• Jerry on PieFed@feddit.online
    link
    fedilink
    English
    arrow-up
    4
    ·
    6 hours ago

    You don’t send them the password. The password never leaves your device. The password is the decryption key to decrypt your encrypted private key, which is what they send to your device. This is why, for Proton Mail, and others that use this technique, it is imperative to have a strong password to protect your private key.

    • Orygin@sh.itjust.works
      link
      fedilink
      arrow-up
      1
      ·
      edit-2
      5 hours ago

      How do they authenticate* you? They just send the encrypted key and if you can decrypt it then it’s you?
      If so I can request any account encrypted key and try to brute force it offline