Transcript

A post by [object Object] (@[email protected]) saying: courtesy of @[email protected], Proton is now the only privacy vendor I know of that vibe codes its apps: In the single most damning thing I can say about Proton in 2025, the Proton GitHub repository has a “cursorrules” file. They’re vibe-coding their public systems. Much secure! I am once again begging anyone who will listen to get off of Proton as soon as reasonably possible, and to avoid their new (terrible) apps in any case. https://circumstances.run/@davidgerard/114961415946154957

It has a reply by the author saying: in an unsurprising update for those familiar with how Proton operates, they silently rewrote their monorepo’s history to purge .cursor and hide that they were vibe coding: https://github.com/ProtonMail/WebClients/tree/2a5e2ad4db0c84f39050bf2353c944a96d38e07f

given the utter lack of communication from Proton on this, I can only guess they’ve extracted .cursor into an external repository and continue to use it out of sight of the public

    • sunzu2@thebrainbin.org
      link
      fedilink
      arrow-up
      6
      arrow-down
      1
      ·
      3 months ago

      There is such thing like national security laws.

      So you don’t know shit.

      If they are told to log, they will log. And there is enough meta data leakage to create heat map of your contacts

    • lambalicious@lemmy.sdf.org
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      2
      ·
      3 months ago

      I know that Signal runs on US cloud infrastructure

      And only that one.

      Signal dev is quite adamant on not letting people have their own servers, select a EU provider (yeah, EU is nazifying, but at least it’s a large enough second-hand basket) or host the (suppossedly zero-knowledge) messages on one’s own infrastructure. I’d say that’s curious.