Mick
My feedback
76 results found
-
948 votes
An error occurred while saving the comment An error occurred while saving the comment
Mick
commented
Has this STILL not been sorted? I really don't want to move everything to another provider when my subscription runs out next summer, but I might do because I've had a number of breaches and this has just left me with a couple of extra security holes which I can't patch. It's a matter of principle. Great service, otherwise.
I've actually just had a nice email back from support explaining that I think it's a critical security flaw and that I am speaking on behalf of hundreds of loyal users, many of whom signed up with the full package because of the aliases, without being away that you can log in everywhere, and she said basically it is something they are aware of and would like to implement but she's not privy to the engineers' timelines, which is fair enough.
I replied it would still be nice if somebody basically said something to that effect in one of these 5 or so threads which have literally been here for years, because there's a strong chance they'll lose a lot of customers, otherwise.
An error occurred while saving the comment
Mick
commented
Has this STILL not been sorted? I really don't want to move everything to another provider when my subscription runs out next summer, but I might do because I've had a number of breaches and this has just left me with a couple of extra security holes which I can't patch. It's a matter of principle. Great service, otherwise.
I've actually just had a nice email back from support explaining that I think it's a critical security flaw and that I am speaking on behalf of hundreds of loyal users, many of whom signed up with the full package because of the aliases, without being away that you can log in everywhere, and she said basically it is something they are aware of and would like to implement but she's not privy to the engineers' timelines, which is fair enough.
I replied it would still be nice if somebody basically said something to that effect in one of these 5 or so threads which have literally been here for years, because there's a strong chance they'll lose a lot of customers, otherwise.
An error occurred while saving the comment
Mick
commented
https://proton.me/blog/what-is-email-alias?ref=web-setting-dashboard-a
Again, even their own advise isn't helpful on this. :(
An error occurred while saving the comment
Mick
commented
I hate to say it guys, but they even say precisely this on their own website. I was just looking through some of the blog and manuals in case there were any features I missed.
An error occurred while saving the comment
Mick
commented
Has this STILL not been sorted? I really don't want to move everything to another provider when my subscription runs out next summer, but I might do because I've had a number of breaches and this has just left me with a couple of extra security holes which I can't patch. It's a matter of principle. Great service, otherwise.
I've actually just had a nice email back from support explaining that I think it's a critical security flaw and that I am speaking on behalf of hundreds of loyal users, many of whom signed up with the full package because of the aliases, without being away that you can log in everywhere, and she said basically it is something they are aware of and would like to implement but she's not privy to the engineers' timelines, which is fair enough.
I replied it would still be nice if somebody basically said something to that effect in one of these 5 or so threads which have literally been here for years, because there's a strong chance they'll lose a lot of customers, otherwise.
An error occurred while saving the comment
Mick
commented
Personally, as someone who has been the victim of multiple serious third party breaches, I am extremely concerned about not having attack vectors exposed unnecessarily, and I came to this company in the first place precisely to get away from stuff like that.
I think one of the worst parts is that it literally doesn't say anywhere on the website that aliases can be used to login (as can anything you pipe through from your own domain) and most people seem to find it out by accident or from threads like this. That's critical security information people should be informed about, especially as it's advertised as one of the key selling points for the Unlimited package.
An error occurred while saving the comment
Mick
commented
For the record, I actually emailed customer services on our collective behalf this morning stating that there are hundreds of angry customers who are upset with a major security flaw which is not normally a problem on other paid-for email services, and critically has been ignored for over seven years for reasons we don't understand (and that you're going to lose a lot of customers over it),
and she did get back to me saying words to the effect, "yes, quite a few people have asked about this and I think they did say they wanted to implement it eventually, but I'm not privy to the timeline, but I will pass your comments on".
I forwarded the conversation to another guy on an unrelated team on the remote off-chance that he knew anybody closer to the action.
I can't imagine it being resolved before September when my subscription ends though, so I'll probably be off with you guys.
By the way, this is one of 5 threads I'm aware of on the exact same subject, one of which goes back to 2017 and as far as I can tell nobody has said anything about it, unless you count that just now. I did a fair bit of writing about it all last night.
