Choose which alias can log in to Proton
Hello Outlook.com now is accepting to choose what alias can be used to login on account to improve security.
Why Proton mail dont do the same thing? with this we are protected from botnets(credential stuffing or brute force), because we can create a alias and dont share the username with anyone.
Thanks
-
Paul
commented
Indeed, as per the countless other paid unlimited customers, this deficiency seems serious. Please address in a fashion that enables us to create an undistributed alias to use as the "real" account login or use any other email address as soon as possible.
-
Rasmus commented
I was under the assumption that alias mails could not be used to log in to the main account.
I proved myself wrong today out of curiosity, and I am shocked to learn that this entire time Proton has been just as unsafe as any regular email, if not more. -
Mick
commented
I've actually just had a nice email back from support explaining that I think it's a critical security flaw and that I am speaking on behalf of hundreds of loyal users, many of whom signed up with the full package because of the aliases, without being away that you can log in everywhere, and she said basically it is something they are aware of and would like to implement but she's not privy to the engineers' timelines, which is fair enough.
I replied it would still be nice if somebody basically said something to that effect in one of these 5 or so threads which have literally been here for years, because there's a strong chance they'll lose a lot of customers, otherwise.
I reckon it would probably be worth more of you doing that, as then they might eventually get the message. I get the impression that a lot of people are signing up for the "Unlimited" package in part of this, unaware that the aliases are functionally useless if you want to maintain security hygiene, and having just checked again, I can confirm that there is no warning about this anywhere. Which I think is a bit sad.
-
Mick
commented
Word on the street is that if you use any of Proton VPN, Authenticator, Pass, or Wallet, they can also be accessed by the same means, which IMO is even worse. How the **** have people been flagging this since 2017 and nothing has been done about it?
-
Mick
commented
That's five threads I've counted on the exact same issue now, with no apparent acknowledgement.
-
Mick
commented
This really should be at the top of the list of things to fix and it should be trivial to code. And it will only enhance your supposedly legendary security, rather than decreasing it.
-
James
commented
public emails are an obvious attack vector, this should be locked down!
-
Mick
commented
What K said. I regularly have drive-by attacks on my old website using usernames which haven't been in use for years, yet are still in a database somewhere. Knowing that they're bots, I like to send them to funny places, but the point stands. Hugely increased attack surface for no reason.
-
Mick
commented
How on earth has this not been fixed yet? My subscription is up in September.
Having been on the receiving end of three life-altering cyberattacks since 2002, I am extremely disappointed that a company which prides itself on security and privacy above all else, fails to mention when offering to set up aliases that they can ALL then be used to log in, using the same password (and this is also true if you connect your own domain to it), vastly increasing the available attack surface. I simply can't believe this hasn't been fixed yet.
As I say, I'm looking into options for other providers, in case this still hasn't been resolved by September, which I expect it won't be. I am reluctant to pay for another two years with such a glaring vulnerability like that in situ.
Which is a pity, because I really like the system and their ethos in general.
-
Jay See
commented
I have been using Proton Mail for about 6 months now. I do not share the email address for the account with anyone. I don't send or receive email to that address. I don't want anyone to know that email address because someone can try to access my account with it.
Now I have learned that the 5 aliases that I created to compartmentalize and protect myself form login attempts has been null and void. Any alias can login to the same account. I am mystified as to why an alias could be used to login to the account. Using the Plus feature does nothing except to perhaps track the original leak for later spam. The main account address is still exposed.
So, I now have 6 sets of keys to a door which I thought there was only one and it was hidden in my pocket. I can create true aliases at iCloud, Outlook, Gmail and Mailbox which cannot be used to login to the account.
Why are Proton aliases just extra sets of keys? What is the point? Why don't we have true alias email addresses? I was liking Proton a lot until I discovered that all I've done is place flashing red signs across the internet for gaining access to my account.
-
MS
commented
I'd received an email to say that this vital request (and other similar requests) was Under Review but I can't tell whether this is the case or not. Could Proton report on this issue in one of its upcoming road maps? It's honestly such a critical matter and one of the few areas where I think Proton has really fallen short.
