• @GenderNeutralBro@lemmy.sdf.org
    link
    fedilink
    English
    82 months ago

    They could avoid storing the recovery email in plaintext. A hash would be sufficient if they require the user to enter their recovery email for confirmation when they really need to recover the account.

    For an ostensibly privacy-oriented service, Proton makes some weird architectural choices.

      • @GenderNeutralBro@lemmy.sdf.org
        link
        fedilink
        English
        42 months ago

        they need plaintext because they send you a recovery code or a support ticket

        Sure, but we’re talking about architectural choices. It is Proton’s choice to use that system; it is not required for the goal of account recovery.

          • @CaptObvious
            link
            English
            12 months ago

            Can you? Didn’t someone else mention that Proton don’t allow another Proton account?

              • @CaptObvious
                link
                English
                12 months ago

                This person isn’t a terrorist.

                Proton also don’t allow temp addresses.

                  • @CaptObvious
                    link
                    English
                    22 months ago

                    Did you read the story? Or are you just here to stir the pot and display your Proton Fanboi bona fides?