An error occurred while saving the comment
Mick
commented
I reiterated that it would be really nice if somebody official could just respond to these threads with a yes or no, and if no why not, because this has been going on for years, and it's transparently clear that a lot of people signed up for the Unlimited package specifically for the extra aliases, and yet still there is no indication anywhere on the site (same with private domains) that they constitute a security risk. I can understand them losing a lot of customers over that, and to reiterate it would be nice if somebody just said something, because this is far from an idle concern, especially if you've experienced multiple security breaches in the past.
An error occurred while saving the comment
Mick
commented
I actually just had a message back from support, having decided to just email them, making it clear that there are at least 5 threads here going back years before I joined and I am representing hundreds of loyal customers who are concerned about the glaring security hole:
---
Hello,
Thank you for sharing your concerns and feedback regarding Proton Mail's login system and alias functionality. We understand that security is a top priority for you and many of our users.
The feature that you have requested, i.e. to restrict login access to only selected addresses, has already been requested by a number of our users.
Our developers are currently working on an implementation for this, however, I cannot comment on when this feature would be released, as I am not privy to their timelines.
I will forward your feedback to them as well. Thank you for helping us make Proton more user-friendly! Please rest assured that our team is continuously working to improve our systems to ensure the highest level of security for all users.
To further protect your account, we strongly recommend enabling two-factor authentication (2FA), which adds an extra layer of security and helps prevent unauthorized access:
https://proton.me/support/two-factor-authentication-2fa
Additionally, setting up verified recovery methods can help secure your account:
https://proton.me/support/email-sms-recovery
If you have any other questions or need assistance with your account security, please let us know.Kind regards,
Nikolina
Customer SupportAn error occurred while saving the comment
Mick
commented
Word on the street is that if you use any of Proton VPN, Authenticator, Pass, or Wallet, they can also be accessed by the same means, which IMO is even worse. How the **** have people been flagging this since 2017 and nothing has been done about it?
An error occurred while saving the comment
Mick
commented
Congratulations on being the fifth person to have started a thread pointing out the exact same security flaw which amazingly they still haven't fixed, since in fact it does precisely the opposite insofar as creating additional extra attack surfaces for no good reason.
They don't appear to have acknowledged any of them when really this should be at or near the top of their to-do list. Bad practice and bad customer service if you ask me. I'm minded to leave when my subscription is up. I've had to disable all of mine. By the way, you can also do the same with any private domain you pipe through it, so yes that's yet further decreased security.
An error occurred while saving the comment
Mick
commented
Has this STILL not been sorted? I really don't want to move everything to another provider when my subscription runs out next summer, but I might do because I've had a number of breaches and this has just left me with a couple of extra security holes which I can't patch. It's a matter of principle. Great service, otherwise.
An error occurred while saving the comment
Mick
commented
Are there any decent alternatives to ProtonMail in case they don't sort this out? I've heard AtomicMail are quite good?
An error occurred while saving the comment
Mick
commented
Does anybody at ProtonMail actually read these?
I notice a couple of people on page 2 saying "this is finally under review". Where did you find that? Do you have a link, please?
An error occurred while saving the comment
Mick
commented
Does anybody at ProtonMail actually read these?
An error occurred while saving the comment
Mick
commented
I have a website which I shut down two years ago due to a massive cyberattack which went on for three days. Every now and again, while I figure out what to do with it (it was a creative thing), I log on, and there are STILL people regularly trying drive-by attacks on all the previous usernames which the version of WordPress I was using back then allowed them to enumerate easily. I automatically divert them to people like the NSA and GCHQ on the off-chance that it catches out some eejits, but the fact remains that even 3-4 years after I effectively closed that account, people are still attempting on a very regular basis to log into my site based on accounts which have been released into the wild. It's fully protected, but my point is that they still try, and there is absolutely no reason to increase your attack surface tenfold for no benefit.
An error occurred while saving the comment
Mick
commented
I've just come here to point out how absolutely ludicrous a security hole this is, especially as I've spent over 5 hours this weekend contacting nearly 200 people about yet another data breach, one of which has recent credentials in it.
