Live data from Hacker News

Proton announces Proton Pass, a password manager

techcrunch.com

21–30 of 94 posts

Re: Proton announces Proton Pass, a password manager

#21
post #11

I hope it's good enough to finally ditch 1Password.

Why not Vaultwarden?

(Another user) I've been trying to switch from Keeweb, and Vaultwarden is extremely keyboard-unfriendly in comparison. Perhaps the normal user only use it for auto-completing web forms using a browser extension, but I feel it's actively painful to use the web interface.

Re: Proton announces Proton Pass, a password manager

#22
> Like every other Proton service, Proton Pass will be open source and publicly auditable upon launch, so anyone can independently verify our security features and their implementation.

I doubt its going to include sever side code like bitwarden. But I pay for proton and I'm happy to switch if their product can fully compete.

Re: Proton announces Proton Pass, a password manager

#23

Earlier quoted context omitted.

The general gist is that any legal, above board company providing privacy-oriented services is subject to the laws of where they operate, ergo, if privacy and security is something that matters to you, don't trust a third-party because they will want to stay in business. They received a court order, they cooperated with the police, for better or worse (I have zero opinion on it; frankly don't care), and handed over a…

That's why we published a threat model that goes over what Proton Mail can and cannot protect against: https://proton.me/blog/protonmail-threat-model .

It's hard to take it seriously when you invoke an XKCD comic in threat model documentation. It isn't cute.

Anybody receiving sensitive information via email is doing email wrong. Email in and of itself is not fit for purpose as anything but a means of notification that something needs their attention on x, hence banks tell you to login to read a sensitive notification, hence the government tell you to login to the web portal to read a message.

Re: Proton announces Proton Pass, a password manager

#24

With how Proton handled the French climate activist debacle, who is going to trust this over pretty much any alternative if they're concerned about privacy or security?

Proton Pass utilizes end-to-end encryption, so not even Proton can decrypt user data, and there have been hundreds of court cases that have proven that Proton's encryption cannot be bypassed by court orders. Proton like all law abiding companies must follow court orders. But unlike most companies, Proton actually fights in court and won a legal victory against the Swiss government after the case in question, overturn…

> Proton Pass utilizes end-to-end encryption, so not even Proton can decrypt user data

… unless they decide they want to, in which case they can, because they serve the software, and can thereby easily exfiltrate the key.

I have to keep on saying it: first-party end-to-end encryption is snake oil. https://hn.algolia.com/?query=chrismorgan+snake+oil&type=com...

It does resist casual or accidental leaking, and is even proof any form of disclosure if you have stopped using the service altogether, but is absolutely not robust against rogue employee, rogue company, legal compulsion, infiltrating attacker, &c. as long as you continue to use the service.

If you want actually valuable end-to-end encryption, start by getting your software and network services from different providers. (And avoid the web’s distribution model like the plague, and probably mobile app distribution models too.)

Re: Proton announces Proton Pass, a password manager

#25
As a Proton Unlimited subscriber & general supporter of the company:

I don't care who it is hosting it, I don't want my password manager connected to the internet. There is cognitive dissonance when this community that distrusts IoT, call-home LLMs, URL bars that send data to Google and 5G-connected vehicles is willing to connect their most critical private data to a single, profit-seeking source-of-failure.

The password generation and encryption is an easy, solved problem that you can get for free! For any of these services, you're only paying for the UI, backup and internet connectivity. Companies have failed at this before and will fail again.

Re: Proton announces Proton Pass, a password manager

#26

Earlier quoted context omitted.

Why not Vaultwarden?

(Another user) I've been trying to switch from Keeweb, and Vaultwarden is extremely keyboard-unfriendly in comparison. Perhaps the normal user only use it for auto-completing web forms using a browser extension, but I feel it's actively painful to use the web interface.

Have you tried the desktop application? (I haven't, but there is one, which is assumedly better)

If not, Bitwarden clients are open source, might be worth raising a feature request or offering someone a few bucks to implement what you want to see if you can't DIY.

With my particular use case, I don't auto-fill as that's a security vuln waiting to happen.

Re: Proton announces Proton Pass, a password manager

#27
post #2

While I like players such as Proton entering the Password manager space, I hope they don't lose focus with the multitudes of products. What I liked about Proton was the simplicity on just one product and executing it well, but lately they've kept on adding new products some in their wheelhouse and aligns well (VPN for example), but some a stretch (Drive/Calendar).

New products were part of the original Indiegogo fundraising. This has always been the plan.

Re: Proton announces Proton Pass, a password manager

#28

Earlier quoted context omitted.

Why? Why even pursue another password manager at all when they are about to be totally dead anyway...

Would you like to explain why they are "about to be totally dead"?

I’m guessing PassKeys / WebAuthn rolling out everywhere but at the same time not every site will get it I know. After all, there’s still sites in 2023 that ask users to limit their password length to 16 and only use certain characters.

Re: Proton announces Proton Pass, a password manager

#29
post #11

I hope it's good enough to finally ditch 1Password.

What's wrong with 1Password?

Version 8 has been plagued with various bugs with editing, scrolling, sync and stability issues on the Mac and iOS apps. It has become extremely difficult to rely on, and really the only path back to stability has been to downgrade to 1Password v7.

Re: Proton announces Proton Pass, a password manager

#30

Earlier quoted context omitted.

That's why we published a threat model that goes over what Proton Mail can and cannot protect against: https://proton.me/blog/protonmail-threat-model .

It's hard to take it seriously when you invoke an XKCD comic in threat model documentation. It isn't cute. Anybody receiving sensitive information via email is doing email wrong. Email in and of itself is not fit for purpose as anything but a means of notification that something needs their attention on x, hence banks tell you to login to read a sensitive notification, hence the government tell you to login to the we…

They have a link, mostly near the bottom of the report, as a way of (politely) saying that their service won't protect you from "rubber hose cryptanalysis".

It's a cheeky way of saying "this won't stop people from torturing shit out of you", and the rest of the article looks fine.

It's hard to take a poster seriously when they dismiss the entire model based on a hyperlink who fails to address the points in the model.

I'll agree with your point about email though: it's a tool for correspondence, not for secure transfer of sensitive info.

Post reply on HN