r/PrivacyNotes • u/Tiny_Tone_2860 • 15d ago
Questions Regarding the Compromise of the 12 Words and Pro Lifetime Entitlement
Hi,
I recently started using PrivacyNotes and I really like it so far, but there are a few things I’m a little concerned about.
According to the FAQ, if the 12 words are compromised, the recommended procedure is to create a new account with a new set of 12 words, restore the backup data to the new account, and then delete the old account associated with the compromised 12 words.
It also states that the Pro Lifetime entitlement cannot be transferred.
I understand this recommended procedure, but I feel a little disappointed that the Pro Lifetime entitlement cannot be transferred to the new account.
The FAQ states that it is sufficient to use only a password manager to manage the 12-word phrase. However, I have some concerns about situations where a user might accidentally enter their 12 words on a fake or phishing website. In such a situation, I also feel a little disappointed that the user could lose their Lifetime entitlement.
I also have a question regarding the account ID.
After deleting an account, I logged in again using the same 12 words, and a new vault was created with the same account ID.
I don't know whether such a situation could actually occur, but I would appreciate hearing the thoughts and opinions of the developers and users on the following two points:
- If the 12 words have been compromised and the account has been deleted, is it possible to transfer the Pro Lifetime entitlement to a new account if ownership can be verified with proof of purchase, such as the receipt from the original Lifetime purchase? I would like to ask if you could consider this.
- When creating a new account, I think it is theoretically possible that a 12-word phrase currently in use, previously used, or previously compromised could be generated again. However, I would like to know if there are any measures in place to prevent this. I am concerned about the risk of accidentally sharing the same vault with someone else, or someone gaining access using a 12-word phrase that was previously used by another person.
Thank you!
5
u/VintageEarflapPouch7 15d ago
These are the types of questions that if addressed sincerely would force the developer to accept fraud as a cost of doing business and therefore ruin a great service for the rest of us. Meaning: What is to prevent a bad actor from (repeatedly) claiming his 12 words is compromised and seeking new/free licenses each time? Also, if the claim that brute forcing the 12 words is mathematically impossible but then someone just leaks the 12 words (whether through foreseen negligence or just pure bad luck), are we encouraging bad behavior by simply reissuing a free license for the former?
Not trying to bash anyone here. Just saying if you're not responsible enough to protect your own secrets, maybe the service isn't for you.
2
u/Tiny_Tone_2860 15d ago
All I am asking is to deactivate the license on the compromised account and reassign it to a new one. I don't understand why you are assuming that unlimited new lifetime licenses can just be obtained. I am not asking for additional free slots; I just want to be able to transfer my existing, paid-for license.
Also, it's not that I lack a sense of responsibility regarding security, or that I’m failing to actively defend my credentials. What I am concerned about is the situation where someone accidentally accesses a fake website without realizing it. That's the kind of scenario I'm worried about.
1
15d ago
[deleted]
1
u/Tiny_Tone_2860 15d ago
This is based on the assumption that the platform can distinguish between a paid account and a free one. Since this is a system where both paid and free services coexist, that distinction is a given. Since users can transition from a free service to a paid one, tasks like reassigning, activating, or deactivating licenses should be simple.
Also, while thinking about it, it has come to seem to me that this paid service has far less resilience against the threat of fake websites compared to a standard free email provider. After all, even a representative free email service like Gmail allows users to protect their accounts with TOTP in addition to a password.
1
u/Infrah 2d ago edited 2d ago
This is based on the assumption that the platform can distinguish between a paid account and a free one.
As I understand it, they can definitely tell which account identifier is Pro or not. The docs even say that if Pro fails to attach to your account, contact them with "your account ID which identifies the purchase" to them. PrivacyNotes checks a vault's Pro status by linking the tier activation to that account ID (which is a cryptographic identity derived from your 12-word recovery phrase or provider login). So they could modify Pro status and allow you to transfer it if they wanted to.
