Live data from Hacker News

Proton Pass: Open-Source and Encrypted Password Manager App

proton.me

101–110 of 114 posts

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#101

It grinds my gears when password managers bundle 2FA/MFA without pointing out how this weakens the security of it, or discussing mitigations. "Proton Pass makes 2FA easier with an integrated authenticator that stores your 2FA codes and automatically displays and autofills them." Is it really multiple factor auth if you're using the same device for the password and automatically filling in the token? It's not a unique…

It depends on your threat model.

If my Bitwarden vault gets leaked AND their encryption gets broken, I’m fucked anyway. So I might as well just store my 2FA keys in it too.

I’m more interested in protection against keyloggers, and leaks from the database of the sites I use. And for my critical accounts (Gmail…) I use a physical key for 2FA.

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#102
post #25

I prefer to diversify. That's why I have Bitwarden, Tutanota, NextCloud & ProtonVPN. IMO it does not make sense to use any service from your VPN provider at the same time - it's like not using a VPN at all since they do know your real IP. No idea why this is not known to more people.

Arguably, that’s a very bad idea from a security perspective. The possibility of your passwords leaking are 4-times now.

But if your Nextcloud password gets leaked, your Bitwarden is safe.

Not sure what you mean?

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#103
post #95

Would like to see web/desktop clients for this. When I used it recently I found the unexpandable pop-up overlay in the browser to not be adequate for managing my hundreds of logins- it just felt annoying to be confined to such a small "window"- also would like to see along with that more options for managing items in batches (select multiple and move to another vault, etc). EDIT: Credit cards are available. Somehow I…

Credit cards are supported and available already!

Oh, wow. Edited my original post. Thanks for the clarification. I think it wasn't available when I signed up, as far as I could tell, so maybe it was just added recently (or I just completely missed it...)

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#104
post #77

Earlier quoted context omitted.

> there could be legitimate security reasons to keep server code confidential If this is ever the case, it means the server code has been written in a horribly vulnerable way and you should never use it.

Not necessarily : defense in depth is a thing.

While it is theoretically possible that the proprietary software is well-written, I would feel much safer if “defense in depth” were achieved by opening the server code and exposing it to as much audit and commentary as possible.

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#105
post #91
post #40

Earlier quoted context omitted.

You might be thinking of https://encryp.ch/blog/disturbing-facts-about-protonmail/ edit: I'd like to inject a reminder that protonmail doesn't encrypt all of your mailbox contents. From their privacy policy: "we have access to the following email metadata: sender and recipient email addresses, the IP address incoming messages originated from, attachment name, message subject, and message sent and received times"

> "we have access to the following email metadata: sender and recipient email addresses, the IP address incoming messages originated from, attachment name, message subject, and message sent and received times" Is there any of that that’s not basically required by the fact that they’re running an _email_ service?

Sure, for sending/receiving the email all of that is accessible/needed but some (all, even) of this could be stored encrypted by the user's password/mailbox-password.

If I remember correctly: one of the reasons they don't encrypt that metadata is so they can do the search box server-side.

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#106
post #29
post #4

Earlier quoted context omitted.

It’s okay if you use a regular OpenVPN client, but yes I agree that they could at least clarify that the Proton VPN client is broken for most Linux use-cases.

Hard disagree. I've been using it on Ubuntu for over a year now and it's worked absolutely perfectly

Good for you!

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#107
post #7

Earlier quoted context omitted.

How so? I've only briefly used the client.

"Logical server not found" happened 132 times while out of town for two days. I also use an Ubuntu LTS pretty recently reinstalled with minimal network customization, so I guess that other person was very lucky. This happens on two different Ubuntu computers with different graphics cards and CPU vendors so I don't think I'm imagining things. If I enable the kill switch, it can convince itself there is no network conn…

I completely agree. Shifted to Mullvad for this reason, precisely. Definitely not touching anything from Proton. It's Kryptonite.

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#108

Does this reliably detect username password fields on mobile ? 1password is getting really bad on that

Sadly no. It is a hit or miss. Particularly, URL match detection is comically bad. I also despise the way the browser extension injects code in every webpage where it detects forms. There's also no way to manually trigger the autofill.

I use keepassxc to auto type. it's pretty fun to watch

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#109
post #92

Earlier quoted context omitted.

I think in general one might consider "the cloud" to be virtual resources on hardware shared with third parties. So of course AWS/GCP/Azure, but DigitalOcean would probably also qualify since to my knowledge droplets are virtual servers on shared hardware. Although renting virtual resources on shared hardware can be convenient (much easier to provision virtual resources than real servers), there are a couple of drawb…

So if you store a file in OneDrive or Google Drive, you'd say it's not storing a file in the cloud? No third parties involved there after all. Just you, the service provider, and the hardware owned and operated by said service provider in their own datacenters.

I'd say there are colloquial and technical definitions of the word. Colloquially people have taken to referring to servers not their own, particularly operated by Amazon/Google/Microsoft, as "the cloud", such as OneDrive and Google Drive. I might even use the word colloquially sometimes. But when technical precision is needed, "cloud" refers to virtual resources on shared hardware.

Applied to this particular context, the colloquial interpretation doesn't make any sense whereas the technical interpretation does.

Post reply on HN