Live data from Hacker News

Proton Pass: Open-Source and Encrypted Password Manager App

proton.me

111–114 of 114 posts

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#111
post #70

Earlier quoted context omitted.

Yup, for proton open source means client code only

I tend to think this is a fair trade-off for services like this because: 1) for end-to-end encrypted services, I think what you most want to verify is: is my data actually being encrypted with my keys before being sent over the network, which open-source clients allow you to do 2) you can't personally verify what code is running on a company's servers anyway and to a lesser extent: 3) there could be legitimate securi…

[dead]

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#112
post #70

Earlier quoted context omitted.

Yup, for proton open source means client code only

I tend to think this is a fair trade-off for services like this because: 1) for end-to-end encrypted services, I think what you most want to verify is: is my data actually being encrypted with my keys before being sent over the network, which open-source clients allow you to do 2) you can't personally verify what code is running on a company's servers anyway and to a lesser extent: 3) there could be legitimate securi…

There's a big difference in that with bitwarden you can host the server part yourself - and that is a great guarantee for continuity of service (and bug fixes) if upstream goes away for some reason.

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#113

Earlier quoted context omitted.

I think in general one might consider "the cloud" to be virtual resources on hardware shared with third parties. So of course AWS/GCP/Azure, but DigitalOcean would probably also qualify since to my knowledge droplets are virtual servers on shared hardware. Although renting virtual resources on shared hardware can be convenient (much easier to provision virtual resources than real servers), there are a couple of drawb…

Yes, this is indeed what we mean. Proton does not use third-party providers for hosting encrypted user data. So none of the providers that people typically consider to be "cloud" such as AWS. What we do instead is own and operate all of our physical server hardware and network equipment in datacenters in Switzerland and Germany.

With properly managed encryption, it shouldn't matter to which cloud (yours or theirs) the data goes to.

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#114

Earlier quoted context omitted.

Yes, this is indeed what we mean. Proton does not use third-party providers for hosting encrypted user data. So none of the providers that people typically consider to be "cloud" such as AWS. What we do instead is own and operate all of our physical server hardware and network equipment in datacenters in Switzerland and Germany.

With properly managed encryption, it shouldn't matter to which cloud (yours or theirs) the data goes to.

Why have just one layer of protection when you can have multiple? https://www.comptia.org/blog/what-is-defense-in-depth

Mistakes happen in the most secure systems. The more layers of defense you have, the less likely a mistake causes an incident.

Post reply on HN