default 'Hide my email' alias leaks website name to Proton
By default the Pass Extension will prefix the website name in the aliased email address. For example uservoice.pacify917@aleeas.com for this website.
Since Proton / SimpleLogin need to route this alias it will remain readable to those systems - revealing the websites that a user has accounts on (uservoice in the example above).
The prefix is unnecessary since it could be stored in the E2E metadata of the Alias entry or via a linked ProtonPass Login entry instead of in the email address.
The current work around is to create the alias manually and modify the prefix. It would be very handy to have this more private option as default in the popup.
3
votes
jroddev
shared this idea