# Proton Pass (Password manager)

**URL:** https://discuss.privacyguides.net/t/proton-pass-password-manager/12416
**Category:** Tool Suggestions
**Tags:** completed
**Created:** 2023-04-20T21:36:09Z
**Posts:** 174

## Post 1 by @PoorPocketsMcNewHold — 2023-04-20T21:36:09Z

> **[Proton Pass is now in beta | Proton](https://proton.me/blog/proton-pass-beta)**
>
> The beta version of Proton Pass, Proton’s new password and identity manager, is now available to Proton Lifetime plan subscribers.

> Today, we’re happy to announce another significant milestone in the growth of the Proton ecosystem with the launch of the Proton Pass beta for Lifetime and Visionary users. Invites will roll out over the next week, and **you’ll receive an email from us at your Proton Mail email address when you’re eligible**.  
> […]  
> A password manager has been one of the most common requests from the Proton community ever since we first launched Proton Mail. However, while Proton Pass uses end-to-end encryption to protect your login credentials, it will be much more than a standard-issue password manager. This will become clear over the next weeks and months as we prepare Proton Pass for a public launch later this year.  
> […]  
> We’re launching Proton Pass now for two primary reasons. First, joining with SimpleLogin increased our ability to develop a new password manager without impacting efforts on other Proton services. Second, passwords are such sensitive information that an insecure password manager is a risk to the Proton community. Proton Pass is not just another password manager. It’s perhaps the first one built by a dedicated encryption and privacy company, leading to tangible differences in security. For example, while many other password managers only encrypt the password field, Proton Pass uses end-to-end encryption on all fields (including the username, web address, and more).

> **[Proton announces Proton Pass, a password manager | TechCrunch](https://techcrunch.com/2023/04/20/proton-announces-proton-pass-a-password-manager/)**
>
> Proton, the company behind Proton Mail and Proton VPN, is announcing a password manager called Proton Pass.

> **[Proton launches an end-to-end encrypted password manager](https://www.theverge.com/2023/4/20/23691097/proton-end-to-end-encrypted-password-manager-e2ee)**
>
> Proton Pass is only available as a beta for now.

_Still limited to a few testers, not fully edited or released yet, obviously. They do point out that they haven’t had the green flag for the Firefox extension of it, recommending Brave Browser until then._

---

## Post 2 by @canary2638 — 2023-04-21T00:42:21Z

I tried searching for it in the Chrome Web Store (for Brave), and I can’t seem to find it.  
Is it just me?

I managed to find it in Google Play Store though.

---

## Post 3 by @anon73250778 — 2023-04-21T05:54:36Z

I mean I get it, limiting people/company/software/apps trust to less entities and maybe limiting the attack surface as well, but at what point does ito becomes all egg in one basket kind of situation?

---

## Post 4 by @anon30510143 — 2023-04-21T06:16:51Z

In my opinion, using any password manager is putting all your eggs in one basket. If someone gains access, all your accounts are compromised no matter which one you go with. So you might as well make it slightly more convenient by keeping everything in one place. Just my thoughts though.

---

## Post 5 by @anon66296745 — 2023-04-22T15:07:43Z

When Proton Pass comes out I don’t see a reason to list Bitwarden anymore and here are a few reasons why just out of the top of my head:

- [This](https://tosdr.org/en/service/1348).

- FIDO2 WebAuthn being paywalled.

---

## Post 6 by @ph00lt0 — 2023-04-22T16:52:38Z

If you don’t put your 2FA codes in it i don’t really agree but I get your opinion. Still passwords managers are the only way to make people use good password security so I don’t see a way without them.

Proton Pass is still in beta for now and we should wait a bit to see how things will evolve. Other password managers as of now are more feature rich. But i am confident this will become a good option and I probably will use it eventually

---

## Post 7 by @ph00lt0 — 2023-04-22T16:53:16Z

I had the same and asked the team. All Visionary users will get download links in the coming weeks.

---

## Post 8 by @PoorPocketsMcNewHold — 2023-04-22T20:36:16Z

Would still be worth being listed, as a self-host option. When self-hosting, most critics of their terms of services aren’t taken in consideration, and paid locked features are free.

---

## Post 9 by @anon66296745 — 2023-04-22T20:48:06Z

Self-hosting a password manager isn’t something that I would recommend for an individual. But that’s just me.

---

## Post 10 by @matchboxbananasynergy — 2023-04-22T20:50:27Z

I think the important thing to look forward to when looking at password managers is passkey support. Both Bitwarden and 1Password (the cloud options listed on Privacy Guides) have committed to supporting them.

