So I decided to buy a domain and wanted to opt for some more private or “ethical” company. I decided to buy from infomaniak only to find out, after paying for my domain, that they block it until I install their mobile app, upload my ID and my selfie in it. That is completely insane. I have bought domain from cloudflare in the past and nothing like that was needed.
How is this supposed to be ethical if I have to install application that can do whatever and upload my personal information that they do not need?
Does anyone have similar experience with infomaniak?
The myth of a data protection paradise: Switzerland and its Intelligence Services Act
Switzerland enjoys an international reputation as a safe haven for data - outside the EU, with political stability and a modernized data protection law. But this reputation is deceptive if you take a closer look at the Intelligence Service Act (ISA). Since 2017, it has allowed the Federal Intelligence Service (FIS) to carry out far-reaching interventions: cable reconnaissance, state trojans, data retention and exchanges with foreign intelligence services are possible - in some cases even without concrete suspicion. Particularly explosive: in the run-up to the vote in 2016, the Federal Council assured that no nationwide surveillance was planned and that only data traffic abroad would be affected. In fact, it later became known that national traffic was also being recorded. Terms such as “filtering” or “surveillance” were never clearly defined politically - a breeding ground for a lack of transparency and loss of trust.
It seems that Swiss privacy laws are not very good for us consumers. It seems to be a myth that privacy in Switzerland is particularly good.
Honestly it was foreshadowed by the fact that when I arrived to Zurich to Go for Brussels, For their Airport WiFi, they literally were asking people their phone numbers or ID.
LOL
Like camon, does Switzerland really expect I would have my second phone number always? With the potential undermining encryption, I started to doubt Switzerland’s reputation as a country with best privacy laws so…
As someone who lived in Switzerland I agree with the above. Mainly that inside the country there are some really weird practices. Not like shady. But they are very conservative to the point where many institutions need you to post sensitive things via post!
What is the real benefit of switzerland is that only swiss law is applicable and so when there are requests for (meta)data, those requests must be made by the swiss government. No third country or mutlinational party can come and rightfully demand something like this. Also, from what I heard, some tech companies are benefiting from laws that do not need logging of some metadata, but in this area I am not that knowledged, so I will leave it at that.
Anyway I was comparing some European domain registrars and infomaniak looked quite well… until they didn’t…
What gets me the most is the fact that they say that “its to secure my account well” but there is no option to opt out. I can take care of my account just fine, thank you very much and goodbye.
I need to add, that I corresponded with the support and they cancelled the order without unnecessary delays, so at least that was good.
Thank you for providing this valuable feedback on Infomaniak.
MY EXPERIENCE WITH INFOMANIAK:
I’ve never used Infomaniak as a domain registrar, but for quite a few years I have been planning to sign up to their free KSuite because it comes with a free email address. However, I quickly found out to my disappointment that it requires you to provide your phone number, which sucks. I’m still trying to figure out how to get around that.
I discovered Infomaniak years ago when I was looking for a free alternative to Tresorit Send, the Swiss E2EE cloud service that allows you to send up to 5 GB of files on their free version. The files I wanted to send were more than 5 GB.
That’s when I found out about Swiss Transfer, which is owned by Infomaniak and allows you to send up to 50 GB of files for free that will self-destruct in 30 days.
INFOMANIAK DOES NOT RESPECT PRIVACY…
Because of their aggressive marketing around privacy, I assumed Swiss Transfer was E2EE. But since their website didn’t explicitly say so, I decided to ask them, and they revealed to me that they were not E2EE. Their email/K-Suite service is not E2EE either.
I personally do not understand why any email or cloud company, especially a Swiss one, would aggressively market themselves as privacy preserving, when they are not E2EE. Especially when Proton, Tuta, and Tresorit exist.
This is why poking holes in the myth of Switzerland as a privacy haven is so important. Strong privacy laws and strong cryptography are key to protect citizens’ privacy. Without E2EE, Infomaniak seems to rely solely on the former, which recently has been demonstrated to be not that strong.
If my memory serves me right, in my exchanges with them, they implied they planned to integrate E2EE in the future, but it did not seem like a sure thing. Even so, I feel skeptical about trusting companies that integrate E2EE years after launching their service instead of having it baked in from the start.
…BUT THEY’RE BETTER THAN BIG TECH COMPANIES
That said, I have little doubt that they are better than all the Big Tech companies like Google and Yahoo when it comes to email privacy.
I still wish to get an account as part of my e-mail strategy, for when I need to email friends and family who don’t use Proton or Tuta, which is literally everyone in my personal circle.
That is interesting. I was wondering why I don’t see them much as recommendation for privacy email and stuff, well this explains it.
What is your strategy regarding emails? Why not mail them from your Proton? And why not have second (free) Proton mail for that? Just curious. For me email is anyway mostly for registrations (which I do with aliases) or professional communication in rare occasions when I do not use company email.
That is a fair question. I have a paid Proton Mail account with multiple addresses. And I also have a paid Proton Pass account with aliases.
TL ; DR:
Figuring out the right email strategy is very tricky for me. On the one hand, I want all my emails to be E2EE. On the other hand, I don’t want my Proton addresses to be exposed to SPAM via (meta)data. This is also why I don’t want any of my personal contacts to initiate an email to me, because it won’t be E2EE. The alternative is aliases which are not E2EE. Also, using aliases becomes complicated when you have to include personal and business contacts in the same email, because it’s confusing for personal contacts to remember which alias to use.
