Beginner advice: Go all-in on Proton vs keeping my current setup?

Hey everyone,

I’m a privacy newbie trying to figure out my setup. I don’t have tons of data, but I want to protect my basics (emails, passwords, browsing, location) from Big Tech, public WiFi snoops, and my roommates. I also need to bypass local ISP blocks in Italy (Piracy Shield) and do some torrenting.

I still use WhatsApp for social reasons, but I want to de-Google the important stuff.

Right now I’m using:

  • Firefox
  • Bitwarden for pass
  • NordVPN Premium but will soon expire

I need a secure email and I was looking at Proton. Since my needs are pretty basic, does it make sense to just grab an entry-level Proton plan and move everything there for convenience (ProtonMail, Proton Pass (also for aliases), ProtonVPN)?

Or is it really that better and secure to stick with Bitwarden + NordVPN, and just use Proton for email?

Thanks for any tips!

Proton is easy to use and beginner-friendly, so I recommend to switch to Proton Mail and VPN. There are other good options, too, though I imagine you’ll be happy with Proton’s ecosystem.

Using an ecosystem instead of multiple services from different companies has both benefits and downsides, but I think this is not that relevant for beginners.

You could stick with Bitwarden for now and focus on transitioning your email and other services first. When you’re comfortable, you could try out Proton Pass and switch to it if you like it better (the email alias integration is really nice). Remember to take it slow and not burn out (your privacy journey is a marathon, not a sprint).

Regarding Firefox, I recommend to harden some of the default settings and to install only a single extension: uBlock Origin. You can find more information about browsers on these Privacy Guides pages:

Thank you for your advices. I was wondering, you said I should only install uBlock as extension but what about BitWarden? Do you reckon it’s better to use the app? Because I’m currently using the extension.

Also, what about firefox for android? It’s not mentioned in the guide.. Is there any particular reason?

Browser extensions make you stand out and can make you unique. It’s part of browser fingerprinting. Besides that, browser extensions increase your attack surface, since they can get access to almost anything you do in the browser.

You could use the Bitwarden and/or Proton Pass extension besides uBlock Origin. I prefer to use the desktop application. I think that your preference is more important in this case.

Firefox-based browsers for Android are less secure than Chromium-based browsers. I use primarily the Brave Browser on my devices (in combination with other, more niche browsers like the Tor Browser).

I see this mentioned often but I wouldn’t be concerned about it if you aren’t using a browser that seems to be effective against commercial fingerprinter, fingerprint.com, for surveillance capitalism threat model. That being, Mullvad and Tor Browser.

Fingerprint.com demonstrates cross-profile and incognito tracking on chromium-based browsers in my experience, regardless of extensions.

100% agree about attack surface, though and also extensions are frequently compromised or malicious. Not saying that a trusted extension like Bitwarden would have that happen, it’s mostly random shady extensions, but something to note.

I think going all in on the Proton ecosystem makes sense if your threat model allows for it and you understand the limitations. It’s great value if you use all the products.

It’s also easy to migrate away from the ecosystem, you can change your VPN and password manager and so on pretty easily in the future should you want to break things up a little more.

Regarding Bitwarden application vs extension, I definitely prefer the app for both privacy and security. The browser has a huge attack surface and has a lot of moving parts, so since my password manager is probably the single most sensitive piece of software I use, I don’t want it to be integrated into my browser. Also the extension can be fingerprinted, so there’s that.

Whatever you do I recommend moving away from NordVPN to something more reputable, such as IVPN, Mullvad or Proton.

Personally, I lean against putting all my eggs in one basket – I use Proton mail, but I use Bitwarden for pw (like you), and other products from other sources. That way, if one goes down or is compromised, everything else isn’t as well.

I agree with those recommending you at the very least switch to one of PG’s recommended VPNs. Given your stated needs, I don’t think Proton’s suite sounds like a bad idea. :slightly_smiling_face:

To your overall question, other threads in this forum have some relevant reflections. In particular, I recommend you read through this one, offering advice specific to your dilemma:

I personally find the idea of “bundles”, “buckets” or “islands” helpful. Specifically, what services and data makes sense for the same providers to handle / what you want more or less easily linked. Two examples:

In general, have a look through the PG recommendations. Even without the bundles, they provide decent options, including recommendations for configuring Firefox.

Thanks everyone for the replies and advice!

After thinking about what you all said, here’s how I’ve decided to proceed: for now, I’ll stick with NordVPN since my subscription is still active, but as soon as it expires, I’ll make the switch to Proton VPN.

Unfortunately, I don’t really have a budget allocated for this stuff right now, so I’ll try to make the most out of the free/budget-friendly options for the time being. I’m going to use Proton for my emails (and take advantage of their aliases as a result). For passwords, I’ll keep things separate by using the Bitwarden app across all my devices. For 2FA, I’ve decided to go with Ente.

As for browsing: on my PC, I’ve set up a privacy-optimized Firefox with uBlock Origin and DuckDuckGo as my search engine. On mobile, I’m going to use Brave and set up AdGuard DNS directly on my phone.

Once you get to three plus services. There is no beating Proton price wise.

That being said I am not sure if (1) you require the premium version of each service and (2) if price is more important then vendor lock-in. I would say if you don’t require all three premium services or do not want to be locked into one ecosystem its better to test the waters with other services (check PGs reccomendations for alternatives).

Seems like an okay strategy. Don’t rush the things. Make slow steps to improve your privacy and it will be easier to live with.

Regarding the discussion on extensions. Yes generally only Unlock Origin should be used. However complex passwords are very important, and because a password manager can also recognise the website, it can also help defending against phishing. I wouldn’t worry about adding bitwarden or proton pass as an additional add-on.

Like on our website is written using a VPN does not make you anonymous.

so you’d suggest I remove my 1password browser extension (desktop Firefox) ? just log in via a new tab should I need it?

on my phone I use 1p and brave browser (now, was using duck) and PIA for VPN, and migrating away from G maps to osmand and I forget the newer one I just learnt of..

Linux desktop 1p and Fastmail now (desktop and phone) choosing it over Proton as it had more flexibility with email aliases (something I find essential to dealing with everyone wanting your email and then selling it on) but the trade off was less cloud space than Proton, maybe by a factor of 5 (50gb v 250gb ? :thinking:)

Fast mail has calendars, cloud storage, contacts so it does a big part of carrying that load for me.

If you want true privacy switch to Linux if you are using Firefox switch to any privacy search engine . You can also switch to proton email and their vpn is too good and it is worth it.i if you want any social chat app you can switch to Simplex.

If you’re considering shifting away from a free Gmail address, what I strongly suggest is you buy a domain and use that for your email. It’s very easy to do, and relatively inexpensive. You can have Proton host the email and get all the benefits of both worlds.

The primary reason to do this is that if you own the domain, you can change email hosting a hundred times and you keep the same email address. Proton’s Mail Plus plan supports this already, so you might as well get your money’s worth. I did this a couple years ago, and kick myself because I didn’t do it earlier.

This also enhances privacy in that if your hosting allows for multiple addresses (Proton allows 10 on one domain), you can have your main account under something like Mainaddress@domain.com and then you can create other addresses, like yourname@domain.com or whatever. One address gets too much spam? Delete it. Don’t trust a service? You’re not using the same address used to log in to your email to sign in to other services. So leaked credential lists can’t be used to hijack your email account. Your financial logins are under Yournamemoney@domain.com so leaked credentials can’t hijack your money.