https://en.wikipedia.org/wiki/Crypto_AG
As a rule, never depend on only one company for all your opsec. Use different companies for you mail/VPN/password manager/antivirus/...
https://en.wikipedia.org/wiki/Crypto_AG
As a rule, never depend on only one company for all your opsec. Use different companies for you mail/VPN/password manager/antivirus/...
Proton makes open-source alternatives to big tech spyware and provides the service with a freemium model. Not sure what the comparison you're trying to make here is; they're both headquartered in Switzerland?
Can you link to the open-source repository for this password manager?
https://proton.me/blog/proton-pass-security-model So the beta isn't free software, but the release will be? I don't understand why you'd do that, surely the beta is when you most want people to try and break things, but the rest of their products do seem to be in their repos so it doesn't seem like a completely bullshit claim. https://github.com/ProtonMail
Whereas if you really wanted an open source server-based password manager, you could use VaultWarden with BitWarden clients, or one of countless other options. At this point, people are spoiled for choice.
How does releasing an open-source version prove their production code doesnt have a backdoor in it?
Unless you compile it yourself, which in the case of the server VaultWarden (Rust implementation of a BitWarden server), you absolutely can, otherwise you cannot be sure you can trust it.
If for some reason you end up needing to read the server-side code, then it would technically mean that client-side encryption has failed and does not deliver the necessary assurance.
If you think about it in terms of threat model, we are operating on the assumption that the provider may be malicious, or compromised. There is no context in which reviewing the source code of the server-side component would help us, because the provider would always be able to modify the source code, whether we read it or not.
On the other side if proton reveals the server-side part of the service, it would likely reveal nothing in terms of your security as a customer but it would reveal a lot of proprietary information that could help wannabe competitors.
The famous/traditional Switzerland bank privacy was severely weakened at US pressure.