Skip to content

Proton’s Lumo AI chatbot: not end-to-end encrypted, not open source

Technology
86 44 1
  • This post did not contain any content.

    It can't be that stupid, you must be prompting it wrong

    Eat shit

    Edit: is that a tag or something for the website? I still don't like the sentiment (or the chatbot) but if it's not something that came from Proton then I take back some of my vitriol

  • It can't be that stupid, you must be prompting it wrong

    Eat shit

    Edit: is that a tag or something for the website? I still don't like the sentiment (or the chatbot) but if it's not something that came from Proton then I take back some of my vitriol

    This is an anti-AI blog, that tagline is a joke.

  • It can't be that stupid, you must be prompting it wrong

    Eat shit

    Edit: is that a tag or something for the website? I still don't like the sentiment (or the chatbot) but if it's not something that came from Proton then I take back some of my vitriol

    He’s being sarcastic

  • He’s being sarcastic

    Yeah I got there eventually

  • This is an anti-AI blog, that tagline is a joke.

    I'm not familiar with this blog, so I can't comment on their general stance, but this particular article seems balanced and fair. They point out questionable implementation practices on Proton's side rather than criticising the AI itself.

  • This post did not contain any content.

    The worst part is that once again, proton is trying to convince its users that it's more secure than it really is. You have to wonder what else they are lying or deceiving about.

  • This post did not contain any content.

    For a critical blog, the first few paragraphs sound a lot like they're shilling for Proton.

    I'm not sure if I'm supposed to be impressed by the author's witty wording, but "the cool trick they do" is - full encryption.

    Moving on.

    But that’s misleading. The actual large language model is not open. The code for Proton’s bit of Lumo is not open source. The only open source bit that Proton’s made available is just some of Proton’s controls for the LLM. [GitHub]

    In the single most damning thing I can say about Proton in 2025, the Proton GitHub repository has a “cursorrules” file. They’re vibe-coding their public systems. Much secure!

    oof.

    Over the years I've heard many people claim that proton's servers being in Switzerland is more secure than other EU countries - well there's also this now:

    Proton is moving its servers out of Switzerland to another country in the EU they haven’t specified. The Lumo announcement is the first that Proton’s mentioned this.

    No company is safe from enshittification - always look for, and base your choices on, the legally binding stuff, before you commit. Be wary of weasel wording. And always, always be ready to move* on when the enshittification starts despite your caution.


    * regarding email, there's redirection services a.k.a. eternal email addresses - in some cases run by venerable non-profits.

  • For a critical blog, the first few paragraphs sound a lot like they're shilling for Proton.

    I'm not sure if I'm supposed to be impressed by the author's witty wording, but "the cool trick they do" is - full encryption.

    Moving on.

    But that’s misleading. The actual large language model is not open. The code for Proton’s bit of Lumo is not open source. The only open source bit that Proton’s made available is just some of Proton’s controls for the LLM. [GitHub]

    In the single most damning thing I can say about Proton in 2025, the Proton GitHub repository has a “cursorrules” file. They’re vibe-coding their public systems. Much secure!

    oof.

    Over the years I've heard many people claim that proton's servers being in Switzerland is more secure than other EU countries - well there's also this now:

    Proton is moving its servers out of Switzerland to another country in the EU they haven’t specified. The Lumo announcement is the first that Proton’s mentioned this.

    No company is safe from enshittification - always look for, and base your choices on, the legally binding stuff, before you commit. Be wary of weasel wording. And always, always be ready to move* on when the enshittification starts despite your caution.


    * regarding email, there's redirection services a.k.a. eternal email addresses - in some cases run by venerable non-profits.

    Moving the servers out of Switzerland may bein response to the proposed? regulations allowing more access to data of foreigners or something like that.

  • For a critical blog, the first few paragraphs sound a lot like they're shilling for Proton.

    I'm not sure if I'm supposed to be impressed by the author's witty wording, but "the cool trick they do" is - full encryption.

    Moving on.

