Proton announces Proton Pass, a password manager
techcrunch.com
techcrunch.com
I don't care who it is hosting it, I don't want my password manager connected to the internet. There is cognitive dissonance when this community that distrusts IoT, call-home LLMs, URL bars that send data to Google and 5G-connected vehicles is willing to connect their most critical private data to a single, profit-seeking source-of-failure.
The password generation and encryption is an easy, solved problem that you can get for free! For any of these services, you're only paying for the UI, backup and internet connectivity. Companies have failed at this before and will fail again.
If I'm not hosting it then it isn't.
I use KeepassXC though, I'm still not terribly confident that I haven't lost data from forgetting to merge another modified database before overwriting it.
You have to pair the add-on with the KeepassXC program once. Whenever you visit websites that you have saved passwords for, you are asked (via popup) if you want the add-on to fetch the login name and password (because it can handle multiple login combinations for the same websites). Then you have a second click on a small symbol next to the login form which then actually fills in your login data.
I would actually prefer an even less feature-rich password manager. I've thought of trying to fork something like KeePass for my purposes (or use a restricted subset) but I haven't been willing to devote the time and effort necessary.
In a way, actually. If I use a self-hosted service for hosting the file and keep it open only to myself, then someone who wants that file is targeting me specifically. That's not something I'm particularly worried about. (Obviously someone worrying about that might reconsider this as a line of defense.)
https://en.wikipedia.org/wiki/Crypto_AG
As a rule, never depend on only one company for all your opsec. Use different companies for you mail/VPN/password manager/antivirus/...
Proton makes open-source alternatives to big tech spyware and provides the service with a freemium model. Not sure what the comparison you're trying to make here is; they're both headquartered in Switzerland?
Can you link to the open-source repository for this password manager?
https://proton.me/blog/proton-pass-security-model So the beta isn't free software, but the release will be? I don't understand why you'd do that, surely the beta is when you most want people to try and break things, but the rest of their products do seem to be in their repos so it doesn't seem like a completely bullshit claim. https://github.com/ProtonMail
Whereas if you really wanted an open source server-based password manager, you could use VaultWarden with BitWarden clients, or one of countless other options. At this point, people are spoiled for choice.
How does releasing an open-source version prove their production code doesnt have a backdoor in it?
Unless you compile it yourself, which in the case of the server VaultWarden (Rust implementation of a BitWarden server), you absolutely can, otherwise you cannot be sure you can trust it.
If for some reason you end up needing to read the server-side code, then it would technically mean that client-side encryption has failed and does not deliver the necessary assurance.
If you think about it in terms of threat model, we are operating on the assumption that the provider may be malicious, or compromised. There is no context in which reviewing the source code of the server-side component would help us, because the provider would always be able to modify the source code, whether we read it or not.
On the other side if proton reveals the server-side part of the service, it would likely reveal nothing in terms of your security as a customer but it would reveal a lot of proprietary information that could help wannabe competitors.
The famous/traditional Switzerland bank privacy was severely weakened at US pressure.
I doubt its going to include sever side code like bitwarden. But I pay for proton and I'm happy to switch if their product can fully compete.
Having the server code would be useful for self-hosting, but if you're relying on Proton to host the code for you, then you have to have a certain level of trust with them regardless.
They received a court order, they cooperated with the police, for better or worse (I have zero opinion on it; frankly don't care), and handed over a customer's IP, which led to the arrest of the activist.
The problems that Proton is trying to solve, e.g., email, are better taken care of by other tools depending on a user's threat model. Likewise, if someone actually needs privacy and security because their life is on the line in an oppressive regime, utilizing a service like Proton's is a shit idea.
Anybody receiving sensitive information via email is doing email wrong. Email in and of itself is not fit for purpose as anything but a means of notification that something needs their attention on x, hence banks tell you to login to read a sensitive notification, hence the government tell you to login to the web portal to read a message.
