Only allow login with single/main address/username
Do not allow that you can log into the account with every address.
If my account name is john.smith then only allow login with john.smith or john.smith@protonmail.com. Not with finance.john.smith@protonmail.com or any other address.
Perfect would be if you would have the choice what address can be used in order to log into your account.
With the current way you have to give away your login username in order to send emails. Hiding the username from the public would be an advantage, since they would have to guess your username and the password. Not only one of them.
-
Mick
commented
Personally, as someone who has been the victim of multiple serious third party breaches, I am extremely concerned about not having attack vectors exposed unnecessarily, and I came to this company in the first place precisely to get away from stuff like that.
I think one of the worst parts is that it literally doesn't say anywhere on the website that aliases can be used to login (as can anything you pipe through from your own domain) and most people seem to find it out by accident or from threads like this. That's critical security information people should be informed about, especially as it's advertised as one of the key selling points for the Unlimited package.
-
Mick
commented
For the record, I actually emailed customer services on our collective behalf this morning stating that there are hundreds of angry customers who are upset with a major security flaw which is not normally a problem on other paid-for email services, and critically has been ignored for over seven years for reasons we don't understand (and that you're going to lose a lot of customers over it),
and she did get back to me saying words to the effect, "yes, quite a few people have asked about this and I think they did say they wanted to implement it eventually, but I'm not privy to the timeline, but I will pass your comments on".
I forwarded the conversation to another guy on an unrelated team on the remote off-chance that he knew anybody closer to the action.
I can't imagine it being resolved before September when my subscription ends though, so I'll probably be off with you guys.
By the way, this is one of 5 threads I'm aware of on the exact same subject, one of which goes back to 2017 and as far as I can tell nobody has said anything about it, unless you count that just now. I did a fair bit of writing about it all last night.
-
Mick
commented
I reiterated that it would be really nice if somebody official could just respond to these threads with a yes or no, and if no why not, because this has been going on for years, and it's transparently clear that a lot of people signed up for the Unlimited package specifically for the extra aliases, and yet still there is no indication anywhere on the site (same with private domains) that they constitute a security risk. I can understand them losing a lot of customers over that, and to reiterate it would be nice if somebody just said something, because this is far from an idle concern, especially if you've experienced multiple security breaches in the past.
-
Mick
commented
I actually just had a message back from support, having decided to just email them, making it clear that there are at least 5 threads here going back years before I joined and I am representing hundreds of loyal customers who are concerned about the glaring security hole:
---
Hello,
Thank you for sharing your concerns and feedback regarding Proton Mail's login system and alias functionality. We understand that security is a top priority for you and many of our users.
The feature that you have requested, i.e. to restrict login access to only selected addresses, has already been requested by a number of our users.
Our developers are currently working on an implementation for this, however, I cannot comment on when this feature would be released, as I am not privy to their timelines.
I will forward your feedback to them as well. Thank you for helping us make Proton more user-friendly! Please rest assured that our team is continuously working to improve our systems to ensure the highest level of security for all users.
To further protect your account, we strongly recommend enabling two-factor authentication (2FA), which adds an extra layer of security and helps prevent unauthorized access:
https://proton.me/support/two-factor-authentication-2fa
Additionally, setting up verified recovery methods can help secure your account:
https://proton.me/support/email-sms-recovery
If you have any other questions or need assistance with your account security, please let us know.Kind regards,
Nikolina
Customer Support -
Mick
commented
Word on the street is that if you use any of Proton VPN, Authenticator, Pass, or Wallet, they can also be accessed by the same means, which IMO is even worse. How the **** have people been flagging this since 2017 and nothing has been done about it?
-
Mick
commented
Congratulations on being the fifth person to have started a thread pointing out the exact same security flaw which amazingly they still haven't fixed, since in fact it does precisely the opposite insofar as creating additional extra attack surfaces for no good reason.
They don't appear to have acknowledged any of them when really this should be at or near the top of their to-do list. Bad practice and bad customer service if you ask me. I'm minded to leave when my subscription is up. I've had to disable all of mine. By the way, you can also do the same with any private domain you pipe through it, so yes that's yet further decreased security.
-
Mick
commented
Has this STILL not been sorted? I really don't want to move everything to another provider when my subscription runs out next summer, but I might do because I've had a number of breaches and this has just left me with a couple of extra security holes which I can't patch. It's a matter of principle. Great service, otherwise.
-
Малин Цветкашки
commented
Hello Proton Team,
I am a Proton Unlimited user and would like to suggest an optional security feature that would separate a user's public email identities from the identifier accepted for signing in to the Proton Account.
