The Story
Nilay Patel brings Bart Butler on for a very Decoder kind of conversation: what does it take to build software that asks people to trust it, and what happens when that trust runs into governments, growth pressure, and the ugliest parts of the internet. Butler is clear from the start that Proton does not mainly sell email, cloud storage, or calendars. It sells trust. The products matter, but the pitch is that Proton has arranged its technology and its business so that betraying users is hard by design. Data is encrypted so Proton often cannot read it, and the company makes money from users instead of ads, which Butler argues keeps the incentives pointed in the right direction.
That leads into the harder question Nilay keeps pressing: if trust is the product, where does it actually live? In the cryptography? In the nonprofit-style foundation that controls Proton? In the people? Butler says all of it has to work together. Proton is a Swiss corporation, but a controlling stake sits with the Proton Foundation, which is meant to guard the mission if management ever drifts. Even so, he does not pretend the structure frees Proton from market pressure. His point is almost the opposite. If Proton wants privacy to be the default for ordinary people, it has to get big enough to compete with Google and Microsoft on convenience and features, not just ideals.
The conversation gets more concrete once Nilay brings up the Stop Cop City case, where Proton turned over payment data to Swiss authorities, who then shared it with the FBI. Butler’s answer is blunt: no company is above the law, and Proton complies with valid Swiss orders. The whole bet, he says, is that Switzerland is a better buffer than many other jurisdictions and that Proton’s systems limit what can be handed over in the first place. But he also admits the pressure is rising. If European surveillance laws get worse, Proton is actively thinking about what it would mean to move parts of its operations elsewhere.
From there the episode turns into a long argument about child safety, age verification, and encryption. Butler does not deny the scale of harm, especially around CSAM. He says Proton spends heavily on abuse prevention and claims it can disrupt bad actors without scanning everyone’s content, though he refuses to explain exactly how. That is the sharpest tension in the episode: he asks listeners to trust a company whose whole philosophy is supposed to reduce the need for trust.
They end on AI, where the same conflict shows up again. Butler sees enterprises feeling pushed to dump sensitive data into model companies, and he wants Proton’s AI products to offer a different option. His view is that privacy should mean control over when and how you share data, not total isolation from modern tools.
Main Themes
The main thread is that privacy is not just a feature. It is a set of technical limits, legal choices, and business incentives that have to reinforce each other. Butler keeps returning to the idea that good intentions are weak on their own. If a company can read everything, mine everything, and change course when money gets tight, then promises about values do not mean much.
A second theme is that scale cuts both ways. Proton needs growth to matter, but growth can warp the mission it claims to defend. Butler insists those two goals are linked, while Nilay keeps pointing out how often companies say that right before the compromises start.
The episode also keeps circling one uncomfortable fact: every system has a failure point. For Proton, that might be the legal authority of the Swiss state, the practical limits of abuse detection in encrypted systems, or the pull of AI and enterprise demand. Butler’s case is that you cannot remove pressure from the system, only choose where it lands and reduce the damage when it hits.
Full Transcript
Support for this show comes from Comcast Business. Modern enterprise is a lot of moving parts. Comcast Business helps you orchestrate it all with SD-WAN working at scale to keep 150 hospital locations connected and working as one. Plus SASE and zero trust security protecting financial data across a bank's 2,000 branches, and AI-powered networking that optimizes traffic across five continents. No one does business like Comcast Business. This series is presented by Comcast Business. Hello and welcome to Decoder. I'm Nilay Patel, editor-in-chief of The Verge, and Decoder is my show about big ideas and other problems. Today, we've got the first of a two-part series on the systems that run the world. I'm talking with Bart Butler, the CTO of Proton, a company that makes private and secure productivity software. You probably know it best for ProtonMail, which is encrypted by default, but the company also has Docs, Sheets, Calendar, even a new AI assistant called Lumo, all built and marketed around the idea that they should be vastly more private than the similar products from big tech companies. You'll hear Bart say pretty plainly that the thing Proton sells at a high level isn't really the products themselves, but actually trust. And trust, in the software world, isn't only about the people who run the companies, but also the technology they develop and sell and the corporate structures in place to make sure that technology is built against the right incentives. This is pure Decoder bait, in other words. The challenge is that Bart also says Proton's mission is very much to succeed at being a viable competitor to big tech, and that means the company has to grow and expand to competitive scale, all while preserving its core values. That philosophy and that challenge are baked directly into Proton's structure and even its physical location. The company and its servers are based primarily in Switzerland, in part because of the Swiss government's geopolitical neutrality. Two years ago, Proton also transitioned to a nonprofit structure governed by a foundation, which is a familiar model used by all kinds of companies that ostensibly operate in the public interest, but which has failure modes of its own, as we just saw with OpenAI. Bart and I talked about all of that, of course, but I really wanted to talk to him because he's responsible for the technical construction of some very complex systems that interact with all those complex politics. I really wanted to know how Bart translates all of those lofty ideals and concepts like user trust into real privacy-centric products and features that can withstand all of this policy pressure. And of course, there are real examples of this. Earlier this year, the Swiss government came knocking on Proton's door with a request for payment data to help the FBI unmask a protester associated with the Stop Cop City movement in Atlanta, Georgia. Proton complied. They gave the Swiss government that data, which then went to the FBI. So, of course, I had to ask Bart about all of that and what it means that the