    But that’s misleading. The actual large language model is not open. The code for Proton’s bit of Lumo is not open source. The only open source bit that Proton’s made available is just some of Proton’s controls for the LLM. [GitHub]

    In the single most damning thing I can say about Proton in 2025, the Proton GitHub repository has a “cursorrules” file. They’re vibe-coding their public systems. Much secure!

    oof.

    Over the years I've heard many people claim that proton's servers being in Switzerland is more secure than other EU countries - well there's also this now:

    Proton is moving its servers out of Switzerland to another country in the EU they haven’t specified. The Lumo announcement is the first that Proton’s mentioned this.

    No company is safe from enshittification - always look for, and base your choices on, the legally binding stuff, before you commit. Be wary of weasel wording. And always, always be ready to move* on when the enshittification starts despite your caution.


    * regarding email, there's redirection services a.k.a. eternal email addresses - in some cases run by venerable non-profits.

    Regarding the fact that proton stops hosting in Switzerland :
    I thought it was because of new laws in Switzerland and that they hzf not much of a choice ?

  • This post did not contain any content.

    How much longer until the AI bubbles pops? I'm tired of this.

  • The worst part is that once again, proton is trying to convince its users that it's more secure than it really is. You have to wonder what else they are lying or deceiving about.

    Mullvad FTW

  • Yes, indeed. Even so, just because there is a workaround, we should not ignore the issue (governments descending into fascism).

  • Yes, indeed. Even so, just because there is a workaround, we should not ignore the issue (governments descending into fascism).

    Very true

  • The worst part is that once again, proton is trying to convince its users that it's more secure than it really is. You have to wonder what else they are lying or deceiving about.

    Both your take, and the author, seem to not understand how LLMs work. At all.

    At some point, yes, an LLM model has to process clear text tokens. There's no getting around that. Anyone who creates an LLM that can process 30 billion parameters while encrypted will become an overnight billionaire from military contracts alone. If you want absolute privacy, process locally. Lumo has limitations, but goes farther than duck.ai at respecting privacy. Your threat model and equipment mean YOU make a decision for YOUR needs. This is an option. This is not trying to be one size fits all. You don't HAVE to use it. It's not being forced down your throat like Gemini or CoPilot.

    And their LLM. - it's Mistral, OpenHands and OLMO, all open source. It's in their documentation. So this article is straight up lies about that. Like.... Did Google write this article? It's simply propaganda.

    Also, Proton does have some circumstances where it lets you decrypt your own email locally. Otherwise it's basically impossible to search your email for text in the email body. They already had that as an option, and if users want AI assistants, that's obviously their bridge. But it's not a default setup. It's an option you have to set up. It's not for everyone. Some users want that. It's not forced on everyone. Chill TF out.

  • For a critical blog, the first few paragraphs sound a lot like they're shilling for Proton.

    I'm not sure if I'm supposed to be impressed by the author's witty wording, but "the cool trick they do" is - full encryption.

    Moving on.

    But that’s misleading. The actual large language model is not open. The code for Proton’s bit of Lumo is not open source. The only open source bit that Proton’s made available is just some of Proton’s controls for the LLM. [GitHub]

    In the single most damning thing I can say about Proton in 2025, the Proton GitHub repository has a “cursorrules” file. They’re vibe-coding their public systems. Much secure!

    oof.

    Over the years I've heard many people claim that proton's servers being in Switzerland is more secure than other EU countries - well there's also this now:

    Proton is moving its servers out of Switzerland to another country in the EU they haven’t specified. The Lumo announcement is the first that Proton’s mentioned this.

    No company is safe from enshittification - always look for, and base your choices on, the legally binding stuff, before you commit. Be wary of weasel wording. And always, always be ready to move* on when the enshittification starts despite your caution.


    * regarding email, there's redirection services a.k.a. eternal email addresses - in some cases run by venerable non-profits.

    Really? This article reads like it's AI slop reproducing Proton copy then pivoting to undermine them with straight up incorrect info.

    You know how Microsoft manages to make LibreOffice pulls errors on Windows 11? You really didn't stop to think that Google might contract out some slop farms to shit on Proton?

  • Both your take, and the author, seem to not understand how LLMs work. At all.

