I have long since left Proton as I don't believe their actions match their supposed mission.
For context, Proton Mail was first launched in 2014, and back then, hCaptcha didn't even exist and there were no other non-broken captcha solutions that worked at scale besides reCaptcha. It wasn't until 2020 that hCaptcha became better known, and until then it was really quite untested at scale. In any case, Proton switched over to hCaptcha soon after but even then, it was not without issues, and did not work for many prospective Proton users.
Whether it's reCaptcha or hCaptcha, Proton's implementation always sandboxed it within an iframe which mitigated the privacy concerns and it honestly could have been left like this. But instead, Proton went out of the way, investing substantial resources to build, launch, and operate it's own captcha service. That's actually pretty extreme commitment to the mission, and putting money and resources to prove it.
You also need to be on the paying tier for a usable product. I evaluated a number of options when I was trying to decide where to park my domain long term. Cue an incident at a border crossing where immigration wanted to see a hotel booking that search insisted didn't exist. Turns out the booking email was a few days outside the free tier search window, and that limitation wasn't obvious in the pressure of an immigration queue. Felt like I had been gaslit once I realized.
I only upgraded to a paid tier about a year ago, before that I was using for about one and a half years for free with 0 issues.
Notifications never arrive late (at least on the IOS app)
Maybe it's because I'm not a heavy E-mail "Power user", but I see most of these as non-issues (this depends on your use case, of course)
Another huge pro for me, as a resident of Germany, the data stays in Germany and is protected under our strong data security laws.
I do have to agree, the search was kind of sucky for a while. But imo it's improved a lot is also pretty useable now.
This makes backing up emails trivial.
Tutanota still doesn't have an easy way to export all emails.
An actual defense-in-depth strategy would be one that uses a tool like this for generic browser/device level signal interrogation AND domain/product-specific behavioral analysis. That would be 2 different layers — depth.
However it's not perfect.
One of the differentiators of ProtonCAPTCHA is that we've built this system with the expectation that someone will break it. So, as you've alluded to, in the event that someone or some thing is able to navigate these challenges either through automated mechanisms, or via third party solvers, we have defenses against such attacks/automations. That is a third hidden level of defense -> however, you will understand that for obvious reasons we do not divulge how this is done.
Taking time on these initiatives shows they are trying to improve things step by step, and that's a good thing for everyone.
Right? Am I stupid or something?