>
Proton Pass utilizes end-to-end encryption, so not even Proton can decrypt user data… unless they decide they want to, in which case they can, because they serve the software, and can thereby easily exfiltrate the key.
I have to keep on saying it: first-party end-to-end encryption is snake oil. https://hn.algolia.com/?query=chrismorgan+snake+oil&type=com...
It does resist casual or accidental leaking, and is even proof any form of disclosure if you have stopped using the service altogether, but is absolutely not robust against rogue employee, rogue company, legal compulsion, infiltrating attacker, &c. as long as you continue to use the service.
If you want actually valuable end-to-end encryption, start by getting your software and network services from different providers. (And avoid the web’s distribution model like the plague, and probably mobile app distribution models too.)