Bitcoin Forum
May 05, 2024, 10:19:16 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Proton-mail is using BIP39 for its recovery phrase!  (Read 255 times)
pooya87 (OP)
Legendary
*
Offline Offline

Activity: 3444
Merit: 10549



View Profile
February 11, 2022, 10:25:37 AM
Merited by Welsh (5), LoyceV (4), hugeblack (4), o_e_l_e_o (4), hosseinimr93 (2), RickDeckard (2), NeuroticFish (1), suchmoon (1), ABCbits (1), buwaytress (1), dkbit98 (1), vv181 (1), m2017 (1), noorman0 (1), Charles-Tim (1), n0nce (1)
 #1

There appears to be a new option to create a recovery phrase in your Proton-Mail that will give you 12 words to write down. So I got curious and checked the words and surprisingly they are all in BIP39 list and the checksum is valid. Then I went to see the source code and surprisingly enough they seem to have adopted the bitcoin proposal to encode their entropy (for recovering email).
Looks like Proton team has some Bitcoin enthusiasts.
https://github.com/ProtonMail/bip39
https://github.com/ProtonMail/WebClients/blob/main/packages/shared/lib/mnemonic/bip39Wrapper.ts

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
"I'm sure that in 20 years there will either be very large transaction volume or no volume." -- Satoshi
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714947557
Hero Member
*
Offline Offline

Posts: 1714947557

View Profile Personal Message (Offline)

Ignore
1714947557
Reply with quote  #2

1714947557
Report to moderator
1714947557
Hero Member
*
Offline Offline

Posts: 1714947557

View Profile Personal Message (Offline)

Ignore
1714947557
Reply with quote  #2

1714947557
Report to moderator
ABCbits
Legendary
*
Offline Offline

Activity: 2870
Merit: 7464


Crypto Swap Exchange


View Profile
February 11, 2022, 11:35:44 AM
Merited by pooya87 (2)
 #2

I didn't expect BIP39 is used outside cryptocurrency wallet. Looking at this commit, i found file MnemonicPhraseStep.tsx which state it can be used for both account access and data decryption. I wonder how regular user react to this new backup/restore option.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
dkbit98
Legendary
*
Offline Offline

Activity: 2226
Merit: 7129



View Profile WWW
February 11, 2022, 11:48:30 AM
 #3

There appears to be a new option to create a recovery phrase in your Proton-Mail that will give you 12 words to write down. So I got curious and checked the words and surprisingly they are all in BIP39 list and the checksum is valid. Then I went to see the source code and surprisingly enough they seem to have adopted the bitcoin proposal to encode their entropy (for recovering email).
This is very cool and it means that you could use your email address and your bitcoin wallet addresses derived from the same BIP39 words.
I don't know how safe that is because proton is probably holding the same recovery words, and I can't find more explanation about this.
Proton does accept Bitcoin (not any shitcoins) payments for their pro features so it's no surprise they have some bitcoiners in their team.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
NeuroticFish
Legendary
*
Offline Offline

Activity: 3668
Merit: 6377


Looking for campaign manager? Contact icopress!


View Profile
February 11, 2022, 11:51:23 AM
Merited by LoyceV (4), hugeblack (4)
 #4

This is very cool and it means that you could use your email address and your bitcoin wallet addresses derived from the same BIP39 words.
I don't know how safe that is because proton is probably holding the same recovery words, and I can't find more explanation about this.

And if you ever have to recover your mail, you'll expose online the seed of your funds?
It doesn't sound like a good idea to me...
(Am I missing something obvious? I am not a Proton-mail user...)

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
Quickseller
Copper Member
Legendary
*
Offline Offline

Activity: 2870
Merit: 2298


View Profile
February 11, 2022, 01:01:25 PM
Merited by LoyceV (4), hugeblack (4), pooya87 (2), Oshosondy (2), ABCbits (1)
 #5

There appears to be a new option to create a recovery phrase in your Proton-Mail that will give you 12 words to write down. So I got curious and checked the words and surprisingly they are all in BIP39 list and the checksum is valid. Then I went to see the source code and surprisingly enough they seem to have adopted the bitcoin proposal to encode their entropy (for recovering email).
This is very cool and it means that you could use your email address and your bitcoin wallet addresses derived from the same BIP39 words.
I don't know how safe that is because proton is probably holding the same recovery words, and I can't find more explanation about this.
Proton does accept Bitcoin (not any shitcoins) payments for their pro features so it's no surprise they have some bitcoiners in their team.
I wouldn't do this. It would be trivial for protonmail to modify their webclient to send the seed to their servers, even on an ad-hoc basis, so unless you check every time, there is the risk you are transmitting your seed over the internet.

It is also generally not a good idea to reuse private keys or seeds.
DaveF
Legendary
*
Offline Offline

Activity: 3472
Merit: 6263


Crypto Swap Exchange


View Profile WWW
February 11, 2022, 01:11:00 PM
 #6

It's cool. But it does make you wonder if it's programmers who like BTC. Or, lazy programmers who had to come up with a recovery method and did a copy - paste - edit of something else and poof a known working way of generating something that has been audited every which way and is known to a lot of people.