U.S. government can use words like terrorism to coerce foreign governments to apply pressure on Proton and how Proton decides when and how to take on those fights. This pressure manifests in all kinds of ways. Proton is on the record saying it would leave Switzerland and also consider ditching its operations in EU countries like Germany and Norway if the various surveillance laws in those states continue to threaten Proton's privacy mission. Bart told me that these aren't just empty threats and that Proton is in the process of figuring out what it would mean to leave Europe if things get, in his words, more dystopian. There's a lot going on in this episode. We actually ran long because we got so deep into the weeds. We first spent time talking out the broad frameworks that Proton uses before talking about the real problems of child safety, age verification, and AI, all of which are testing Proton's values with some of the highest stakes problems on the Internet today. But we took the extra time to get there, and I hope you'll think it's worth it. Okay, Bart Butler, the CTO of Proton. Here we go. Bart Butler, you're the chief technology officer at Proton. Welcome to Decoder. Thank you. Happy to be here. I am excited to talk to you. It feels like Proton sits at the center of an escalating, spiraling debate about how we build technology systems, how we regulate them, and how consumers can protect their data or have any control at all over their data at the center of it. Let's start at the very start. I think most people understand Proton as ProtonMail, but there's now a suite of office products or productivity products. Describe what Proton is and how you see all the products working together. Proton is an ecosystem, if you will, a collection of products that all sort of share the same DNA in the sense that they are, they fundamentally are versions of, in many cases, versions of products you can buy elsewhere, but that are privacy preserving, right? And yes, we started with mail. We also have a VPN. We have ProtonDrive, which is our file storage and photos and collaborative real-time docs. We have Calendar. We have a password manager called ProtonPass. We have Meet, which is a video conferencing software. So we have a whole collection of products that do things, in some cases, very similar to other products that you might be more familiar with, but are also privacy preserving. One of the reasons I'm excited to talk to you, you specifically as chief technology officer, is the idea that there is a set of products that are familiar, but the company running them is going to behave better than the other company, is a familiar pattern in this industry. And Proton's promise is that the products are actually architected differently, right? That from the very beginning, the way the products are built is actually what makes and keeps the promise of protecting privacy, not a benevolent CEO or a benevolent board of directors. We'll come to that. There's some of that in the mix here. There's some of that, too. There's some corporate structure stuff. But there are actually, I would say, two primary structural, maybe, or systems. You could call them systems engineering, right, at a broader scale, but structural constraints on how Proton operates. The first is that we encrypt all the data we can, right? So if we wanted to turn around and sell that data to somebody, we can't. It's mathematically not possible for us to do it, right? This also has other benefits, right? We can't easily lose it to hackers or other interested parties. And there's some data that we can respond to for, say, legal requests, but there's some data we can't, right? And this helps us, basically, we can't give up data that we don't have access to. The second is the business model. It's not, I mean, there are other SaaS players, of course, that do this. I don't think there are a whole lot of B2C consumer-based SaaS players at our size who do this, but our revenue model is getting paid by our users, right? So we don't sell ads. The products are not carrots to get people to come in and give us our data so we can sell it to advertisers, right? And that means that those users, the ones who pay our bills, pay our salaries, allow us to grow the business, if we were to betray them, then that would essentially undermine the value of the business, right? So we have tied the value of the business and the growth of the business to protecting our users so that our interests are aligned. And this is also very important because, you know, temptations are a thing, right? People respond to incentives, and we have structurally arranged our company such that those incentives are aligned with the people to whom we have promised to protect. And that's a very reductively summarized what you just said is, we take money from consumers and what we sell them is encrypted versions of popular services that they rely on, like email, like a VPN, like an office suite. Do you think consumers understand that what they're buying is the technology solution, or are they buying the promise of privacy? Or is it some mix? Because I'm not actually sure consumers really understand at mass scale how it all works, right? They think their iPhones are listening to them. I will tell product people and engineers, you know, in meetings about new features, if you've mentioned the word encryption to the user, you've already failed, right? I mean, people don't understand what this is. That's fine. Our goal is to make products that are as usable and as functional as our competitors, or more, or more functional. I don't want to sound entirely derivative, right? We do have features that nobody else has that are often geared towards privacy and functionality for people who need confidential communications. However, in general, we're selling the promise. We're selling the promise that we're a different kind of company. We're selling the trust, right? And that trust is critical. Without the trust, that is where the real value of the company is. Now, that trust is backed up by technology, right? But we're selling the trust. The reason I'm pushing on it, and specifically, I'm happy that you mentioned trust, is the big tech players will all make the same kinds of promises about your data being private. Facebook will happily tell you that they don't sell an ounce of your data, and it's actually not in their interest to sell the data because the ad targeting that they do depends on the data being theirs and not anyone else's. We can get into this for days and days and days. I'm just curious where you see that trust being expressed or where you feel like that trust is most communicated from Proton. Because if you ask me as a more technical person, I do look at the architecture of it's all encrypted and probably mathematically it's impossible to get into. And sure, we'll come to how much metadata can be shared with authorities