to disable it. It's just in a situation where you

00:08:04.360 --> 00:08:08.840
can't connect to Proton to log in. It's going to allow alternative routing to still try to make it

00:08:08.880 --> 00:08:13.600
work if for whatever reason Proton is censored. Moderate NAT you should keep off unless you

00:08:13.900 --> 00:08:17.780
absolutely really need the feature. It's for peer-to-peer applications. It kind of gives a

00:08:17.860 --> 00:08:22.100
description there. It's not a feature I've used before, but this is one of the few features that

00:08:22.120 --> 00:08:26.980
Proton specifically says slightly reduces your privacy. So it's something to keep off if you're

00:08:26.990 --> 00:08:30.980
able to keep it off. And just like I covered in the last hardening guide, you know, I think there's

00:08:30.980 --> 00:08:35.840
a difference between like invasive telemetry and analytics designed to just track you versus an

00:08:36.000 --> 00:08:40.020
organization that is privacy respecting like Proton who wants to collect basic information.

00:08:40.110 --> 00:08:44.320
But this is a hardening guide. So if you are trying to make things as private as you possibly can,

00:08:44.740 --> 00:08:49.460
definitely keep these off. Custom DNS is something that I've covered more in other content. I made a

00:08:49.480 --> 00:08:53.900
whole video that does like DNS versus VPN. And I would really check that out if you want to learn

00:08:54.080 --> 00:08:59.300
more. If you are watching this video and you just need a basic VPN connection, you're in the Proton

00:08:59.500 --> 00:09:04.260
ecosystem, I don't think you need to touch custom DNS. But I do sometimes like using a custom DNS

00:09:04.480 --> 00:09:08.540
provider. And so if you want to learn more, check out that video and make sure you're using a trusted

00:09:08.740 --> 00:09:13.800
DNS provider if you do choose to use a custom DNS. This is going to override NetShield. Again,

00:09:14.020 --> 00:09:15.880
NetShield is a DNS filtering tool.

00:09:16.170 --> 00:09:17.960
So if you use a custom DNS here

00:09:18.070 --> 00:09:19.480
and you use your own DNS provider

00:09:19.490 --> 00:09:22.580
like Mulvad DNS or NextDNS or even Control-D,

00:09:22.840 --> 00:09:24.660
you are going to override NetShield.

00:09:24.670 --> 00:09:27.980
So you are having to shift that feature to another tool.

00:09:28.120 --> 00:09:30.060
My last thing to mention about ProtonVPN

00:09:30.190 --> 00:09:32.720
is that there is kind of these like always connected

00:09:32.950 --> 00:09:34.760
slash kill switch features on mobile.

00:09:34.930 --> 00:09:36.400
I would just overall treat mobile

00:09:36.700 --> 00:09:38.620
as a little bit less robust,

00:09:39.000 --> 00:09:40.900
especially on the iOS side of things.

00:09:40.970 --> 00:09:42.140
We see time and time again,

00:09:42.400 --> 00:09:45.080
that full system-wide VPNs on iOS,

00:09:45.250 --> 00:09:46.900
while they still very much do something,

00:09:47.130 --> 00:09:49.860
we can't fully guarantee that 100% of your traffic

00:09:50.280 --> 00:09:52.400
is guaranteed to go through the VPN tunnel.

00:09:52.640 --> 00:09:53.680
This is a serious issue.

00:09:53.870 --> 00:09:56.640
It is an Apple problem that Apple refuses to acknowledge

00:09:56.930 --> 00:09:58.200
within the iOS ecosystem

00:09:58.390 --> 00:10:00.520
because they still try to, at times,

00:10:01.080 --> 00:10:03.060
make weird exceptions for their own traffic.

00:10:03.380 --> 00:10:05.360
On Android, while this is much better

00:10:05.580 --> 00:10:06.700
than what we've seen on iOS,

00:10:07.100 --> 00:10:08.740
we have still seen examples in the past

00:10:08.980 --> 00:10:10.419
where some things didn't go through

00:10:10.440 --> 00:10:16.620
even the whole like only allow connections through your VPN feature on Android. So just in general,

00:10:16.830 --> 00:10:21.840
I would treat mobile devices as like, hey, your VPN is going to work for you potentially 99% of the

00:10:21.960 --> 00:10:26.020
times. And that's still really good. But I really want to make that clear so that no one feels

00:10:26.320 --> 00:10:30.500
misled by the privacy they're getting on a mobile operating system. All right, the next tool is

00:10:30.510 --> 00:10:35.880
going to be Proton Pass. And it's my favorite Proton tool, like for the record. So for this one,

00:10:35.960 --> 00:10:38.420
I actually want to start in the settings first.

