Hacker News new | ask | show | jobs
by myfavoritetings 645 days ago
Kind of a dramatic title. If you're so concerned about it, couldn't you just make another proton email and link them to each other as recoveries?
1 comments

> couldn't you just make another proton email and link them

I thought about this, but no, that would fully compromise the data stored in both accounts. This is because the new recovery message would be intercepted by Proton, relayed to the attacker, and then it's game over, first for the first account, and then similarly for the second account. The encryption of Proton applies only to historical messages.