Best E-mail configuration for 1P

Options
Florian_Krumm
Florian_Krumm
Community Member
edited April 2022 in Lounge

Hi,
I currently use for 1Password an e-mail address that I also use for other websites/applications/...

For security reasons, I wondered if it would be useful to use an e-mail address for 1P that is only dedicated to this use.
If yes, what is the best way to proceed?


1Password Version: 8.7.0
Extension Version: Not Provided
OS Version: Windows 10

Comments

  • Kakkoister2
    Kakkoister2
    Community Member
    Options

    @Florian_Krumm I myself use an alias email just for my 1PW account, if you have a paid Protonmail or Tutanota account, you could set up an alias that way for your 1PW account or use some other service specifically that does email aliases.

  • Hey @Florian_Krumm:

    Which email address you use is more or less up to you. Do you have a specific threat or concern you're worried about by using an email you use elsewhere for your 1Password account?

    One important thing to keep in mind is that if you're using a separate email account from your daily use that you don't generally stay logged into, if you lose access to your account due to forgetting your account password, but your account is able to be recovered by an administrator or family organizer, you may not be able to sign into your registered email account to begin the recovery process.

    Jack

  • Florian_Krumm
    Florian_Krumm
    Community Member
    Options

    Thanks a lot for your answer @tomatoshadow2 , I already thought about this option but a question remains: if someone manages to connect to your Proton mail account for example, he will have access to all your aliases right? So should I never use the "main" mail and only the aliases (so that nobody knows the main mail and therefore can't hack it)?

    Hi @Jack.P_1P Thanks for your answer :D
    Yes, I use an email address that I have owned for a long time and therefore I registered on many sites with this email address, so I think it is not very secure to use an address that has already turned a lot on the internet, is my subscription founded?

  • Kakkoister2
    Kakkoister2
    Community Member
    Options

    @Florian_Krumm you’re welcome, yes and no, the no part would be, I have a complex password on my email generated from 1P, so not guessable, then I also have my email protected with 2FA with an authenticator app. So really improves security. But yes I only use my 1P alias email with 1P for extra piece of mind.

  • [Deleted User]
    [Deleted User]
    Community Member
    Options

    @Florian_Krumm Using a unique email address for 1Password reduces the risk that you will be targetted by a phishing attack on your 1Password account.

    An attacker can check lists of email addresses against the 1Password web interface and, due to a hard to fix implementation issue, can tell which ones are associated with 1Password accounts. They can then send emails to those individual addresses trying to trick users into visiting a fake 1Password website or reverse proxy.

    If you use a unique email address for 1Password then it will not appear in lists of addresses obtained from compromised websites. However, you are still at risk of a random phishing attempt against one of your other addresses. So you still need to take care not to click on links, to only go to 1password.com via the extension or a bookmark, etc.

    Whatever email address you use, its messages should be delivered to an inbox that you monitor regularly. An alias is useful because it can be a unique email address delivered to an inbox that you already monitor regularly. You shouldn't rely on an alias providing any security for your email account and some email services actually allow you to use any of your aliases for login. I think this is the case with ProtonMail.

    So, whatever you decide, make sure your email account has a complex, unique password and two factor authentication. I store these outside 1Password in case I need access to my email account, for example, when another family organizer helps me recover my 1Passsword account.

  • Florian_Krumm
    Florian_Krumm
    Community Member
    Options

    Okey, thank you for the additional information :D @tomatoshadow2

    Thank you very much for your answer @rootzero
    I understand better now the usefulness of creating an alias and the things to be careful about.
    One small question remains for me,
    Let's say I have a mail and some aliases that are connected to it, is there a way to name the mail for more security?
    For example create the main mail with something not guessable (not the basic ''firstname.lastname'') or on the contrary create the main mail with firstname.lastname but create more complicated aliases?

    Thank you in advance for your answer and sorry for having delayed to answer

    Have a nice day

    FK

  • [Deleted User]
    [Deleted User]
    Community Member
    edited May 2022
    Options

    @Florian_Krumm When creating a new email account I use something non-guessable for the root email address and then create aliases with the addresses I need. As login is often possible with aliases, this doesn't protect against brute force attacks, but it does add some useful camouflage in other cases.