I find it difficult to believe that Proton Pass won’t do the same, but I think we should at least wait until it’s stable/more feature rich. Password managers are critical pieces of software, so they require careful consideration before they’re adopted/recommended.

I disagree with de-listing Bitwarden, by the way, as they’ve shown that they’re willing to improve and have over time, but regardless, even if we were to have that conversation, it should be in its own thread, not here.

---

## Post 11 by @Kris — 2023-04-23T02:30:50Z

I stay with my local KeePassXC. I trust my computer more than any cloud

---

## Post 12 by @ph00lt0 — 2023-04-23T07:29:45Z

KeePassXC called out Proton for the narketing claims:  
[https://twitter.com/KeePassXC/status/1649417549510062081](https://twitter.com/KeePassXC/status/1649417549510062081)

---

## Post 13 by @anon73250778 — 2023-04-23T15:28:27Z

KeePassXC has no chill :rofl:.

Their rants are not without merit though. In the grand scheme of things, it is fine.

---

## Post 14 by @Nour — 2023-04-23T16:44:13Z

I can definitely see where KeePassXC are coming from, but I initially read the Proton announcement and didn’t think it was a big deal since it obviously seems targeted towards commercial/mainstream password manager users (like LastPass) and not people who use KeePassXC or similar.

---

## Post 15 by @susan — 2023-04-28T05:25:15Z

Until more people get access to it and there is a more verified audit, I will stick with Bitwarden. Most probably I will migrate to Proton Pass, but also it is very important for me to have the same functionality as Bitwarden. I love to use the Bitwarden storage as a safe backup for really important documents that I can than Bitwarden shares automatically with my family in case of death(It is set to send them 60 days after the last login), which looks like it is not possible with Proton Pass.

---

## Post 16 by @anon73250778 — 2023-04-28T06:19:09Z

I need it to be better than bitwarden, and maybe more closer to the features of KeePassXC but I am already a paying customer of Proton.

---

## Post 17 by @CostcoFanboy — 2023-05-22T21:50:25Z

Removing BitWarden, the most highly regarded password manager out there, because you don’t want to pay 10$/y for FIDO2 is absolutely nuts.

---

## Post 20 by @xe3 — 2023-06-06T20:59:07Z

Yeah without articulating reasons why Proton Pass is functionally better, or shortcomings of Bitwarden, its crazy to suggest removing Bitwarden simply because Proton _announced_ / _is beta testing_ a new and unfinished password manager of their own. Especially onsidering Bitwarden is one of the two most well regarded password managers (the other being 1password), and considering that the main complaint seems to be there is a small and extremely fair yearly cost.

---

## Post 21 by @canary2638 — 2023-06-07T01:02:53Z

(Preface: Am paying Bitwarden user and am not advocating for de-listing of Bitwarden)

I don’t really understand why Bitwarden keeps FIDO2 WebAuthn behind a paywall though.

I assume maintaining FIDO2 WebAuthn support probably takes up some of Bitwarden’s resources.  
But if they’re really serious about providing an open-source solution to password management with high level of security, then FIDO2 WebAuthn support really shouldn’t be the piece that they dangle in front of free users to entice them to pay.

Afaik, Bitwarden doesn’t do regional pricing, so $1 per month could still be a (minor) financial burden for some people around the world, compared to what $1 per month means to, say, someone in Europe or North America.  
Security keys are even more expensive, but there are different ways of obtaining them for free or with heavy discount. And security keys have much more applications beyond just one service and doesn’t involve any recurring fees.

For a password manager, using FIDO2 WebAuthn as 2FA is probably the gold standard, for now anyways.  
I wouldn’t trust or take seriously any password manager that doesn’t support FIDO2 WebAuthn (i.e. Dashlane afaik).  
If there ever was a high-priority application for security keys, it’d be for password managers.

In this front, Proton Pass would definitely have an edge over Bitwarden.

Like others said, it is definitely premature to consider listing Proton Pass on PG, especially since how buggy and feature-poor some of Proton’s service have been at launch.  
But Proton Pass should definitely be an option to keep at a corner of the PG team’s mind, imo.

EDIT: Forgot to point out that another PG-listed password manager Psono offers FIDO2 WebAuthn as 2FA even at the free tier.

---

## Post 22 by @CostcoFanboy — 2023-06-07T01:35:52Z

> I don’t really understand why Bitwarden keeps FIDO2 WebAuthn behind a paywall though.

They’re allowed to make money dude. Wanting BitWarden to essentially be a non-profit company is absolutely nuts. They need to pay their staff somehow. This is even more ridiculous with their offers of self-hosted. It’s just 10$/y. You all need to get over it. That’s ridiculous.