00:10:38.820 --> 00:10:43.380
In general, while I'm not saying that the ProtonPass beta is insecure,

00:10:44.060 --> 00:10:49.340
I do like to run stable software for something as sensitive for me personally as my password manager.

00:10:49.700 --> 00:10:54.860
So I don't enable the beta and that is something I do recommend if you have a higher security threat model.

00:10:55.040 --> 00:10:59.840
Website favicons, favicons, however you want to say that, that's a polarized topic, I think.

00:11:00.040 --> 00:11:02.060
This is going to be anonymously proxy.

00:11:02.340 --> 00:11:06.040
Just be aware that is technically something that you are adding a bit of trust in.

00:11:06.110 --> 00:11:07.360
I do keep it enabled.

00:11:07.470 --> 00:11:11.800
I like the icons next to the entry, but just be aware that there is a little bit of trust

00:11:11.850 --> 00:11:12.660
you're handing over there.

00:11:12.960 --> 00:11:14.660
Offline mode, I would always enable.

00:11:14.860 --> 00:11:19.400
It's not necessarily a security thing, but I've been in so many situations where I need

00:11:19.430 --> 00:11:20.780
to be able to log into something.

00:11:21.000 --> 00:11:22.960
I think my Wi-Fi router is a perfect example.

00:11:23.280 --> 00:11:24.600
I don't know the password to my Wi-Fi.

00:11:24.720 --> 00:11:25.760
It's in my password manager.

00:11:26.240 --> 00:11:30.279
But if I don't have internet for whatever reason, and then I can't log into ProtonPass

00:11:30.280 --> 00:11:31.740
because it requires an internet connection,

00:11:32.280 --> 00:11:34.100
then I can't get the password, so I'm stuck.

00:11:34.580 --> 00:11:36.540
So enable this, it's very good to have,

00:11:36.760 --> 00:11:38.440
and I can't think of anything it's going to cost you

00:11:38.460 --> 00:11:39.980
from a privacy or security perspective.

00:11:40.340 --> 00:11:42.880
Next is the security tab, and guys, I want to be clear here.

00:11:43.040 --> 00:11:44.980
There is, in my view, no right answer.

00:11:45.060 --> 00:11:47.120
I do think a pin code might not be the right answer,

00:11:47.360 --> 00:11:48.660
and none is not the right answer.

00:11:48.800 --> 00:11:51.260
So I think picking between password and biometrics

00:11:51.300 --> 00:11:53.080
is really where the real debate's going to lie

00:11:53.080 --> 00:11:54.320
for most of you out there.

00:11:54.560 --> 00:11:56.860
Biometrics are really nice because they're convenient,

00:11:57.120 --> 00:12:00.260
they're easy, and also there's no way to shoulder surf

00:12:00.260 --> 00:12:05.780
biometric. If I'm out and about and I'm traveling and I'm using, you know, touch ID or something like

00:12:05.880 --> 00:12:10.420
that. And if there's someone sitting next to me, they can't see me type in my Proton password to

00:12:10.420 --> 00:12:14.240
get into my password manager, which is a really important benefit. And think about security

00:12:14.500 --> 00:12:18.460
cameras and stuff like that, too. The nice thing about a password, though, is that it actually has,

00:12:18.700 --> 00:12:22.820
you know, different jurisdiction benefits because police probably can't compel you to hand over a

00:12:22.900 --> 00:12:26.900
password, but they can compel you to unlock something via biometrics. So this is something

00:12:26.920 --> 00:12:31.480
that you need to make a decision on. I think maybe a safe thing like what I would personally do if

00:12:31.540 --> 00:12:36.040
I'm trying to pick between these situations. If I have a mobile device, biometrics might make more

00:12:36.200 --> 00:12:39.760
sense because I'm on the go. I want things to be convenient. And also I want to prevent that

00:12:40.000 --> 00:12:44.800
shoulder surfing concern. And if I'm at home at my desktop, I'm personally still going to be using

00:12:44.920 --> 00:12:49.220
biometrics, but I could see someone where they do like password on their desktop and then they use

00:12:49.320 --> 00:12:53.520
biometrics on the go. Or if you have a different threat model, you could even end up reversing that

00:12:53.540 --> 00:12:55.900
where if your main concern is traveling over a border,

00:12:56.240 --> 00:12:58.660
you may actually be more likely to use biometrics at home

00:12:59.100 --> 00:13:00.400
and then a password when you're traveling.

00:13:00.660 --> 00:13:04.320
Autolock is something that is not even able to turn off with ProtonPass.