    For example, if an alias appears in a website breach then you can delete it and replace it with another. And an attacker trying to socially engineer their way into your email account would not know the root email address and so would find it diffcult to persuade customer services that they are the legitimate user.

  • Florian_Krumm
    Florian_Krumm
    Community Member
    Options

    @rootzero thank you for your answer!
    Do you have a mail ''host'' to recommend?

    ProtonMail ? Tutanote ? or anything else ?

    FK

  • [Deleted User]
    [Deleted User]
    Community Member
    Options

    @Florian_Krumm It depends what you need. I like ProtonMail and Tutanota for their privacy. I find FastMail and Zoho Mail easier for sharing with family members.

  • XIII
    XIII
    Community Member
    Options

    Fastmail is a great service with special 1Password integration: Masked Email.

  • Kakkoister2
    Kakkoister2
    Community Member
    Options

    @Florian_Krumm It depends what you need. I like ProtonMail and Tutanota for their privacy. I find FastMail and Zoho Mail easier for sharing with family members.>

    Protonmail and Tutanota is what I use as well, great services, with privacy as their main philosophy.

  • Florian_Krumm
    Florian_Krumm
    Community Member
    Options

    Thank you very much for all your answers!
    @XIII
    I already tested Fastmail with 1P integration but I'm not a fan of some things.
    Like for example the IOS application that I don't find very convenient to use.

    @rootzero / @tomatoshadow2
    I've never tried Tutanota so maybe I'll give it a chance!
    I saw that in some offers a domain name is included in it, do you find it useful? Is there anything to be careful about from a security point of view with this? (like not including personal information for example?)

    Thank you in advance for your precious help and have a nice day

    FK

  • Kakkoister2
    Kakkoister2
    Community Member
    Options

    @Florian_Krumm I only use Tutanota for banking emails. There shouldn’t be any risk at all, it’s up to you, how personal you want to get with your email name. I would only recommend you give out your personal email to people you trust. Everything else use a Tutanota alias. I use my Protonmail alias for everything. Keeps my personal Protonmail address more private. I imagine the Tutanota alias would work just like Protonmail does, where you can send and receive from the alias.

    Make sure when you sign up for Tutanota, you store your recovery code you get in 1P, as if you lose your password, you won’t be able to recover your email without your recovery code.

  • XIII
    XIII
    Community Member
    Options

    Like for example the IOS application that I don't find very convenient to use.

    There are some things I don't like either, but due to Masked Email support I do prefer it above third-party clients (which can be used, via IMAP or JMAP).

  • prime
    prime
    Community Member
    edited May 2022
    Options

    @Florian_Krumm I myself use an alias email just for my 1PW account, if you have a paid Protonmail or Tutanota account, you could set up an alias that way for your 1PW account or use some other service specifically that does email

    I did this with a Tutanota alias for my 1Password. That email doesn’t get use for anything else.

  • Florian_Krumm
    Florian_Krumm
    Community Member
    Options

    Thank you very much for all these tips!

    @tomatoshadow2 Thank you for the precision, indeed I will try to keep the ''main'' email as confidential as possible.
    I will also see what ProtonMail proposes as a backup solution in case of problems.

    @XIII Yes indeed I can understand this point of view,
    Again, thank you very much for your reply!

    @prime It's a good idea! I'll have to see how many aliases Tutanota/ProtonmAil offers and if I can afford to dedicate one only to 1P!

    Thanks again to everyone and have a nice day !

    FK

  • prime
    prime
    Community Member
    Options

    @Florian_Krumm

    @prime It's a good idea! I'll have to see how many aliases Tutanota/ProtonmAil offers and if I can afford to dedicate one only to 1P!

    For $1 a month with Tutanota, you get 5 (or 6) aliases. I think that’s a good price.

  • Kakkoister2
    Kakkoister2
    Community Member
    Options

    @Florian_Krumm Your're welcome, Protonmail has options of setting a 'recovery phrase' this allows you to also recovery your emails, if you would ever forget your password for example.

    @prime Yes Tutanota is great, I use that as my backup to Protonmail.

This discussion has been closed.