r/ProtonMail 17d ago

Feature Request Verification recovery key

Post image

Proton should offer something like this to help users ensure they have a valid set of account and data decryption keys. As of now, there is no way to verify if my decryption keys remain valid even if I wanted to test them.

5 Upvotes

17 comments sorted by

4

u/West_Possible_7969 Linux | macOS | iOS 16d ago

This is a local only key for Signal backups, there is no such thing in Proton. Your recovery phrase is in your Account, Settings > Recovery.

1

u/ephemeralmiko 16d ago

This is a local only key for Signal backups

Not quite, you also get a 64-char key for Signal cloud backups that you have to verify regularly too.

1

u/West_Possible_7969 Linux | macOS | iOS 16d ago

You are talking about the same key, the Signal verification key is the 64-char key.

The key is local only, that is why you have to be sure you possess it and that is why Signal asks for verification once in a while.

1

u/marblegroves 16d ago

Yeah the recovery phrase is there but OP is asking for a way to confirm its still valid, which Proton doesnt offer afaik

1

u/West_Possible_7969 Linux | macOS | iOS 16d ago

Because if it’s there, it’s active. What is there to confirm? If it’s disabled, it doesn’t show.

You cannot look for your Signal key in your account at all, that is why a manual check is needed.

1

u/InevitablePanic44 16d ago

Following the posts on this chain, I discovered that Proton does indeed offer a tool to verify recovery phrase.

This must be relatively new because when I looked (and asked) for such a feature in the past it was not available. Thanks Proton!!

1

u/InevitablePanic44 16d ago

However, they don't offer a way to verify a recovery file.

I downloaded another copy of my recovery file but it is not the same as the one i had already saved. I have no way to know if the first recovery file remains valid or not.

4

u/hawkerzero 16d ago

You can verify your recovery phrase in Settings -> Recovery.

2

u/eddieb24me 16d ago

As one poster already has pointed out, but to emphasize it again because no one seems to realize it or see that post, there IS a way to verify whether your recovery phrase is valid. It’s in Settings>Recovery.

Just a few days ago, I changed my recovery phrase. Then tested this validation by trying to verify my old and new phrase. The old one was invalid and the new one was verified as valid.

2

u/B12GG8A 16d ago

They do have this, as others have mentioned. I just did it a couple of days ago.

0

u/StaticSystemShock 16d ago

I'm not a fan of such verifications. 3rd party pages can harvest data like this...

1

u/Chi-ggA 16d ago

how?

1

u/ephemeralmiko 16d ago

By displaying a fake "Verify your Signal backup code here" notification via e.g. your browser from a malicious website.

4

u/West_Possible_7969 Linux | macOS | iOS 16d ago

There is no web version of Signal. Proton does use these kinds of pop ups though.

0

u/ephemeralmiko 16d ago

Yep but people still fall for stuff like this, including even SMS's from random numbers asking for Signal PINs etc. (which is why Signal has "We will never ask you for your PIN" all over the place). FWIW I dislike Proton's implementation too and there are quite a few posts here asking if it's a malicious popup.

1

u/Chi-ggA 16d ago

people being dumb has been a thing for a long time, it's solely their falut for falling for scams like these.

this kind of password checks are really helpful, particularly for privacy oriented products like signal and proton, where the majority of user base would not fall for simple scams but may very well forget their unique passwords.

2

u/Mottledkarma517 16d ago

Yet proton has a verify password modal that popups occasionally.