because there is some debate about that. But that's the piece that resonates for me, as opposed to I have to trust Like, I think that when the time comes to really make a push to B2B, the B2C uh user base and product suite will be a will be a benefit to us. One of the tensions there as AI sort of infiltrates more and more businesses is the frontier model companies want every ounce of data. I think a bunch of big enterprises are very leery of giving a bunch of data to frontier model companies. The AI works best when they have a bunch of data. And so there's this big choice about how much of your business will you expose to Claude? How much of yourself will you expose to Claude to get the most value out of those models? Proton sits right in the middle of that with a technical architecture that you're saying would provide choice. But it also seems like the the game for a lot of these companies is to just hand everything over and say, go run my business, AI. How do you see that working with your enterprise customers today? It's a fraught decision, right? It's giving all their all their sensitive data over. And they feel like in many cases, they don't have a choice. And uh in some ways, that's why we developed Lumo, which is our AI offering, which I think may have left off the list before, unfortunately. But uh we, I think we just launched Lumo 2.0, which is a big revamp of the models we use. And part of that is, you know, the goal of Lumo project in general is to have something which integrates with the rest of our products and can do this in a safe way. This is to address this sort of trade-off between do I give random AI companies, possibly in different countries, possibly, you know, have compliance problems, all this other all this other thing, do I give them all my sensitive business data? Or can I do it in a way that is still is still more protected? Now, you know, in many ways, uh there are still trade-offs on our side to make, but we keep it in-house within Proton with the guarantees that we give, that should be a more attractive option for those kinds of workflows. And that's what we're, that's what we're hoping as we develop Lumo. I think this does bring us to the decoder questions about structure and organization, because that's where it feels like the structure has to be where the trust lies, not necessarily the technical architecture. So how is Proton structured today? How many people is it? Proton today is approximately 650 people total. That also includes engineering, support functions, marketing, et cetera. It also includes customer support, which we do in-house. We always have. We are a corporation, Proton AG, a Swiss corporation. However, a controlling stake in Proton AG is held by the Proton Foundation, which was seeded with shares from Andy, our CEO and other early employees and has a controlling stake. There are other fellow travelers with, with, I would say a similar, uh in somewhat similar structures. Signal and Mozilla and our reasons are the same. We have a, you know, the Proton Foundation controls, has a controlling stake in the Proton company, and has and is empowered to protect the mission as a Swiss foundation, which is, I've been told, I'm not a lawyer, but I've been told is very difficult to change. And its job is sort of the guardian of the values and the mission of Proton. So if Proton the company were to stray from that mission, the Proton Foundation would be empowered to correct the correct course, if that makes sense. Has that ever happened? Uh, those, no, thus far, no. We have uh our founder, CEO, Andy, um he would Andy Yen was, he founded the company as as founder CEO implies. And as long as he is uh in charge, I don't think that'll be necessary. But, you know, if he gets hit by the bus, there's, there's, there's still a uh there's a corporate structure which is designed to protect the mission going forward and to make sure the company doesn't stray regardless. And, and because of the ownership model too, the company is insulated from, say, some sort of takeover that or or purchase that could also redirect its um its uh its priorities. But I do, I, I, I do say that, I mean, I think that and the tech and, and the business model basically are interlocking protections against against us, you know, betraying the compact that we have with our users. One of the things that strikes me as I talk to more and more companies that have transitioned to this kind of foundation model is that that structure is essentially there to insulate you from the rapacious demands of capitalism, right? Like, you, you aren't being pressured to make as much money every quarter as possible to do the things that would lead you to make the most money. And that means maybe the technology can develop in a pure and idealistic state of protecting privacy instead of chasing the dollars. Do you feel that insulation, right? I mean, you do have to make money and pay your employees and and grow in some way. But what's the dynamic for you architecting the products? The short answer is no. And um The reason for that is that we have to compete in capitalism. Our our main competitor is big tech, right? Even though we are much smaller than big tech, you know, where our users come from when we convert people, when we get new new customers, they're big tech in general, right? And um we have to play the same game. And I uh our corporate motto, this might be a little cheesy, but our corporate motto is, you know, privacy by default. And that default part is doing a lot of heavy lifting. I mentioned before that our goal is to design products which are easy to use and secure, right? There are plenty of tools that are secure and nobody but a few, you know, a few experts use them. And that's fine. Like I'm, I'm not criticizing the existence of those tools, but our goal is to make tools that everybody can use without understanding the cryptography, without even knowing that it's cryptography, that they can use and that are as easy to use and as feature-filled as are unencrypted, you know, unencrypted and essentially data mining competitors, right? It's a tall order. I'm not saying we're, I'm not saying we're 100% there yet, but that is the goal. But the default word in that privacy by default means that we have to be at the scale where we can offer a real alternative to big tech. And small startups, small scale-ups, you know, being 100 times or 10 times smaller than than big tech is not gonna cut it, right? In order to to do that, we need to grow. So growth is actually part of the mission, if you will. And that means that we have to be, the word, not rapacious, but we have to be as hungry and as efficient and as growth-minded as we possibly can because that's part of the mission to grow big enough to actually challenge the paradigm. We can talk about all kinds of ways capitalism is kind of broken right now, but like, we have to play the