• 0 Posts
  • 2 Comments
Joined 2 years ago
cake
Cake day: June 9th, 2023

help-circle

  • I’m sure proton would clear the inboxes before making the addresses available, so there’s no risk of seeing legitimate mail meant for someone else.

    this is just completely wrong. obviously Proton wouldn’t grant access to existing mails, but the new owner of the address will still receive new emails intended for the previous owner. this is where the main risk lies.

    there are most likely accounts with various services attached to these email addresses. you can discover some via data breaches, some via emails they send to you, and some you might discover via trial and error. it might even just be a service telling you that am account already exists when you try to sign up.

    combine that with most services allowing account recovery by just using email, even for the services without publicly leaked passwords, you will be able to easily recover access to the accounts and in many cases get access to sensitive information.