
Bart Butler on encryption, child safety, and why there's no such thing as a backdoor for only the good guys.
Loading summary
Comcast Business Announcer
Support for this show comes from Comcast Business. Modern Enterprise is a lot of moving parts. Comcast Business helps you orchestrate it all with SD WAN, working at scale to keep 150 hospital locations connected and working as one, plus SASE and Zero Trust Security, protecting financial data across a bank's 2,000 branches, and AI powered networking that optimizes traffic across five continents. No one does business like Comcast Business. This series is presented by Comcast Business.
Nilay Patel
Hello and welcome to Decoder. I'm Neelai Patel, Editor in Chief of
Nilay Patel (Host, The Verge Decoder)
the Verge and Decoder is my show about big ideas and other problems. Today we've got the first of a two part series on the systems that run the world. I'm talking with Bart Butler, the CTO of Proton, a company that makes private and secure productivity software. You probably know it best for ProtonMail, which is encrypted by default, but the company also has docs, sheets, calendar, even a new AI assistant called Lumo, all built and marketed around the idea that they should be vastly more private than the similar products from big tech companies. You'll hear Bart say pretty plainly that the thing Proton sells at a high level isn't really the products themselves, but actually trust. And trust in the software world isn't only about the people who run the companies, but also the technology they develop and sell and the corporate structures in place to make sure that technology is built against the right incentives.
Nilay Patel
This is pure decoder bait.
Nilay Patel (Host, The Verge Decoder)
In other words, the challenge is that Bart also says Proton's mission is very much to succeed at being a viable competitor to big tech, and that means the company has to grow and expand to competitive scale, all while preserving its core values. That philosophy and that challenge are baked directly into Proton's structure and even its physical location. The company and its servers are based primarily in Switzerland, in part because of the Swiss government's geopolitical neutrality.
Nilay Patel
Two years ago, Proton also transitioned to
Nilay Patel (Host, The Verge Decoder)
a non profit structure governed by a foundation, which is a familiar model used by all kinds of companies that ostensibly operate in the public interest, but which has failure modes of its own, as we just saw with OpenAI.
Nilay Patel
Bart and I talked about all of
Nilay Patel (Host, The Verge Decoder)
that, of course, but I really wanted to talk to him because he's responsible for the technical construction of some very complex systems that interact with all those complex politics.
Nilay Patel
I really wanted to know how Bart
Nilay Patel (Host, The Verge Decoder)
translates all of those lofty ideals and concepts like user trust into real privacy centric products and features that can withstand all of this policy pressure. And of course there are real examples of this earlier this Year, the Swiss government came knocking on Proton's door with a request for payment data to help the FBI unmask a protester associated with the Stop Cop City movement in Atlanta, Georgia. Proton complied. They gave the Swiss government that data, which then went to the FBI. So, of course, I had to ask Bart about all that and what it means that the US Government can use words like terrorism to coerce foreign governments to apply pressure on Proton and how Proton decides when and how to take on those fights. This pressure manifests in all kinds of ways. Proton is on the record saying it would leave Switzerland and also consider ditching its operations in EU countries like Germany and Norway if the various surveillance laws in those states continue to threaten Proton's privacy mission. Bart told me that these aren't just empty threats and that Proton is in the process of figuring out what it would mean to leave Europe if things get, in his words, more dystopian.
Nilay Patel
There's a lot going on in this episode.
Nilay Patel (Host, The Verge Decoder)
We actually ran long because we got so deep into the weeds. We first spent time talking out the broad frameworks that Proton uses before talking about the real problems of child safety, age verification, and AI, all of which are testing Proton's values with some of the highest stakes problems on the Internet today. But we took the extra time to get there, and I hope you'll think it's worth it. Okay, Bart Butler, the CTO of Proton.
Nilay Patel
Here we go. Bart Butler, you're the chief Technology Officer at Proton. Welcome to Decoder.
Bart Butler
Thank you. Happy to be here.
Nilay Patel
I'm excited to talk to you. It feels like Proton sits at the center of an escalating, spiraling debate about how we build technology systems, how we regulate them, and how consumers can protect their data or have any control at all over their data. At the center of it, let's start at the very start. I think most people understand Proton as Proton Male, but there's now a suite of office products or productivity products. Describe what Proton is and how you see all the products working together.
Bart Butler
Proton is an ecosystem, if you will. A collection of products that all sort of share the same DNA in the sense that they are. They fundamentally are versions of, in many cases, versions of products you can buy elsewhere but that are privacy preserving.
Chris McFarland
Right.
Bart Butler
And yes, we started with mail. We also have a vpn. We have Proton Drive, which is our file storage, and, you know, photos and collaborative real time docs. We have Calendar. We have a password manager called Proton Pass. We have meet, which is a video conferencing software. So we have a whole Collection of products that do things, in some cases very similar to other products that you might be more familiar with, but are also privacy preserving.
Nilay Patel
One of the reasons I'm excited to talk to you specifically as Chief Technology Officer is the idea that there's a set of products that are familiar, but the company running them is going to behave better than the other company. Is a familiar pattern in this industry. And Proton's promise is that the products are actually architected differently, right. That, that from the very beginning, the way the products are built is actually what makes and keeps the promise of protecting privacy. Not a benevolent CEO or a benevolent board of directors, we'll come to that. There's some of that in the mix.
Bart Butler
Some of that. There's some of that too. There's some corporate structure stuff, but there are actually, I would say two primary structural, maybe, or systems, you could call them systems engineering, right? At a broader scale, but structural constraints on how Proton operates. The first is that we encrypt all the data we can, right? So if we wanted to turn around and sell that data to somebody, we can't. It's mathematically not possible for us to do it. Right. This also has other benefits, right? We can't easily lose it to hackers or other interested parties. And we, you know, there's some data that we can respond to for say, legal requests, but, you know, there's some data we can't. Right? And this, this helps us, basically. We can't, we can't give up data that we don't have access to. The second is the business model. It's not, I mean, There are other SaaS players, of course, that do this. I don't think there are a whole lot of B2C consumer based SaaS players at our size who do this, but our revenue model is getting paid by our users, right? So we don't sell ads. The products are not carrots to get people to come in and give us our data so we can sell it to advertisers, right? And that means that those users, the ones who pay our bills, pay our salaries, allow us to grow the business. If we were to betray them, then that would essentially undermine the value of the business, right? So we have tied the value of the business and the growth to the business to protecting our users so that our interests are aligned. And this is also very important because, you know, temptations are a thing, right? People respond to incentives and we have structurally arranged our company such that those incentives are aligned with the people to whom we have promised to protect.
Nilay Patel
If I was to very reductively summarize what you just said is we take money from consumers and what we sell them is encrypted versions of popular services that they rely on, like email, like a vpn, like an office suite. Do you think consumers understand that what they're buying is the technology solution, or are they buying the promise of privacy, or is it some mix? Because I'm not actually sure consumers really understand at mass scale how it all works. Right. They think their iPhones are listening to them.
Bart Butler
I will tell product people and engineers, you know, in meetings about new features if, if you've, if you've mentioned the word encryption to the user, you've already failed, right? I mean, people don't understand what this is, that's fine. Our goals is to make products that are as usable and as functional as our competitors, or more or more functional. I mean, I don't want to sound entirely derivative, right? We do have features that nobody else has that are often geared towards privacy and functionality for people who need confidential communications. However, in general, we're selling. We're selling the promise. We're selling the promise that we're a different kind of company. We're selling the trust, right? And that trust is, is critical. Without the trust, that is where the real value of the company is. Now, that trust is backed up by technology, right? But, but we're selling the trust.
Nilay Patel
The reason I'm pushing on it, and specifically I'm happy that you mentioned trust, is the big tech players will all make the same kinds of promises about your data being private, happily tell you that they don't sell an ounce of your data. It's actually not in their interest to sell the data because the ad targeting that they do depends on the data being theirs and not anyone else's. We can get into this for days and days and days. I'm just curious where you see that trust being expressed or where you feel like that trust is most communicated from Proton. Because if you ask me as a more technical person, I do look at the architecture of it's all encrypted and probably mathematically it's impossible to get into. And sure, we'll come to how much metadata can be shared with authorities, because there's some debate about that, but that's the piece that resonates for me. As opposed to I have to trust you or a board of directors, there are some other people who just look at the promises and take them at face value. Then there's some set of regulators that say, actually we have a Bunch of other interests in being able to see the data that goes on here. And we actually don't trust you to be a good player in the ecosystem. So when you think about trust, is it, does it come down to the data is encrypted and that's the core promise we're making and anything that breaks, that breaks the whole product. Or is there some other dimension of trust that is important at Proton as you build the systems?