-
Liesbeth
commented
I only realised that any alias can be used to login to any part of the Proton suite when I started using it more. I've kept my initial proton address completely safe, but to what end, I'm not sure now.
Even with 2 step authentication this seems odd. -
Professor Tor Coolguy
commented
It's kind of silly this still hasn't been addressed by a potential Google/Outlook alternative. Serious users don't want to have to use a silly SimpleLogin alias for their business emails. I want to be jsmith @ proton.me or johnsmith @ proton.me in my correspondence with clients, not jsmith.420bananastand @ aleeas.com
-
DZFr
commented
For those who support this, you can also support a similar request here : https://protonmail.uservoice.com/forums/935538-accounts-payments/suggestions/31027744-only-allow-login-with-single-main-address-username
-
meowmeow
commented
This missing feature should be at the top of their to-do list. I've structured my aliases to be used long term for specific accounts and its very worrying that I'm actually exposing myself to significantly more potential threats to the same account because my all of aliases can be used to sign in. For example, the aliases used for my social media logins vs. the logins for my bank have very different potential threat audiences and back when i was using Gmail there was the relief that if one account was in a breach, I wouldn't have to worry about my other accounts being compromised.
I know simple login and proton pass aliases exist but they aren't as reliable and I can't send emails on behalf of those accounts. I just want my aliases for my main proton account to be toggleable as far as sign in capabilities. Otherwise it feels just as vulnerable as giving out my account's main address for every website I use. We need this ASAP.
-
Arsene Olazy commented
+1
-
Xavier B
commented
I can't believe this feature is still not available...this is like the most simple and basic way to protect an account, even Microsoft have it, for free on top of that.
I finally bought a plan recently because I need some other features, but this one was the main reason why I delayed for so long to take one.
And like some people said 2FA and proton pass aliases are not the solution, just complementary ways to secure our account. For instance, my account on Outlook was spammed DAILY with connection attempt from all over the world until I created a brand new email on my account defined as the only login and that I never share anywhere... No more connection attempt on my account, which bring me more peace and no more notification failure attempt at all.
Because of that I must select carefully when I use my proton email (which is a nonsense for a provider that is supposed to be my main). And guess what ? Even like that one of my proton email has been detected in a breach and I have no way to cover it.
-
Strut
commented
I didn't even dare to think this would be an issue in Proton when I did the switch from Outlook. Now I'm missing my Outlook, because of a security / privacy feature. Extremely ironic.
-
Mick
commented
I have a website which I shut down two years ago due to a massive cyberattack which went on for three days. Every now and again, while I figure out what to do with it (it was a creative thing), I log on, and there are STILL people regularly trying drive-by attacks on all the previous usernames which the version of WordPress I was using back then allowed them to enumerate easily. I automatically divert them to people like the NSA and GCHQ on the off-chance that it catches out some eejits, but the fact remains that even 3-4 years after I effectively closed that account, people are still attempting on a very regular basis to log into my site based on accounts which have been released into the wild. It's fully protected, but my point is that they still try, and there is absolutely no reason to increase your attack surface tenfold for no benefit.
-
Mick
commented
I've just been for a walk and had a think about this, and I actually had to take a day off work today due to the stress of a possible system intrusion over the weekend.
The way I see it, there needs to be, at an absolute minimum a CLEAR WARNING before creating them that these will be effectively used as additional log-ins, using the same password. That way, if that's what the user wants, then fair enough. I think it's clear from the fact that there are 4 separate threads about this precise matter with over a thousand upvotes on them then it's clearly a significant community issue, and if it hasn't been fixed by the time my subscription ends, then I'll have to find somewhere else, especially with the inability to delete said emails. I think that's such a glaring omission for a company which markets itself on world-leading security and privacy, that I simply can't beleive it's been left standing for a decade. I can't subject myself to the likes of LastPass or anything similar yet again. It will break me. That's what I have to say about that. Which is a pity because you saved me from the **** of what gmail put me through.