Introducing Proton Authenticator: Secure 2FA, your way

I think this is an important point. Even if we do not think that Proton is trying to grow their consumer base, it can still be their primary targeted audience, which I discuss below.

I think you may be attributing malice needlessly to Proton. If their consumer base knew what Bitwarden Authenticator or Aegis were already, then there would be no need to market to them. It could be that the targeted audience here is not people within the privacy community who are already aware of the many alternatives, but rather the many people who use privacy-invasive products/services from big tech such as Microsoft or Google.

To the average internet user, Proton Authenticator would be entering the field as a competitor of MS Auth and Authy and Google Auth. However, to people within the privacy community, we know that Proton Authenticator’s actual competitors are that of Aegis and Bitwarden and the likes. If it is true that Proton’s targeted audience is outside the privacy community (which I think is the case), then I see no intentional malice being done.

Competition is not a word that can make sense by itself in this context. Businesses compete for customers. If Proton promotes their new Authenticator app as being a competitor of MS Auth and the likes, then their targeted audience is IMO clearly big/privacy-invasive tech customers.

5 Likes

This is a silly thing to be mad about. No company has their marketing team mention other available alternatives when they promote a new product, unless its to throw shade like they did at Microsoft.

1 Like

According to this reddit post the TOTP secrets are stored in plaintext, the user discovered this while creating a log file.

2 Likes

Can you check your link because it is not working.

1 Like

Here’s the link here, I saw this earlier too

1 Like

Well, I also discovered that at least the local backup option on Android stores everything in plain text. I don’t think there is yet confirmation how they do this on iOS or could they be storing those backups unencrypted in the cloud as well.

I wanted to try and replicate this with Proton Authenticator but the app just crashes for me. Which was an issue previously, then it started working following an update, and now crashing again.

If what this Reddit post claims is true, it’s beyond concerning. Especially when paired with this post:

1 Like

nice to have 10 working fingers …

2 typing digits is a pain !

100% agree with this.

People here and on reddit or Lemmy seem to think that the Proton client base is some sort of monolithic group of security snobs and ghosts that expect only their needs met. Proton’s running 100 million accounts. Which may actually be more than 10 million real people (I know I have 3 accounts).

It’s a diverse pool of people, and it’s a solid first stop for people on a De-Googling journey. Self-hosting one’s email isn’t something I can convince my spouse or family to do when they don’t see anything wrong with posting photos on Facebook from their Chrome browser with 900 tabs open on Win11.

I’m not even a fan of every single thing Proton does, but I’m a paid subscriber and the misplaced, under-informed and overly-contorted expectations and hate really only demonstrate to me that they’re trying stuff and looking at what else they can do for a more encompassing UI. Growing pains are real, early adopters find bugs, and the most conservative among us should know better than to jump into something brand new and expect it to be 100% locked down. Anyone who doesn’t realize that doesn’t deserve to complain loudly that something wasn’t perfect from the start. That’s unreasonable. But they probably don’t pay for anything anyway.

1 Like

Came here to ask about the same thing. Link I saw: Reddit - The heart of the internet

Try it out. I did. It’s no better than Ente which has tags and some other organizational features. But it works, and I see it as a ā€œpublic serviceā€ app that will bring no revenue to them. There is no Mac desktop app, in reality it is the iPad app ā€œcompatibleā€ with Mac. I am sticking with Ente Auth which is really good.

I also agree with many comments on this forum saying that the launch was not clean.

And it worries me that the logs do contain all the secrets in plain text. This is a really BIG oversight from them to be honest.

Here is Protons follow up to that. They did release a patch on iOS this morning.

Thanks for reporting this, this is an oversight in our iOS app, it should only log the entry ID and not the secret (this is the way it is done in our Android app). This will be changed in the next version of the app.

Note, secrets are never transmitted to the server in plaintext, and all sync of secrets is done with end-to-end encryption. Logs are local only (never sent to the server), and these secrets can also be exported on your device to meet GDPR data portability requirements. In other words, even if this was not in the logs, somebody who has access to your device to get these logs, would still be able to obtain the secrets. Proton’s encryption cannot protect against device side compromise, so you must always secure your device.

4 Likes

https://archive.is/fqw4R

mods on r/privacy removed the post

reply from Proton team:

Thanks for reporting this, this is an oversight in our iOS app, it should only log the entry ID and not the secret (this is the way it is done in our Android app). This will be changed in the next version of the app.
This is fixed in 1.1.1, which is live on the App Store

1 Like

I understand you but from my POV the most important thing is to drive away users from big tech services, not from other privacy projects.

To be fair, ente does not compare itself to Proton photos on their website

2 Likes

I guess that depends on what your definition is for considerably longer is. If by 5 or 6 seconds is considerably longer to you then I guess it is. When I go to unlock my phone there isn’t anything that cant wait an extra 5 seconds for me to get into my phone. If I ever need to call 911 that can be done without unlocking the phone. So I really don’t see the downside to using the password. If I had fat fingers and it took me a minute to enter my password then I would probably reconsider using a password.

That would’ve been trivially caught given 5 minutes of testing by their devs. This poor behavior is starting to become a pattern for Proton.

Makes one wonder do they not pentest their products before major release? I mean this seems obvious to check.

6 Likes

So, the version 1.1.1 fixes this and yet, Proton doesn’t share that in the release notes, and only talks about fixing something with import. Seems like they want to limit the spread of the information that their app had a serious security issue :roll_eyes:

2 Likes

I see many comments saying to avoid being in Proton’s ecosystem, but also many who are in the Apple ecosystem already.

I think being in an ecosystem is fine as long as you can easily bail if/when policies go down the toilet. Apple’s ecosystem isn’t exactly easy to leave, especially if you have all their hardware.

Just backup critical data in multiple locations/services.

But specific to the Auth app, I like that it has .rpm Linux support from the go.
Now, Proton Drive support plz…

Ente Auth (and Photos) has a verified flatpaks. I usually prefer flatpaks to .rpms on linux (Secureblue on my case).