Hacker News new | ask | show | jobs
by teknologist 3286 days ago
Does anyone know why they require existing ProtonMail users to enter their account's password AND the decryption password? Fair enough, they're linking my account, they require the account password. But the key that encrypts the email data too?
1 comments

Your access token to the service is encrypted with your primary public key as an extra security measure, thus your client needs to decrypt it to use it.
OK, makes sense. Thanks!

It might be a good idea to mention that on the page as (I'd guess) many tech literate people use the service.