Encrypt recovery email
Proposed
There are currently two option to recover an account. I think that adding an option to encrypt the email recovery to the public key on the account would be a benefit. This could help prevent an attacker from "recovering" an account if the attacker gained access to the the recovery account instead.
For example: if the recovery email account was set up on a less secure service, an attacker may gain access to it and then initiate a recovery of the mailbox.org account and gain access to both. If the recovery email were encrypted, then an extra layer of protection would be in place.
This should be a selectable option in case a user is more concerned about losing access to a private key than access to an external email account.
No connection
Real-time notifications may not work
I like this idea
Replies have been locked on this page!