Mick
My feedback
35 results found
-
1,905 votes
Mick
supported this idea
·
-
48 votes
Mick
supported this idea
·
-
2 votes
Mick
shared this idea
·
-
939 votes
An error occurred while saving the comment An error occurred while saving the comment
Mick
commented
For the record, I actually emailed customer services on our collective behalf this morning stating that there are hundreds of angry customers who are upset with a major security flaw which is not normally a problem on other paid-for email services, and critically has been ignored for over seven years for reasons we don't understand (and that you're going to lose a lot of customers over it),
and she did get back to me saying words to the effect, "yes, quite a few people have asked about this and I think they did say they wanted to implement it eventually, but I'm not privy to the timeline, but I will pass your comments on".
I forwarded the conversation to another guy on an unrelated team on the remote off-chance that he knew anybody closer to the action.
I can't imagine it being resolved before September when my subscription ends though, so I'll probably be off with you guys.
By the way, this is one of 5 threads I'm aware of on the exact same subject, one of which goes back to 2017 and as far as I can tell nobody has said anything about it, unless you count that just now. I did a fair bit of writing about it all last night.
An error occurred while saving the comment
Mick
commented
I reiterated that it would be really nice if somebody official could just respond to these threads with a yes or no, and if no why not, because this has been going on for years, and it's transparently clear that a lot of people signed up for the Unlimited package specifically for the extra aliases, and yet still there is no indication anywhere on the site (same with private domains) that they constitute a security risk. I can understand them losing a lot of customers over that, and to reiterate it would be nice if somebody just said something, because this is far from an idle concern, especially if you've experienced multiple security breaches in the past.
An error occurred while saving the comment
Mick
commented
I actually just had a message back from support, having decided to just email them, making it clear that there are at least 5 threads here going back years before I joined and I am representing hundreds of loyal customers who are concerned about the glaring security hole:
---
Hello,
Thank you for sharing your concerns and feedback regarding Proton Mail's login system and alias functionality. We understand that security is a top priority for you and many of our users.
The feature that you have requested, i.e. to restrict login access to only selected addresses, has already been requested by a number of our users.
Our developers are currently working on an implementation for this, however, I cannot comment on when this feature would be released, as I am not privy to their timelines.
I will forward your feedback to them as well. Thank you for helping us make Proton more user-friendly! Please rest assured that our team is continuously working to improve our systems to ensure the highest level of security for all users.
To further protect your account, we strongly recommend enabling two-factor authentication (2FA), which adds an extra layer of security and helps prevent unauthorized access:
https://proton.me/support/two-factor-authentication-2fa
Additionally, setting up verified recovery methods can help secure your account:
https://proton.me/support/email-sms-recovery
If you have any other questions or need assistance with your account security, please let us know.Kind regards,
Nikolina
Customer SupportAn error occurred while saving the comment
Mick
commented
Word on the street is that if you use any of Proton VPN, Authenticator, Pass, or Wallet, they can also be accessed by the same means, which IMO is even worse. How the **** have people been flagging this since 2017 and nothing has been done about it?
An error occurred while saving the comment
Mick
commented
Congratulations on being the fifth person to have started a thread pointing out the exact same security flaw which amazingly they still haven't fixed, since in fact it does precisely the opposite insofar as creating additional extra attack surfaces for no good reason.
They don't appear to have acknowledged any of them when really this should be at or near the top of their to-do list. Bad practice and bad customer service if you ask me. I'm minded to leave when my subscription is up. I've had to disable all of mine. By the way, you can also do the same with any private domain you pipe through it, so yes that's yet further decreased security.
An error occurred while saving the comment
Mick
commented
Has this STILL not been sorted? I really don't want to move everything to another provider when my subscription runs out next summer, but I might do because I've had a number of breaches and this has just left me with a couple of extra security holes which I can't patch. It's a matter of principle. Great service, otherwise.
An error occurred while saving the comment
Mick
commented
Are there any decent alternatives to ProtonMail in case they don't sort this out? I've heard AtomicMail are quite good?
An error occurred while saving the comment
Mick
commented
Does anybody at ProtonMail actually read these?
I notice a couple of people on page 2 saying "this is finally under review". Where did you find that? Do you have a link, please?
An error occurred while saving the comment
Mick
commented
Does anybody at ProtonMail actually read these?
An error occurred while saving the comment
Mick
commented
I have a website which I shut down two years ago due to a massive cyberattack which went on for three days. Every now and again, while I figure out what to do with it (it was a creative thing), I log on, and there are STILL people regularly trying drive-by attacks on all the previous usernames which the version of WordPress I was using back then allowed them to enumerate easily. I automatically divert them to people like the NSA and GCHQ on the off-chance that it catches out some eejits, but the fact remains that even 3-4 years after I effectively closed that account, people are still attempting on a very regular basis to log into my site based on accounts which have been released into the wild. It's fully protected, but my point is that they still try, and there is absolutely no reason to increase your attack surface tenfold for no benefit.