game. All right, I'm gonna make a comparison that you are going to hate, OK? Just letting you know. I I know you're gonna hate it. Maybe the most famous will build a foundation to protect ourselves from the demands of the market and make sure the thing is healthy is OpenAI, which basically killed that structure in order to chase an IPO, right? Like, and maybe they still have really important and idealistic ideas about how AI should be developed. Maybe, maybe there's some people in that company who really feel that way. And it just didn't work, right? They needed to chase growth in very specific ways for whatever reasons that they felt. Maybe it was money, maybe it was just in order to take on Google search, the way that OpenAI felt like it wanted to take on Google search, they had to change the structure of the company. That obviously happened, right? It's like one of the most like apocalyptic foundation moments that has ever happened. Like this thing just like exploded or imploded onto itself. When you look at that and then you look at, OK, we have to grow. In order to be the default, we have to grow to be big, but we're making this promise that Google doesn't have to make, or Microsoft doesn't have to make. Where is the tension in that? How does that express itself as you design the architecture of the products, which might preclude some opportunities? It's not, but well, it could also be our corporate motto is go big or go home, right? We don't set modest goals in that regard. But, but I think that there are, there are a couple of things that that that make it different. I mentioned before uh a lot of constraints, but one thing I didn't mention is we don't have VC investors. We don't have private equity investors. We aren't burning other people's money with VCs burning down, you know, breathing down our necks that we must exit soon or otherwise we go belly up, right? We, we, our goal, we built a sustainable business. We reinvest the profits from that business back into the business. And this insulates us from some of the pressure, which I'm sure OpenAI felt given that they were, you know, lighting enormous stacks of money on fire all the time, right? But that said, uh, you know, personnel is policy, right? There's certainly always this risk. And at the same time, you know, sometimes you find it, we, we, we found out a lot recently that sometimes, you know, rules or otherwise or norms or guidelines, unwritten or not, they're not worth the paper that they're written on. But that's also where the architecture comes in. We make choices about the tech stuff. And obviously I'm on the tech side of this And there you have fundamental nature of the universe. I consider that kind of a mission-driven occupation. I also had a stint in Silicon Valley afterward, which was fun and interesting technical problems, but I wouldn't, you know, I missed that, right? And with Proton, the mission is really, we have to be careful that it doesn't paper over organizational problems that we should really solve. Let's put it that way. It's, but it really does make the job easier when everybody is sort of aligned in that regard. We need to take a quick break. We'll be right back. Support for this show comes from Comcast Business. Modern enterprise. It's a lot of moving parts, multiple locations, a constant flow of data, endless applications, critical systems that can't go wrong. Comcast Business helps you orchestrate it all with SD-WAN working at scale to keep 150 hospital locations connected and working as one. So patient data flows securely and care is delivered without interruption. That's a healthy approach. Plus SASE and zero-trust security protecting financial data across a bank's 2,000 branches. That means identity is verified, transactions secure, threats blocked, net stacks safe and sound in the best of hands. And AI-powered networking that optimizes traffic across five continents. So yeah, modern enterprise is complex. Comcast Business makes it simple. When you add it all up, no one does business like Comcast Business. We're back with Proton's Bart Butler. Before the break, we went over the decoder questions, but now I wanted to put Bart's answers into practice and discuss how Proton is maneuvering in an increasingly threatening policy landscape both here in the United States and in Europe. Early on in my career, I had no idea how to manage anyone. And I went to a bunch of people and asked them a bunch of questions. And one of the smartest mentors in all this told me very seriously, sat me down and she's like, Look, you don't hire people to make them like you. You hire people to change your organization. And I've taken that to heart. And maybe at 15 years into this, I'm like, that's actually a pendulum. You need people to buy into what you're doing. Otherwise, every new person you hire is going to radically disrupt what everyone else is doing because they are maybe overpowered and they're not actually on the same page. Proton has a mission, right? You're describing it as a mission-driven company. How do you strike that balance of you want to hire new people and get the outside perspective on what are we doing wrong and then not actually get knocked totally off track? Because it seems very important inside of a company like Proton. I mean, culture is extremely important. It's extremely important. And that comes from the top as well, Andy. If you were to ask him, what's the most important thing in any business, he'd very likely to say culture. And as a result, we try, we're very careful about who we hire. We hire relatively slow. I think we could, I wish we could hire faster. And maybe, you know, I think hiring is one of the things that we could be better at. But we don't do these, you know, massive hires, massive layoffs, things like this because, and we don't hire so fast that we dilute the culture. Like we want to integrate people into the Proton culture, not necessarily. And yes, sometimes we have to change it. Sometimes we have to evolve it, but we want that to be done in a deliberate way. I think, yeah, I also had maybe a similar evolution. I've been there through most of all of Proton's growth phases. So, you know, early on, I wrote a lot of code. Then I was, you know, effectively a team lead. Then I was a manager of managers. At some point I was running all of Proton's engineering. Then I was more, you know, handed off some of the management things, but, you know, kept the sort of CTO technical direction stuff. And in that course, definitely made a lot of mistakes. Mistakes too, right? Early on, it was a, I had to, you know, teach myself not to make other people like me, not to maybe not micromanage, but not to tell, not to just tell people what to do and have them execute it. And then I went through a phase later where I let people, you know, OK, people need to learn. People need to make their own mistakes. People need, you