Choose which alias can log in to Proton
Hello Outlook.com now is accepting to choose what alias can be used to login on account to improve security.
Why Proton mail dont do the same thing? with this we are protected from botnets(credential stuffing or brute force), because we can create a alias and dont share the username with anyone.
Thanks
-
Mick
commented
Well, I’ve finally decided I’m not renewing my subs and I’m off to Fastmail. No point paying for security like that when there’s a hole in the castle which nobody has noticed for 10 years.
-
Mick
commented
I hate to say it guys, but they even say precisely this on their own website. I was just looking through some of the blog and manuals in case there were any features I missed.
-
Paul
commented
Indeed, as per the countless other paid unlimited customers, this deficiency seems serious. Please address in a fashion that enables us to create an undistributed alias to use as the "real" account login or use any other email address as soon as possible.
-
Rasmus commented
I was under the assumption that alias mails could not be used to log in to the main account.
I proved myself wrong today out of curiosity, and I am shocked to learn that this entire time Proton has been just as unsafe as any regular email, if not more. -
Mick
commented
I've actually just had a nice email back from support explaining that I think it's a critical security flaw and that I am speaking on behalf of hundreds of loyal users, many of whom signed up with the full package because of the aliases, without being away that you can log in everywhere, and she said basically it is something they are aware of and would like to implement but she's not privy to the engineers' timelines, which is fair enough.
I replied it would still be nice if somebody basically said something to that effect in one of these 5 or so threads which have literally been here for years, because there's a strong chance they'll lose a lot of customers, otherwise.
I reckon it would probably be worth more of you doing that, as then they might eventually get the message. I get the impression that a lot of people are signing up for the "Unlimited" package in part of this, unaware that the aliases are functionally useless if you want to maintain security hygiene, and having just checked again, I can confirm that there is no warning about this anywhere. Which I think is a bit sad.
-
Mick
commented
Word on the street is that if you use any of Proton VPN, Authenticator, Pass, or Wallet, they can also be accessed by the same means, which IMO is even worse. How the **** have people been flagging this since 2017 and nothing has been done about it?
-
Mick
commented
That's five threads I've counted on the exact same issue now, with no apparent acknowledgement.
-
Mick
commented
This really should be at the top of the list of things to fix and it should be trivial to code. And it will only enhance your supposedly legendary security, rather than decreasing it.
-
James
commented
public emails are an obvious attack vector, this should be locked down!
-
Mick
commented
What K said. I regularly have drive-by attacks on my old website using usernames which haven't been in use for years, yet are still in a database somewhere. Knowing that they're bots, I like to send them to funny places, but the point stands. Hugely increased attack surface for no reason.
-
Mick
commented
How on earth has this not been fixed yet? My subscription is up in September.
Having been on the receiving end of three life-altering cyberattacks since 2002, I am extremely disappointed that a company which prides itself on security and privacy above all else, fails to mention when offering to set up aliases that they can ALL then be used to log in, using the same password (and this is also true if you connect your own domain to it), vastly increasing the available attack surface. I simply can't believe this hasn't been fixed yet.
As I say, I'm looking into options for other providers, in case this still hasn't been resolved by September, which I expect it won't be. I am reluctant to pay for another two years with such a glaring vulnerability like that in situ.
Which is a pity, because I really like the system and their ethos in general.
-
Jay See
commented
I have been using Proton Mail for about 6 months now. I do not share the email address for the account with anyone. I don't send or receive email to that address. I don't want anyone to know that email address because someone can try to access my account with it.
Now I have learned that the 5 aliases that I created to compartmentalize and protect myself form login attempts has been null and void. Any alias can login to the same account. I am mystified as to why an alias could be used to login to the account. Using the Plus feature does nothing except to perhaps track the original leak for later spam. The main account address is still exposed.
So, I now have 6 sets of keys to a door which I thought there was only one and it was hidden in my pocket. I can create true aliases at iCloud, Outlook, Gmail and Mailbox which cannot be used to login to the account.
Why are Proton aliases just extra sets of keys? What is the point? Why don't we have true alias email addresses? I was liking Proton a lot until I discovered that all I've done is place flashing red signs across the internet for gaining access to my account.
-
MS
commented
I'd received an email to say that this vital request (and other similar requests) was Under Review but I can't tell whether this is the case or not. Could Proton report on this issue in one of its upcoming road maps? It's honestly such a critical matter and one of the few areas where I think Proton has really fallen short.
-
Liesbeth
commented
I only realised that any alias can be used to login to any part of the Proton suite when I started using it more. I've kept my initial proton address completely safe, but to what end, I'm not sure now.
Even with 2 step authentication this seems odd. -
Professor Tor Coolguy
commented
It's kind of silly this still hasn't been addressed by a potential Google/Outlook alternative. Serious users don't want to have to use a silly SimpleLogin alias for their business emails. I want to be jsmith @ proton.me or johnsmith @ proton.me in my correspondence with clients, not jsmith.420bananastand @ aleeas.com
-
DZFr
commented
For those who support this, you can also support a similar request here : https://protonmail.uservoice.com/forums/935538-accounts-payments/suggestions/31027744-only-allow-login-with-single-main-address-username
-
meowmeow
commented
This missing feature should be at the top of their to-do list. I've structured my aliases to be used long term for specific accounts and its very worrying that I'm actually exposing myself to significantly more potential threats to the same account because my all of aliases can be used to sign in. For example, the aliases used for my social media logins vs. the logins for my bank have very different potential threat audiences and back when i was using Gmail there was the relief that if one account was in a breach, I wouldn't have to worry about my other accounts being compromised.
I know simple login and proton pass aliases exist but they aren't as reliable and I can't send emails on behalf of those accounts. I just want my aliases for my main proton account to be toggleable as far as sign in capabilities. Otherwise it feels just as vulnerable as giving out my account's main address for every website I use. We need this ASAP.
-
Arsene Olazy commented
+1
-
Xavier B
commented
I can't believe this feature is still not available...this is like the most simple and basic way to protect an account, even Microsoft have it, for free on top of that.
I finally bought a plan recently because I need some other features, but this one was the main reason why I delayed for so long to take one.
And like some people said 2FA and proton pass aliases are not the solution, just complementary ways to secure our account. For instance, my account on Outlook was spammed DAILY with connection attempt from all over the world until I created a brand new email on my account defined as the only login and that I never share anywhere... No more connection attempt on my account, which bring me more peace and no more notification failure attempt at all.
Because of that I must select carefully when I use my proton email (which is a nonsense for a provider that is supposed to be my main). And guess what ? Even like that one of my proton email has been detected in a breach and I have no way to cover it.
-
Strut
commented
I didn't even dare to think this would be an issue in Proton when I did the switch from Outlook. Now I'm missing my Outlook, because of a security / privacy feature. Extremely ironic.