They literally have the best reputation in the industry.

1Password doesn’t do regional pricing either and everyone licks their butthole. I say this as a 1Password user. Regional pricing is actually fairly rare in companies. Even without regional pricing 10$/y is dirt cheap except if you live in some GENUINELY financially destitute countries like Venezuela, Turkey or Argentina. The extremes of the extremes.

Otherwise it’s affordable by many.

---

## Post 23 by @ph00lt0 — 2023-06-07T09:33:39Z

It’s funny when you mention the webauthm pricing issue together with open source as if you actually would have checked, when self hosting bitwarden it is not paywalled so that invalidates your argument.

Nevertheless I agree that paywalling security is odd. I would have suggested other restrictions, but just pay 30 a year for your family and you can share passwords to your netflix accounts :slight_smile:

---

## Post 24 by @canary2638 — 2023-06-07T20:56:26Z

You’re missing my point.

[1] I never questioned the reputation or motives of Bitwarden.  
Like I said, I’m a paid user, and I wouldn’t go with Bitwarden if I didn’t trust them.

[2] I also never dismissed the financial aspect.  
I never said they’re not allowed to make money or should be a non-profit organization, or criticized them for being a for-profit company.  
I specifically said that a strong 2FA option shouldn’t be the thing that they highlight to entice free users.

[3] I also never said regional pricing is a common thing.  
I was talking about regional pricing in regard to accessibility of Bitwarden and its many features for many people around the world.

[3] Paywalling security is just unusual and seems inconsistent with the aim of providing a highly secure password manager (though not in any way a dealbreaker for me).  
This is especially true when competitor like Psono doesn’t paywall a strong 2FA option.  
Pointing this out is not an attack on Bitwarden as a product or company.  
Biwarden paid tier offers things like encrypted file attachments, authenticator, emergency access, priority support, encrypted password sharing and etc.  
These extras should be compelling enough to convince someone to spend $1 a month.

[4] Self-hosting isn’t an option for everyone, whether due to pricing, technical knowledge, or etc.  
More importantly, FIDO2 WebAuthn as 2FA is still paywalled even if you self-host, last time I checked when considering self-hosting.

[5] If you think that Venezuela, Turkey, or Argentina are representative examples of what I meant, you really need to expand your world view.

Anyways, it’s not my intention to hijack a thread about Proton Pass to talk about another product, so I’ll stop now…

---

## Post 25 by @xe3 — 2023-06-07T23:05:16Z

> I specifically said that a strong 2FA option shouldn’t be the thing that they highlight to entice free users.

I can respect where you are coming from, and feel that generally speaking encouraging security best practices or at least not discouraging them is commendable. But In my opinion, hardware 2fa support is exactly the type of thing that is reasonable to include as a premium feature considering that:

1. It is a feature that probably less than 1% of users use excluding orgs, enterprise and business customers who 100% should be paying customers.
2. They do offer strong free alternatives (TOTP as an example) sufficient for the vast majority of use-cases/threat models.
3. Everyone using a hardware key has already shown a willingness to spend money on security. It seems inconsistent to be willing to spend ~$50 at a minimum on hardware keys and then balk at the idea of paying $10 a year for a password manager.

---

## Post 26 by @Viper — 2023-06-25T02:52:57Z

For those that have access to this, does it have 2fa like in bitwarden free? Tx

---

## Post 28 by @Laitinlok — 2023-06-25T04:14:03Z

Nextcloud also encrypts your data so essentially double encryption.

---

## Post 29 by @vicky — 2023-06-25T15:07:34Z

TBH, while proton pass is good, it is not good enough yet to be listed. It needs time. At least 6 months more, to come to the level of Bitwarden in ease of use. While the Firefox extension is good, the android app is nowhere close to Bitwarden’s in ease of use, and comfort. Better to look back at Proton Pass after a couple of more months, and to shelf this suggestion for now. One point Where Proton Pass exceeds Bitwarden currently is that the UI Design looks a lot nicer and beautiful than Bitwardens.

---

## Post 30 by @vicky — 2023-06-25T15:08:32Z

Yes it does

---

## Post 31 by @ch3k — 2023-06-25T16:14:58Z

what do you mean by supporting 2fa? If you’re talking about putting 2fa for accounts in the password manager, that won’t make any difference to security, assuming your randomly generated passwords are already long enough.

Whole point of 2fa is to protect accounts if your password manager somehow gets compromised, whether that be due to malware on your device, or a breach of the password manager. If you’re putting 2fa secrets in the password manager.. that’d also be compromised along with the passwords.