E-MAIL STRATEGY FOR BUSINESSES:
When it comes to emailing businesses, by default, I use unique Proton Pass aliases. However, I do have a Proton address for scenarios where I need to send sensitive information via E2EE.
E-MAIL STRATEGY FOR FRIENDS & FAMILY:
When it comes to emailing regular people, however, ie friends and family, who all use Big Tech surveillance providers, I haven’t figured out my strategy. I have 2 imperfect options.
OPTION 1: E-Mail them from a Proton Address
IMHO, there is no point in using Proton Mail if I’m not going to E2EE every email I send to a non-Proton user. First, because the emails I send will sit on Big Tech servers, and I don’t want that.
Secondly, I want my friends and family to think about privacy every time I email them. And if they need a password every time they want to read my emails, it will accomplish exactly that.
The Problem:
My problem is, I don’t want to expose my Proton address to Big Tech. I don’t want to get spam. Also, if I share my Proton address with friends and family, there will inevitably come a time when they will email me first, at which point there is no E2EE. I also suspect they won’t appreciate me replying with an E2EE email. They will lose the full email history, and it also expires in 30 days.
I’m aware that I can create a Proton address just for friends and family. But if I receive SPAM or for whatever reason, need to delete that address because it’s too compromised, it creates a mess. There’s the fact that Proton only allows you to delete one address per year. Moreover, when you delete an address, you lose all the data that came with it. So any past emails with potentially important stuff are gone.
Option 2: E-Mail them with a Proton Pass Alias
The second option is to use a Proton Pass alias for friends and family. If my emails are not gonna be E2EE, I’d rather use an alias than a Proton address. But that means I will never send E2EE email to friends and family because they’re not on Proton, which kinda defeats the purpose of using Proton.
I’ve been a paying Proton user for more than 5 years, and I have yet to send a single email to friends or family with any of my Proton addresses. I don’t want to risk exposing them to SPAM.
To put it another way, I have yet to email an address from a Big Tech provider
THE COMPLICATIONS OF MIXING BUSINESS & PERSONAL LIFE:
As I’ve previously said, I use unique aliases for every business I have to deal with. I have hundreds of them. But quite regularly, when I email certain businesses, I have to copy family members in the email. For e.g. if my sister and I live together, and I emailed a plumber, I need to copy her.
There are various businesses that I exchange with, in which various family members are copied. Some of these family members repond to the emails. Some of them even intiate emails. None of my family members are going to remember that this is my alias for the plumber, and that is my alias for our lawyer, etc… In fact they don’t.
Even though I have unique aliases for each business me and my family interact with, every time they need to initiate an email, they use my GMail address. Even though I haven’t sent an email from my GMail acount in years.
Option 3: Use a E-Mail Provider like Infomaniak for friends and family.
My email won’t be E2EE, but my family won’t have to remember all my aliases either. They’ll just have to remember one address, and it won’t be a Big Tech address. Another reason I’m aiming for Infomaniak, is because their KSuite email service is quite new, and I’m likely to obtain my desired username.
The kyc is not from them, its from icann. Every accredited registrar are bound to icann rules to verify registrant details when registering a domain name. Cloudflare, infomaniak, godaddy, whatever signed those agreement to verify your details. Unless you go for a proxy registrar like njal.la that register using their details and rerent the domain back to you, the kyc should be expected. Just because other registrar didn’t ask for the kyc at the time of registration doesn’t mean they won’t ask it next day, next month, next year etc. Its randomised and would come eventually.
I do agree though that infomaniak way of doing kyc is horrible. God knows what their shitty app are doing in the background. I’ve experienced their terrible kyc myself few years ago and have avoided them ever since. They’re not a privacy respecting company. See their privacy policy and read what they collect.
I see you have been thinking about this a lot. Thank you for sharing this, its always interesting to see what others do (and if we can implement it).
I gotta say that I actually do use my proton mail when I need to send something to a family member and I have never seen spam mail in my almost also 5 years as a proton user. That said my main communication channel with them is Signal Is it impossible to teach your family use this? I managed because I set up family group and now we share a lots of stuff there, something that is harder to do with email with all the ‘reply all’ and the readability stuff.
I also have one more possible suggestion for you, maybe if you want them to think about privacy, do not show them your dark side. I mean if they think that with e2e encrypted email they will have to use passwords on every mail (which is not true, but ordinary people do not understand these things) you will never get them to move to e.g. proton. But what you could do is to create a signature that would constantly remind them that their email is being read by random people (and machines). Something like “Sent from Proton mail where only you can read your emails. Google (or fill other) reads your emails (link to article).” And the link to an article, you can also periodically change the link. It can be various leaks and stuff. Basically show them the negative of their way, don’t show them the negative of your way.
Lastly, the business thing I get it totally. Now I have it separated because I have to have company email (nothing is private there). But when I had to solve this my own way I was also having different email address and provider. It was more than 5 years back though. Back then I didn’t really think about privacy much. Nowadays, it would be hard thing to think about.
post by OncommingStorm on Apr 27, 2025
post by OncommingStorm on Apr 27, 2025
post by guest on Apr 27, 2025
post by OncommingStorm on Apr 27, 2025
post by guest on Apr 27, 2025
post by OncommingStorm on Apr 27, 2025
post by PurpleDime on Apr 28, 2025
post by OncommingStorm on Apr 30, 2025
1 month later
post by PurpleDime on Jun 10, 2025
New & Unread Topics
Topic list, column headers with buttons are sortable.