Bart Butler
So end to end encryption is obviously important. It's the gold standard and it's what we strive to. However, there are definitely features that, you know, we. Privacy, at least to me personally is about control, right? And there are some times where I want an integration with an external service or something like this where I'm going to have to, I mean, my choices are no integration or my choices are breaking end to end encryption. And our goal is to make this. The user has an informed choice and control over who sees their data. So it's not the same as never share your data, never share your photos with anybody. But the point is instead of sharing your photos with somebody like Facebook, who might is sharing your photos with grandma and grandpa and only grandma and grandpa, right? So that's not to say that the encryption is everything. There's the fundamental engineering which backs up the trust. People like you look at the architecture and say, okay, this is encrypted, this is important to me. And then you go tell somebody else, you say, I trust Proton because of this, this and this. The other person, all they know is, hey, I like, I know Nilay, I trust him. And he says Proton is good. There's a whole cohort, much, much greater than the techie cohort. The techie cohort is our core, of course, and has been since the beginning. But there's a whole cohort of people who trust Proton because other people they know whether. And by no, I mean it might just be people who they trust on Reddit, right? But other people they know say Proton is there. And we've all been getting object lessons in that. You know, rules, bylaws, laws, other things are, can be worth something. But personnel really matters, right? Who enforces them really matters. So we have the technical layer which is designed to constrain what we can do technically. And then we also have the, you know, the legal, the corporate structure layer, which is it's defense in depth, right? All of these things are interlocking guarantees to our users that we are trustworthy. And ultimately that's the important, the most important thing about the business.
Nilay Patel
I Do want to come to the corporate structure? It is decoder, after all. But just one more turn on the product set itself. You started with ProtonMail. You've got the other suite of products, including now an AI assistant. You talked about the fact that the business model is the consumers pay you money directly for the products. Is ProtonMail still the core product that's making the most money? Are the other lines of business growing? How does this look?
Bart Butler
We don't disclose direct financials. Mail and VPN are the two oldest products and as you might expect, they are the two largest products still. But you know, we also have a lot of people who buy bundles like, you know, and buy multiple products. We try to make the products work well together. In an ecosystem, some products are more tightly bound than others. And the new products, the more recent ones, Calendar. Calendar is very tightly tied with mail, of course, but we also have drive and pass. Those are not as big as the older products. They have less of a head start, if you will, but they are growing rapidly. So they all contribute. But yeah, they contribute differently often. I'm not going to say it's exactly how old they are, but those that have had the bigger Runway are usually bigger.
Nilay Patel
One of the patterns with consumer productivity software is the suites get bigger, the bundles get bigger, and then the companies realize the class of customers that will actually pay for increased productivity is enterprise. And we kind of see this over and over again in the space notion. Did it Dropbox, did it ever. Like I can go on and on and on of companies that we covered as consumer software companies that eventually pivoted to being enterprise companies. Does Proton feel that same pressure that you're going to have to go have more corporate clients, enterprise clients to grow, or are you still focused on consumer.
Bart Butler
I think we definitely feel the pressure. There's. What is it? I don't know if it's apocryphal or not, but the old John Dillinger quote like why do I rob banks? Well, it's where the money is, right? There's a little bit of why do you go B2B? Well, it's where the people who have budgets and are willing to pay for this goes. I think we're definitely considering it. And we have a. Even as a primarily consumer focused business, we have a lot of people who, small businesses in particular, who use our products for business purposes. Right. You just use the consumer. And we've also made forays into small business offerings and things like that. I think this is something that growth will probably demand. And I think there Are a lot of businesses for whom things that we offer, confidentiality, you know, non US based, you know, European sovereignty type stuff in particular, and, and just our reputation that are very appealing to those businesses. Right. That said, we have to do a balance, right? And today our business is B2C. We're not going to jettison the B2C business. I also think that having the B2C business being as strong as it is, is a. Is a competitive strength. There aren't. I mean, as you said, there are several that have transitioned to B2B sort of from B2C. But at the same time, I think there are a lot more B2B players that start off B2B and stay there. Right. And one of the things that we're looking at, you know, communication between businesses and their customers is something that is, is certainly important and confidentiality is important there. And you see things like with, you know, WhatsApp forays into, you know, having businesses connect to people who have consumers who have WhatsApp. Like, I think that when the time comes to really make a push to B2B, the B2C user base and product suite will be a. Will be a benefit to, to us.
Nilay Patel
One of the tensions there as AI sort of infiltrates more and more businesses is the frontier model companies want every ounce of data. I think a bunch of big enterprises are very leery of giving a bunch of data to frontier model companies. The AI works best when they have a bunch of data. And so there's this big choice about how much of your business will you expose to Claude? How much of yourself will you expose to Claude to get the most value out of those models? Proton sits right in the middle of that with a technical architecture that you're saying would provide choice. But it also seems like the game for a lot of these companies is to just hand everything over and say, go run my business AI. How do you see that working with your enterprise customers today?
Bart Butler
It's a fraud decision, right? It's giving all their sensitive data over and they feel like in many cases they don't have a choice. And in some ways that's why we developed Lumo, which is our AI offering, which I, I think may have left off the list before, unfortunately. But I think we just launched Lumo 2.0, which is a big revamp of the models we use. And part of that is the goal of Lumo project in general is to have something which integrates with the rest of our products and can do this in a safe way. This is to address this Sort of trade off between do I give random AI companies possibly in different countries, possibly have compliance problems, all those other things, do I give them all my sensitive business data or can I do it in a way that is still, is still more protected now? You know, in many ways there are still trade offs on our side to make, but we keep it in house within Proton with the guarantees that we give. That should be a more attractive option for those kind of workloads. And that's what we're, that's what we're hoping as we develop. Luma.
Nilay Patel
I think this does bring us to the decoder questions about structure and an organization because that's where it feels like the structure has to be where the trust lies, not necessarily the technical architecture. So how is Proton structured today? How many people is it?
Bart Butler
Proton today is approximately 650 people total. That also, that includes engineering support functions, marketing, et cetera. It also includes customer support, which we do in house. We always have. We are a corporation. Proton ag, a Swiss corporation. However, a controlling stake in, in Proton AG is held by the Proton foundation, which was seeded with shares from Andy, our CEO and other early employees, and has a controlling stick. There are other fellow travelers with, with I would say a similar and somewhat similar structure signal and Mozilla. And our reasons are the same. We have a, you know, the Proton foundation controls, has a controlling stake in the Proton company and has as and is empowered to protect the mission. It's a Swiss foundation, which is, I've been told, I'm not a lawyer, but I've been told it's very difficult to change and its job is sort of the guardian of the values and the mission of Proton. So if Proton, the company were to stray from that mission, the Proton foundation would be empowered to correct the correct course, if that makes sense.
Nilay Patel
Has that ever happened?
Bart Butler
No. Thus far, no. We have our founder CEO Andy, Andy Yen was, he founded the company as founder CEO implies. And as long as he is in charge, I don't think that'll be necessary. But you know, if he gets hit by the bus, there's, there's, there's still a, there's a corporate structure which is designed to protect the mission going forward and to make sure the company doesn't stray regardless. And because of this ownership model too, the company is insulated from say some sort of takeover or purchase that could also redirect its, its, its priorities. But I do, I do say that. I mean, I think, I think that and the tech and the business model basically are interlocking protections against us betraying the compact that we have with our users.
Nilay Patel
One of the things that strikes me as I talk to more and more companies that have transitioned to this kind of foundation model is that that structure is essentially there to insulate you from the rapacious demands of capitalism, right? Like you, you aren't being pressured to make as much money every quarter as possible to do the things that would lead you to make the most money. And that means maybe the technology can develop in a pure and idealistic state of protecting privacy instead of chasing the dollars. Do you feel that insulation? Right? I mean, you do have to make money and pay your employees and grow in some way. But what's the dynamic for you architecting the products?
Bart Butler
The short answer is no. And the reason for that is that we have to compete in capitalism. Our main competitor is big tech, right? Even though we are much smaller than big tech, where our users come from, when we convert people, when we get new customers, they're big tech in general and we have to play the same game. Our corporate motto, this might be a little cheesy, but our corporate motto is privacy by default. And that default part is doing a lot of heavy lifting. I mentioned before that our goal is to design products which are easy to use and secure, right? There are plenty of tools that are secure and nobody but a few, you know, a few experts use them. And that's fine, like, I'm not criticizing the existence of those tools, but our goal is to make tools that everybody can use without understanding the cryptography, without even knowing that it's cryptography that they can use and that are as easy to use and as feature filled as our unencrypted, you know, unencrypted and essentially data mining competitors, right? It's a tall order. I'm not saying we're, I'm not saying we're 100% there yet, but that is the goal. But the default word in that privacy by default means that we have to be at the scale where we can offer a real alternative to big tech and small startups, small scale ups, you know, being 100 times or 10 times smaller than big tech is not going to cut it, right? In order to do that, we need to grow. So growth is actually part of the mission, if you will. And that means that we have to be the word not rapacious, but we have to be as hungry and as efficient and as growth minded as we possibly can, because that's part of the mission, to grow big enough to actually challenge the paradigm. We can talk about all Kinds of the ways capitalism is kind of broken right now, but, like, we have to play the game.