00:13:04.720 --> 00:13:07.520
Obviously, the sooner you can make the autolock, the better.

00:13:07.660 --> 00:13:10.360
What this is going to do is if you unlock ProtonPass,

00:13:10.500 --> 00:13:12.880
you copy a password and you don't use it,

00:13:13.180 --> 00:13:14.100
it's going to autolock itself.

00:13:14.540 --> 00:13:15.620
So I do 10 minutes.

00:13:15.680 --> 00:13:18.280
I think 10 minutes is a nice middle ground here.

00:13:18.600 --> 00:13:19.600
You can do quicker,

00:13:19.760 --> 00:13:22.000
but then you're going to have to constantly be unlocking your vault.

00:13:22.060 --> 00:13:30.620
If you want extra security, and this is nice because, you know, you are still ultimately logging into ProtonPass with the same password as the rest of your Proton account.

00:13:30.900 --> 00:13:32.840
And I know that bothers a lot of people.

00:13:33.220 --> 00:13:39.880
So you can add an extra password so that you need to only protect ProtonPass with this extra password.

00:13:40.000 --> 00:13:41.840
You're definitely going to gain security when you do this.

00:13:42.080 --> 00:13:44.940
It's a question of convenience and how it's going to benefit you.

00:13:45.220 --> 00:13:49.760
But you definitely should enable this if you have the absolute highest security needs.

00:13:50.040 --> 00:13:52.100
And that is going to be the best way forward for you.

00:13:52.380 --> 00:13:54.680
This is one I do also recommend everybody uses.

00:13:54.920 --> 00:13:57.100
You know, a lot of programs can read your clipboard

00:13:57.300 --> 00:13:59.660
or you could accidentally paste something from your clipboard.

00:14:00.000 --> 00:14:02.200
And so this is going to automatically clear your clipboard

00:14:02.320 --> 00:14:03.540
when you copy a password.

00:14:03.700 --> 00:14:06.820
So I open ProtonPass, copy my password, I paste it.

00:14:07.140 --> 00:14:09.040
And then two minutes later, it's just going to clear it.

00:14:09.100 --> 00:14:10.860
So that way I can't paste my password again.

00:14:11.360 --> 00:14:13.340
You can paste it as many times as you want within the two minutes.

00:14:13.620 --> 00:14:16.520
Of course, you can turn it off, but I do think it's a good feature to enable.

00:14:16.800 --> 00:14:18.380
Now I created this test vault here.

00:14:18.700 --> 00:14:22.940
And within the vault, keep in mind, when you're generating a password, you have a lot of options

00:14:23.120 --> 00:14:28.220
here for most situations. The defaults are pretty good. They normally default to like four or five

00:14:28.460 --> 00:14:32.880
words, I've noticed, for the memorable passwords. And there's also the random passwords. And you

00:14:32.880 --> 00:14:36.620
can just drag it here. You can have advanced options just to make sure you're generating

00:14:36.770 --> 00:14:40.400
strong passwords, because you are using a password manager and you have that luxury.

00:14:40.760 --> 00:14:45.600
Parts of Pass also integrates with SimpleLogin, which I think is actually my favorite feature.

00:14:46.020 --> 00:14:51.120
Now, something I didn't know that a Techlorian told me in our call is if I generate this here,

00:14:51.340 --> 00:14:53.820
like I just generated this alias and then I click save.

00:14:54.120 --> 00:14:58.900
If I create this alias, right, and this is for like, let's say use this to become a Techlorian,

00:14:59.020 --> 00:14:59.640
which you guys should do.

00:14:59.680 --> 00:15:01.600
You can support what we do down in the description.

00:15:01.720 --> 00:15:04.440
We have a private signal group and there's lots of other fun perks there.

00:15:04.660 --> 00:15:08.480
If I email you to your alias, it's going to go to your regular email inbox

00:15:08.780 --> 00:15:12.920
and you're never going to expose your email to me directly, which is a huge privacy benefit.

00:15:13.520 --> 00:15:15.940
But let's say you want to email me first, right?

00:15:16.360 --> 00:15:24.120
Normally, what I would do is I have to log into SimpleLogin, find the alias, generate the reverse alias, and then I have to email it to that.

00:15:24.200 --> 00:15:25.480
If you guys know, you know.

00:15:25.640 --> 00:15:26.680
It's kind of a pain in the butt.

00:15:26.860 --> 00:15:30.520
But what the Techlorian taught me is that if you go to the alias here, right?

00:15:30.680 --> 00:15:31.860
Like this is just for the email.

00:15:32.320 --> 00:15:35.620
If you go to contacts, if I already emailed you, it's going to show up here.