Think about it BIP39 does not exist in the crypto world, Proton starts using something like it, how much crap are they going to get about it's security....

-Dave

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Charles-Tim
Legendary
*
Offline Offline

Activity: 1540
Merit: 4845



View Profile
February 11, 2022, 01:12:44 PM
Merited by pooya87 (2)
 #7

---snipped---

---snipped---

---snipped---

From what pooya87 posted, I do not think this has any connection to your coins, but only your proton mail account recovery process. So I think the recovery phrase is about recovery words that is needed to recover proton mail account.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
pooya87 (OP)
Legendary
*
Offline Offline

Activity: 3444
Merit: 10549



View Profile
February 11, 2022, 01:19:09 PM
Last edit: February 11, 2022, 01:30:30 PM by pooya87
 #8

There appears to be a new option to create a recovery phrase in your Proton-Mail that will give you 12 words to write down. So I got curious and checked the words and surprisingly they are all in BIP39 list and the checksum is valid. Then I went to see the source code and surprisingly enough they seem to have adopted the bitcoin proposal to encode their entropy (for recovering email).
This is very cool and it means that you could use your email address and your bitcoin wallet addresses derived from the same BIP39 words.
I don't know how safe that is because proton is probably holding the same recovery words, and I can't find more explanation about this.
Proton does accept Bitcoin (not any shitcoins) payments for their pro features so it's no surprise they have some bitcoiners in their team.
I couldn't find any explanations either, and I can't read JS. I only figured it out since the words looked familiar and the number 12 is obviously familiar to us bitcoiners. But there is a good chance that it is happening on the client side though and only encrypted messages are sent to the server.

In any case it is never a good idea to use a bitcoin key for anything else or vice versa. This was just interesting to see how a bitcoin proposal finds its way to other fields that have nothing to do with bitcoin.
However, if you know what you are doing and if they allowed entering your own entropy you could technically use your bitcoin mnemonic to derive a child key at a certain derivation path (eg. m/1853125232/0' :1853125232 is equal to prtn) and use that as a recoverable entropy from your main mnemonic.

Think about it BIP39 does not exist in the crypto world, Proton starts using something like it, how much crap are they going to get about it's security....
Well to be fair BIP39 is a very compact way of converting entropy to words. The alternative (existing algorithm) would be the PGP word list that encodes 8 bits at a time (BIP39 encodes 11 bits).

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
dkbit98
Legendary
*
Offline Offline

Activity: 2226
Merit: 7129



View Profile WWW
February 12, 2022, 09:27:11 PM
Merited by pooya87 (2)
 #9

I couldn't find any explanations either, and I can't read JS. I only figured it out since the words looked familiar and the number 12 is obviously familiar to us bitcoiners. But there is a good chance that it is happening on the client side though and only encrypted messages are sent to the server.
I would never make a connection with real bitcoin address, but I could in theory I could use my twelve seed words from Proton mail and use it as donation address for that specific email address.
This would be a good idea to use as a backup if you are self hosting personal email, so everything could be done offline and no server would hold seed words.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
Quickseller
Copper Member
Legendary
*
Offline Offline

Activity: 2870
Merit: 2298


View Profile
February 13, 2022, 04:12:27 PM
 #10

I couldn't find any explanations either, and I can't read JS. I only figured it out since the words looked familiar and the number 12 is obviously familiar to us bitcoiners. But there is a good chance that it is happening on the client side though and only encrypted messages are sent to the server.
I would never make a connection with real bitcoin address, but I could in theory I could use my twelve seed words from Proton mail and use it as donation address for that specific email address.
This would be a good idea to use as a backup if you are self hosting personal email, so everything could be done offline and no server would hold seed words.

Although most donation addresses for individuals rarely receive large amounts of bitcoin, for some entities with a "good cause" often will receive larger amounts of donations. For example the EFF, Project Veritas, etc. So using the same seed will still have the same security implications.
Welsh
Staff
Legendary
*
Offline Offline

Activity: 3262
Merit: 4110


View Profile
February 14, 2022, 02:58:16 PM
Merited by pooya87 (2), ABCbits (1)
 #11

It's cool. But it does make you wonder if it's programmers who like BTC. Or, lazy programmers who had to come up with a recovery method and did a copy - paste - edit of something else and poof a known working way of generating something that has been audited every which way and is known to a lot of people.
Does it matter on the type of person for implementing it? As long as its been implemented properly, and securely, it shouldn't matter. As you probably know, a lot of programmers rely on libraries, and basically copy, and paste code to make a functional product. I find lazy has a negative stigma around it, but in terms of programming, and copying code that has already been proven to work, and of course you're allowed to do so, I don't see that as the negative lazy, but rather efficient.

In any case it is never a good idea to use a bitcoin key for anything else or vice versa. This was just interesting to see how a bitcoin proposal finds its way to other fields that have nothing to do with bitcoin.
However, if you know what you are doing and if they allowed entering your own entropy you could technically use your bitcoin mnemonic to derive a child key at a certain derivation path (eg. m/1853125232/0' :1853125232 is equal to prtn) and use that as a recoverable entropy from your main mnemonic.
This is my takeaway from this. Just because Proton mail uses a similar system to Bitcoin seeds, doesn't mean a user should use the same words as their recovery seed of their wallet. Obviously, this is basic security, but I bet a lot of people aren't going to heed that advice.