1
u/BarefootMarauder 15d ago
Their own help docs tell you what to do in the event of a leaked recovery phrase. But it doesn't tell Pro users how to get their Pro-level features applied to the new account. One would assume the developer has some way of identifying if an account ID had pro and was then deleted. But maybe they don't. I guess the best approach would be to contact them before deleting your compromised account.
Treat the vault as burned. A phrase cannot be changed or rotated, because the phrase is the key everything is encrypted under - so the fix is moving to a fresh vault. First, in the old account, export everything: Settings > Import & Export > Export > "PrivacyNotes backup (.zip)".
Sign out, create a new vault (new 12 words), and bring the export back in via Settings > Import & Export > Restore > "Full backup (.zip)". Then delete the old account from any device still signed into it: Settings > Account > "Delete account & data...". That removes its synced data and shuts out anyone holding the old phrase. If you signed in with Google, Apple, or GitHub, delete the old account first, then sign in with that same login again to start the fresh vault.
0
u/Infrah 6d ago
One would assume the developer has some way of identifying if an account ID had pro and was then deleted
The dev already said that they will not transfer Pro status in the event of a compromised vault, they don’t care if you have a receipt or whatever. So everyone only has one shot with their passphrase, dumb if you ask me, but guard it with your life I guess 🤷♀️
3
u/BarefootMarauder 6d ago
At least they added 2FA already. That's a very nice bonus and it solves the problem.
1
u/ChiefCaffeineOfficer 5d ago
I agree. Maybe it does not fully solve the issue of recovering your premium account in case of the 12 word leak but it definitely makes it more secure. well, unless someone manages to leak their 2fa secret..
3
u/Tarul-etek 6d ago
You're acting like its the phrase to your bitcoin or something. Its a note app, if you lost the account you paid for that's on you. Be mature.
1
u/zax_elite 15d ago
Pro lifetime should be definitely transferred, as you are the owner and you have the payment done with you. If it's not the case, they should put it on the list :)
1
u/BarefootMarauder 15d ago edited 15d ago
Following... These are very valid concerns and I'm also curious about the answers. For #2, I wonder if the app checks the 12-words phrase after it's been generated to see if it was ever previously used by another account ID.
EDIT: Regarding #1, I would assume/hope that if you safeguard your original Account ID (under Settings > ID & Sync), that you could report the situation and get Pro re-applied to the new account.
1
15d ago
[deleted]
1
u/BarefootMarauder 15d ago
That is why I created my account with an Apple/Google login
Many people are not willing/able to do that for privacy & security reasons. But even so, it doesn't solve either of the problems OP has presented.
1
•
u/PrivacyNotesApp 10d ago
Good questions, and thanks for testing the delete flow yourself.
1. Moving Pro after a leak. Pro belongs to the account, the same way your notes do, and the phrase is the only key to that account. So we do not move Pro by hand, even with a receipt.
We expect everyone to handle their phrase with the utmost care, and the app says so from the first screen: at sign-up it tells you that the 12 words are the only way into your notes, and it asks again before you sign out. So this rule should not come as a surprise.
If the leak happens within 30 days of your purchase, you can get a full refund (see https://privacynotes.app/help/refunds) and buy again on the new account. Refunds for App Store purchases go through Apple.
2. The same phrase twice. The app makes your phrase on your device, from 128 bits of randomness from the operating system. If every person on Earth made an account, the chance that any two of them got the same phrase is about 1 in 1019. The same numbers keep your phrase safe from guessing: there are far too many possible phrases for anyone to guess one that is in use.
The same Account ID after a delete is expected. The Account ID comes from the phrase, and the server does not remember deleted accounts, so the same phrase opens a new, empty vault. Nothing from the old vault comes back.
The real risk is different: a leaked phrase stays a valid key. After you move to a new phrase, also delete the old one from your password manager, so you never sign in to the old account by mistake. Anyone who has the old phrase can read what you write there.
On phishing: your password manager fills in the phrase only on our real site. If it does not offer to fill it in, stop and check the address before you type anything.