Live data from Hacker News

Proton Pass: Open-Source and Encrypted Password Manager App

proton.me

51–60 of 114 posts

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#51

It grinds my gears when password managers bundle 2FA/MFA without pointing out how this weakens the security of it, or discussing mitigations. "Proton Pass makes 2FA easier with an integrated authenticator that stores your 2FA codes and automatically displays and autofills them." Is it really multiple factor auth if you're using the same device for the password and automatically filling in the token? It's not a unique…

> Is it really multiple factor auth if you're using the same device for the password and automatically filling in the token?

Yes, the two factors are having the device with the password database on it, and knowing the unlock code for the database or being the biometrically identified owner

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#54
post #29
post #4

Earlier quoted context omitted.

It’s okay if you use a regular OpenVPN client, but yes I agree that they could at least clarify that the Proton VPN client is broken for most Linux use-cases.

Hard disagree. I've been using it on Ubuntu for over a year now and it's worked absolutely perfectly

In the end, we can only rely on anecdotal evidence, but my experience is that it doesn't work on NixOS and the issues are also mostly full of people who encounter multiple problems [1, 2, 3].

[1]: https://github.com/ProtonVPN/linux-app/issues/110

[2]: https://github.com/ProtonVPN/linux-app/issues/109

[3]: https://github.com/ProtonVPN/linux-app/issues/96

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#55

It grinds my gears when password managers bundle 2FA/MFA without pointing out how this weakens the security of it, or discussing mitigations. "Proton Pass makes 2FA easier with an integrated authenticator that stores your 2FA codes and automatically displays and autofills them." Is it really multiple factor auth if you're using the same device for the password and automatically filling in the token? It's not a unique…

I saw someone refer to that at 1.5FA, and I agree with them. It's still multiple factors if the weakest link is the websites you are using your passwords on. If your password gets leaked they still need the password manager vault to get a 2fa code. However if your vault gets compromised then it's not 2FA

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#56
post #33
post #26

I'm a bit skeptical about having one more solution in that space, considering that 1) password managers built in OSs and web browsers are becoming better and better (for example the new version of iCloud Keychain) and 2) passkeys are coming.

1 there really requires you to be all-in on an ecosystem though. Have an iPhone but use Windows/Linux? Doesn't really matter how good iCloud is if you can't get it to sync your passwords easily to half of your devices. I suspect Passkeys will be a similar issue that further pushes people towards single-ecosystem life, unless I'm missing something.

I agree with you, but I think a majority of users are fine with being on one ecosystem, as long as it is convenient. iCloud Keychain works on Windows and Chrome using an extension provided by Apple. It is possible to login using passkeys on another device outside of the ecosystem by using QR codes.

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#57

It grinds my gears when password managers bundle 2FA/MFA without pointing out how this weakens the security of it, or discussing mitigations. "Proton Pass makes 2FA easier with an integrated authenticator that stores your 2FA codes and automatically displays and autofills them." Is it really multiple factor auth if you're using the same device for the password and automatically filling in the token? It's not a unique…

> Is it really multiple factor auth if you're using the same device for the password and automatically filling in the token

No it's not, but plenty of services force MFA, even if the user doesn't want it. And in those scenarios it seems perfectly reasonable to store the 2FA token in a password manager. For some things (frankly most things) 2FA isn't critical as long as you have a high-quality password.

I would also point out that given that most people:

1. Have 2FA codes on their phone (either as SMS or TOTP)

2. Have their password manager installed on their phone (if they use one)

Then in many ways the phone (something easily lost!) becomes a single point of failure anyway.

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#58
post #56
post #33

Earlier quoted context omitted.

1 there really requires you to be all-in on an ecosystem though. Have an iPhone but use Windows/Linux? Doesn't really matter how good iCloud is if you can't get it to sync your passwords easily to half of your devices. I suspect Passkeys will be a similar issue that further pushes people towards single-ecosystem life, unless I'm missing something.

I agree with you, but I think a majority of users are fine with being on one ecosystem, as long as it is convenient. iCloud Keychain works on Windows and Chrome using an extension provided by Apple. It is possible to login using passkeys on another device outside of the ecosystem by using QR codes.

Oh sure, but that's not necessarily Proton's market - that's what I'm pointing towards. There's a group of folks who are both most likely to use a password manager, and also don't necessarily want that password manager attached to their Google/MSFT/iCloud accounts.

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#59
post #39
post #27

Earlier quoted context omitted.

No real sources but hn comments, but hey if the river sounds.. https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que... The NSA/CIA are just too good at hijacking swiss -neutral- companies for their own bidding

A circular reference to baseless conjecture is not a source.

Agreed. I'll look for where I read this... Maybe it was just a paranoid loon on the internet but for some reason I shelved it mentally as trustworthy... Bah don't trust me

Re: Proton Pass: Open-Source and Encrypted Password Manager App

#60
post #51

It grinds my gears when password managers bundle 2FA/MFA without pointing out how this weakens the security of it, or discussing mitigations. "Proton Pass makes 2FA easier with an integrated authenticator that stores your 2FA codes and automatically displays and autofills them." Is it really multiple factor auth if you're using the same device for the password and automatically filling in the token? It's not a unique…

> Is it really multiple factor auth if you're using the same device for the password and automatically filling in the token? Yes, the two factors are having the device with the password database on it, and knowing the unlock code for the database or being the biometrically identified owner

You might say those are 2 factors, but when it's happily auto-filling passwords and MFA codes automatically, uhh, that's a lot of trust in computer built to run arbitrary code, let alone Javascript etc in a browser environment! Maybe it's 1.5 factor? It's not truly separate. To encourage people to do this with no warning is irresponsible. Variants of timing attacks that can result in arbitrary code execution come out often. Browsers have such a massive attack surface.
Post reply on HN