Transcript

A post by [object Object] (@[email protected]) saying: courtesy of @[email protected], Proton is now the only privacy vendor I know of that vibe codes its apps: In the single most damning thing I can say about Proton in 2025, the Proton GitHub repository has a “cursorrules” file. They’re vibe-coding their public systems. Much secure! I am once again begging anyone who will listen to get off of Proton as soon as reasonably possible, and to avoid their new (terrible) apps in any case. https://circumstances.run/@davidgerard/114961415946154957

It has a reply by the author saying: in an unsurprising update for those familiar with how Proton operates, they silently rewrote their monorepo’s history to purge .cursor and hide that they were vibe coding: https://github.com/ProtonMail/WebClients/tree/2a5e2ad4db0c84f39050bf2353c944a96d38e07f

given the utter lack of communication from Proton on this, I can only guess they’ve extracted .cursor into an external repository and continue to use it out of sight of the public

    • InFerNo@lemmy.ml
      link
      fedilink
      arrow-up
      40
      arrow-down
      3
      ·
      3 months ago

      This is the argument people use when discussing Microsoft products

      • алсааас [she/they]@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        15
        arrow-down
        7
        ·
        edit-2
        3 months ago

        Is M$ stuff provably e2ee? Is Proton a publicly traded company? Does M$ have even close as good a track record as Proton? Are most M$ clients OSS?

        Edit: Proton isn’t perfect, not by a long stretch. I’m not stanning them either way, but being alarmist and giving in to mob mentality is counterproductive.

        For me they just offer the right balance of being partially OSS, strong privacy and strong security that I can pragmatically “overlook” things even as a leftist and free/libre “hardliner” (as I already mentioned: the pragmatic kind. I don’t see a point in using Linux-Libre and am ok with proprietary blobs or “tainted” packages for codecs necessary for piracy if there is no alternative and if they don’t cause active harm (as in “phoning home” or shit like that. Linux-libre is a detriment to your security BTW)

        • Doomsider@lemmy.world
          link
          fedilink
          arrow-up
          1
          arrow-down
          4
          ·
          3 months ago

          Oh lookie here we got another Proton payer slash sucker who likes to rationalize giving money to corporations because “privacy”.

          I don’t mean to sound alarmist, but you seem really naive while trying to lick Proton’s boots.

      • алсааас [she/they]@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        11
        arrow-down
        4
        ·
        3 months ago

        I use it with the full knowledge that they will start to track me and share my IP with Europol if they come with a warrant. (They are unable to comply with anything further, thanks to their e2e architecture)

        It is part of my threat model and I use it solely for private stuff.

        I couldn’t care less that the CEO had one slipup praising a Republican with a seemingly good track record (although I did not investigate that matter)

        And being a Luddite about AI is really counterproductive, it has arrived in our society and if correctly utilised will be just another tool used to automate or autocomplete etc.

        Basically what your IDE already does but on steroids

        (Disclaimer: it’s Friday and I’m tired so there is a real – if small – chance I’m being a contrarian armed with superficial knowledge. I can’t rly tell myself 🙃)

        • ayyy@sh.itjust.works
          link
          fedilink
          arrow-up
          2
          arrow-down
          2
          ·
          3 months ago

          They are unable to comply with anything further, thanks to their e2e architecture

          How do you know some crappy generated code isn’t doing some kind of stupid logging?

          • psivchaz@reddthat.com
            link
            fedilink
            arrow-up
            2
            ·
            3 months ago

            TBH this isn’t a great argument for open source code. You know it’s not doing something stupid in the exact same way you know a human written application isn’t doing something stupid.

            1- You review it yourself to double check OR

            2- You hope that the community is reviewing it and that you would be made aware of problems OR

            3- You just don’t know.