Under the current system, any email address associated with a Proton Account can be used to sign in. This is convenient, but it also means that every Proton Mail address used publicly for correspondence, online registrations or important accounts is also a valid login identifier.
I suggest allowing users to choose between three sign-in modes:
* Sign in with any Proton Mail address associated with the account - the current system
* Sign in only with the primary Proton Mail address
* Sign in only with a separate **private Login ID** that is not an email address and is never publicly exposed through correspondenceThe current system could remain the default, so nothing would become more difficult for users who value convenience. Users who prefer additional protection could select one of the more restrictive modes and change their choice later through the account security settings.
A separate **private Login ID** would not replace a strong unique password, two-factor authentication or passkeys. It would provide an additional defence-in-depth layer by ensuring that knowing a user's public email address does not automatically reveal a valid identifier for attempting to access the account.
This could be particularly useful for people who use Proton addresses for important financial, administrative, professional or personal accounts, as well as for users whose email addresses are publicly available or may appear in third-party data breaches.
I am deliberately not proposing a specific verification or recovery procedure, since Proton is better placed to design and implement that part securely.
I believe this optional feature would fit Proton's focus on privacy, security and user control, while fully preserving the simplicity of the existing sign-in system for users who prefer it.
-
Northman
commented
Exactly! Probably the most important suggestion on here.
I really dont like to be able to log in to my account with several of my email adresses.One address that i keep completly secure, just for login would be much safer.
-
James
commented
I thought this was a given when I started my Proton Duo membership - but yes, for a security focused product, this should be the expected behaviour. A private login that is used for login purposes only that is separated from any and all public emails associated with the account.
Public emails are an obvious attack vector.
-
Tom
commented
I don't understand why Proton is so mute about this. Even FREE Microsoft accounts have this functionnality. It's critical and much needed
-
Sophie
commented
This is critical for me - I won't be upgrading until this is fixed/added. I want to use the feature of separate email addresses for different services (e.g. banking, friends/family, work, other important user accounts) without exposing my Proton login username. I can't use hide-my-email for everything. Please implement the option to use only one Proton email address for login!
-
Fenasi
commented
I don't know why this isn't still implemented
-
Lord Justice Disappointed
commented
Proton's aliases were the main draw for me. I'm ten hours into organising and updating email addresses for all my accounts, and now I find out that you can just log in with any alias... so my login is public-facing all of a sudden.
Protecting an account username is a big part of the picture. Sites will be breached and my aliases (and therefore Proton login) will be out in the world in... I dunno. A few days or weeks. Just let me choose a username.
-
Alex
commented
Please fix this! This was a big reason I moved to proton as I was under the impression that there would only one user name/email address to login which I’d avoid giving out to anyone, there by making my account secure.
-
Steven
commented
This is crucial! It's been 9 years since this suggestion was posted, what is the status?....
-
Zireael
commented
What's the point of allowing me to have 15 email addresses if any of them could be used to login to the entire account? I thought I had one truly private one for logging in, drive, pass, and calendars I will not share, another using my nickname for personal contacts and calendar invites, another using firstname.lastname for professional contacts and calendar invites and then one each for other primary accounts, banking, doctors, shopping, forums, and social media. Yeah its not quite as secure as having a hide-my-email alias for every individual account but there's enough of a buffer to only have to disable and create one new address and change a few accounts at a time.
Now I'm sitting here realizing that doesn't work. All 8 of these email addresses are out there in the world and I need to alter everything to hide-my-email addresses, then disable the proton ones because I don't even want the aliases to filter to them because they're known, so I need to create new email addresses for the aliases to forward to. I'm basically redoing everything I did a year ago when I migrated from gmail. And I'm going to have to get on the phone to change at least 25 of these accounts.My doctor's office is going to look at me like I've lost my mind.
And that still won't correct the problem that inviting people to a calendar event will reveal the email address associated with that calendar and thus a proton login option. It's not that I don't trust my personal and professional contacts, it's that people are stupid and give out your email because they're so used to only using one or two for the last 15-20 years. And the second one is usually a work/school one. I was fine with that risk when I thought those two email addresses, which are variations of my real name anyway, couldn't be used to login to my account.
-
unlimited user
commented
Disregard my last comment:
“Tuta has the exact same problem. Tuta allows login using a Tuta alias, which defeats the value of having the alias. Despite this being a known issue since 2019, it doesn’t appear to be a priority for them to fix. So switching to Tuta doesn’t solve your core grievance. Both services currently share this vulnerability. Keep that front of mind as you read the rest.”
-
BK
commented
Essential feature. Our business requires an address specifically for logging in; one that is never used to send/receive email.
-
unlimited user
commented
Look into Tuta Mail.