know, I want to import people with expertise, so I'm not infallible. Let's let's let's do this. And that was probably too permissive and it caused, you know, we had some, nothing catastrophic, but we had some expensive mistakes that I had a bad feeling about, but I let go through anyway because, you know, that's the worst because I was trying to do this. And so I think, you know, moderation doesn't tend to be the sexiest thing to sell, but it is, it's a balance. You know, you don't want to mandate how things are done, but you also want to make sure that you're there to stop people from doing like truly catastrophic or expensive decisions that you, you can see the wreck wall in the distance and you want to make sure that doesn't happen. It's not the most dramatic answer, but a lot of this is finding the right balance there. And it's a certain amount of moderation. The reason I spent so much time on the technical side, the corporate structure side, and the culture is because Proton faces a lot of pressure. And all of this is you've described is designed to resist that pressure, is designed to build products that can't be broken by that pressure in different ways. Let's just start with, I don't know, the governments of the world, which are a lot of pressure and have found lots and lots of ways to get past the kinds of controls you've put in place to protect user data. We'll just start with the slopsiest one. In March, a report from Forrester Media found that Proton handed over the payment data of an account called Stop Cop City, which is located in the United States. They handed that data to the Swiss authorities who then gave that data to the FBI. And that led to their identification. And this is metadata. It's, I don't think it's actually the data, the contents of the emails. Proton's argument is, look, we never actually gave anything to the FBI. We just complied with a legal request from the Swiss government. Let's start at the very basics. What is the Swiss government legally allowed to request from you? And does the fact that they can just serve as a proxy for the United States government undermine any of this trust or put any novel kind of pressure on your structures? Any company anywhere is going to have a jurisdiction and be subject to jurisdiction. There is no company or an individual which is above the law. Right. And no company is going to go to jail for you. Right. That said, you can arrange structures such that there are safeguards here. And our safeguard, for instance, is that we are a Swiss company. And we've actually been asked repeatedly, hey, can you just respond to requests from friendly government agencies? And we have repeatedly said no, because it can't be our job to decide what is legitimate and what is not. That is not something that we can take on. So what we do is we engineer our products to have, you know, within constraints like making a product that people want to use and can use and do the job. Right. But we engineer our products to be as private as possible. And the Swiss and we are subject to Swiss jurisdiction. Mutual legal assistance treaty requests. MLAT requests come in from governments. The Swiss authorities decide what is legitimate, what is not. We have no stake in that. And then they issue an order and we comply with those orders. And that's the way that's the way it has to be. And we very deliberately chose our jurisdiction in a way that, you know, the Swiss are famously neutral, and they also have a certain like every government is made up of humans, but they have a reputation for, for, for being reasonable people. And as a result, and that system has worked pretty well in general, in general, there are countries that are less trustworthy than others, less trustworthy than others. And those requests, we don't have a lot of visibility into where the requests are coming from, but those requests, we have on good authority are usually not honored. Whereas, you know, this, people's opinions may vary these days, but US, you know, the FBI requests, they tend to be, they tend to be given a certain presumption, but they're still a presumption of legitimacy, but they're still evaluated by the Swiss authorities. And then what we do is we comply. We have no, we have no discretion here. And this would be the case for any of them, but we have arranged the system such that we think it is the safest, one of the safest that can be constructed, you know, and, and, and stay legal. So let me just ask you about that because you are a systems person and you're describing a system. The failure point in that system as you're describing to me is the Swiss government is going to make a bunch of decisions about what you have to comply with in the United States government, in this case specifically, I think has realized if they just say that everything is terrorism, the mechanisms for data sharing, sort of the floodgates open, right? So in this case, this is an account called stop cop city. They, they said, this is terrorism here in the United States, whether or not the government's claims of everything being terrorism are legitimate or not, I think are wide open for debate. Sure. It feels like they found what you would describe as an attack vector on the Swiss government's mechanisms, where if you say these magic words, the Swiss government will come to you and start asking for We made some preparations about where we could possibly land for this if both the EU and Switzerland become inhospitable to this. This is a, you know, there are separate things. There's the practical challenges that we all know this stuff is happening. There's a wave of whether it be age verification or breaking encryption or stuff like this that seems to be in vogue right now. And it's something we are fighting on the policy front. It's, in my opinion, very misguided. And we are trying, and hopefully that at some point the fever breaks and this, you know, you cannot brand a backdoor with an American flag and say that only good people can use it. And it doesn't work like that or a EU flag or anything like that. And maybe this comes a little bit back. So there's the practical part. What do we do if this happens? What do we do if this happens? And, you know, at the end of the day, governments hold a lot of power on policy. And we, you know, you have to figure out how you can comply. Or if you can't comply, you leave. You do something else, right? But there are a lot of countries in the world and I think we can do, you know, ultimately, we will do what we have to. The other part, just to, I guess, use your platform a bit to make the case. This chat control, age verification, all this stuff, it's a very bad idea. And I don't want to say, like, there are real threats to children online, and it's not that we shouldn't take them seriously, but there are ways to do this in, we talked about systems thinking before, and systems design. There