Proton announces Proton Pass, a password manager
91–94 of 94 posts
Re: Proton announces Proton Pass, a password manager
#92Earlier quoted context omitted.
Unless something has changed, Proton's "open source" doesn't include the servers themselves, only the clients. Whereas if you really wanted an open source server-based password manager, you could use VaultWarden with BitWarden clients, or one of countless other options. At this point, people are spoiled for choice.
I dont understand. How does releasing an open-source version prove their production code doesnt have a backdoor in it?
If for some reason you end up needing to read the server-side code, then it would technically mean that client-side encryption has failed and does not deliver the necessary assurance.
If you think about it in terms of threat model, we are operating on the assumption that the provider may be malicious, or compromised. There is no context in which reviewing the source code of the server-side component would help us, because the provider would always be able to modify the source code, whether we read it or not.
On the other side if proton reveals the server-side part of the service, it would likely reveal nothing in terms of your security as a customer but it would reveal a lot of proprietary information that could help wannabe competitors.
Re: Proton announces Proton Pass, a password manager
#93Earlier quoted context omitted.
I dont understand. How does releasing an open-source version prove their production code doesnt have a backdoor in it?
It depends on what kind of software you need to assess. In the case of client side encryption, which is the market in which Proton positions itself, you can verify the security of the implementation by just looking at the client-side code. If for some reason you end up needing to read the server-side code, then it would technically mean that client-side encryption has failed and does not deliver the necessary assuran…
Re: Proton announces Proton Pass, a password manager
#94Earlier quoted context omitted.
(Another user) I've been trying to switch from Keeweb, and Vaultwarden is extremely keyboard-unfriendly in comparison. Perhaps the normal user only use it for auto-completing web forms using a browser extension, but I feel it's actively painful to use the web interface.
Curious why you're looking to switch from KeeWeb. Been using KeeWeb for several years and have been really happy with it for my desktop.