00:15:35.780 --> 00:15:37.620
But I can also create the contact here, right?

00:15:37.720 --> 00:15:39.440
So I can do contact.techlor.tech.

00:15:39.660 --> 00:15:44.060
And then you can click this and it'll open in your email client or you can copy the forwarding address.

00:15:44.520 --> 00:15:49.420
And that forwarding address, it looks like gibberish, but that allows you to be able to email someone.

00:15:49.620 --> 00:15:51.900
And I would only ever see this alias.

00:15:52.020 --> 00:15:54.380
So it looks like you're emailing me from this alias.

00:15:54.500 --> 00:15:57.120
I would recommend all of you enable pass monitor.

00:15:57.160 --> 00:16:00.900
I think it's on by default, but there is no reason not to use this.

00:16:01.120 --> 00:16:03.920
It's going to monitor your passwords to see if any of them got breached.

00:16:04.200 --> 00:16:07.040
This could be where you find out that one of your services got breached.

00:16:07.340 --> 00:16:10.020
Here, first, before the company tells you about it.

00:16:10.140 --> 00:16:11.080
That's not uncommon.

00:16:11.480 --> 00:16:13.680
It's going to tell you if you have reused passwords, weak passwords.

00:16:14.160 --> 00:16:19.980
It also can check if you put a domain, if that domain has 2FA, but you don't have it enabled in ProtonPass.

00:16:20.340 --> 00:16:22.580
It'll tell you that so you can enable two-factor authentication.

00:16:22.840 --> 00:16:25.900
And we already talked about ProtonSentinel in the last hardening guide.

00:16:26.080 --> 00:16:32.380
The last two things, again, guys, go back to the first hardening guide because your ProtonPass, where all of your passwords live,

00:16:32.840 --> 00:16:36.820
largely inherits the security of your Proton account, which was covered in the first video.

00:16:37.120 --> 00:16:38.920
So that is always a thing I'm going to remind you about.

00:16:39.160 --> 00:16:42.060
The last thing I want to talk about is shared links.

00:16:42.340 --> 00:16:46.340
This is when I go to an item and I click share and it's going to give you a secure link.

00:16:46.760 --> 00:16:50.140
Guys, if you give that secure link to anybody, they have access to that credential.

00:16:50.600 --> 00:16:54.400
And also keep in mind, when you have a shared vault, when you share it with somebody else,

00:16:54.920 --> 00:16:56.820
they're also going to have access to everything in the vault.

00:16:56.940 --> 00:16:59.660
There actually was some really interesting research from Zurich,

00:16:59.860 --> 00:17:02.880
which found that there were some password managers and their sharing features

00:17:03.360 --> 00:17:06.819
were actually how they were exploited to access many things in the vault.

00:17:07.300 --> 00:17:09.520
They did not study ProtonPass specifically,

00:17:09.939 --> 00:17:19.199
But it's really important to read into that research and understand that just having any kind of sharing enabled on your account, period, is opening up your attack surface a little bit.

00:17:19.439 --> 00:17:22.000
So I try to avoid sharing unless I absolutely need to.

00:17:22.030 --> 00:17:26.839
As you can see, I actually have one link that I generated recently to someone I had to share one credential with.

00:17:27.069 --> 00:17:28.940
But keep your sharing as minimal as you can.

00:17:29.200 --> 00:17:31.720
Proton Drive is pretty straightforward.

00:17:32.160 --> 00:17:36.140
And honestly, I don't have too much to share, but there are still a few things I wanted to cover.

00:17:36.500 --> 00:17:39.220
First off, a lot of these will have app blocks on mobile.

00:17:39.460 --> 00:17:44.840
So you can set some kind of way to make sure that you need extra authentication to access the app on mobile.

00:17:45.220 --> 00:17:47.600
Proton Drive also has share link controls.

00:17:48.060 --> 00:17:53.180
So if I create a new folder here, you should understand what those controls are.

00:17:53.290 --> 00:17:57.460
So if I click share, you can share it with other people within the Proton ecosystem,

00:17:57.630 --> 00:17:59.800
which would keep it encrypted between those people.

00:18:00.300 --> 00:18:02.280
And then you also can do a public link.

00:18:02.700 --> 00:18:06.360
If you do a public link, you can set it to editor so anyone with the link can view.

00:18:06.540 --> 00:18:09.760
But keep in mind, there is this feature down here, which a lot of people don't know about,

00:18:09.810 --> 00:18:12.640
which is you can require a password as well.