are ways to do this that balance the appropriate concerns, that say, you know, can gate mature material behind age gates that don't reveal who you are, right? And once you build a system that essentially abolishes anonymity online, how long before that system, I mean, it's Chekhov's gun. How long before somebody comes along to use, if it's built, somebody's going to use it eventually for purposes that it wasn't designed for? How long until China says, hey, identify all the dissidents for me, right? Who are using this? Because they have to use their ID for everything on the internet, right? We want to build systems, internet systems, that can't be commandeered like this. This is how we will approach that. But I think this principle applies to the larger internet. This is a kind of a thought experiment, right? But there were some, I'm probably going to butcher this, but there was some crazy statistic that a huge fraction of East Germans were actually employed as informants by the Stasi on the other East Germans, right? In the height of the Cold War. The Iron Curtain, of course, fell pretty much right before the dawn of the digital age, in some ways, the internet age, right? I think you could argue, and I think you can look at counterfactual-, or, you know, counterexamples like, like China, and what do I think? You could argue that had some of these, the Eastern Bloc authoritarian regimes made it into the digital age, that maybe they would have had enough control over information to not fall anymore, right? Because it's so much easier to do this. So the fact that Facebook and Google, arguably, with their ad ecosystems, have built the most sophisticated, okay, China, perhaps, but the most sophisticated surveillance systems ever built, right? And we do the most American thing ever with it, which is we use them to sell, sell you crap you don't need, right? But that doesn't mean that's the only use for those. And the fact that those are sitting on the mantlepiece, like Chekhov's gun, waiting for somebody, waiting for somebody to pick them up and do something truly horrific with them, is a threat to free society. And all this other, you know, all this other stuff with chat control and age verification is the same thing. It's saying, we have this harm, let's build a system to prevent this harm that then can be used for, for really nefarious purposes. We need to make sure that we don't engineer, engineer systems that threaten the existence of free society. Sorry, that was a way soapbox, my soapbox speech, but it's, it's something I care deeply about. This is advertiser content from Comcast Business. As cyber threats become more and more machine-based and driven by AI agents, those of us in the cyber defense space are having to invest at the same pace. Hi, I'm Chris McFarland, Chief Development Officer at Comcast Business. So when we think about the threat of cybersecurity attacks to businesses, they're just a lot more automated. They have the ability to think, they could scale literally anywhere from a hundred to thousands of time faster than a human can. The reality is, is that today, you need to protect every device, every endpoint, every workload that's running on a server, whether it's your own server or in the cloud. This is an area that Comcast Business excels at. We're enabling intelligence-driven defense with integrated visibility, AI powered threat detection, and automated response capabilities that prioritize, correlate, and contain risks before they escalate. And so it doesn't matter whether you're a small business or a medium-sized business or a really large enterprise, we've got this incredible portfolio of cybersecurity solutions and services to really enhance your cybersecurity posture. To learn more about how Comcast Business can help protect your business today, visit ComcastBusiness.com slash cybersecurity. We're back with Proton CTO Bart Butler. You just heard Bart give a pretty impassioned defense of online privacy and why he thinks it's so dangerous to build systems capable of mass surveillance under the assumption that they won't ever be used nefariously. Now, I really want to dive into the tension that exists between that philosophy, which I broadly agree with, and one of the hardest problems playing out in politics and tech, where we draw the lines when it comes to child safety on the internet and what technology should or even can do to reduce harm. And the reason I asked you so much about the structure of the company and its culture and how the systems are built are because that idealism is often expressed in Silicon Valley. I've heard it from all of the big companies that you have described. I hear it from big companies today. And then the compromises creep in. And sometimes the compromises are, well, we're done on the side of the United States. We're just going to have to listen. There's nothing we can do. You can look at our warrant canary page to see how many legal requests we're getting. And that's going to be that answer. Sometimes the compromises are, look, we have to grow. We have to get bigger, and that's it. And sometimes the compromises are, there's no way to build the system that would protect people the way we want and comply with the legal regimes. And I think encryption sits at the absolute heart of that tension. I'll give the example of Apple because I think probably everyone's familiar with Apple. Apple routinely resists these calls for a backdoor, right? And it's, they're big enough to do it in the ways that they can do it. And then the iPhone gets zero-rated anyway. It kind of doesn't matter. And like that cycle repeats in a way that it repeats. But you know, if you talk to the folks at Apple, they're like, look, the regulators come to us and they're like, just be smart. Just do some smart stuff, smart guys. And find a way to do a backdoor that will preserve privacy. And Apple's response is, you cannot. It's impossible. We cannot nerd hard enough to solve this problem for you. I think there's some willful ignorance on the part of the regulators. I think the regulators know this. And then I think there's a massive activists who want to protect children who maybe they do understand it, maybe they don't understand it, but what they certainly understand at a visceral level is the kids are being harmed, right? And all of the other systems that everyone claims can ameliorate the problems or mitigate the risk of encryption do not actually exist such that the kids are not being harmed at the rate they're being harmed today. You sit in the middle of this, right? The governments of the world come to you. They've asked you for backdoors. They've asked you for client-side scanning of chat messages to detect CSAM. What's your response to just be smart, just nerd harder and figure it out? It's impossible to create a backdoor that can only be used by the good guys. And the consequences of the