Малин Цветкашки
My feedback
1 result found
-
937 votes
An error occurred while saving the comment
Малин Цветкашки
supported this idea
·
1 result found
Hello Proton Team,
I am a Proton Unlimited user and would like to suggest an optional security feature that would separate a user's public email identities from the identifier accepted for signing in to the Proton Account.
Under the current system, any email address associated with a Proton Account can be used to sign in. This is convenient, but it also means that every Proton Mail address used publicly for correspondence, online registrations or important accounts is also a valid login identifier.
I suggest allowing users to choose between three sign-in modes:
* Sign in with any Proton Mail address associated with the account - the current system
* Sign in only with the primary Proton Mail address
* Sign in only with a separate **private Login ID** that is not an email address and is never publicly exposed through correspondence
The current system could remain the default, so nothing would become more difficult for users who value convenience. Users who prefer additional protection could select one of the more restrictive modes and change their choice later through the account security settings.
A separate **private Login ID** would not replace a strong unique password, two-factor authentication or passkeys. It would provide an additional defence-in-depth layer by ensuring that knowing a user's public email address does not automatically reveal a valid identifier for attempting to access the account.
This could be particularly useful for people who use Proton addresses for important financial, administrative, professional or personal accounts, as well as for users whose email addresses are publicly available or may appear in third-party data breaches.
I am deliberately not proposing a specific verification or recovery procedure, since Proton is better placed to design and implement that part securely.
I believe this optional feature would fit Proton's focus on privacy, security and user control, while fully preserving the simplicity of the existing sign-in system for users who prefer it.