If I had the slightest idea when I signed up that all the additional emails could also be used to log in using the same password, then there was no way I would have done it in the first place. And no I didn't know about aliases or SimpleLogin or whatever because I had just signed up and it was 4 years ago.
Yes, obviously you need a strong password and 2FA, but as many other people have pointed out, how is it possibly not LESS safe having 15x as many attack vectors.
As everyone else has said, you should be able to use your default to log in and not give it out to anybody, thus considerably increasing the effort required to break in. As someone who signed up here off the back of three genuinely life-altering cybersecurity incidents, I am astonished that this hole is still there. It really is as bad as WordPress being able to be brute forced out of the box. Though I am heartened that they seem to have finally fixed that.
-
3 votes
Mick
supported this idea
·
-
404 votes
Mick
supported this idea
·
-
580 votes
An error occurred while saving the comment
Mick
commented
Well, I’ve finally decided I’m not renewing my subs and I’m off to Fastmail. No point paying for security like that when there’s a hole in the castle which nobody has noticed for 10 years.
An error occurred while saving the comment
Mick
commented
I hate to say it guys, but they even say precisely this on their own website. I was just looking through some of the blog and manuals in case there were any features I missed.
An error occurred while saving the comment
Mick
commented
I've actually just had a nice email back from support explaining that I think it's a critical security flaw and that I am speaking on behalf of hundreds of loyal users, many of whom signed up with the full package because of the aliases, without being away that you can log in everywhere, and she said basically it is something they are aware of and would like to implement but she's not privy to the engineers' timelines, which is fair enough.
I replied it would still be nice if somebody basically said something to that effect in one of these 5 or so threads which have literally been here for years, because there's a strong chance they'll lose a lot of customers, otherwise.
I reckon it would probably be worth more of you doing that, as then they might eventually get the message. I get the impression that a lot of people are signing up for the "Unlimited" package in part of this, unaware that the aliases are functionally useless if you want to maintain security hygiene, and having just checked again, I can confirm that there is no warning about this anywhere. Which I think is a bit sad.
An error occurred while saving the comment
Mick
commented
Word on the street is that if you use any of Proton VPN, Authenticator, Pass, or Wallet, they can also be accessed by the same means, which IMO is even worse. How the **** have people been flagging this since 2017 and nothing has been done about it?
An error occurred while saving the comment
Mick
commented
That's five threads I've counted on the exact same issue now, with no apparent acknowledgement.
An error occurred while saving the comment
Mick
commented
This really should be at the top of the list of things to fix and it should be trivial to code. And it will only enhance your supposedly legendary security, rather than decreasing it.
An error occurred while saving the comment
Mick
commented
What K said. I regularly have drive-by attacks on my old website using usernames which haven't been in use for years, yet are still in a database somewhere. Knowing that they're bots, I like to send them to funny places, but the point stands. Hugely increased attack surface for no reason.
An error occurred while saving the comment
Mick
commented
How on earth has this not been fixed yet? My subscription is up in September.
Having been on the receiving end of three life-altering cyberattacks since 2002, I am extremely disappointed that a company which prides itself on security and privacy above all else, fails to mention when offering to set up aliases that they can ALL then be used to log in, using the same password (and this is also true if you connect your own domain to it), vastly increasing the available attack surface. I simply can't believe this hasn't been fixed yet.
As I say, I'm looking into options for other providers, in case this still hasn't been resolved by September, which I expect it won't be. I am reluctant to pay for another two years with such a glaring vulnerability like that in situ.
Which is a pity, because I really like the system and their ethos in general.
An error occurred while saving the comment
Mick
commented
I have a website which I shut down two years ago due to a massive cyberattack which went on for three days. Every now and again, while I figure out what to do with it (it was a creative thing), I log on, and there are STILL people regularly trying drive-by attacks on all the previous usernames which the version of WordPress I was using back then allowed them to enumerate easily. I automatically divert them to people like the NSA and GCHQ on the off-chance that it catches out some eejits, but the fact remains that even 3-4 years after I effectively closed that account, people are still attempting on a very regular basis to log into my site based on accounts which have been released into the wild. It's fully protected, but my point is that they still try, and there is absolutely no reason to increase your attack surface tenfold for no benefit.