backdoors being used by the bad guys are basically catastrophic, right? You mentioned, you know, there are still harms being perpetrated, you know, at these rates. Like at massive scale. I do think it's important to say that clearly. The harm is being perpetrated at massive scale. The concerns are legitimate, right? But we tolerate a lot of harms in the, we tolerate, you know, ingesting things that aren't good for you if you're an adult, right? And there have been, this is maybe US-centric, but there have been, there have been several, I mean, I don't know if it's still precedent with the way things are going, but there have been several court precedents that have basically said that, said that, and I think this actually has to do with scanning or otherwise, they've said that, okay, you, these must be compatible and balanced against restricting the freedom of adults to essentially be, be, you know, you can make society very, very, very secure by taking away all freedom whatsoever, right? You can do that. This is a trade-off of what we want to make, but I don't think, but I don't think people fully internalize the fact that, that too much security is maybe a world that they don't want to live in as well, right? Because it really, I think it was Right with Apple over App Store policies, this seems like one where their interest would be obvious to say, actually, we will maintain control. This 30%, like, stop bothering us about the 30% regulators, because we will provide you age verification. They might view it as simply a no-win game in the sense that you can KYC, know your customer as hard as you want, but there's going to be some that slip through and then you're responsible. So maybe they just want a third party to do it so that it's not their problem, right? I don't know. That might be the whole answer. Let me ask you, we've talked about age verification. I'm not sure there's like an answer, right, that will solve every problem, but you've laid out some technical approaches that will at least balance the harms. When I said that harm is happening at mass scale, what I meant was CSAM, right? What I meant is child sexual abuse material. That is happening at mass scale over the internet. We all know it. There's lots and lots of ways to mitigate it. And then there's just platforms you can't see into where it's going to happen anyway. proton is one of them. iMessage is actually another. If you fully encrypt iMessage, Apple gets a lot of criticism for that. You know, their response is the same as proton's. Like, there's no way to do this. We simply cannot give you a way to do this that does not create the backdoors for all the other bad actors you want. We're not going to do it. What are the solutions to mitigating the harms of CSAM without creating the backdoors? Because I feel like that is also missing from this conversation, especially when I talk to the activists who are laser focused on the scale of the harm. I can't describe exactly what proton does because, you know, anti-abuse is one of the things where security through obscurity really does actually help, right? It helps that the bad actors don't know what we do. But I can say that you can fight CSAM without content scanning. Like, it is possible. And a lot of that is, anyway, I probably shouldn't say anything, but you can fight CSAM. I'm not saying it's the same as, it's not as effective as scanning everything, but also in the age of AI image generation, who knows what's real or not? Not that AI generated CSAM is good, but the point is, like, you don't know if there's a real victim, if they're not, et cetera. So I think there are alternative things to scanning every image that you can do to fight CSAM. And we've done this for years and it's hard to know how effective we've been at it because we don't really know what the denominator is, but we have been, I think, at least in terms of networks that we've identified, like it's, we've identified some and we've shut them down and we've mitigated this. We have a strong interest in keeping, in keeping bad actors of all kinds off the platform. The mission is not going to be served if it's, if it's all, this is a platform for criminals. And as a result, it's not, we put nearly 10% of total company resources to fight abuse. We are dead serious about driving, you know, making abuse as little as possible on the platform. So it can be done. It's a cost center and one that we eat, right? It doesn't make us any money, but it can be done. I think the other thing is, you know, the digital sphere isn't the only place where these crimes are committed, right? And, you know, there's the physical sphere too. There's the actual victims. There's the actual people harmed by this. And I think, you know, everybody wants their job to be easier. Cops are not accepted from this, right? So they would love to scan everything on the internet. And I don't actually blame them for this, for this request because it would make their jobs much easier and they, you know, they really do want to reduce harm. However, I think we need to make a trade-off between that and the harm, you know, the threat that is to free society as well. So I think that there's probably more that can be done in the, in the sort of physical space as well to fight these kinds of, these kinds of abuse with resourcing and whatnot. But I will say, yeah, I will, I'll repeat, content scanning is not the only way to do this. And there's also some content scanning that can be done without violating and, you know, it can be client-side. It can be other things. It can be done in secret, in ways. This is very fraught too, but there, there are things that can be done to do this that don't violate privacy at a massive scale, which is a price that I think is simply too high. You're saying there's a system you can't quite describe that is effective at stopping the harms of CSAM at scale. Is that verifiable from some of the people that wish to impose the regulations? Is it auditable? Security through obscurity has these problems, right? It's, we have to, we have to trust you. A lot of this conversation has come back to how much we can trust proton structurally, personally. The, the problem is I don't know what the denominator is. I don't know if we found 50% of them. I don't know if we found 10% of them. I don't know if we found 1% of them because all I know is the stuff we've found. And even then it's a probabilistic, you know, it's a, we don't see the images, right? Sometimes we have a better clue, but I won't say how, but, I mean, but we don't see the images in any case. We are not legally capable of doing that. And God knows we don't want to subject our employees to that anyway. But no, we don't know what the denominator is. So I don't know how effective it is. I, I do know that uh, that uh that we can correlate this to some degree with the kind of legal requests we get and that those are