    At some point, yes, an LLM model has to process clear text tokens. There's no getting around that. Anyone who creates an LLM that can process 30 billion parameters while encrypted will become an overnight billionaire from military contracts alone. If you want absolute privacy, process locally. Lumo has limitations, but goes farther than duck.ai at respecting privacy. Your threat model and equipment mean YOU make a decision for YOUR needs. This is an option. This is not trying to be one size fits all. You don't HAVE to use it. It's not being forced down your throat like Gemini or CoPilot.

    And their LLM. - it's Mistral, OpenHands and OLMO, all open source. It's in their documentation. So this article is straight up lies about that. Like.... Did Google write this article? It's simply propaganda.

    Also, Proton does have some circumstances where it lets you decrypt your own email locally. Otherwise it's basically impossible to search your email for text in the email body. They already had that as an option, and if users want AI assistants, that's obviously their bridge. But it's not a default setup. It's an option you have to set up. It's not for everyone. Some users want that. It's not forced on everyone. Chill TF out.

    Their AI is not local, so adding it to your email means breaking e2ee. That's to some extent fine. You can make an informed decision about it.

    But proton is not putting warning labels on this. They are trying to confuse people into thinking it is the same security as their e2ee mails. Just look at the "zero trust" bullshit on protons own page.

  • This post did not contain any content.

    This was it for me, cancelled my account. Fuck this Andy moron

  • How much longer until the AI bubbles pops? I'm tired of this.

    depends on what and with whom. based on my current jobs with smaller companies and start ups? soon. they can't afford the tech debt they've brought onto themselves. big companies? who knows.

  • This post did not contain any content.

    Who Proton???? Nooo come on… who could ever seen this coming? 🐸🍲

  • For a critical blog, the first few paragraphs sound a lot like they're shilling for Proton.

    I'm not sure if I'm supposed to be impressed by the author's witty wording, but "the cool trick they do" is - full encryption.

    Moving on.

    But that’s misleading. The actual large language model is not open. The code for Proton’s bit of Lumo is not open source. The only open source bit that Proton’s made available is just some of Proton’s controls for the LLM. [GitHub]

    In the single most damning thing I can say about Proton in 2025, the Proton GitHub repository has a “cursorrules” file. They’re vibe-coding their public systems. Much secure!

    oof.

    Over the years I've heard many people claim that proton's servers being in Switzerland is more secure than other EU countries - well there's also this now:

    Proton is moving its servers out of Switzerland to another country in the EU they haven’t specified. The Lumo announcement is the first that Proton’s mentioned this.

    No company is safe from enshittification - always look for, and base your choices on, the legally binding stuff, before you commit. Be wary of weasel wording. And always, always be ready to move* on when the enshittification starts despite your caution.


    * regarding email, there's redirection services a.k.a. eternal email addresses - in some cases run by venerable non-profits.

    Over the years I've heard many people claim that proton's servers being in Switzerland is more secure than other EU countries

    Things change. They are doing it because Switzerland is proposing legislation that would definitely make that claim untrue.
    Europe is no paradise, especially certain countries, but it still makes sense.

    From the lumo announcement:

    Lumo represents one of many investments Proton will be making before the end of the decade to ensure that Europe stays strong, independent, and technologically sovereign. Because of legal uncertainty around Swiss government proposals(new window) to introduce mass surveillance — proposals that have been outlawed in the EU — Proton is moving most of its physical infrastructure out of Switzerland. Lumo will be the first product to move.

    This shift represents an investment of over €100 million into the EU proper. While we do not give up the fight for privacy in Switzerland (and will continue to fight proposals that we believe will be extremely damaging to the Swiss economy), Proton is also embracing Europe and helping to develop a sovereign EuroStack(new window) for the future of our home continent. Lumo is European, and proudly so, and here to serve everybody who cares about privacy and security worldwide.