An error occurred while saving the comment
Mick
commented
I've just been for a walk and had a think about this, and I actually had to take a day off work today due to the stress of a possible system intrusion over the weekend.
The way I see it, there needs to be, at an absolute minimum a CLEAR WARNING before creating them that these will be effectively used as additional log-ins, using the same password. That way, if that's what the user wants, then fair enough. I think it's clear from the fact that there are 4 separate threads about this precise matter with over a thousand upvotes on them then it's clearly a significant community issue, and if it hasn't been fixed by the time my subscription ends, then I'll have to find somewhere else, especially with the inability to delete said emails. I think that's such a glaring omission for a company which markets itself on world-leading security and privacy, that I simply can't beleive it's been left standing for a decade. I can't subject myself to the likes of LastPass or anything similar yet again. It will break me. That's what I have to say about that. Which is a pity because you saved me from the **** of what gmail put me through.
An error occurred while saving the comment
Mick
commented
I also notice that you can only delete one email address a year.
I've just gone in and ticked the "disable" button next to all but two of them and received this message. If, despite rendering it unusable, it can STILL be used to log in, then that's even more preposterous than I thought.
"By disabling this address you will no longer be able to send or receive emails using this address and all the linked Proton products will be disabled.
Are you sure you want to disable this address?
Mick
supported this idea
·
-
2 votes
Mick
shared this idea
·
-
254 votes
Mick
supported this idea
·
-
4 votes
Mick
supported this idea
·
-
17 votes
Mick
supported this idea
·
-
6 votes
Mick
supported this idea
·
An error occurred while saving the comment
Mick
commented
Precisely what I used to do with my HEAVILY filtered four windows (whole panel on the left with three vertically spaced thirds on the right), all heavily head by filters... this was on gmail, by the way. It took a lot of work but so greatly improved my productivity.
-
4 votes
Mick
supported this idea
·
-
4 votes
Mick
supported this idea
·
-
4 votes
Mick
supported this idea
·
-
4 votes
Mick
supported this idea
·
-
6 votes
Mick
supported this idea
·
-
4 votes
Mick
supported this idea
·
-
4 votes
Mick
supported this idea
·
-
3 votes
An error occurred while saving the comment
Mick
commented
I just had a look at their site and I'm almost embarrassed I literally just resubscribed for another two years half an hour or so ago. Oh well.
Mick
supported this idea
·
-
60 votes
An error occurred while saving the comment
Mick
commented
@Arie, with gmail's setup, you can absolutely do just that with a simple filter, last time I checked.
An error occurred while saving the comment
Mick
commented
YES! This is precisely the feature I was trying to describe earlier because I hadn't seen it mentioned by anyone else yet. And I'd say "windows" rather than inboxes to avoid confusing people, but yes, mate! It's the only thing I miss about gmail. My extremely elaborate system of 80+ filters all feeding four separate windows, the "main" one on the left of the screen, and three smaller ones specifically for stuff about finance or from my dad; one about my music; and updates from my website. It took a long time to customise but it was a beauty to use. Hugely increased my productivity. And of course everything was automatically lablelled as it came in, so if I wanted to reinstall some music software and need the receipt, I just need to click the button for the label I've constructed specifically for that purpose... etc etc... I've largely abandoned them now due to a serious personal grudge against the company, but this is definitely one thing which would draw in more users. And yes also to GTD. I need to read some more of his stuff again
Mick
supported this idea
·
-
8 votes
Mick
supported this idea
·
-
6 votes
Mick
supported this idea
·
Not that it's a competition, but knowing that my subscription runs out today, I actually went and collated ALL of the messages I could on here and forwarded to to customer support, asking ARE YOU EVEN AWARE that this is a problem and peopl have been on about it for 7 years now, and the lady responded basically, "we're aware, but I'm not privy to the engineers timescale, so I couldn't tell you when it will be fixed." Utterly farcical. Anyway, I've left for FastMail and am having a much better time with them, and critically, they don't do this one really stupid thing. In fact, I have one single (secret) login username and up to 600 aliases plus masking, so it's truly possible to do the different credentials for each site thing. Much faster as well. Infinitely so. I suppose it depends on how much you're scared of the CIA, doesn't it?