Nilay Patel
All right, I'm going to make a comparison that you are going to hate. Okay. I'm just letting you know I, I know you're going to hate it. Maybe the most famous. We'll build a foundation to protect ourselves from the demands of the market and make sure the thing is healthy. Is OpenAI, which basically killed that structure in order to chase an ipo. Right? Like, and maybe they still have really important and idealistic ideas about how AJ should be developed. Maybe, maybe there's some people in that company who really feel that way and it just didn't work. Right. They needed to chase growth in very specific ways for whatever reasons that they felt. Maybe it was money, maybe it was just in order to take on Google Search the way that OpenAI felt like it wanted to take on Google Search, they had to change the structure of the company. That obviously happened. Right. It's like one of the most, like, apocalyptic foundation moments that has ever happened. Like this thing just like exploded or imploded onto itself. When you look at that and then you look at, okay, we have to grow in order to be the default. We have to grow to be big. But we're making this promise that Google doesn't have to make or Microsoft doesn't have to make. Where is the tension in that? How does that express itself as you design the architecture of the products which might preclude some opportunities?
Bart Butler
It's not. But what could also be our corporate motto is go big or go home. Right? We don't set modest goals in that regard. But I think that there are a couple things that, that make it different. I mentioned before a lot of constraints, but one thing I didn't mention is we don't have VC investors, we don't have private equity investors. We aren't burning other people's money with VCs burning down, you know, breathing down our necks that we must exit soon or otherwise we go belly up. Right? We, our goal, we built a sustainable business. We reinvest the profits from that business back into the business. And this insulates us from some of the pressure which I'm sure OpenAI felt, given that they were lighting enormous stacks of money on fire all the time. But that said, personnel, as policy, there's certainly always this risk. And at the same time, sometimes you find that we found out a lot recently that sometimes rules or otherwise or norms or guidelines, unwritten or not, they're not worth the paper that they're written on. But that's also where the architecture comes in. We make choices about the tech stuff. And obviously I'm on the tech side of this business, but we have made choices and some of that is for business competitive reasons. Right. We want to sell products where we say, we can't access your data. We don't have access to data. We can't lose it, we can't sell it, we can't do this. But that also constrains us from deciding one day to turn around and sell it because we have locked it in a box and we can't access it. And therefore we can't turn around and say, you know what, sorry guys, we changed our mind. We're actually going to mine all this data and go right now. Is anything perfect? No, but I mean, the structure is designed such that we have these interlocking, as I said, controls. The Proton foundation is barred from selling Proton. Proton ig, as far as I'm aware. Right. But even if some reason, some happens and this happens, the value of Proton is in the reputation. And we said this, and this has been a sort of a deliberate choice. The value of Proton is in the trust that we have. You know, if Google bought us, it would have no value because Google does not have the credibility to run Proton. Do you see what I mean?
Nilay Patel
It's not the fault of Google buying anything. I just want to be very clear about it.
Bart Butler
I don't know. They shut it down and then it's gone. Right?
Nilay Patel
The clock would start ticking that day.
Bart Butler
Yeah, I know, I know. This has happened before again, I'm sure, I'm sure. But that ends. But the Proton foundation structure is designed to say that no, the company cannot be sold to a buyer. Right.
Nilay Patel
That's the macro structure. Just tell me about the more tactical structure inside the company that's building a product. How is Proton itself structured? Is there a team that makes the Lumo assistant? Is there a team that makes email? Is it divisions? Is it functional? How does that work?
Bart Butler
We do have a division structure, a business unit structure. We have certain products are bundled together like mail and calendar because they're bundled into the same division. Other ones are separate. So we have Lumo, we have Drive, we have Pass, and we have vpn. These are, these are separate, separate divisions. You make choices about corporate structure based on what communication you want to be easiest. Right. So that's designed to allow people to move fast and to have autonomy and make decisions within their product. And then we also have teams that work sort of cross organization teams or support teams and things like that. And, and on that side, the trade off of the business unit structure is there. We sometimes have to work harder. Right. It's a little bit like corralling cats, right? Where you have to make sure that, okay, I'm building this feature that touches all the products. I need to make sure that all the products are on board and they have it in their planning so that we can ship it correctly. So we've made a deliberate decision to sort of prioritize in product communication and then we have to work and then we try to compensate for the shortcomings of that in our cross product communication. And then as we transition to more and more ecosystem based stuff, we may make different choices about the corporate structure to support that. The whole Conway's law thing, you ship your org chart, but sometimes you want the best of both worlds. And this is where process comes along. It's not always sexy, but you find it super important as you scale organizations for sure.
Nilay Patel
You might be the first decoder guest to make the connection directly between the fact that I ask everyone how their company is structured and you ship your org chart, which is why I always ask, because it's the fundamental truth.
Bart Butler
You do. And we struggle with that to some degree. We try to compensate for it. But you do ship your org chart and therefore, if you want your products to look different, you should adjust your org chart to support that difference. Right.
Nilay Patel
Ultimately, the other decoder question I ask everybody is about decisions. You have a lot of decisions to make. You are trying to build a new kind of product architecture against a lot of the same constraints as your competitors. How do you make decisions? What's your framework?
Bart Butler
We are a founder led company. Right. Andy started Proton. I was, I think Employee 6, I want to say, or something. That's a funny story in itself. You know how I met Andy?
Nilay Patel
How's that?
Bart Butler
He was my grad student at the cern. I was a postdoc at Harvard and he was my grad student. And then he comes and finds me in Silicon Valley after I left physics and it's like, hey, you want to join my startup? You can be CEO or CTO rather. But yeah, so he's still heavily involved. He has a lot of input on product direction, strategy, and he's a visionary, right. And I think he's responsible for a lot of Proton success. He's willing to take risks, this kind of stuff. And I obviously believe in his leadership. I wouldn't still be here after 11 years. That said, I think one thing that sometimes happens with visionaries is they need to surround themselves with people who will challenge them when they get maybe a little too far over their skis or to also make sure that we have ideas from other places. One thing that we really try to make sure is that ideas are judged on their merits, not their origin necessarily. We have a senior leadership team whose job is to, yes, execute, but also, you know, bring new ideas and sell them. And things like this, we try. I'm not going to say that we always. That we're perfect in this. We have plenty of things that we can improve, but, you know, we try to push decision making down the orgs. The whole point of an organization is that you have. It's a way to align lots of different people in the same direction. Right. And the trick is always how do you get alignment in the same general direction while still having autonomy so that you're not micromanaging everything. And I'm not saying we always get the balance right, but that's the goal here. And when, you know, we do this sort of orientation, when we hire new people into Proton, and one of the things, one of the things we always say there is like, I want to hear, you know, you're not used to our. Our way of doing things yet, so I want you to look at our way of doing things. And if you've experienced another employer or you think this is either crazy or inefficient, I want you to tell us, right? And we're very clear. Yes, of course we have a hierarchy, but it's, you know, level. And part of this is our size, of course, but we very rarely have more than, say, three or four levels of management. We always say, look, if you need to ping me, you need to ping the CEO. You need to directly talk to people, just do it. That's another thing. And again, I'm speaking for myself, but I think this is sort of common throughout Proton is that I tell people, I'm not promising or obligated to agree with you, but you're never going to regret telling me what you think we have. And this is. I credit Andy with this. We have very little internal politics. Maybe this is something just because we're not very big yet, but we have very zero tolerance for fiefdoms or internal politics. And that also makes things. There's very much a sense that we're all pointing in the same direction and that it's not my division that I'm trying to grow, it's Proton in general. Some of that comes with being a mission Driven company. I don't know if you've ever had this experience, but for those of you who haven't, I, I, I've had both. Right. I, I, I was, I was a physicist as part of the CERN collaboration a long time ago. And there you have, you know, fundamental nature of the universe. I, I consider that kind of a mission driven occupation. I also had a stint in Silicon Valley afterward which was, which is fun and interesting technical problems, but I, I, I, I wouldn't, you know, I missed that. Right. And with Proton, the mission is really, we have to be careful that it doesn't paper over organizational problems that we should really solve, let's put it that way. But it really does make the job easier when everybody is sort of aligned in that regard.
Nilay Patel
We need to take a quick break. We'll be right back.
