Emergency access - allow non-proton accounts
My emergency contact doesn't have a proton account nor do I think we should force them to have one. This feature is therefore useless to me.
In an emergency, the last thing I want my contact doing is having to remember how to log in to a service they never use. This should be a genuinely useful feature, and I hope not a feature to leverage obtaining new users.
-
Tyler
commented
I agree with this. Though I am a big fan of Proton, very few people I know use it and certainly none of my would-be emergency contacts. It is not practical to force people to create accounts they won't otherwise use simply to be an emergency contact. I think it would be much better if a system were created where emergency contacts could create an account during the emergency access request process, should they ever need to use it.
Here's my proposal: delay the account registration requirement until an emergency access request succeeds. Allow subscribers to list any contact as an emergency contact. Update login pages with a link to request emergency access. From that link, emergency contacts could enter the email address registered as an emergency contact by the subscriber. A password-less authentication could occur (send a code/authentication link to the email), after which the visitor could be presented with a list of subscriber accounts for which they are registered as an emergency contact. From there, they could request access. If the request period elapses and the emergency contact is granted access, at THAT point prompt them to create an account if they don't already have one.
This is a more intuitive, user-friendly approach for the fairly likely circumstance that the emergency contact requiring emergency access isn't nearly as tech-savvy as the subscriber who opted to use a password manager in the first place.
The stated goal of this feature we are paying for is to allow a trusted person a pathway to access our vaults in an emergency. It should be easy (and secure, of course) for the emergency contact to get authenticated once satisfying the necessary authorization steps. We hope it won't be necessary, but if it does become necessary, it would be a real shame if our emergency contact can't get in because they don't remember a random account we told them to create several years prior and they never used again.