00:18:13.040 --> 00:18:15.740
So if you do a public link, again, you can do it with a password,

00:18:15.790 --> 00:18:17.920
which is nice if that person doesn't have Proton.

00:18:18.120 --> 00:18:20.600
Keep in mind, if you are sharing access to someone else,

00:18:20.900 --> 00:18:24.200
the email address of your Proton account, if you're sharing a document or something,

00:18:24.340 --> 00:18:25.540
is visible to the recipient.

00:18:26.140 --> 00:18:28.080
So just be aware of that before you share things.

00:18:28.440 --> 00:18:31.080
Proton does also say if you're doing a photo backup,

00:18:31.580 --> 00:18:34.180
there is the creation date that is not encrypted.

00:18:34.440 --> 00:18:37.080
That's just so that they can actually chronologically sort your photos.

00:18:37.220 --> 00:18:41.680
I don't think there's anything really privacy invasive there, but it is something I wanted to flag.

00:18:42.060 --> 00:18:44.640
In terms of docs and sheets, it's pretty well done.

00:18:44.820 --> 00:18:49.420
Document names, the contents, the edits, the comments, suggestions, those are all end-to-end encrypted.

00:18:49.540 --> 00:18:54.120
And so the documents are all very well thought out and there's no caveats I wanted to share there.

00:18:54.360 --> 00:19:01.280
Now, one question I do see a lot, which I did want to clear up, is should I encrypt my files before uploading them to ProtonDrive,

00:19:01.620 --> 00:19:03.900
specifically with tools like Cryptomator, which are designed for that?

00:19:04.060 --> 00:19:08.740
And I have a whole guide on Cryptomator if you guys want to encrypt your files before they go on any cloud provider.

00:19:08.840 --> 00:19:11.480
I think it's really unnecessary, right?

00:19:11.720 --> 00:19:14.160
Like this is by itself end-to-end encrypted.

00:19:14.500 --> 00:19:21.780
So unless you have a crazy high threat model where even Proton themselves having some weird, let's say, vulnerability in their encryption,

00:19:22.100 --> 00:19:27.680
and you want to make sure all your documents are completely secure, then sure, you can combine Cryptomator with ProtonDrive.

00:19:28.020 --> 00:19:34.260
But you're getting double end-to-end encryption for what I think is really no real benefit and also less reliability.

00:19:34.880 --> 00:19:38.160
Lumo AI is next, and it is their LLM chat.

00:19:38.560 --> 00:19:42.860
They made a lot of updates to this over time, and it's really developed since I first looked at it.

00:19:43.060 --> 00:19:47.720
The first feature is their ghost mode, so this disappears when you close it and is never saved.

00:19:47.820 --> 00:19:54.540
I don't think this meaningfully changes the privacy or security in terms of how much you're trusting Proton or anything like that.

00:19:54.780 --> 00:19:59.000
They do have a very good write-up on how they're able to process these queries as privately as they do.

00:19:59.540 --> 00:20:01.400
And it's very cool and interesting text.

00:20:01.540 --> 00:20:03.440
So if you guys want to check that out, definitely look into that.

00:20:03.720 --> 00:20:06.280
Based on what I've seen, Ghost Mode doesn't change any of that system.

00:20:06.450 --> 00:20:08.280
It just is a local feature.

00:20:08.470 --> 00:20:13.640
So if you want to be able to do things locally and it's not going to save the history locally in your browser,

00:20:14.080 --> 00:20:15.800
that's what Ghost Mode is really for.

00:20:15.880 --> 00:20:19.240
It's kind of like incognito mode in a more traditional browser setting.

00:20:19.460 --> 00:20:22.240
If you go into the settings, the personalization is stored zero access.

00:20:22.560 --> 00:20:25.220
So nothing here should impact your privacy or security.

00:20:25.320 --> 00:20:28.700
So feel free to have fun and use those features to your heart's content.

00:20:29.180 --> 00:20:29.960
Memory is the same thing.

00:20:30.240 --> 00:20:31.100
Also zero access.

00:20:31.300 --> 00:20:32.540
So you can turn it on.

00:20:32.740 --> 00:20:35.060
It's not going to really jeopardize your privacy in any way.

00:20:35.240 --> 00:20:40.220
The main feature actually that I really think in any way changes the privacy of LUMO.

00:20:40.320 --> 00:20:43.640
It's a pretty reliable and similar experience across the board.

00:20:43.900 --> 00:20:45.080
But automatic web search.

00:20:45.460 --> 00:20:48.780
So this actually will transmit, if you have it enabled,

00:20:49.100 --> 00:20:52.360
it transmits a simplified version of your request.

00:20:52.420 --> 00:20:56.260
to a select partner API to retrieve results.