Comcast Business Announcer
Support for this show comes from Comcast Business, Modern Enterprise. It's a lot of moving parts, multiple locations, a constant flow of data, endless applications, critical systems that can't go wrong. Comcast Business helps you orchestrate it all with SD Wan working at scale to keep 150 hospital locations connected and working as one. So patient data flows securely and care is delivered without interruption. That's a healthy approach. Plus SASE and Zero Trust Security protecting financial data across a bank's 2,000 branches. That means identities verified, transactions secure, threats blocked, nest eggs safe and sound in the best of hands and AI powered networking that optimizes traffic across five continents. So, yeah, Modern Enterprise is complex. Comcast Business makes it simple when you add it all up. No one does business like Comcast Business.
Nilay Patel (Host, The Verge Decoder)
We're back with Proton's Bart Butler. Before the break, we went over the decoder questions. But now I wanted to put Bart's answers into practice and discuss how Proton is maneuvering an increasingly threatening policy landscape both here in the United States and in Europe.
Nilay Patel
Up early on my career, I had no idea how to manage anyone. And I went to a bunch of people and asked them a bunch of questions. And one of the smartest mentors and all this told me very seriously, she sat me down and she's like, look, you don't hire people to make them like you. You hire people to change your organization. And I've taken that to our, and maybe at 15 years into this, I'm like, that's actually a pendulum, right? You, you need people to buy into what you're doing. Otherwise every new person you hire is going to radically disrupt what everyone else is doing because they're maybe over empowered and they're not actually on the same page. Proton has a mission. Right, you're describing as a mission driven company. How do you strike that balance of you want to hire new people and get the outside perspective on what are we doing wrong and then not actually get knocked totally off track? Because it seems very important inside of a company like Proton.
Bart Butler
I mean, culture is extremely important. It's extremely important that comes from the top as well. Andy, if you were to ask him what's the most important thing in any business, he very likely to say, to say culture. And as a result, we, you know, we try, we're very careful about who we hire. We hire relatively slow. I think we could, I wish we could hire faster and maybe, you know, I think hiring is one of the things that we could be better at. But we don't do these, you know, massive hires, massive layoffs, things like this because, and we don't hire so fast that we dilute the culture. Like we want, we want to integrate people into the Proton culture. Not necessarily. And yes, sometimes we have to change it, sometimes we have to evolve it, but we want that, we want that to be done in, in a, in a deliberate way, I think. Yeah, I, I also had a, maybe a similar evolution. I've been there through most of all of Proton's growth phases. So, you know, early on I wrote a lot of code. Then I was more, you know, effectively a team lead. Then I was a manager of managers. At some point I was running all of Proton's engineering. Then I, then I was more, you know, handed off some of the management things but, you know, kept the sort of CTO technical direction stuff and in that course, definitely made a lot of mistakes. Mistakes too. Right. Early on it was a, I had to, you know, teach myself not to make other people like me not to, maybe not micromanage, but not to tell, not, not to just tell people what to do and have them execute it. And then I went through a phase later where I let people, you know, I need, okay, people need to learn. People need to make their own mistakes. People need, you know, I want to import people with expertise. So I, I, I'm not infallible. Let's, let's let's do this. And that was probably too permissive and it caused, you know, we had some, nothing catastrophic, but we had some expensive mistakes that I had a bad feeling about, but I let go through anyway because, you know, I, because I was trying to do this. And so I think, you know, moderation doesn't tend to be the sexiest thing to sell, but it is. It's a balance. You know, you don't want to mandate how things are done, but you also want to make sure that you're there to stop people from doing, like, truly catastrophic or expensive decisions that you. You can see the brick wall in the, you know, in the distance, and you want to make sure that doesn't happen. It's not the most dramatic answer, but a lot of this is finding the right balance there, and it's a certain amount of moderation.
Nilay Patel
The reason I spent so much time on the technical side, the corporate structure side, and the culture is because Proton faces a lot of pressure. And all of this, as you've described, is designed to resist that pressure, is designed to build products that can't be broken by that pressure in different ways. Let's just start with, I don't know, the governments of the world, which are a lot of pressure and have found lots and lots of ways to get past the kinds of controls you put in place to protect user data. We'll just start with the splashiest one. In March, A report from 404 Media found that Proton handed over the payment data of an account called Stop Cop City, which is located in the United States. They handed that data to the Swiss authorities, who then gave that data to the FBI and that led to their identification. This is metadata. I don't think it's actually the data, the contents of the emails. Proton's argument is, look, we never actually gave anything to the FBI. We just complied with illegal request from the Swiss government. Let's start at the very basics. What is the Swiss government legally allowed to request from you? And does the fact that they can just serve as a proxy for the United States government undermine any of this trust or put any novel kind of pressure on your structures?
Bart Butler
Any company anywhere is going to have a jurisdiction and be subject to jurisdiction. There is no country, there's no company or an individual which is above the law, Right? And nobody, you know, no company is going to go to jail for you. Right? That said, you can arrange structures such that there are safeguards here. And our, our safeguard, for instance, is that we are a Swiss company and we've actually been asked repeatedly, hey, can you just respond to requests from friendly government agencies? And we have repeatedly said no, because it can't be our job to decide what is legitimate and what is not. That is not something that we can take on. Right? So what we do is we engineer our products to have, you know, within constraints like making a product that people want to use and can use and do the job right. But we engineer our products to be as private as possible. And the Swiss government, and we are subject to Swiss jurisdiction. Mutual legal assistance treaty requests, MLAT requests come in from governments. The Swiss, Swiss authorities decide what is legitimate, what is not. We have no stake in that. And then they issue an order and we comply with those orders, and that's the way it has to be. And we very deliberately chose our jurisdiction in a way that the Swiss are famously neutral. And they also have a certain, look, every government is made up of humans, but they have a reputation for being reasonable people. And as a result, and that system has worked pretty well in general, there are countries that are less trustworthy than others. And those requests, we don't have a lot of visibility into where the requests are coming from. But those requests of on good authority are usually not honored. Whereas, you know, this. People's opinions may vary these days, but us, you know, the FBI requests, they tend to be, they tend to be given a certain presumption, but there's still a presumption of legitimacy, but they're still evaluated by the Swiss authorities. And then what we do is we comply. We have no, we have no discretion here. And this would be the case, the case for anything. But we have arranged the system such that we think it is the safest, one of the safest that can be constructed, you know, and, and, and, and stay legal.
Nilay Patel
So let me just ask you about that, because you are a systems person. You're describing a system. The failure point in that system, as you're describing to me, is the Swiss government is going to make a bunch of decisions about what you have to comply with in the United States government, in this case specifically, I, I think has realized if they just say that everything is terrorism, the mechanisms for data sharing, sort of the floodgates open, right? So in this case, this is an account called Stop Cop City. They said this is terrorism here in the United States. Whether or not the government's claims of everything being terrorism are legitimate or not, I think are wide open for debate.
Chris McFarland
Sure.
Nilay Patel
It feels like they found what you would describe as an attack vector on the Swiss government's mechanisms, where if you say these magic words, the Swiss government will come to you and start asking for metadata. Does that feel appropriate? Does that feel survivable?
Bart Butler
I think a lot of this stuff, at some point it's going to be up to people, right? We've done the best we can. And I don't think, you know, it's never going. People are Going to have different opinions about what. Which requests are legitimate or not. But we've done the best we can in saying that, okay, the Swiss authorities will decide, we will comply with whatever they say because we are. We are a Swiss jurisdiction. In the meantime, we do and can. And arrange our. And this. Of course, there are laws that govern this, but we do whatever we can to minimize the amount of data that we can give. I mean, payment data is sort of. There's not. We can't encrypt it. That we use payment processors, like, they can get it. They can get it from lots of different sources. So if you have a credit card attached and there's a legal request coming in, there's not a whole lot we can do. Right. You mentioned systems. Because I think this is important. What's important to me, and I realize this, I don't want this to sound callous for, like the specific, you know, a specific hypothetical abusive case. Right. That might have not been, you know, the, you know, mistakes can, can be made, of course. But I want a system like the system we have, which is that if the government has some sort of reasonable cause and can convince people in a. In a defined process to give data. Yeah, the data should probably be given. What I, What I really worry about is that we often live in a world where you can, basically, the government can instead ask, give me all your data, and I'm going to look for. Look for problems. I'm going to look for a crime. Right. You know, the word wiretap comes from a time where they had to literally go to your house and tap the wire. And I don't think it was really thought of at the time. But this, the actual physical act of having to do this had a barrier to the fact that you couldn't surveil everybody at once. Right. It was just. It was simply logistically impossible. We live in a world today where you can surveil everybody. So we want to build services and systems where this is impossible. Right. Where you have to. Where the default should be privacy, as I said, privacy by default. And yes, we are also responsive to legitimate law enforcement requests, however you define legitimate. And that legitimate question will always be a matter of process, which we, of course, are only one player in this process, but I think that's.