---

## Post 32 by @ch3k — 2023-06-25T16:20:23Z

Anyone know if this is selfhostable? As not being able to self-host it would be a deal breaker for me.

Gotta say, the overall ui & simplelogin integration of protonpass looks nice

---

## Post 33 by @Viper — 2023-06-25T16:25:59Z

Yes putting 2fa totp inside password manager. I currently use keepassxc but no sync :sleepy_face: i need cross platform, and would like sync.  
Bitwarden for passwords.

---

## Post 34 by @ch3k — 2023-06-25T16:31:18Z

> Yes putting 2fa totp inside password manager.

Yeah i wouldn’t bother doing this, just gives people a false sense of security really. Theres no increase in security unless the service you’re using is capping password length to a very small number of characters, in which case 2fa would increase entropy.

If you want 2fa to actually serve a purpose, keep it on a seperate device like a phone, its not meant to in your password manager or synced. [Authenticator Pro](https://github.com/jamie-mh/AuthenticatorPro) or raivo if you’re on ios, are good apps for it.

---

## Post 35 by @Laitinlok — 2023-06-25T18:47:51Z

2fa the password manager login I think

---

## Post 36 by @Laitinlok — 2023-06-25T18:49:19Z

Probably why I now use yubikey or yubico authenticator

---

## Post 37 by @xe3 — 2023-06-25T21:27:36Z

> [@ch3k](#):
>
> Whole point of 2fa is to protect accounts if your password manager somehow gets compromised.

I respectfullly disagree. I used to share this opinion, but I came to realize it was a misconception on my part.

The “_Whole_ point” of 2fa has nothing to do with password managers. 2fa _can_ mitigate the harm caused if your vault is breached, but this is not the only (or even primary) reason 2fa exists, and the other benefits still apply if you keep your 2fa secrets in your vault. (and remember that your vault should be protected with it’s own 2fa so any attacker who gains access to your vault has already demonstrated an ability to get around your 2fa at least one time).

A password manager breach is one of the most catastrophic _BUT least likely_ ways in which your accounts can be compromised.

Conceptually 2fa simply means that we raise the bar for accessing an account from one ‘factor’ to two ‘factors’ (something you _know_ (a password) and something you _have_ (access to, like a phone, a security key, etc). This is a rather simple concept that can apply to your security in various ways.

The likelihood of one of your accounts being breached due to your password manager vault itself being breached is substantially _less likely_ than some of the more common ways accounts are compromised:

1. Getting your credentials through Phishing or human engineering.
2. A breach of the remote website, server or service
3. Malware/Spyware
4. Sloppiness, negligence, or laziness on your part (reusing passwords, using easy to guess passwords, writing passwords down, storing passwords in an unencrypted format, etc).
5. Some sort of targeted attack (spearphishing, keylogger, etc) if you are wealthy enough or interesting enough to be a target.

In all of these cases–which are more common than password manager vault breaches–using 2fa through your password manager would provide the same degree of protection as 2fa from another app or hardware key. 2fa in any form will meaningfully improve security over no 2fa at all. And the likelihood of your password manager being breached is much lower than other threats that 2fa might protect against.

---

## Post 38 by @ch3k — 2023-06-25T21:43:29Z

> using 2fa through your password manager would provide the same degree of protection as 2fa from another app or hardware key

First of all, hardware keys share one key advantage over software, in that its not prone to phishing, so they shouldn’t be grouped together

Second, there’s quite literally zero increase in security when putting 2fa secrets in your password manager. What possible attack scenarios would it protect against?

Two reasons to use 2fa, (alongside a password manager), would be:

1. the PW manager encountering a breach

2. Or more likely, the user’s computer being infected with malware. However these are only valid when 2fa secrets are stored on a seperate, secure, device.

When placing 2fa secrets in the password manager, you’d be compromised in both of these scenarios, if the PW manager has had a breach, your 2fa secrets are also gone. If you were infected with malware which gets your PW manager’s database, it would also have access to your 2fa secrets.

> Malware/Spyware/targeted keylogging attack

as mentioned above

> Sloppiness, negligence, or laziness on your part - reusing passwords

You’d be breaking the fundamental reasons to use a password manager by re-using passwords. If you created a unique password per service, you’d be protected against this.

> Getting your credentials through Phishing or human engineering.

software 2fa wouldn’t protect against this

> A breach of the remote website, server or service

passwords should be unique

Storing 2fa secrets in a password manager only leads to a false sense of security, you might as well just not use 2fa for convenience if the passwords you generated via the PW manager were long enough.