An error occurred while saving the comment
Mick
commented
I've just come here to point out how absolutely ludicrous a security hole this is, especially as I've spent over 5 hours this weekend contacting nearly 200 people about yet another data breach, one of which has recent credentials in it.
If I had the slightest idea when I signed up that all the additional emails could also be used to log in using the same password, then there was no way I would have done it in the first place. And no I didn't know about aliases or SimpleLogin or whatever because I had just signed up and it was 4 years ago.
Yes, obviously you need a strong password and 2FA, but as many other people have pointed out, how is it possibly not LESS safe having 15x as many attack vectors.
As everyone else has said, you should be able to use your default to log in and not give it out to anybody, thus considerably increasing the effort required to break in. As someone who signed up here off the back of three genuinely life-altering cybersecurity incidents, I am astonished that this hole is still there. It really is as bad as WordPress being able to be brute forced out of the box. Though I am heartened that they seem to have finally fixed that.
Mick
supported this idea
·
-
577 votes
An error occurred while saving the comment
Mick
commented
I've actually just had a nice email back from support explaining that I think it's a critical security flaw and that I am speaking on behalf of hundreds of loyal users, many of whom signed up with the full package because of the aliases, without being away that you can log in everywhere, and she said basically it is something they are aware of and would like to implement but she's not privy to the engineers' timelines, which is fair enough.
I replied it would still be nice if somebody basically said something to that effect in one of these 5 or so threads which have literally been here for years, because there's a strong chance they'll lose a lot of customers, otherwise.
I reckon it would probably be worth more of you doing that, as then they might eventually get the message. I get the impression that a lot of people are signing up for the "Unlimited" package in part of this, unaware that the aliases are functionally useless if you want to maintain security hygiene, and having just checked again, I can confirm that there is no warning about this anywhere. Which I think is a bit sad.
An error occurred while saving the comment
Mick
commented
Word on the street is that if you use any of Proton VPN, Authenticator, Pass, or Wallet, they can also be accessed by the same means, which IMO is even worse. How the **** have people been flagging this since 2017 and nothing has been done about it?
An error occurred while saving the comment
Mick
commented
That's five threads I've counted on the exact same issue now, with no apparent acknowledgement.
An error occurred while saving the comment
Mick
commented
This really should be at the top of the list of things to fix and it should be trivial to code. And it will only enhance your supposedly legendary security, rather than decreasing it.
An error occurred while saving the comment
Mick
commented
What K said. I regularly have drive-by attacks on my old website using usernames which haven't been in use for years, yet are still in a database somewhere. Knowing that they're bots, I like to send them to funny places, but the point stands. Hugely increased attack surface for no reason.
An error occurred while saving the comment
Mick
commented
How on earth has this not been fixed yet? My subscription is up in September.
Having been on the receiving end of three life-altering cyberattacks since 2002, I am extremely disappointed that a company which prides itself on security and privacy above all else, fails to mention when offering to set up aliases that they can ALL then be used to log in, using the same password (and this is also true if you connect your own domain to it), vastly increasing the available attack surface. I simply can't believe this hasn't been fixed yet.
As I say, I'm looking into options for other providers, in case this still hasn't been resolved by September, which I expect it won't be. I am reluctant to pay for another two years with such a glaring vulnerability like that in situ.
Which is a pity, because I really like the system and their ethos in general.
An error occurred while saving the comment
Mick
commented
I have a website which I shut down two years ago due to a massive cyberattack which went on for three days. Every now and again, while I figure out what to do with it (it was a creative thing), I log on, and there are STILL people regularly trying drive-by attacks on all the previous usernames which the version of WordPress I was using back then allowed them to enumerate easily. I automatically divert them to people like the NSA and GCHQ on the off-chance that it catches out some eejits, but the fact remains that even 3-4 years after I effectively closed that account, people are still attempting on a very regular basis to log into my site based on accounts which have been released into the wild. It's fully protected, but my point is that they still try, and there is absolutely no reason to increase your attack surface tenfold for no benefit.
An error occurred while saving the comment
Mick
commented
I've just been for a walk and had a think about this, and I actually had to take a day off work today due to the stress of a possible system intrusion over the weekend.
The way I see it, there needs to be, at an absolute minimum a CLEAR WARNING before creating them that these will be effectively used as additional log-ins, using the same password. That way, if that's what the user wants, then fair enough. I think it's clear from the fact that there are 4 separate threads about this precise matter with over a thousand upvotes on them then it's clearly a significant community issue, and if it hasn't been fixed by the time my subscription ends, then I'll have to find somewhere else, especially with the inability to delete said emails. I think that's such a glaring omission for a company which markets itself on world-leading security and privacy, that I simply can't beleive it's been left standing for a decade. I can't subject myself to the likes of LastPass or anything similar yet again. It will break me. That's what I have to say about that. Which is a pity because you saved me from the **** of what gmail put me through.
An error occurred while saving the comment
Mick
commented
I also notice that you can only delete one email address a year.
I've just gone in and ticked the "disable" button next to all but two of them and received this message. If, despite rendering it unusable, it can STILL be used to log in, then that's even more preposterous than I thought.
