Please fix this exploit vector related to the Proton Sync Feature in the Authenticator App
Context:
A user stores passwords in Proton Pass but maintains 2FA Tokens in Proton Authenticator to ensure that, in the event of a Proton account breach, accounts remain protected because the passwords and 2FA Tokens are isolated from one-another and therefore the breach of Pass only offers up the passwords.
The Exploit Scenario:
An attacker gains access to an account (for example by gaining access to a recovery passphrase or a compromised emergency contact), which resets the Proton account password and disable the existing 2FA measures for the Proton account. The attacker can then install Proton Authenticator on a new device and enable account sync using the updated credentials.
Because synced 2FA Token data is not cleared from Proton’s servers during a password reset or account recovery event, the attacker can successfully sync all of the legitimate user's 2FA Tokens to their own device. This provides the attacker with access to both the user’s passwords and their 2FA Tokens codes -- defeating the purpose of keeping the 2FA Tokens on the separate isolated Authenticator app.
While Proton currently disables the sync feature on the legitimate user’s device during such an event, the previously synced 2FA Token data remains available for a new sync on an unauthorized device.
This is a critical gap that should be addressed to maintain the security integrity of the Proton ecosystem.