Nilay Patel
There's legitimacy and there's like a market dynamic here. So the Swiss government has applied a lot of pressure to Proton the last few years. They wanted you to basically have an unencrypted VPN and be able to decrypt User data that was traveling over vpn. I believe Proton threatened to leave Switzerland over this. And then you, you announced that you were going to build a more distributed infrastructure and place some of that infrastructure in Germany and Norway. We're going to come to chat control at some point. The EU is going to. Yesterday, I think they passed a version of this law and Proton's response was we'll just leave the eu. Like we're going to take ourselves out of this legal jurisdiction. I want to talk about that stuff in detail, but just in the sort of broader context that you're talking about right now. You have to, you're picking, right, you're picking a foundation. And often the response is, well, if you change the legal foundation here, we will leave.
Bart Butler
Yeah.
Nilay Patel
How real is that?
Bart Butler
It's dead serious. I mean it's, with all due respect to Swiss authorities and everybody else, I think it would be absolutely suicidal to continue down this path. Part of the Swiss brand is privacy. It's been that way for 80 years. And you know, they have a good. And via Proton largely, but also they have a good case for bringing that reputation and that economic advantages because there's a lot of businesses, a lot of commerce that requires confidentiality to the 21st century, to the digital age. And throwing it away is I think, short sighted to say the least. But it's a serious threat. The thing about digital services is they can be moved. There's a lot of flexibility in this and if we get truly dystopian, there may be a world where there's no place to move to. But at the moment there are options we hope to not have to do it. We hope that the powers that be are responsive to this and change course.
Nilay Patel
That's a cost, right? I'm curious about this.
Bart Butler
It's a cost. Well, it is a cost. It's maybe not as much of a cost as you might might think, right. We, we already have, we already have employees in different countries. We have, we have satellite offices, we have other things. We, we have data centers in Germany. We have, we have our data centers in Norway. You know, not to, not, not to be, not to be too blase about it, but we could do a corporate inversion to us somewhere else and then say, okay, all, all the legal requests have to come through here, right.
Nilay Patel
And all the play with, you can't sell it, right? The, the part where you're like, it's a Swiss foundation, it's very hard to sell. You want to leave Switzerland and reincorporate in Germany or is Swiss Government going to stop you?
Bart Butler
I'm going to have to defer on that because I am not a lawyer. I have no idea. But I'm sure it's possible.
Nilay Patel
Yeah. I'm just curious because it feels like, at least as of this conversation, you know, NATO still exists, Germany, Norway are still in the eu. Like, there's Swiss law, there's German law, then there's EU law. And the EU law is also getting increasingly intense about what they can scan, what can't they scan. I mentioned chat control earlier. That's the law that in the EU would require service providers to scan the contents of messages for CSAM material, for other kinds of infringing material. That's a big problem. Right? I mean, a bunch of. I think Proton has said we will just leave the EU if you make us do this. Right. This is going to break the core premise. If you move to Germany and Norway and then the EU passes the, the harshest version of control. Are you geared up to leave?
Bart Butler
Yeah.
Nilay Patel
Like how ready are you? Can you pull the switch tomorrow? Where would you go?
Bart Butler
I can't. I don't know. I have to consult with other people for that. I'm not deep in that. But it's a real threat. I know it's a real threat and I know we made some preparations about where we could possibly land for this if both the EU and Switzerland become inhospitable to this. This is a, you know, there, there are separate things. There are the, there's the, there's the practical challenges that we, we all know this stuff is happening. There's a wave of, whether it be age verification or, or breaking encryption or stuff like this, that this seems to be in vogue right now, and it's something we are fighting on the policy front. It's, in my opinion, very misguided. And we are trying and hope, hopefully, that at some point the fever breaks and, and, and this, you know, you cannot brand a backdoor with an American flag and say that only good people can use it. And it doesn't work like that or EU flag or anything like that. And maybe this comes a little bit back. So there's the practical part. What do we do if this happens? What do this happen? At the end of the day, governments hold a lot of power on policy and you have to figure out how you can comply, or if you can't comply, you leave, you do something else. But there are a lot of countries in the world and I think we can, you know, ultimately we, we will do what we have to. The other Part just to, I guess, use, use your platform a bit to, to, to make, to make the case. This chat control, age verification, all this stuff, it's a very bad idea. And, and I don't want to say like there are real threats to children online. It's not that we shouldn't take them seriously, but there are ways to do this in. We talked about systems thinking before and systems design. There are ways to do this that balance the appropriate concerns that, say, can gate mature material behind age, gates that don't reveal who you are. Right. And once you build a system that essentially abolishes anonymity online, how long before that system, I mean, it's Chekhov's gun. How long before somebody comes along to use, if it's built, somebody's going to use it eventually for purposes that it wasn't designed for. How long until China says, hey, identify all the dissidents for me. Right, who are using this because they have to use their, their, their ID for everything on the Internet, right? We want to build systems, Internet systems that can't be commandeered like this, this is how we build Proton. But I think this, this principle applies to the larger Internet. This is a kind of a thought experiment, right? But there were some, I'm probably going to butcher this, but there was some crazy statistic that a huge fraction of East Germans were actually employed as informants by the Stasi on the other East Germans, right? In the height of the Cold War. The Iron Curtain, of course, fell pretty much right before the dawn of the digital age. In some ways, the Internet age. I think you could argue, and I think you can look at counterfactual or counterexamples like China. I think you could argue that had some of this, the Eastern Bloc, authoritarian regimes made it into the digital age, that maybe they would have had enough control over information to not fall anymore, right? Because it's so much easier to do this. So the fact that Facebook and Google, arguably, with their ad ecosystems, have built the most sophisticated, okay, China, perhaps, but the most sophisticated surveillance systems ever built, right? And we do the most American thing ever with it, which is we use them to sell, sell you crap you don't need, right? But that doesn't mean that's the only use for those. And the fact that those are sitting on the mantelpiece like, like Chekhov's gun, waiting for somebody, waiting for somebody to pick them up and do something truly horrific with them is a threat to free society. And all this other, you know, all this, all this other stuff with Check control and age verification is the same thing. It's saying, we have this harm, let's build a system to prevent this harm that then can be used for really nefarious purposes. We need to make sure that we don't engineer systems that threaten the existence of free society. Sorry, that was my soapbox speech. But it's something I care deeply about.
Nilay Patel
We need to take another quick break. We'll be right back.
Bart Butler
Foreign.
Chris McFarland
This is advertiser content from Comcast Business. As cyber threats become more and more machine based and driven by AI agents, those of us in the cyber defense space, we're having to invest at the same pace. Hi, I'm Chris McFarland, Chief Development Officer at Comcast Business. So when we think about the threat of cybersecurity attacks to businesses, they're just a lot more automated. They have the ability to think they could scale literally anywhere from a hundred to thousands of times faster than a human can. The reality is that today you need to protect every device, every endpoint, every workload that's running on a server, whether it's your own server or in the cloud. This is an area that Comcast Business excels at. We're enabling intelligence driven defense with integrated visibility, AI powered threat detection and automated response capabilities that that prioritize, correlate and contain risks before they escalate. And so it doesn't matter whether you're a small business or a medium sized business or a really large enterprise. We've got this incredible portfolio of cybersecurity solutions and services to really enhance your cybersecurity posture. To learn more about how Comcast Business can help protect your business today, visit comcastbusiness.com Cybersecurity Security.
Nilay Patel (Host, The Verge Decoder)
We're back with Proton CTO Bart Butler. You just heard Bart give a pretty impassioned defense of online privacy and why he thinks it's so dangerous to build systems capable of mass surveillance under the assumption that they won't ever be used nefariously. Now I really want to dive into the tension that exists between that philosophy, which I broadly agree with, and one of the hardest problems playing out in politics and tech tech, where we draw the lines when it comes to child safety and the Internet and what technology should or even can do to reduce harm.
