I heard that they require plaintext data to work. What are the other factors to this?

  • TehPers@beehaw.org
    link
    fedilink
    English
    arrow-up
    2
    ·
    2 days ago

    recovery email which they did not hash

    How do you recover an account on the other providers? Do you have to provide the same recovery email you set before during account recovery? If you hash the email, you have no way of reading it anymore, so someone has to provide it to you again.

    • sanzky@beehaw.org
      link
      fedilink
      arrow-up
      2
      ·
      2 days ago

      you ask the user for it if they want to recover the account and hash it. if the hash matches your previously stored hash then you send the email

      other providers that position themselves as secure for activists or journalists do exactly that and they cannot handle that information

    • Steve@communick.news
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      1
      ·
      edit-2
      2 days ago

      That’s the only way I can imagine it working.

      People frequently confuse privacy with anonymity. Proton never claims you can’t be identified. Only that your communications are as private a possible. Though they provide tools for you to ensure your anonymity if that’s important to you.