Proton

Why secure link sharing is safe

Reading
2 mins
Category
Using Proton Pass

If you have a paid Proton Pass account, you can securely share individual Pass items such as logins, credit card details, and notes with anyone, even if they don’t use Proton Pass.

Learn how to use secure link sharing on the Proton Pass:

Unlike most other ways to share sensitive information, secure link sharing using Proton Pass is very secure. In this article, we’ll explain why.

You’re in control

With secure link sharing, you’re always in control.

  • You choose what to share
  • You set the expiry time
  • You decide how many times the link can be used
  • You can monitor how many times the link has been used

You can delete the secure link at any time, so that it can never be used again. Just click the Remove link button in your dashboard.

Your data is end-to-end encrypted

Your Pass items are encrypted on your device, and can only be decrypted on your own devices using your private key (that only you have access to). When you generate a secure link:

  1. A random link key (share secret) is generated locally on your device.
  2. Your shared item key (the key that encrypts the item contents) is encrypted with that link key.
  3. The link key is encrypted with your vault key. This allows you to access it if you loose or forget the link.
  4. The encrypted item key and the encrypted link key are uploaded to the server.
  5. Pass locally creates a URL (https://pass.proton.me/s/RANDOM_TOKEN#link_key) to the encrypted item that includes the share secret.
  6. You share this URL with someone.

At no point does Proton have access to the link key, so we can never access your items. This also means your shared items will never be compromised in the unlikely event that our severs are somehow breached.

When sharing a link, be sure to use a secure channel. It’s almost certain that any channel you use will be encrypted (so the risk is minimal), but if an adversary can gain access to the the full share URL, they’ll be able to access the shared item (if within the expiry date and if its use limit hasn’t been reached).

Tips for sharing Pass items securely

Use the sharing controls

With Proton Pass secure sharing, you can place a time limit and a number-of-views limit on shared items. Use these controls.

Update your items after you stop sharing

Once you’ve finished sharing an item, update the password or other item details to keep them secure. Another good option is to enable two-factor authentication on the item’s account.

Be careful who you share with

Only share items with people you trust with those details.

Didn’t find what you were looking for?

General contactcontact@proton.me
Media contactmedia@proton.me
Legal contactlegal@proton.me
Partnerships contactpartners@proton.me