It's a cheeky way of saying "this won't stop people from torturing shit out of you", and the rest of the article looks fine.
It's hard to take a poster seriously when they dismiss the entire model based on a hyperlink who fails to address the points in the model.
I'll agree with your point about email though: it's a tool for correspondence, not for secure transfer of sensitive info.
Proton like all law abiding companies must follow court orders. But unlike most companies, Proton actually fights in court and won a legal victory against the Swiss government after the case in question, overturning an earlier ruling that email providers can be classified as telecommunications providers. Details here: https://proton.me/blog/court-strengthens-email-privacy.
Replace "French climate activist" with "dissenter in an oppressive regime" and that person would be dead.
Who cares if they later won in court? They still threw someone under the bus. Trusting a third-party business who is subject to the laws of where they operate means this will always be a problem, doesn't matter if they're an email provider or a VPN operator, the solutions aren't fit for purpose.
… unless they decide they want to, in which case they can, because they serve the software, and can thereby easily exfiltrate the key.
I have to keep on saying it: first-party end-to-end encryption is snake oil. https://hn.algolia.com/?query=chrismorgan+snake+oil&type=com...
It does resist casual or accidental leaking, and is even proof any form of disclosure if you have stopped using the service altogether, but is absolutely not robust against rogue employee, rogue company, legal compulsion, infiltrating attacker, &c. as long as you continue to use the service.
If you want actually valuable end-to-end encryption, start by getting your software and network services from different providers. (And avoid the web’s distribution model like the plague, and probably mobile app distribution models too.)
By default, who generates the keys?
If you are compromised and your software starts to exfiltrate the keys to a third party, how long do you think it would be before anyone noticed?
What I liked about Proton was the simplicity on just one product and executing it well, but lately they've kept on adding new products some in their wheelhouse and aligns well (VPN for example), but some a stretch (Drive/Calendar).
Overall though, I agree with you. Proton seems like a solid company with good offerings and it would be a shame if they lost quality in their core offerings for the sake of adding features.
https://proton.me/blog/proton-pass-security-model
https://proton.me/blog/proton-pass-beta
From their existing github, i expect they will only open up the client part, unlike bitwarden.
I’m a Proton fan mainly for one reason - assuming that they aren’t a CIA company with back doors, my government must get a warrant to access my data there. This is my right and is recognized in the fourth amendment but increasingly my government chooses to ignore it. I am simply reasserting my rights.
Before I used Proton I used Hushmail for the same reason but they gave up years ago on innovation, and Canada is practically a totalitarian state nowadays anyway so I don’t trust them anymore.
"Proton Pass is also one of the first password managers to include a fully integrated two-factor authenticator (2FA) and supports 2FA autofill."
Highly doubt that. There are already multiple password managers with the feature.
I would like to see other apps such as proton contacts or proton notes, that provide the same values.
However, I'm not sure if we need another password manager, there are so many already that propose exactly the values listed above...
If not, Bitwarden clients are open source, might be worth raising a feature request or offering someone a few bucks to implement what you want to see if you can't DIY.
With my particular use case, I don't auto-fill as that's a security vuln waiting to happen.
FWIW: I was a very vocal complainer about v8 issues and was actively searching for alternatives. However, v8 finally doesn't suck and I'm satisfied for now. I'm hoping they learned a bunch of lessons from that completely botched launch.
Edit: looks like someone has posted about the issue in their support community although it has devolved a bit into a hot topic. https://1password.community/discussion/138165/edit-jumps-to-...
It's a rather peculiar bug.
It's also just another electron web app and if there's one thing I don't want electron "apps" doing is storing my secrets.
They no longer support offline / non-cloud vaults and force a recurring subscription.
Beyond that it shows the kind of attitude that's present within their company now - it's all about cutting costs to sell as many recurring subscriptions to pay off their VC funding and investors.
edit: i really like that they leverate simple login, that might be a reason to switch.
I need to set that up then.