Nilay Patel
The reason I I asked you so much about the structure of the company and its culture and how the systems are built are because that idealism is often expressed in Silicon Valley. I've heard it from all of the big companies that you have described. I hear it from big companies Today and then the compromises creep in. And sometimes the compromises are, well, we're domiciled in the United States so we're just going to have to listen. There's nothing we can do. You can look at our warrant canary page to see how many legal requests we're getting and that's going to be that answer. Sometimes the compromises are, look, we have to grow, we have to get bigger and that's it. And sometimes the compromises are there's no way to build the system that would protect people the way we want and comply with illegal regimes. And I think encryption sits at the absolute heart of that tension. I'll give the example of Apple because I think probably everyone is familiar with Apple. Apple routinely resists these calls for backdoor, right? And it's, they're big enough to do it in the ways that they can do it and then the iPhone gets zeroed it anyway, it kind of doesn't matter. And like that cycle repeats in a way that it repeats. But you know, if you talk to the folks at Apple, they're like, look, the regulators come to us and they're like, just be smart, just do some smart stuff, smart guys and find a way to do a backdoor that will preserve privacy. And Apple's response is, you cannot, we cannot nerd hard enough to solve this problem for you. I think there's some willful ignorance on the part of the regulators. I think the regulators know this and then I think there's a massive activists who want to protect children who, maybe they do understand it, maybe they don't understand it, but what they certainly understand at a visceral level is the kids are being harmed. Right? And all of the other systems that everyone claims can ameliorate the problems or mitigate the risk to encryption do not actually exist such that the kids are not being harmed at the rate they're being harmed. Today you sit in the middle of this, right? The governments of the world come to you, they've asked you for backdoors, they've asked you for client side scanning of chat messages to detect csam. What's your response? To just be smart, just nerd harder and figure it out.
Bart Butler
It's impossible to create a backdoor that can only be used by the good guys. And the consequences of the backdoors being used by the bad guys are basically catastrophic. Right? You mentioned, you know, there are still harms being perpetrated, you know, at these rates and that, that, that, that like a massive scale.
Nilay Patel
I do think it's Important to say that clearly the harm is being perpetrated at massive scale.
Bart Butler
The concerns are legitimate. Right. But we tolerate a lot of harms in the, in, in the. We tolerate, you know, ingesting things that aren't good for you if you're an adult. Right. And there have been, this is maybe US centric, but there have been, There have been several. I mean, I don't know if it's still precedent, the way things are going, but there have been several court precedents that have basically said that, said that. And I think this actually has to do with scanning or otherwise that have said that, okay, these must be compatible and balanced against restricting the freedom of adults to essentially be. You know, you can make society very, very, very secure by taking away all freedom whatsoever. Right. You can do that. This is a trade off of what we want to make. But I don't think, But I don't think people fully internalize the fact that too much security is maybe a world that they don't want to live in as well. Right. Because it really, I think it was Ben Franklin, again, not to be too American, but people who would trade in freedom for security deserve neither. I'm paraphrasing. I am American. I live in Europe now, but I am, I am American originally, but there are a lot of people who really beat the drum of freedom in the US but are willing to essentially give away all privacy. And I think, you know, privacy and freedom are inextricably connected. You cannot be free without privacy. Right. So I think there's a trade off to be made here and we can discuss what the trade off is, but the trade off should not be that we make the entire system transparent to whoever wants to look, look, because there are some really bad people who want to look. And even if you think that the government will never be that bad person, which, okay, seems naive, but even if you think that's the case, there's all kinds of cyber criminals and everywhere else and those backdoors or vulnerabilities, I guess vulnerabilities are more easily back doors, but those vulnerabilities that have been found or introduced in cryptographic that have a long history of being exploited by bad actors. Right. I mean, the history of this is clear. It's impossible to have a backdoor that can't be exploited by just. Except for the people who it's intended for. So I think there are other ways to do this. I think we need.
Nilay Patel
Can you describe those other ways? I think maybe this is missing from the conversation. Right. If there's other technical solutions to mitigate the harm. What would they look like?
Bart Butler
A lot of it would be getting in the weeds about how. That's what the show is for sure, about how to do things. But for instance, there's such a thing as zero knowledge proofs, which basically involves the ability to prove that I am over 18 without actually giving you any other information about it. There's actually multiple ways to do that, some of which don't involve zero knowledge proofs. But these are a far cry from, say, you know, discord got in trouble, I forget a month or two ago from having a security breach where, you know, they required, they did age verification and then they had a. I forget what it was. Some sort of open S3 bucket or something with tons of people's IDs and stuff like this is not the right way to do it. But I guarantee you that people will do this wrong. If every website has to collect your id, we are in deep, right? So there are ways to have issuers have say a trusted person issue you an id. It can be a local credential, right? It can be a credential and it can also be a credential that's stored in the cloud, but in an encrypted way so the server can't see what the credential is. And then have your device selectively disclose age over 18. You know, the site that you go to requires that. It doesn't have to be this is your address, this is your name, this is whatever. It can just be, oh yes, this person has a cryptographically signed affidavit that says age of routine, let them in.
Nilay Patel
That's a technical solution to a regulatory demand, right? Do you think that the technical solution has to be written into the regulation or there has to be some regime of this is how to do it the right way way. Or do you think the industry has to come together and say we're going to do zero knowledge proofs?
Bart Butler
I think it certainly helps that the industry comes together. Like there's a EU ID initiative which is actually fairly good. It's not zero knowledge but it's fairly good. There are some problems with this kind of credential. Obviously digital credentials can be copied. So you want to make sure that it doesn't get copied and posted on the Internet and used by a million people. Right? So there's some anti abuse trade offs, right? You don't want one guy's ID from, from some country being used by every teenager in the U.S.
Nilay Patel
i would have been that teenager just to be 100% clear, I would have absolutely been that teenager.
Bart Butler
Yeah. For sure. And I think in general the history of writing the timescales are just so different. The history of writing exact solutions into regulatory frameworks is pretty dismal. Right. But I think that the law could. Laws that do this could write things in ways that mandate privacy protections in a way that I think has not
Nilay Patel
been done or that would lead to the technical solution. This is kind of what I'm asking, right?
Bart Butler
Yeah, yeah.
Nilay Patel
The government says, look, you have to start doing age verification. The kids are looking at all kinds of weird stuff online. We have to start gating some of this content the way that we gate, I don't know, porn stores physically. Okay. Where we get R rated movies. Okay. We got to do it. And the industry is going to sort of inevitably pick the cheapest solution. We're just going to store driver's license in S3 bots basket.
Chris McFarland
Sure.
Bart Butler
Or they're inevitably going to going to pick the solution that allows them to market that information in some way.
Nilay Patel
I guess this is like you sit at the middle of it. Your ideals and your structure prevent you from doing the cheapest, worst version of this. How do you make the industry match your values? Is it the regulator mandates the solution which you seem to think is a bad idea? Is it. They put constraints on the solution which lead everybody to do the right thing. Where does that come from?
Bart Butler
If I knew the answer, I would be pushing it. But partnerships are one of them. I think certainly regulatory guidelines about what you can store, what you can't store, how much you can know about your customers is probably key. This gets into maybe competition stuff a little bit. But a lot of potential harms also comes from full vertical integration of a lot of stuff. So mandating that things be separate entities and thus I'm not going to flush that out. Right. And this talk. But this can do a lot to prevent certain types of harms and temptations to abuse stuff. But I think regulation and having privacy requirements in the regulations is certainly the first step and that compliant implementations there at least have that baked in. I think also this is hard. Pushing it on the operating system manufacturers is also. Which is. It can also be kind of dangerous because it helps entrench those choke points. Right. We already have a lot of choke points where Google and Apple, you know, have these.
Nilay Patel
It's funny, Apple really is pushing against this. But Apple loves to be entrenched as the choke point. Why do you think they're pushing against being the age verifier It's a good question.
Bart Butler
I don't actually know. You'd think that they would jump at it, right? I mean they certainly love having being the choke point of the App Store and, and charging everybody 30%.
Nilay Patel
I know you have been in a fight like Proton has been in a fight with Apple over App Store policies. This seems like one where their interest would be obvious to say actually we will maintain control this 30%. Like stop bothering us about the 30% regulators because we will provide you age verification.
Bart Butler
They might view it as simply a no win game in the sense that you can kyc know your customer as hard as you want, but there's going to be some that slip through and then you're responsible. So maybe they just want a third party to do it. So that's not their problem, right? I don't know.
Nilay Patel
That might be the whole answer. Let me ask you, we talked about age verification. I'm not sure there's like an answer. Right. That will solve every problem. But you've laid out some technical approaches that will at least balance the harms. When I said that harm is happening at massive scale, what I meant was csam, right? What I meant is child sexual abuse material that is happening at massive scale over the Internet. We all know it. There's lots and lots of ways to mitigate it. And then there's just platforms. We can't see into where it's going to happen anyway. Proton is one of them. Imessage is actually another. If you fully encrypt imessage, Apple gets a lot of criticism for that. You know, their, their response is the same as Proton. It's like there's no way to do this. We, we simply cannot give you a way to do this that does not create the backdoors for all the other bad actors you want. We're not going to do it. What are the solutions to mitigating the harms of CSAM without creating the backdoors? Because I feel like that is also missing from this conversation, especially when I talk to the activists who are laser focused on the scale of the harm.
Bart Butler
I can't describe exactly what Proton does because you know, anti abuse is one of the, one of the things where security through obscurity really does actually help. Right. It helps that the bad actors don't know what we do. But I can say that, that you can fight CSAM without content scanning like it is possible.