00:20:56.370 --> 00:20:58.720
They say that they are privacy-respecting partners,

00:20:59.280 --> 00:21:02.180
but it is worth mentioning that if you do have web searches enabled,

00:21:02.450 --> 00:21:05.960
it is going to leave that Proton encrypted envelope

00:21:06.230 --> 00:21:08.300
and where the normal privacy guarantees exist.

00:21:08.440 --> 00:21:12.380
Every other Lumo feature is zero access encrypted end-to-end,

00:21:12.450 --> 00:21:14.440
but the web search is the one feature

00:21:14.700 --> 00:21:16.460
where obviously you can't really do that.

00:21:16.550 --> 00:21:18.000
They have to search the web somehow.

00:21:18.230 --> 00:21:20.920
I think if you're already trusting Proton with Lumo,

00:21:21.100 --> 00:21:24.320
I don't see how this is going to make a huge difference for you.

00:21:24.800 --> 00:21:27.920
But again, this is a hardening guide, so I want to make sure you guys are aware of that.

00:21:28.080 --> 00:21:32.220
There is a delete everything button if you just want a simpler way to clear all the chats on your system.

00:21:32.620 --> 00:21:37.080
Otherwise, Lumo is a pretty safe, reliable experience that doesn't have much variability

00:21:37.510 --> 00:21:40.800
from the most to least possibilities of how secure you can make it.

00:21:41.720 --> 00:21:45.380
Proton Calendar also doesn't have a huge amount here.

00:21:45.490 --> 00:21:50.600
I think the one thing to just flag right out the gate is that event start and end times.

00:21:51.080 --> 00:21:54.140
and time zones are signed, but not encrypted.

00:21:54.420 --> 00:21:56.120
That's needed because the Proton servers

00:21:56.150 --> 00:21:57.980
need to be able to index and retrieve them.

00:21:58.300 --> 00:22:01.400
I kind of see this as the subject lines in ProtonMail,

00:22:01.540 --> 00:22:02.840
which I covered in the last video.

00:22:03.280 --> 00:22:05.640
So it's just kind of a necessary part of running the service.

00:22:05.940 --> 00:22:06.840
The other main thing,

00:22:06.840 --> 00:22:08.220
and this is probably the main exposure

00:22:08.540 --> 00:22:09.880
to kind of flag for you,

00:22:10.050 --> 00:22:12.420
even though Proton Calendar is end-to-end encrypted

00:22:12.820 --> 00:22:14.920
and does a lot of really good stuff to help your privacy,

00:22:15.400 --> 00:22:18.000
if you have an external attendee,

00:22:18.240 --> 00:22:21.040
so you create an event and you add a participant

00:22:21.040 --> 00:22:27.860
who does not use ProtonMail, the whole invite actually falls back to a normal unencrypted email

00:22:28.300 --> 00:22:31.820
flow. In terms of sharing your calendar, you have a couple options. The first of which

00:22:32.260 --> 00:22:37.460
is to just share your calendar with another Proton user. And this is end-to-unencrypted,

00:22:37.940 --> 00:22:41.740
has all the collaboration. And so if you have someone you want to share your calendar with,

00:22:42.060 --> 00:22:46.860
and they are a Proton user, this is always the way you should go. However, these links that you

00:22:46.880 --> 00:22:51.380
generate here. I mean, there's some obscurity there because if I create a link, it's going to

00:22:51.400 --> 00:22:55.820
be just random gibberish and then I can import that into any other calendar. But keep in mind

00:22:55.840 --> 00:23:00.180
that that link, anybody theoretically could get that link if you leak it for whatever reason.

00:23:00.640 --> 00:23:05.080
And now anyone can read your calendar entries. So keep in mind that this is a huge amount of

00:23:05.360 --> 00:23:09.520
exposure. It's just part of how calendars work. It's not something that Proton is doing wrong.

00:23:09.840 --> 00:23:13.700
But the nice thing is that this is view only and they cover that in their documentation. So this

00:23:13.720 --> 00:23:17.940
is more for being able to just view your calendar from another calendar like Apple Calendar,

00:23:18.070 --> 00:23:21.920
Google Calendar, etc. So you can subscribe to it essentially from a third party. The last piece of

00:23:22.000 --> 00:23:27.300
advice I have is to compartmentalize calendars if you are using Proton Calendar for more than one

00:23:27.370 --> 00:23:30.760
thing on the same account. So that way you can have maybe a shared calendar with co-workers,

00:23:31.010 --> 00:23:35.420
a different shared calendar with someone in your personal life, and then maybe just a third calendar

00:23:35.640 --> 00:23:40.920
for events that is made public for maybe like a group that you run or an event that you organize.

