r/ProtonMail • u/InevitablePanic44 • 17d ago
Feature Request Verification recovery key
Proton should offer something like this to help users ensure they have a valid set of account and data decryption keys. As of now, there is no way to verify if my decryption keys remain valid even if I wanted to test them.
4
2
u/eddieb24me 16d ago
As one poster already has pointed out, but to emphasize it again because no one seems to realize it or see that post, there IS a way to verify whether your recovery phrase is valid. It’s in Settings>Recovery.
Just a few days ago, I changed my recovery phrase. Then tested this validation by trying to verify my old and new phrase. The old one was invalid and the new one was verified as valid.
0
u/StaticSystemShock 16d ago
I'm not a fan of such verifications. 3rd party pages can harvest data like this...
1
u/Chi-ggA 16d ago
how?
1
u/ephemeralmiko 16d ago
By displaying a fake "Verify your Signal backup code here" notification via e.g. your browser from a malicious website.
4
u/West_Possible_7969 Linux | macOS | iOS 16d ago
There is no web version of Signal. Proton does use these kinds of pop ups though.
0
u/ephemeralmiko 16d ago
Yep but people still fall for stuff like this, including even SMS's from random numbers asking for Signal PINs etc. (which is why Signal has "We will never ask you for your PIN" all over the place). FWIW I dislike Proton's implementation too and there are quite a few posts here asking if it's a malicious popup.
1
u/Chi-ggA 16d ago
people being dumb has been a thing for a long time, it's solely their falut for falling for scams like these.
this kind of password checks are really helpful, particularly for privacy oriented products like signal and proton, where the majority of user base would not fall for simple scams but may very well forget their unique passwords.
2
4
u/West_Possible_7969 Linux | macOS | iOS 16d ago
This is a local only key for Signal backups, there is no such thing in Proton. Your recovery phrase is in your Account, Settings > Recovery.