Chris McFarland
And
Bart Butler
a lot of that is anyway, I probably shouldn't say, but you can, you can fight csam. I'M not saying it's the same as, it's not as effective as scanning everything, but also in the age of AI image generation, who knows what's real or not? Not that AI generated CSAM is good, but the point is like you don't, you don't know if there's a real victim, is there not? Et cetera. So I think are alternative things to scanning every image that you can do to fight csam. And we've done this for years and it's hard to know how effective we've been at it because we don't really know what the denominator is. But we have been, I think, at least in terms of networks that we've identified. Like we've identified some and we've shut them down and we've mitigated this. We have a strong interest in keeping, in keeping bad actors of all kinds off the platform. The mission's not going to be served if it's, oh, this is a platform for criminals. And as a result it's not. We put nearly 10% of total company resources to fight abuse. We are dead serious about driving, you know, making abuse as little as possible on the platform. So it can't be done. It's a cost center and one that we eat. Right. It doesn't make us any money, but it can be done. I think the other thing is, you know, the digital sphere isn't the only place for these crimes are committed. Right. And you know, there's the physical sphere too. There's the actual victims, there's the actual people harmed by this. And I think, you know, everybody wants their job to be easier. Cops are not accepted from this. Right. So they would love to scan everything on the Internet. And I don't actually blame them for this, for this request because it would make their jobs much easier and they, you know, they really do want to reduce harm. However, I think we need to make a trade off between that and the threat that is to free society as well. So I think that there's probably more that can be done in the sort of physical space as well to fight this kind of abuse with resourcing and whatnot. But I will say, yeah, I'll repeat, content scanning is not the only way to do this. And there's also some content scanning that can be done without violating and it can be client side, it can be other things, it can be done in ways is, this is very fraught too. But there, there are things that can be done to do this that don't violate privacy at A massive scale, which is a price that I, I think is simply too high.
Nilay Patel
You're saying there's a system you can't quite describe that is effective at stopping the harms of CSAM at scale. Is that verifiable from some of the people that wish to impose the regulations? Is it auditable? Security theory of security has these problems, right?
Bart Butler
Yeah.
Nilay Patel
We have to, we have to trust you. A lot of this conversation has come back to how much we can trust Proton structurally, personally.
Bart Butler
The problem is I don't know what the denominator is. I don't know if we found 50% of them. I don't know if we found 10% of them. I don't Know if you found 1% of them. Because all I know is the stuff we found. And even then it's a probabilistic, you know, it's. We don't see the images. Right. Sometimes we have a better clue, but I won't say how, but, but I mean, but we don't see the images. In any case, we are not legally capable of doing that and God knows we don't want to subject our employees to that anyway. But no, we don't know what the Denominat is, so I don't know how effective it is. I do know that. We can correlate this to some degree with the kind of legal requests we get and that those are pretty few and far between. Right. I would think that if this were, you know, if this were a massive problem on the platform, that we would get a lot more legal requests for metadata regarding that is our proxy, not for CSAM in particular because we often don't know where the requests come. But in general, one of our proxies is, okay, how many legal requests are we getting for data as opposed to, you know, how much, how good we are at Anti abuse. Right. If legal requests go through the roof, which they haven't, then obviously we have a big problem with Anti Abuse. And that has not been the case. So I know that's kind of a wishy washy answer, but the data is private. Private. We can't read it. That's, that's our entire, that's our entire thing. We also have a reporting system. Of course, you know, people make mistakes like any other. So if, you know, if you, if they share an image, which is, this can be reported, that, that can go. So there are lots of mechanisms. Again, I'm sort, sort of tiptoeing around saying any details because I don't want, I don't want this stuff to not become effective, but we do a good job, I think, relative to external indicators that we can see. And yeah, I'll give you an example where this is. It's not csam, but it's a similar thing. Okay. We used to get a lot of requests, relatively speaking, a lot of requests for ransomware accounts. Okay. Because people go to Proton, they said a Proton email that you would, I don't know, with a Bitcoin something, right. Whatever we got. And we would get this in the legal request, right. We'd get this and we'd be able to look at that and say, oh, that's definitely a ransomware account for various reasons. Right. We got really, really good at killing ransomware accounts. And now when we still occasionally will get them, but they'll have been disabled by us for abuse six months before we get the legal request. Right. So this, I'm using the ransomware as an analogy, but we do have kind of a feedback loop.
Nilay Patel
So there's something in your system, there's some set of indicators that you can detect and you're just not going to tell me what they are, but there's some set of indicators of how an account operates in your system that lets you know what it's being used for.
Bart Butler
Yes.
Nilay Patel
Has any government ever asked you what that set of indicators is?
Bart Butler
No.
Nilay Patel
Interesting. I'm just, I. Hopefully that doesn't happen today. Cops, if you're listening, forget. Forget that you heard any of this. We're running out of time here. I want, I do want to quickly at the end, ask about AI, because we've talked about systems and dynamics that I think are pretty familiar. Like, I came up on Usenet and Slash Dot and I probably heard that quote about liberty and security 10,000 times. Like that is the foundation of my life on the Internet. Right. Is like this debate from, I don't know, the 80s and 90s up until now is the same debate. And maybe AI is going to like flip over the whole Apple cart, right? We can now do cyber security at scale in ways that governments are stepping in and stopping the models from shipping. Whether or not that is correct or not, that is the thing that is actually happening in the world. We can generate vast amounts of synthetic data that might trip all your detection systems. Whether or not any harms are actually downstream of that data. You've shipped an AI assistant because a bunch of countries do not want to rely on American model companies. And having data sovereignty in Europe is important to them. That seems like a market opportunity for you. What is Your approach to all of this, are you reliant on the frontier companies? Are you building your own model? How do you protect your data from them? All of this at the very end feels like it upsets in significant ways the structures and the systems we've been describing up until now.
Bart Butler
I don't think it's had as much of a dramatic effect on the topics that we've discussed. We have Lumo, our own internal, which is run on. We control the systems that it's running on. And this is our, we want to be independent of third party models and things like that.
Nilay Patel
Is that actually a model you've trained or is that reliable?
Bart Butler
No, no, it's open source models that we've compiled and it's a collection of open source models that we sort of stitch together based on their strengths and weaknesses. But yeah, we, I mean, I mean we, we don't have a billion dollars to sell to train our own models. So. And, and this is actually why we might be one of the few, the few AI companies that actually makes money doing it, because we don't do any training. Right. We just sell the, we, we sell the inference. I mean, not that there's not a lot of work involved in doing, in, in doing, in building Lumo and, and, but, but yeah, we don't train our own models. I, I guess two different sides. There's how is AI going to affect the industry in general and maybe how it's affected us and how we use it. So for a lot of our stuff in particular, the client side stuff is open source, right? And the client side stuff is not user secrets either. So we've tried models from Anthropic and ChatGPT. We've also tried Lumo and OpenAI because a lot of it's public anyway and it's not user secrets, right? So we're going to use the best tool to make us go as quickly as possible. And it has changed software engineering probably permanently. Right. A lot of the, in terms of the amount of time spent on actually writing code versus the other things. But maybe not so fundamentally. I mean, people talk about this saaspocalypse thing that every company is going to be writing their own enterprise software and I just don't buy it. There's a very big difference between, between being able to cook up your own custom purchase order software or ERP or whatever that works for your small business maybe sort of. And the kind of things, whether it's compliance, whether it's scaling, whether it's reliability, all these things which Enterprises need. I just cannot see every company building, you know, oh, software is dead. We're not going to have vendors to do this that can promise us things that we need. Right? The other thing about this is to me, if anything, it shifted what is valued in software engineering towards more senior level skills perhaps, right? But it's not fundamentally changed what good software is or how to architect good software, whatever. If anything, things like reviewing other people's code. Well, today you're reviewing other people's code and you're reviewing the robot's code, but it's kind of the same skill, right? I mean, so what maybe the balance before was a little more towards okay, can you write code very quickly, accurately with you know, this kind of thing? Where now it's like, okay, it's more towards can you review code very quickly. But that's, which is maybe a more senior level skill. But it's still part of the software engineer toolkit. Designing good software what good software means what good software looks like. Like one thing that we found I think is that LLMs work a lot better when your code is well architected. Like if your code is well designed, the LLM will actually work better. If your code is a spaghetti mess, the LLM will not work as well because they are, you know, they're logic engines, right? There's more chances for them to get confused. So a lot of the fundamentals of building software, yes, the industry has changed, but a lot of the fundamentals of building software are different. The other thing we found is that, you know, the time you spend writing code has gone down. Now there are other bottlenecks in your pipeline that you, that you have to do now. Maybe your CI takes too long now maybe your other things take too long, right? So it changes maybe what kinds of things you need to optimize. But at the end of the day for I think for most senior software engineers, the amount of, of time that they actually spent writing code was, was frankly not the mo. Not the, either the hardest part of their job or what they spent most of their time on. Right? Software is probably the most, the most affected industry and the most tractable industry for LLMs that I've seen, at least so far. Obviously there are other uses for it, but you know, it's software, it's rule based. You can test for correctness, you can mitigate. A lot of the things that LLMs make might kind of go off the rails and hallucination. At the end of the day you need working code, right? So you can test this kind of stuff so you can mitigate a lot of the, a lot of the problems with LLMs software is your best case scenario. And even then from what I've seen, it's an evolution. It's not a revolution. It's definitely a big change but it's largely, it's a productivity change, not a, not a dump everything start over. Maybe I'm wrong about that. Maybe as models improve it'll get more and more dramatic. But, but at the moment it's, it's a hell of an opportunity for productivity. But I, I, I think the fears and software is what I know better best. But I think that, I think the fears are, are a little overblown.
