ProtonBlog(new window)

We are happy to announce the release of Proton Mail v1.09. As usual, please completely clear your browser cache(new window) to make sure you load the latest version of Proton Mail. Among all the security researchers who helped us, we’d like to give special thanks this time to all participants in the first Proton Mail Hackathon for security tests for this Version 1.09 release.

New Features

  • Replied and Forwarded message is indicated.
  • Update encoding scheme to better support some foreign languages.
  • Reminder when leaving compose page without saving a draft.
  • Rearrange the message operation menu.
  • Attachments will be displayed if they are plain text of html text.
  • Add a new form field on sign up to allow user to add notification email to reset login password.
  • Add two extra security headers to enhance XSS protection.

Bug Fixes

  • Quotes in message title are now appropriately displayed.
  • The page will stay the same after enter Mailbox Password in the new opened page, instead of always redirecting to inbox.
  • Fixed the number of new messages in notification email.
  • Fixed a rare case which leads to ‘inside_not_exist’ error

Known Issues

  • Multiple attachments not properly supported.
  • Mobile and Tablet not yet fully supported.
  • Attachments are not encrypted.

Security Fixes

  • Session Cookies are set to HttpOnly. (credit to ElectronMail team in Proton Mail’s hackathon)
  • Security Headers updated for all pages to be more strict.
  • XSS attack on Contacts page (credit Prakhar Prasad @prakharprasad)
  • Enhanced brute-force attack protection.
Secure your emails, protect your privacy
Get Proton Mail free

Related articles

chrome password manager
You likely know you should store and manage your passwords safely. However, even if you are using a password manager, there’s a chance the one you’re using isn’t as secure as it could be. In this article we go over the threats some password managers
sensitive information
We all have sensitive personal information we’d all rather not share, whether it’s documents, photographs, or even private video. This article covers how to handle sensitive information or records, and what you can do to keep private information priv
Social engineering is a common hacking tactic involving psychological manipulation used in cybersecurity attacks to access or steal confidential information. They then use this information to commit fraud, gain unauthorized access to systems, or, in
is whatsapp safe for sending private photos
WhatsApp is the world’s leading messaging app, trusted by billions of people around the globe to send and receive messages. However, is WhatsApp safe for sending private photos? Or are there better ways to share photos online privately? Let’s find ou
passwordless future
With the advent of passkeys, plenty of people are predicting the end of passwords. Is the future passwordless, though? Or is there room for both types of authentication to exist side-by-side?  At Proton, we are optimistic about passkeys and have int
At Proton, we have always been highly disciplined, focusing on how to best sustain our mission over time. This job is incredibly difficult. Everything we create always takes longer and is more complex than it would be if we did it without focusing on