Live data from Hacker News

Proton Pass: Open-Source and Encrypted Password Manager App

proton.me

21–30 of 114 posts

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#21

I know it may be nitpicking or just pedantic, but they say on their page "Your data also never goes to the cloud, as we own and manage our own server infrastructure." But...if you upload your data to their servers (so it can go to all your devices), isn't that the "cloud"?

Definitely somebody else's computer. I guess their point is that if you pay them for mail service, you own [a portion of] them. Or vice versa.

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#22

I know it may be nitpicking or just pedantic, but they say on their page "Your data also never goes to the cloud, as we own and manage our own server infrastructure." But...if you upload your data to their servers (so it can go to all your devices), isn't that the "cloud"?

I think in general one might consider "the cloud" to be virtual resources on hardware shared with third parties. So of course AWS/GCP/Azure, but DigitalOcean would probably also qualify since to my knowledge droplets are virtual servers on shared hardware.

Although renting virtual resources on shared hardware can be convenient (much easier to provision virtual resources than real servers), there are a couple of drawbacks. Most importantly, particularly from a password management perspective, running on shared hardware could expose your virtual resources to hardware exploits like the row hammer effect.

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#23

Wasn't there some article or something claiming that this company was a NSA honeypot or something? Or am I imagining that.

If you can cite some sources, I will be very interested to read all about it. I trust Proton with most of my crucial e-mails(bank, insurance, govt services) and use a cheap alternative for personal things.

If it is really a NSA honeypot, I'd rather let M$ or GOOG have my e-mails anyways.

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#24

I know it may be nitpicking or just pedantic, but they say on their page "Your data also never goes to the cloud, as we own and manage our own server infrastructure." But...if you upload your data to their servers (so it can go to all your devices), isn't that the "cloud"?

I think in general one might consider "the cloud" to be virtual resources on hardware shared with third parties. So of course AWS/GCP/Azure, but DigitalOcean would probably also qualify since to my knowledge droplets are virtual servers on shared hardware. Although renting virtual resources on shared hardware can be convenient (much easier to provision virtual resources than real servers), there are a couple of drawb…

Im guessing they're using cloud in the classical sense of the term, as in they own their own infra and rack servers which are colocated into a datacenter and so don't depend on third parties for infra and nobody else besides them should have access to your data

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#25

I prefer to diversify. That's why I have Bitwarden, Tutanota, NextCloud & ProtonVPN. IMO it does not make sense to use any service from your VPN provider at the same time - it's like not using a VPN at all since they do know your real IP. No idea why this is not known to more people.

Arguably, that’s a very bad idea from a security perspective. The possibility of your passwords leaking are 4-times now.

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#27
post #23

Wasn't there some article or something claiming that this company was a NSA honeypot or something? Or am I imagining that.

If you can cite some sources, I will be very interested to read all about it. I trust Proton with most of my crucial e-mails(bank, insurance, govt services) and use a cheap alternative for personal things. If it is really a NSA honeypot, I'd rather let M$ or GOOG have my e-mails anyways.

No real sources but hn comments, but hey if the river sounds..

https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

The NSA/CIA are just too good at hijacking swiss -neutral- companies for their own bidding

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#28
post #25

I prefer to diversify. That's why I have Bitwarden, Tutanota, NextCloud & ProtonVPN. IMO it does not make sense to use any service from your VPN provider at the same time - it's like not using a VPN at all since they do know your real IP. No idea why this is not known to more people.

Arguably, that’s a very bad idea from a security perspective. The possibility of your passwords leaking are 4-times now.

Not if you use a sso

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#29
post #4
post #3

It's amazing how many new products Proton manages to make while still barely supporting their VPN on Linux. On the one hand, nice work proton team. On the other, you lost a VPN customer today.

It’s okay if you use a regular OpenVPN client, but yes I agree that they could at least clarify that the Proton VPN client is broken for most Linux use-cases.

Hard disagree. I've been using it on Ubuntu for over a year now and it's worked absolutely perfectly

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#30
post #7
post #4

Earlier quoted context omitted.

It’s okay if you use a regular OpenVPN client, but yes I agree that they could at least clarify that the Proton VPN client is broken for most Linux use-cases.

How so? I've only briefly used the client.

"Logical server not found" happened 132 times while out of town for two days. I also use an Ubuntu LTS pretty recently reinstalled with minimal network customization, so I guess that other person was very lucky. This happens on two different Ubuntu computers with different graphics cards and CPU vendors so I don't think I'm imagining things.

If I enable the kill switch, it can convince itself there is no network connection (for itself) because of its own kill switch. I turn the kill switch off and back on and it's fine. That's ridiculous.

They only support udp and tcp in their Linux app. The Android app literally has more features and stability.

On the other hand, now that I've switched to mullvad everything is at least apparently fine. I've been submitting error logs to proton for years, I was one of their first customers and really really wanted them to be good. Instead they just ask me to switch between tcp and udp over and over to provide new logs despite not installing a new version. It's pathetic.

And no, I don't buy the Linux market share thing when it's a VPN! Lol, it's not a video game. Their competitors seem to work great and value the Linux market. Years is enough patience, they redesigned their logo, released drive, and released this without fixing the basic issues with their existing products.

I'm done trying, it's wasting so much time trying to deal with their support now that they clearly just don't care about it. So I'm done.

Post reply on HN