Is it worth using two-password mode for Proton?

applies here.

If you forget your mailbox password, we will not be able to recover your data.

So if your friend resets your mailbox password you are quite fucked.

I don’t see an option you can reset the password? Could you clarify.
Yes there isn’t a way to reset the second password, Unless you mean resetting primary password.

iI you forget your mailbox password proton can just reset it but you loose all data if you do not have means to recover it (which is then the case). They after all have all proof they are the account holder as they can login. It is really not meant for what you are doing, and again I would recommend you to refrain from doing this.

I am confused, there is no Mailbox password just the two password mode.
I am trying the Recovery method and basically you will need to have setup an email and/or phone number for this to occur but if it’s off you can only recover from the phrases which the third party would need to have access to do so.
Also it is fine as I said I have accounted for everything but to make sure though this is why I’m testing it before resorting to Wireguard config which would be safer
and if I click on “Forgot recovery methods”
The third party won’t be able to destroy the encrypted data on it, it basically says “Yeah if you have an account logged elsewhere use that otherwise tough luck”

The mailbox password is the second password / encryption password. It’s different names for the same thing.

1 Like

Thank you for the clarification. Appreciated.

Yeah I don’t see an option to “Reset second password” or something when trying to log in at all. And I’m not making this up


You can try for yourselves
(Referring to Mare on the last one)

Edit: I am second decisioning this so it’s fine. I’ll stick to wireguard config method.

To hop in on this, I think that the two password provides a little more Entropy, IIRC.

I recall Andy writing this when the first changed to the single password mode, however I cannot find it anymore.

1 Like

Sorry if I feel stupid for asking this but, What do you mean by Entropy?
Yeah I guess it was stupid and I apologize but still would appreciate it.

This explains it I better words then I can :slight_smile:

3 Likes

I use two password mode because it is not required to log in to the Proton VPN client on devices that I don’t access my email with. Also just because I am old and haven’t updated since that feature was introduced lol

4 Likes

Mood.

It is not provided via GUI but you can ask support to reset an account. There is no reason why they wouldn’t because no data will flow out and someone clearly can proof to be owner of the account if you litterly give them the keys to the kingdom.

I can only imagine this being true due to you having more input to the function. But i might be wrong. But it surely wont bring a marginal improvement on security.

This seems a valid point actually. If you limit the devices you put in the key used to get the key to decrypt stuff that could be a benefit for security. I personally don’t use my password on more devices for VPN than I read my email on. I do use vpn elsewhere but they are not authenticated via the password typed on that device.

1 Like

Could make a lot of sense for GrapheneOS users using many profiles. I will probably stick with two passwords for this ability alone.

1 Like

Yeah its neglitable, but it is there though, so Id thought id mention it.

1 Like

Yes it’s ok, I’ll inconvenience my best friend with Wireguard and I’ll make them stick to it but yeah.
Two password mode will be a last if the very last resort.