Live data from Hacker News

Proton Pass: Open-Source and Encrypted Password Manager App

proton.me

41–50 of 114 posts

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#41

Any reason for me to switch from Bitwarden?

No good reason yet (or many never). It really depends how happy you are with your current setup, Proton pass is young and clearly is still under development. A lot of the features Bitwarden or any other good password manager provides, its on the Proton pass's roadmap.

So if you are happy with your setup, stick with it and no need to move to Proton pass. Maybe keep an eye and check back after few months if their offerings have changed or upgraded that is worth the effort and shifting trust.

I personally would sign up as first year is free/cheap and I like proton products, although somewhat buggy they are trustworthy and worth supporting. And I am using KeePass as my password manager which is cumbersome to selfhost and manage. I am not giving up on using KeePass yet as I too will wait to see where Proton pass ends up being.

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#42
post #17

I know it may be nitpicking or just pedantic, but they say on their page "Your data also never goes to the cloud, as we own and manage our own server infrastructure." But...if you upload your data to their servers (so it can go to all your devices), isn't that the "cloud"?

I think you're conflating "cloud" to mean any computer on the internet. I think that's generally a fine thing to do most of the time. But, cloud used to mean something a little different and it's been lost to weird arguments it seems. I look at the cloud as something I can spin up a new service or VM very quickly. Think AWS, or Azure or whatever other service lets you quickly and easily deploy something. We've now go…

This is a fine use case for using "cloud" to mean, "somewhere, not here".

I don't feel like my passwords should be stored "somewhere, not here". They should be stored "here" - where I choose to store them, and nowhere else.

I purchased a hardware password manager a while back, which seemed really neat:

https://www.beamu.io/

But, sure enough, bulk import uploads all of your passwords to their servers, even though there's just no rational reason why a server "somewhere, not here" needs to play man-in-the-middle to all your logins. To avoid it, you have to go one by one (even then there's no assurance, but the official docs do not say it's sent up to their servers).

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#43
post #42
post #17

Earlier quoted context omitted.

I think you're conflating "cloud" to mean any computer on the internet. I think that's generally a fine thing to do most of the time. But, cloud used to mean something a little different and it's been lost to weird arguments it seems. I look at the cloud as something I can spin up a new service or VM very quickly. Think AWS, or Azure or whatever other service lets you quickly and easily deploy something. We've now go…

This is a fine use case for using "cloud" to mean, "somewhere, not here". I don't feel like my passwords should be stored "somewhere, not here". They should be stored "here" - where I choose to store them, and nowhere else. I purchased a hardware password manager a while back, which seemed really neat: https://www.beamu.io/ But, sure enough, bulk import uploads all of your passwords to their servers, even though ther…

[deleted]

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#44
post #39
post #27

Earlier quoted context omitted.

No real sources but hn comments, but hey if the river sounds.. https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que... The NSA/CIA are just too good at hijacking swiss -neutral- companies for their own bidding

A circular reference to baseless conjecture is not a source.

Thus why I said not a source?

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#46
With Bitwarden supporting passkeys soon[0] is there any announcement from Proton that they would as well? Seems odd to release a password manager at this time and not mention at least eventually supporting WebAuth/FIDO2/passwordless. 1Password, Google, Apple, and likely Microsoft are all going to be having some level of passkey management. For middle of 2023, it seems like at least a good feature to mention is going to be available even if the release is months out.

[0]: https://bitwarden.com/passwordless-passkeys/

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#47
post #2

Saw this some time ago. Any advantages over, say, Bitwarden ?

If you are paying for Pass Plus or Proton Unlimited then you have integrated 2FA/TOTP which Bitwarden also makes you pay for, same with Yubikey/FIDO2/etc 2-step login, which I think is possible for signing into proton pass. And no desktop app for proton pass, maybe some day though?

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#48
It grinds my gears when password managers bundle 2FA/MFA without pointing out how this weakens the security of it, or discussing mitigations. "Proton Pass makes 2FA easier with an integrated authenticator that stores your 2FA codes and automatically displays and autofills them." Is it really multiple factor auth if you're using the same device for the password and automatically filling in the token? It's not a unique failure of Proton Pass but, people reading this should rightly be sceptical and this is a significant failing. When I read their audits on Proton Drive, I see that the web page claims the PDF is end-to-end encrypted. But the link with the key in the URL hash is public. It's a poor demonstration of their technology. When I see the defects that were found by the audits, it doesn't leave an amazing impression. It's great that they have an open source client and do open audits though. Claiming it's open source, does come across as hype without a server too though. Overall this is a welcome thing but it's very rough around the edges, I wouldn't feel it's a compelling offering yet with these big issues.

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#50

It grinds my gears when password managers bundle 2FA/MFA without pointing out how this weakens the security of it, or discussing mitigations. "Proton Pass makes 2FA easier with an integrated authenticator that stores your 2FA codes and automatically displays and autofills them." Is it really multiple factor auth if you're using the same device for the password and automatically filling in the token? It's not a unique…

Nothing wrong with your second factor being the same device.

The point is to combine something you know with something you own. The thing which you own can contain your passwords too.

Post reply on HN