"By disabling this address you will no longer be able to send or receive emails using this address and all the linked Proton products will be disabled.
Are you sure you want to disable this address?
Mick
supported this idea
·
-
682 votes
An error occurred while saving the comment
Mick
commented
On the LastPass incident in 2022, which is a real-world example of this happening. I've just this second found out they were finally fined by the ICO for it, and there was a class action suit in the USA, this is after years of me unsuccessfully trying to bring a private prosecution.
An error occurred while saving the comment
Mick
commented
Just in response to Jack earlier, LastPass managed to lose my entire set of credentials along with 31 million other customers, back four years ago and then lied about it for 9 months compromising any efforts to fix things. To compound matters, a lot of it was stored in plaintext. It offends and baffles me that not only have they been hacked in a similar manner again since, but that they're still trading, and I still see them recommended as trustworthy. And just for bonus marks, this all happened a mere 6 days after I signed up for 2 years and they refused me any kind of refund.
So they answer to your 1 is, hopefully not, but if the firm you've entrusted your details to are truly incompetent, they may well lose all your contact details, website addresses, usernames, and passwords as a job lot.
I trust NordPass/VPN for that now, and they offer the darkweb monitoring service which you are describing or alluding to here. Infinitely more trustworthy company. I am happy with ProtonMail with the glaring exception of the "being able to log in under any alias" thing which has been well documented in these forums since 2017, but seemingly not even acknowledged. I'm slowly migrating over to using the Proton Authenticator, but again concerned about this lax password security issue.
An error occurred while saving the comment
Mick
commented
Especially as you can log in using the same password on any alias, a complaint which has been documented on five separate threads now and appears not even to have been acknowledged since 2017.
-
9 votes
An error occurred while saving the comment
Mick
commented
That's five threads I've counted on the exact same issue now, with no apparent acknowledgement.
An error occurred while saving the comment
Mick
commented
Word on the street is that if you use any of Proton VPN, Authenticator, Pass, or Wallet, they can also be accessed by the same means, which IMO is even worse. How the **** have people been flagging this since 2017 and nothing has been done about it?
Mick
supported this idea
·
-
20 votes
An error occurred while saving the comment
Mick
commented
I must admit, my favourite thing about Gmail is being able to have four separate windows on screen, which I have separated by an extremely elaborate system of rules... one is anything from my family and other important stuff; one is anything to do with my website, security; one is anything to do with music, and the other is for general stuff. And it's all heavily colour-coded and flagged. :)
-
115 votes
Mick
supported this idea
·
-
391 votes
Mick
supported this idea
·
-
668 votes
Mick
supported this idea
·
-
49 votes
An error occurred while saving the comment
Mick
commented
Do they not already support Yubikey? I swear they did when I bought mine a few years ago.
Mick
supported this idea
·
-
54 votes
An error occurred while saving the comment
Mick
commented
It's essential in case you lose your phone. I have moved away from Authy precisely because they discontinued their desktop app for no good reason.
Mick
supported this idea
·
-
186 votes
An error occurred while saving the comment
Mick
commented
I briefly used Google Authenticator but got locked out of it for some reason. I was very happy with Authy for a while until they inexplicably closed down support for their desktop app, which is annoying (what if you lose your phone, etc)? Plus work insist I use Authy for logging into some systems which is irritating, so I am probably going to have to keep it around.
Then Proton Authenticator came along and I'm very happy with it. I still haven't gotten around to migrating everything over to it, but it seems like a nice bit of kit, and I haven't had any problems, so far. Long may that continue.
-
36 votes
An error occurred while saving the comment
Mick
commented
Hold on, are you saying you can't even change the recovery address, now? Christ on a pogo stick.
An error occurred while saving the comment
Mick
commented
Absolutely critical, as with all the other threads talking about the alternative emails being usable as logins thing. I've got an ancient email address I used from the mid-90s, and in any breach report, it is rare if it's anything other than that one which turns up. If I stayed with Proton for long enough, this would become the same situation ultimately with my "primary" email here. There were a lot of recent and scarily current credentials in this latest one, which was unusual, and I had to inform my friend who writes music FX software, that somehow, someone has got hold of the account details for his shop which I have never written down except quite recently in my PW manager and now that's on the darkweb too, with all the rest of it. Unless he's had a breach he didn't know about, I haven't the slightest clue how that ended up in a report from NordVPN, and yet that's just some of the nonsense I've been dealing with this weekend.
I concur with everything the original poster says.
Mick
supported this idea
·
Personally, as someone who has been the victim of multiple serious third party breaches, I am extremely concerned about not having attack vectors exposed unnecessarily, and I came to this company in the first place precisely to get away from stuff like that.
I think one of the worst parts is that it literally doesn't say anywhere on the website that aliases can be used to login (as can anything you pipe through from your own domain) and most people seem to find it out by accident or from threads like this. That's critical security information people should be informed about, especially as it's advertised as one of the key selling points for the Unlimited package.