00:23:41.320 --> 00:23:46.780
On the topic of Proton Calendar, recently they have also had Proton Meet, which is kind of their Zoom alternative.

00:23:47.160 --> 00:23:52.180
And you can actually have a feature where it automatically attaches a Proton Meet link to Calendar Invites.

00:23:52.560 --> 00:23:54.140
There's not much to talk about here.

00:23:54.290 --> 00:24:01.100
It automatically enables MLS, which is messaging layer security, which is going to give you end-to-end encryption group communication within the call.

00:24:01.290 --> 00:24:02.680
And that is just enabled by default.

00:24:03.060 --> 00:24:08.440
If I start a new meeting here, it's actually going to be part of the link that you share.

00:24:08.510 --> 00:24:10.640
The link that you share is the key.

00:24:10.780 --> 00:24:14.060
So you're going to see here there's the ID and then there's the password there.

00:24:14.360 --> 00:24:19.320
So when I copy the link, if I actually remove that password from the link, it's going to take me to the right room.

00:24:19.760 --> 00:24:23.300
But if I click join, it's going to say, oh, the meeting password is incorrect.

00:24:23.540 --> 00:24:27.100
So again, it really is everything after the hashtag that is the meeting password.

00:24:27.280 --> 00:24:29.120
You can also lock a meeting in the settings.

00:24:29.380 --> 00:24:34.360
So if you're hosting the meeting, once everyone's in the meeting, you can lock it so that no one else can join.

00:24:34.420 --> 00:24:36.760
So that's a way to add a bit more security to the meeting.

00:24:37.020 --> 00:24:42.620
Other than that, I think this is one of those cool privacy kind of services where there's not much to say.

00:24:42.860 --> 00:24:44.580
Like if you use it, you're pretty well off.

00:24:44.860 --> 00:24:47.500
There's not much more to do beyond the defaults in ProtonMeet.

00:24:47.680 --> 00:24:50.560
Similar-ish story with ProtonWallet.

00:24:50.680 --> 00:24:53.820
This is a self-custodial Bitcoin wallet that Proton put out.

00:24:54.000 --> 00:24:57.400
There isn't honestly a huge amount of extra privacy that they've added.

00:24:57.520 --> 00:25:00.160
And I think the biggest thing to flag here is that it is Bitcoin.

00:25:00.460 --> 00:25:02.460
Bitcoin does have a lot of privacy concerns.

00:25:02.920 --> 00:25:04.900
And so I always want to just quickly flag that.

00:25:04.980 --> 00:25:08.700
I would assume most things that Bitcoin does by default are public and permanent.

00:25:09.220 --> 00:25:15.360
And so if somebody really wants to start investigating trends over time, they can probably start to put those trends together.

00:25:15.650 --> 00:25:17.440
That is not on Proton whatsoever.

00:25:18.040 --> 00:25:20.020
That is just a reality of Bitcoin.

00:25:20.620 --> 00:25:26.360
But I do wish that Proton added some more privacy features because it would make Bitcoin more private within the Proton wallet ecosystem.

00:25:26.700 --> 00:25:34.900
The on-ramps, based on what I could find too, if you actually want to buy it, it seems like they're Banksa and Ramp, which do have some KYC as well, if not full KYC.

00:25:34.940 --> 00:25:36.920
and it seems like they want to use a card.

00:25:36.960 --> 00:25:38.360
So you see it's going to ask for a country.

00:25:38.700 --> 00:25:42.000
So there are more private ways to be able to purchase Bitcoin.

00:25:42.280 --> 00:25:44.120
So that is just something to flag right away.

00:25:44.300 --> 00:25:46.940
One thing that is cool is that if you use their Bitcoin via email feature,

00:25:47.040 --> 00:25:48.560
it is going to do address rotation.

00:25:48.820 --> 00:25:52.920
So you're going to be using different Bitcoin addresses every time you send something.

00:25:53.220 --> 00:25:55.460
If you're a Bitcoin nerd and you want to get really technical,

00:25:55.560 --> 00:25:58.740
when you're creating a new wallet, you can actually use Taproot,

00:25:59.040 --> 00:26:02.880
which has some privacy benefits, but it's not as widely supported.

00:26:03.200 --> 00:26:06.940
So if you're more technical and you know what you're doing, they have a few more kind of details there.

00:26:07.200 --> 00:26:10.960
But it's not something I would just widely recommend to everybody unless you know for sure you want to do that.

00:26:11.070 --> 00:26:18.440
The other important thing is that I'd say 80% of your day-to-day safety and protection is actually from the first video.

