After rolling out its password manager to a limited number of users in April, Proton has finally released the service to the general public. The tool, called Proton Pass, uses end-to-end encryption to keep your usernames and passwords away from third parties, including Proton itself. It also lets you create and store randomly generated email aliases that you can use in place of your real address.
Valen ( @valen@beehaw.org ) 39•2 years agoI don’t care which password manager you use, as long as you use one (and it’s secure). It’s such a game changer.
Spellbind0127 ( @Spellbind0127@geddit.social ) 13•2 years agoso this means use a password manager that isn’t lastpass.
Valen ( @valen@beehaw.org ) 3•2 years agoYeah, not lastpass. Migrated from them to 1password.
Elindio ( @Elindio@lemmy.sdf.org ) 25•2 years agoIt looks pretty good. I’m well ensconced in bitwarden, but I’d totally check this out too.
雨 月 ( @Ugetsu@feddit.de ) 14•2 years agoSecurity wise, there´s probably no reason to consider leaving Bitwarden. Feature wise, bitwarden already has almost all bases covered when it comes to being a password manager. UI is where it would probably be easiest to get ahead. Pricing on the other hand seems a bit expensive on Protons side. The have the “limited offer” now for 1€ a month, which is already 2€ more per year than Bitwarden, but they write that the regular price would be 4,99 a month, which would be beyond rough compared to BW.
Pigeon ( @Lowbird@beehaw.org ) 6•2 years agoI’d assume there’s a price tier that includes their other premium services though I think? So you’d also get multiple email addresses with them, 500gb cloud storage, and their VPN’s premium features. Not everyone will want all that but if you do it seems like a good deal as a bundle.
I’ve been using their vpn for maybe 2 years now - i get great service. But switching pw manager from bitwarden seems like a lot effort on my part at this point :-)
cloudless ( @cloudless@lemmy.ml ) English0•2 years agoFor extra 2€ a year you get to keep your passwords overseas……might be something worth considering.
雨 月 ( @Ugetsu@feddit.de ) English3•2 years agoWhat does “keep your passwords overseas” mean?
cloudless ( @cloudless@lemmy.ml ) English4•2 years agoProton’s servers are in Switzerland, and they comply with all EU privacy and security laws. Majority of other password locker solution are US companies, so their equipment and data is subject to US federal and state laws, NSA/DHS surveillance, etc.
雨 月 ( @Ugetsu@feddit.de ) English1•2 years agoAh I see. Well, I live in Germany, so that’s why I was confused about the overseas party.
cloudless ( @cloudless@lemmy.ml ) English2•2 years agoAh yes, pardon my North American assumptions… 🙃 Although theoretically we could turn this the other way around - you as German would still be subject to US laws for any data that is stored on US servers - including Bitwarden cloud saves.
雨 月 ( @Ugetsu@feddit.de ) English1•2 years agoI would. But I also trust in both bitwardens word as well as what I read (I actually did back when I decided to use bitwarden) in the external audit concerning the encryption of my vault. So, as things are at the moment, the feds can raid bitwarden, or azure for that matter, all they want, they will still not get my passwords.
Dane ( @TheLastOfHisName@beehaw.org ) 7•2 years agoBitWarden user as well. LOVE it. I really can’t imagine life without it.
tombuben ( @tombuben@beehaw.org ) English5•2 years agoYeah, I use both Proton and Bitwarden, and unless they allow self hosting for Pass I simply won’t be using it.
Cayenne05dingos ( @Cayenne05dingos@geddit.social ) 12•2 years agoIf you have IOS, then their password manager has all the features proton has, fake emails, 2 factor encryption, for free, these are paid features on proton.
On the other hand proton is open source. and can use it on non apple devices, android, linux, windows.
Moonrise2473 ( @Moonrise2473@feddit.it ) 14•2 years agoProton open source is mainly a marketing facade.