pretty few and far between. Right. I would think that if this were, you know, if this were a massive problem on the platform that we would get a lot more legal requests for metadata regarding this. That is our proxy, not for CSAM in particular because we often don't know where the requests come, but in general, one of our proxies is, okay, how many legal requests are we getting for data as opposed to, you know, how much, how good we are at anti-abuse, right? If legal requests go through the roof, which they haven't, then obviously there, we have a big problem with anti-abuse and that has not been the case. So, um, I know that's a kind of a wishy-washy answer, but the data is private. We can't read it. That's, that's our entire, that's our entire thing. We also have a reporting system, of course. You know, people make mistakes like any other. So if, you know, if, if they share an image, which is, this can be reported that that that can go. So there are lots of mechanisms. Again, I'm, I'm sort of tiptoeing around saying any details because I don't want, I don't want this stuff to not become effective. But, uh, but we do a good job, I think, um, relative to external indicators that we can see. And, um, and yeah, we, uh, I'll give you an example where this is, it's not CSAM, but it's a similar thing, okay? We, we used to get a lot of requests, um, relatively speaking, a lot of requests for ransomware accounts, okay? Because people would go to proton. They'd set up the, the Proton email that you would, I don't know, with a Bitcoin something, right? Whatever. We got, and we would get this in the legal requests, right? We'd get this and we'd be able to look at that and say, oh, that's definitely a ransomware account for various reasons, right? We got really, really good at killing ransomware accounts. And now when it, we still occasionally will get, we'll get them, but they'll have been disabled by us for abuse six months before we get the legal request, right? So this, I'm using the ransomware as an analogy, but we do have kind of a feedback loop. So there's something in your system. There's some set of indicators that you can detect and you're just not going to tell me what they are, but there's some set of indicators of how an account operates in your system that lets you know what it's being used for. Yes. Has any government ever asked you what that set of indicators is? No. Interesting. I'm just, hopefully that doesn't happen today. Cops, if you're listening, forget, forget that you heard any of this. Uh, we're running out of time here. I want, I do want to quickly at the end, ask about AI because we've talked about systems and dynamics that I think are pretty familiar. Like I came up on Usenet and slash dot, and I probably heard that quote about liberty and security 10,000 times. Like that is the foundation of my life on the internet, right? Is like this debate from, I don't know, the 80s and 90s up until now is the same debate. And maybe AI is going to like flip over the whole apple cart, right? We can now do cybersecurity at scale in ways that governments are stepping in and stopping the models from shipping, whether or not that is correct or not. That is the thing that is actually happening in the world. We can generate vast amounts of synthetic data that might trip all your detection systems, whether or not any harms are actually downstream of that data. You've add external people to your mailing list, you are prompted, hey, do you want to, you know, external recipients and you turn off end-to-end encryption. The user says, yes, okay, because that's part of their workflow. They need it. And at that point, we still don't save a copy, right? Everything that's saved on Proton is encrypted at rest. However, we do have the clear text email going through our system because we need to send it out to whoever the external recipients are. That's the kind of model I see in the future with some of these, and it's not just AI systems, it's also integrations, and especially as we get more into business clients and stuff. I need this integration into my CRM, right? I'm going to choose to share this mailbox with my CRM. That's okay. You know, that can be a decision, and they, and we, it's our job to build a user interface which communicates what the consequences of that are, right? But privacy is fundamental. It's not about not sharing stuff. It's not about not sharing your photos, not about not sharing your data with third parties. It's about sharing the data with third parties who you choose, right? And not just by default with everybody, which is sort of the paradigm that's been the big tech paradigm for Web 2.0 or whatever you want to call it the last two decades. So I think that we can reconcile this with the Proton thing because it was never just about the encryption. Like the encryption is a tool to the end. It's all about, hey, the fact that I put, the fact that I store data on somebody else's computer on the internet does not mean that I give them control to do whatever I want, whatever they want with it or that I trust them not to lose it. So we're going to try and build a system where I retain that control and I can still participate, you know, in modern services, modern online services, right? I feel like we're going to have to have you back soon to see how that's all put to the test. Like this is new and I feel like in the next couple of years, we'll find out more. So we'll have you back soon. You've given us so much extra time. Bart, thank you so much for being on Decoder. Thank you. Thank you so much. It was a blast. I'd like to thank Bart Butler for taking the time to speak with me and thank you for listening. I hope you enjoyed it. If you'd like to let us know what you thought about this episode or really anything else at all, drop us a line. You can email us at decoder at theverge.com. We really do read all the emails. Or you can hit me up directly on Threads or Blue Sky. We're also on YouTube. You can watch full episodes at DecoderPod. We also have a TikTok and an Instagram. They're also at DecoderPod and they're a lot of fun. If you like Decoder, please share with your friends and subscribe wherever you get your podcasts. Decoder is produced by The Verge, part of the Vox Media Podcast Network. The show is produced by Kate Cox and Nick Stat. It's edited by Ursa Wright. Our editorial director is Kevin McShane. The Decoder music is by Breakmaster Cylinder. We'll see you next time. Support for this show comes from Comcast Business. Modern enterprise is a lot of moving parts. Comcast Business helps you orchestrate it all with SD-WAN working at scale to keep 150 hospital locations connected and working as one. Plus SASE and zero-trust security protecting financial data across a bank's 2,000 branches. And AI-powered networking that optimizes traffic across five continents. No one does business like Comcast Business.