Nilay Patel
Let me ask you on the other side of that, right the you mentioned earlier now it is possible to look at all the emails and do mass surveillance, you know, anthropic rolled up to the United States government. It's like you can do this with our model. We don't want you to to because we don't actually think it's good enough. And we think there's like real problems with doing that. You're faced with that as well, right? You have your own internal AI model. Your user are probably generating more data inside of your systems than ever before. With AI it just seems like a thing that happens when you add AI to a system. The models get better when you feed them more data. They have a voracious appetite for data. That's a lot of pressure on we're going to keep everything private, right? It's a lot of pressure on who gets to see your stuff and why do they get to see it and what can they do once they have it. And the value of having it seems to be going up, right? The value of collecting all the data seems to be going up. How do you respond to that? Even as you have to roll out AI systems in order to compete with the big tech that is putting it
Bart Butler
literally everywhere I mentioned before is, you know, privacy is control. Privacy is sort of self determination in the sense that you control your data and you control who it's shared with and maybe that who is an AI system, right? And that's okay. And I think as long as this is sort of an opt in thing from the user there, you know, this is actually an internal debate but we already have features like for instance, okay, we have a mailing list feature. Okay. I promise this has something to do with it.
Nilay Patel
It's a big build. Here we go.
Bart Butler
We have a mailing list feature and that feature is done in A way that it is private. I send you an email or I send the mailing list an it sends the email to everybody else. The system doesn't see it. Okay, but if you want people outside Proton in your mailing list, then we can't do end to end encryption anymore. We have to turn it off. Right. So when you add external people to your mailing list, you are prompted, hey, do you want to turn, you know, external recipients, you need to turn off end and encryption. The user says yes. Okay. Because that's part of their workflow. They need it. And at that point, we still don't save a copy. Right. Everything saved on Proton is encrypted at rest. However, we do have the clear text email going through our system because we need to send it out to whoever the external recipients are. That's the kind of model I see in the future with some of these. And it's not just AI systems, it's also integrations, especially as we get more into business clients and stuff. I need this integration into my CRM. Right. I'm going to choose to share this mailbox with my CRM. That's okay. That can be a decision. It's our job to build a user interface which communicates what the consequences of that are. But privacy is fundamentally. It's not about not sharing stuff. It's not about not sharing your photos, not about not sharing your data with third parties. It's about sharing the data with third parties who you choose, and not just by default with everybody. Which is sort of of the paradigm that's been the big tech Paradigm for Web 2.0 or whatever you want to call it the last two decades. So I think we can reconcile this with the Proton thing, because it was never just about the encryption. The encryption is a tool to the end. It's all about, hey, the fact that I store data on somebody else's computer on the Internet does not mean that I give them control to do whatever they want with with it, or that I trust them not to lose it. So we're going to try and build a system where I retain that control and I can still participate in modern services, modern online services. Right.
Nilay Patel
I feel like we're going to have to have you back soon to see how that's all put to the test. This is new.
Bart Butler
Yeah. Yeah.
Nilay Patel
And I feel like in the next couple of years we'll find out more. So we'll have you back soon. You've given us so much extra time. Bart, thank you so much for being on decoder.
Bart Butler
Thank you. Thank you so much. It was a blast.
Nilay Patel
I'd like to thank Bart Butler for taking the time to speak with me
Nilay Patel (Host, The Verge Decoder)
and thank you for listening. I hope you enjoyed it.
Nilay Patel
Let us know what you thought about this episode or really anything else at all.
Nilay Patel (Host, The Verge Decoder)
Drop us a line. You can email us atdecoder the verge.com
Nilay Patel
we really do read all the emails. Or you can hit me up directly
Nilay Patel (Host, The Verge Decoder)
on Threads or Blue sky. We're also on YouTube. You can watch full episodes at Decoder Pod. We also have a Tik Tok and Instagram. They're also at Decoder Pod and they're a lot of fun.
Nilay Patel
If you like Decoder, please share it
Nilay Patel (Host, The Verge Decoder)
with your friends and subscribe wherever you get your podcast. Decoder is fresh from the Verge, part of the Boxing Event Podcast Network. The show is produced by Kate Cox and Nick Stat. It's edited by Ursa Wright.
Nilay Patel
Our Editorial director is Kevin McShane.
Nilay Patel (Host, The Verge Decoder)
The Decoder Music is by Breakmaster Cylinder. We'll see you next time.
Comcast Business Announcer
Support for this show comes from Comcast Business. Modern Enterprise is a lot of moving parts. Comcast Business helps you orchestrate it all with SD WAN, working at scale to keep 150 hospital locations connected and working as one plus SASE and zero trust security, protecting financial data across a bank's 2,000 branches, and AI powered networking that optimizes traffic across five continents. No one does business like Comcast Business.
Guest: Bart Butler (CTO, Proton)
Host: Nilay Patel
Date: July 16, 2026
In this deep-dive episode, Nilay Patel sits down with Bart Butler, CTO of Proton, for a sweeping conversation about trust, privacy, company structure, and the ever-mounting threats against online privacy from governments, regulators, and technology shifts like AI. Proton, known for privacy-first products like Proton Mail and its growing suite of collaborative tools, stands as a rare challenger to Big Tech—aiming to scale while fiercely upholding its privacy mission.
Butler and Patel dissect how Proton constructs not just technology, but also organizational and legal safeguards to guarantee user privacy—even as world governments escalate their demands for access, and as thorny issues like child protection test the boundaries of privacy promises. The conversation balances idealism with gritty realities, moving from architecture and incentives to specific policy flashpoints and the technical weeds of data control.
Proton started with Proton Mail but now offers a broader suite:
What Proton Sells Is Trust:
Balancing Usability and Security:
Mail and VPN are still Proton’s largest products, but new products are gaining traction.
Proton feels pressure to move toward enterprise markets (B2B), but values its consumer base as a unique strength and market differentiator (14:23).
"Our business is B2C. We're not going to jettison the B2C business." — Bart Butler (14:23)
AI Integration and Data Control:
Proton AG (Swiss corporation), majority-owned by Proton Foundation (18:29).
Despite the foundation’s protection, Proton "has to compete in capitalism" and must grow in order to be a true alternative to Big Tech (21:07).
Legal Limits and Swiss Jurisdiction:
Proton must comply with legal requests from Switzerland, which in turn can act as a proxy for US/FBI requests under international agreements.
On US 'terrorism' requests as an "attack vector":
Threats to Privacy from Changing Laws:
Proton has threatened to leave jurisdictions (Switzerland, Germany, Norway) if forced to compromise encryption or comply with sweeping surveillance ("chat control") (46:02).
"It's dead serious [that we would leave]" — Bart Butler (46:02)
Flexibility of digital services is a strength: “If we get truly dystopian, there may be a world where there’s no place to move to. But at the moment there are options...” — Bart Butler (46:54)
Digital sovereignty is central: can relocate legal structure if necessary, though with some costs and legal complexity (47:13).
Opposing Chat Control and Age Verification Laws:
On Regulatory Pressure to Break Encryption:
Technical Solutions for Child Safety & Age Verification:
Industry & Regulatory Approaches:
Fighting Child Sexual Abuse Material (CSAM) Without Content Scanning:
Lumo and Private AI:
AI’s Impact on Engineering and Privacy:
The Ever-Rising Temptation to Loosen Privacy for Utility:
This episode offers a comprehensive, candid insight into how Proton tries to engineer trust at every level: product, legal structure, business model, and culture. Butler articulates both the power and limitations of privacy-first design in a world of rising government pressure, regulatory complexity, and technological disruption from AI. The conversation is a must-listen (or, with this summary, a must-read) for anyone interested in the future of privacy, trust in tech, and the realpolitik of competing with Big Tech.