All the code is in a giant repo all mixed (drive, email, and so on) with no documentation whatsoever. Technically it’s open source, but you can’t take it and self host the service like you can do with a real open source product
Edit: I just watched and it’s even worse than I imagined. No server components are open sourced and the client parts are hard coded to access the official servers. It’s like if I say “this car is open source. Except the engine, all the parts are proprietary design to work only with the secret engine, and anyway there aren’t any instructions, good luck with your diy”
algebro ( @algebro@algebro.xyz ) 3•2 years agoThe point of open source isn’t necessarily that you can self host it for free. If you want to only use services you can host yourself that’s fine, but that doesn’t make proton’s model wrong or bad.
As for the server, you have no way to verify they’re running what is in the repo, so you have to trust them anyway. Open sourcing the server-side components doesn’t accomplish anything other than making their spam filtering easier to bypass.
In models like this (and bitwarden), all the magic happens on the client (which IS open source), so the server can be dumb and more or less untrusted. If you use the Open source bridge application you don’t even have to trust the JavaScript coming from the server. I can compile the bridge and mobile clients myself and have reasonable confidence that things haven’t been tampered with without having to trust the server despite it being proprietary.
Jarmer ( @Jarmer@vlemmy.net ) 2•2 years agoI guess to me, being open source is more about the ability that it can be audited. I don’t care whatsoever about hosting my own proton mail / drive / vpn (which I use constantly all the time) but I do care if it’s audited and secure.
That said, I know they claim to be open source and audited, but I’ve never double checked those claims. Probably should.
unknowing8343 ( @unknowing8343@discuss.tchncs.de ) 8•2 years agoTo name more alternatives, Bitwarden is 10 € per year and you get to support an open source project.
「fleece!」 ( @fleece@pawb.social ) English4•2 years agoUnfortunately I need my password manager available on all the platforms I use. I love Apple’s, and I totally trust them with my data, but I can’t install it on any browser or my Windows or Linux machines so it’s a nonstarter for me.
ciagovv ( @ciagovv@lemm.ee ) 7•2 years agoHonestly, it’s just better to use bitwarden, as they have more reputation, or keepass and syncthing if you want to keep your passwords off the internet completely
Stanislav N. aka pztrn ( @pztrn@bin.pztrn.online ) English5•2 years agoBetter use Bitwarden + self-hosted server like vaultwarden.
Thembo McBembo ( @ThemboMcBembo@beehaw.org ) English1•2 years agoWhat are the advantages? :)
Stanislav N. aka pztrn ( @pztrn@bin.pztrn.online ) English1•2 years agoTo keep passwords safe due to not using anyone’s cloud infrastructure? :)
Yes, of course, there are many more things to take into account when choosing password manager, especially self-hosted. But IMO these things should be self-hosted in first place. Remember all these LastPass breaches?
Leigh ( @SemioticStandard@beehaw.org ) 4•2 years agoI don’t see any reason to migrate away from 1Password, which works great for me. I have a family plan and everyone in the house has their own personal vault.
renard_roux ( @renard_roux@beehaw.org ) 5•2 years agoFor me it was the subscription that pushed me away. Now on BitWarden, very happy.
SPOOSER ( @Spooser@lemmy.zip ) 4•2 years agoI use Protonmail and I really love it. Has anyone had experience with their password manager?
thann ( @thann@beehaw.org ) 3•2 years agoAnyone able to find the source?
bird ( @bird@beehaw.org ) 3•2 years agoI really want to try this out, but there isn’t MacOS Safari support. :(
jplexer ( @jplexer@apollo.town ) 3•2 years agoMy Bitwarden Subcription was about to renew, so I subscribed to Proton Pass and its pretty cool
withersailor ( @withersailor@aussie.zone ) 2•2 years agoProton’s new password manager not only applies E2EE to your passwords but also the usernames, web addresses, and all the other fields associated with your login information. In a blog post explaining the service’s security model, Proton notes that “all cryptographic operations, including key generation and data encryption,” happen locally on your device, which Protons says it can’t decrypt, even if a third party requests it.
No support for passkey yet, but coming.
Marks ( @Marks@beehaw.org ) 1•2 years agoI love the built in 2factor
sophs [she/her] ( @s0phia@beehaw.org ) 1•2 years agoI started using it on Firefox now, seems pretty good so far. Maybe I’ll stay, or go back to Bitwarden. Who knows.