00:26:18.550 --> 00:26:25.780
It is actually the meta account protection because so much of that account is what gets access to these other tools, which is one of the main things I see online.

00:26:26.140 --> 00:26:29.140
People are like, oh, wow, like, do you really want to put all your eggs in one basket?

00:26:29.210 --> 00:26:31.020
And it's like, well, it's kind of a tradeoff.

00:26:31.180 --> 00:26:36.800
Is it better to trust 10 different companies, half of which aren't doing as good as Proton in what they do best?

00:26:37.160 --> 00:26:38.120
It is a trade-off.

00:26:38.120 --> 00:26:39.860
I don't think there's a right answer here.

00:26:40.140 --> 00:26:43.000
And I think it's really up to you and where you want to put trust.

00:26:43.380 --> 00:26:48.180
But keep in mind, just because Proton has all these different things doesn't mean you have to use everything in the ecosystem.

00:26:48.540 --> 00:26:49.840
The ecosystem is an option.

00:26:50.360 --> 00:26:55.240
And you guys should try to use whatever in the ecosystem is benefiting your privacy and security the best.

00:26:55.520 --> 00:27:00.040
The other overall theme between both videos is that when you share something, especially

00:27:00.460 --> 00:27:05.900
outside of the Proton ecosystem, it can downgrade, oftentimes it does downgrade, the privacy

00:27:05.980 --> 00:27:06.840
of what you're sharing.

00:27:07.160 --> 00:27:08.120
Does that mean it's useless?

00:27:08.520 --> 00:27:12.100
Absolutely not, because your data is still being stored in a central place that has zero

00:27:12.260 --> 00:27:12.880
knowledge encryption.

00:27:13.180 --> 00:27:17.120
And it's not your problem that someone else isn't using something that's end-to-end encrypted.

00:27:17.420 --> 00:27:21.640
So if they were also doing what you were doing, then everyone is better protected, right?

00:27:21.660 --> 00:27:24.720
So you are actually still part of the movement of helping secure yourself.

00:27:25.360 --> 00:27:29.880
other people's data. But of course, for a hardening guide, always be a bit cautious when you're

00:27:30.060 --> 00:27:33.600
sharing and just be aware that it is almost entirely a different amount of protection

00:27:34.080 --> 00:27:38.160
when you're sharing anything outside of the Proton ecosystem to a non-Proton user.

00:27:38.320 --> 00:27:42.360
The only other thing I'd say is keep automatic updates enabled on all of your operating systems,

00:27:42.520 --> 00:27:47.180
especially if you're using the local apps and the local programs. Keep those enabled. That's how

00:27:47.460 --> 00:27:51.020
Proton's going to be able to patch any kind of security issues in the software quickly.

00:27:51.340 --> 00:27:57.240
And it's good to just remind you that everything that Proton does is open source, and most of their tools are independently audited.

00:27:57.540 --> 00:28:03.100
So this is kind of a really good place to be for just really good out-of-the-box security and privacy.

00:28:03.400 --> 00:28:07.680
And then with this hardening guide, you can really maximize it and take it to its full potential.

00:28:07.980 --> 00:28:09.760
I want to thank you all for going on this journey.

00:28:09.960 --> 00:28:12.420
If you're watching this, you clearly really care about your safety.

00:28:12.760 --> 00:28:17.140
So that's really exciting for me because I also really care about this, and I have a lot of fun talking about it.

00:28:17.220 --> 00:28:21.980
I want to definitely thank Proton for partnering with us and making it possible to do these kind of guides.

00:28:22.050 --> 00:28:23.680
I would love to make these tutorials anyway.

00:28:23.810 --> 00:28:28.260
So the fact that we're able to work with Proton and make sure that these are as good as they can be, it's just an honor.

00:28:28.480 --> 00:28:30.240
So I really hope that it can help you guys, too.

00:28:30.440 --> 00:28:35.080
And don't forget to stay subscribed because the third video I want to make is just going to be about PGP,

00:28:35.260 --> 00:28:41.140
which is that whole thing of like, oh, how can we actually encrypt our emails to other people who are using PGP?

00:28:41.140 --> 00:28:44.940
And how can we receive other people using PGP's emails in a secure way?

00:28:45.280 --> 00:28:46.880
And that was kind of what I teased in the last video.

00:28:47.120 --> 00:28:51.500
a lot of you asked for that PGP guide. So that will be the next video I'm going to make in this

00:28:51.790 --> 00:28:56.400
series. Thank you again, The Proton. Thank you all for watching and I'll see you next time on Techlore.