Though, I haven't checked whether the words correspond to the words that Bitcoin wallets use, which if they don't is probably a better idea, and was probably purposely implemented that way by the developers to avoid this sort of issue.
o_e_l_e_o
In memoriam
Legendary
*
Offline Offline

Activity: 2268
Merit: 18509


View Profile
February 14, 2022, 03:27:16 PM
Merited by hugeblack (4), Welsh (3), pooya87 (2), ABCbits (1), dkbit98 (1)
 #12

This isn't just a password recovery - it is a full account recovery. Currently on ProtonMail if you need to reset your password to recover your account, then all your old emails will remain encrypted and inaccessible unless you can either remember your old password or you have downloaded an account recovery file. With this seed phrase, you will be able to decrypt all your previous emails.

Though, I haven't checked whether the words correspond to the words that Bitcoin wallets use, which if they don't is probably a better idea, and was probably purposely implemented that way by the developers to avoid this sort of issue.
I generated a set of words on three different ProtonMail accounts, and all of them are valid BIP39 seed phrases, with words from the standard word list and a valid checksum.

Obviously you should never use the same seed phrase for both ProtonMail and holding bitcoin, but it does open the door to future plausible deniability. I can keep a seed phrase with an additional passphrase for storing my coins, and if someone finds the seed phrase, I can tell them it's actually the recovery words for my email account or some other service which might implement the same system in the future.
dkbit98
Legendary
*
Offline Offline

Activity: 2226
Merit: 7129



View Profile WWW
February 14, 2022, 07:13:24 PM
 #13

Obviously you should never use the same seed phrase for both ProtonMail and holding bitcoin, but it does open the door to future plausible deniability. I can keep a seed phrase with an additional passphrase for storing my coins, and if someone finds the seed phrase, I can tell them it's actually the recovery words for my email account or some other service which might implement the same system in the future.
This is a good idea in case you are using strong longer passphrase, or even better multiple passphrases.
It would be very hard for anyone to steal your coins this way, even if original seed words somehow get compromised.
Only problem with long passphrases is that you would need to enter them for every transaction you make, and that can be a hustle sometimes.
Speaking about email providers, I think that self-hosted emails are much better option than proton or anything else.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
pooya87 (OP)
Legendary
*
Offline Offline

Activity: 3444
Merit: 10549



View Profile
February 15, 2022, 04:23:17 AM
 #14

I generated a set of words on three different ProtonMail accounts, and all of them are valid BIP39 seed phrases, with words from the standard word list and a valid checksum.
Though, I haven't checked whether the words correspond to the words that Bitcoin wallets use, which if they don't is probably a better idea, and was probably purposely implemented that way by the developers to avoid this sort of issue.
The beauty of open source: https://github.com/ProtonMail/bip39/blob/main/src/wordlists/english.json == https://github.com/bitcoin/bips/blob/master/bip-0039/english.txt

I'd say it would have been better if they used a different word-list but not because of the conflict between  bitcoin and their system that could lead to misuse but because BIP39 English word-list is just terrible. If you check out the conditions for a good list and the criteria that newer lists like the portuguese one have stuck to, you realize how terrible English list is with words like "aim" and "air" or "bind" and "bird" and a lot more that either look the same or differ in one letter.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
buwaytress
Legendary
*
Online Online

Activity: 2800
Merit: 3443


Join the world-leading crypto sportsbook NOW!


View Profile
February 16, 2022, 08:21:11 AM
 #15

That's a nice find, wonder how I missed that -- I actually use a different mail service but this is something else to consider, given how many of us are now used to the recovery phrase (thanks Bitcoin).

I guess that Bitcoin love certainly goes well with Switzerland's privacy laws =)

██
██
██
██
██
██
██
██
██
██
██
██
██
... LIVECASINO.io    Play Live Games with up to 20% cashback!...██
██
██
██
██
██
██
██
██
██
██
██
██
ABCbits
Legendary
*
Offline Offline

Activity: 2870
Merit: 7464


Crypto Swap Exchange


View Profile
February 16, 2022, 09:56:59 AM
Merited by pooya87 (2), hugeblack (2)
 #16

That's a nice find, wonder how I missed that -- I actually use a different mail service but this is something else to consider, given how many of us are now used to the recovery phrase (thanks Bitcoin).

They don't bother announce it to their blog (https://protonmail.com/blog/) or newsletter, so it's not surprising you don't know about it (especially if you don't use their service).

I guess that Bitcoin love certainly goes well with Switzerland's privacy laws =)

While ProtonMail is better than many email service provider (in terms of privacy), Switzerland's privacy laws might not be as strong as you expected. Check these article,
https://www.techspot.com/news/91126-protonmail-criticized-handing-activist-ip-address-authorities-leading.html
https://protonmail.com/blog/climate-activist-arrest/

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!