  • 220 Stimmen
    39 Beiträge
    287 Aufrufe
    A
    True, they will always play the victim even as they're hurting and exploiting people they see as less than. Don't allow them to have any evidence of credibility. I think his idea of hell would probably be having to lower himself to the standard of living most people would consider normal and comfortable. Having to learn to actually survive day to day if he were to find himself suddenly without a cent of the money he was born into and all future wages and earnings garnished to pay the people he has harmed, would probably be a fate worse than any hell he could imagine. I know there's no justice and there is pretty much no chance of him ever facing any sort of proportional punishment or consequence for his actions. But, if I could make it happen, having to suddenly learn to survive with the rest of us mortals in the society he has helped create, in his late fifties, wondering how he will even afford something as basic as healthcare while his body rapidly ages from stress and gradually falls apart, after a lifetime of unimaginable privilege, unable to go anywhere or do anything he enjoys without being recognized and having people curse his name. That would be the fate I would wish on somebody like him.
  • Google Keeps Making Smartphones Worse

    Technology technology
    202
    1
    765 Stimmen
    202 Beiträge
    3k Aufrufe
    jjlinux@lemmy.mlJ
    In all honesty, I have no idea. I didn't give the stock firmware enough time on my phone to check on anything other than the amount of tracking and the move to the system partition. As for the reason for putting them in this partition, I'm sold on the idea that it's to keep the levels of invasion as high as possible while removing the user's options to get rid of them.
  • New Google AdSense Fill Empty In-Page Ads

    Technology technology
    2
    1
    22 Stimmen
    2 Beiträge
    35 Aufrufe
    S
    I've not seen an ad in years, so they can try to monetize me but will fail spectacularly
  • 47 Stimmen
    13 Beiträge
    148 Aufrufe
    N
    They don't treat their people like shit, they treat them like slaves. In countries outside China at that. https://www.bbc.com/news/articles/c3v5n7w55kpo
  • 2k Stimmen
    214 Beiträge
    5k Aufrufe
    M
    the US the 50 states basically act like they are different countries instead of different states. There's a lot of back and forth on that - through the last 50+ years the US federal government has done a lot to unify and centralize control. Visible things like the highway and air traffic systems, civil rights, federal funding of education and other programs which means the states either comply with federal "guidance" or they lose that (significant) money while still paying the same taxes... making more informed decisions and realise that often the mom and pop store option is cheaper in the long run. Informed, long run decisions don't seem to be a common practice in the US, especially in rural areas. we had a store (the Jumbo) which used to not have discounts, but saw less people buying from them that they changed it so now they are offering discounts again. In order for that to happen the Jumbo needs competition. In rural US areas that doesn't usually exist. There are examples of rural Florida WalMarts charging over double for products in their rural stores as compared to their stores in the cities 50 miles away - where they have competition. So, rural people have a choice: drive 100 miles for 50% off their purchases, or save the travel expense and get it at the local store. Transparently showing their strategy: the bigger ticket items that would be worth the trip into the city to save the margin are much closer in pricing. retro gaming community GameStop died here not long ago. I never saw the appeal in the first place: high prices to buy, insultingly low prices to sell, and they didn't really support older consoles/platforms - focusing always on the newer ones.
  • 403 Stimmen
    143 Beiträge
    3k Aufrufe
    M
    If anyone ever tells you they can't hire enough of blank they are lying to you. People have been running excellent 911 service all over the country for longer than I've been alive maybe they should ask someone?
  • Apple announces iOS 26 with Liquid Glass redesign

    Technology technology
    83
    1
    117 Stimmen
    83 Beiträge
    724 Aufrufe
    S
    you guys are weird
  • Bookmark keywords, again (Firefox)

    Technology technology
    3
    4 Stimmen
    3 Beiträge
    35 Aufrufe
    bokehphilia@lemmy.mlB
    This is terrible news. I also have a keyboard-centric workflow and also make heavy use of keyword bookmarks. I too use custom bookmarklets containing JavaScript that I can invoke with a few key strokes for multiple uses including: 1: Auto-expanding all nested Reddit comments on posts with many comments on desktop. 2: Downloading videos from certain web sites. 3: Playing a play-by-forum online board game. 4: Helping expand and aid in downloading images from a certain host. 5: Sending X (Twitter) URLs in the browser bar to Nitter or TWStalker. And all these without touching the mouse! It's really disappointing to read that Firefox could be taking so much capability in the browser away.