ProtonMail / WebClients

Monorepo hosting the proton web clients
GNU General Public License v3.0
4.24k stars 538 forks source link

Accounts information leak. Risk of abuse #303

Open ghost opened 1 year ago

ghost commented 1 year ago

Hello! Found a site online that leaks the username/password for Proton accounts. Please take action.

https://bugmenot.com/view/protonmail.com

Please contact their team with a request to exclude your domains from the search as well. They exclude all domains that are using to create personal addresses (but they need an official request).

For example here is Gmail domain search result: Screenshot

olavinto commented 1 year ago

To be fair, these are basically dummy accounts so they are not exactly logins that are "leaked by the site" (they are logins that have been created to be shared). Still, protonmail.com and other Proton domains belong into the same category with Gmail so they could very well be blocked too if Proton wishes to prevent sharing free logins via the service. I have not read Proton's terms enough to know if they prohibit this kind of use but usually services do.