this post was submitted on 07 May 2024
519 points (94.4% liked)

Technology

60098 readers
2755 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] Alk 52 points 7 months ago (1 children)

Yeah. Even if they couldn't hand over recovery emails, having a personal email as a backup to a "private and sensitive" email account is bad practice.

[–] [email protected] 7 points 7 months ago (5 children)

But what do you do if that field is needed? A throwaway address won't work as it's easy to recreate. Buy your own domain and run a server?

[–] [email protected] 10 points 7 months ago (2 children)

I put the Simplelogin email alias as my backup mail. Which forwards mail to my proton, so I guess it isn't really a backup. Even more so if you realize I need to sign into simplelogin with my protonmail account and protonmail owns Simplelogin.

[–] [email protected] 16 points 7 months ago

I just have no backup email at all. If I manage to lose my password manager file and forget my password, then I'm just fucking stupid anyway.

[–] [email protected] 6 points 7 months ago

Ah yes the email ouroboros

[–] Alk 10 points 7 months ago* (last edited 7 months ago) (2 children)

I don't believe you need that field with Proton, correct me if I'm wrong. If you do need that field with an email provider, and you need complete opsec, use a different provider.

[–] [email protected] 5 points 7 months ago

It wasn't a requirement when I signed up several years ago, and to my knowledge, it's still not required now. Just as long as you keep your email and password in something like a password manager and don't fuck it up, you're fine.

[–] [email protected] 3 points 7 months ago
[–] [email protected] 7 points 7 months ago (1 children)

No, domain names are tied to a person and, even if that person register the domain with fake person details, there will be a digital payment associated with the purchase.

[–] [email protected] 1 points 7 months ago (1 children)

Some registrars accept crypto though.

[–] asdfasdfasdf 6 points 7 months ago (1 children)

Which also isn't private. In fact, it's the opposite of private since it's a public blockchain.

[–] [email protected] 1 points 7 months ago* (last edited 7 months ago)

Yes, I am aware. But nonetheless it is far easier to use anonymously/pseudonymously than "traditional" payment. Like, exchanging BTC/LTC from Monero, and buying said Monero via a non-kyc method as well. And whatever protections you want to layer, depending on how much effort you think "they" would spend on you.

[–] EncryptKeeper 3 points 7 months ago

It’s not needed, that’s just it.

[–] WaliBoi 1 points 7 months ago

Proton doesn't require recovery. But if you want recovery without email addresses, there're multiple different ways from recovery phases to recovery phone number to even an encrypted recovery file you download onto a local device.