---

## Post 39 by @xe3 — 2023-06-25T22:17:45Z

> [@ch3k](#):
>
> Storing 2fa secrets in a password manager only leads to a false sense of security, you might as well just not use 2fa for convenience

Respectfully, I believe this is very poor advice based on a misconception.

> Second, there’s quite literally zero increase in security when putting 2fa secrets in your password manager. What possible attack scenarios would it protect against?

It would provide protection in _any_ attack scenario where any other form of (TOTP) would protect you, except for the unlikely scenario of a properly secured vault being breached. When comparing between TOTP stored in your vault versus TOTP (or SMS or e-mail), storing TOTP in the vault is at least as secure as the others in all areas except for one of the less likely scenarios (a vault breach).

As you correctly stated hardware keys are a separate topic that shouldn’t be grouped into a comparison of TOTP stored in the password manager vs TOTP in a standalone app, so lets leave them out of this discussion.

Compared to TOTP through your password manager, you will be _marginally_ more secure with a separate (password protected) TOTP app against one threat vector, and marginally more secure with hardware 2fa than any form of TOTP. But the difference is marginal.

_ **In a nutshell my perspective is this:** _ If you want the absolute _highest_ security a hardware key/token is the best choice for a 2nd factor. But if TOTP is sufficiently secure for your threat model, the difference in security between a standalone TOTP app and using your password manager as a TOTP app is at best marginal, and you should choose whatever is most comfortable/convenient for you or whatever makes you feel comfortable.

---

## Post 40 by @ch3k — 2023-06-26T00:25:36Z

> It would provide protection in _any_ attack scenario where any other form of (TOTP) would protect you

But what specific scenarios would 2fa, (when having 2fa secrets stored in the same PW manager), protect against? The two I mentioned weren’t prevented when storing 2fa secrets in the PW manager.

---

## Post 41 by @anon74790864 — 2023-06-28T11:12:47Z

Proton Pass has been released to everyone.

---

## Post 42 by @susan — 2023-06-29T00:47:40Z

I gave it a try. For the coming year I’m going to still use bitwarden. Is so much better right now, and also I already have it configured like I wish.

---

## Post 43 by @Viper — 2023-06-29T06:05:39Z

Tried proton pass specifically for 2fa topt codes. Happy it works but sad its a paid thing. Game over. Until they make it free 2fa top codes i cant use it for I’m poor af.

---

## Post 44 by @dngray — 2023-06-29T06:09:28Z

> [@CostcoFanboy](#):
>
> Removing BitWarden, the most highly regarded password manager out there, because you don’t want to pay 10$/y for FIDO2 is absolutely nuts.

We wouldn’t be removing it unless there was something wrong with it. After all it is the only option with self hosting capability.

As for storing TOTP codes in a hosted password manager, it’s not ideal because it’s really **reducing security to one thing** - authentication to your password manager. Also we wouldn’t suggest storing once-use “backup codes” in there either.

For once use-backup codes I don’t store these on my devices. Something like a LUKS/VeraCrypt container on a few USB sticks or backed up offsite is enough. You could even [attach](https://bitwarden.com/help/attachments/) the LUKS container to your password manager and that would not reach the filesize limit, after all the backup codes are only text files and there is no reason the container couldn’t be 50MB. That way even if access to your password manager was gained the encrypted file would still require a separate password. Obviously don’t store that password in Bitwarden, if you do that.

For convenience however I can see the reason why people might just use a password manager for storing TOTP codes. If you’re going to do that I would think about the value of such codes, for example I would not store a domain/email TOTP secrets in a password manager. It would be totally reasonable to have Aegis with those two things in it, while storing other less valuable TOTP codes in Bitwarden. The exported Aegis JSON file could be added to your LUKS container however for backup. Another good thing to add there would be your LUKS [volume headers](https://www.privacyguides.org/en/encryption/#linux-unified-key-setup).

TOTP codes are not the strongest way to do MFA because they rely on a shared secret. FIDO based security such as using a security key is always the better approach because it provides attestation and doesn’t require the service to hold any private secrets, that makes it the “best” security.

---

## Post 45 by @jonah — 2023-06-30T14:32:23Z

I don’t know why this is seemingly impossible to find out, but I want to know if you link a paid Proton Pass account— **not** Unlimited/Business/Visionary, just the standalone Pass subscription—to a free SimpleLogin account, does it upgrade that SimpleLogin account to Premium status?

If anyone has tested this and _knows for sure_, please let me know.

---

## Post 46 by @Mossturtlecoffee — 2023-06-30T16:02:13Z

The mail addresses generated end in @passinbox.com.

---

## Post 47 by @Mossturtlecoffee — 2023-06-30T16:18:30Z

But the generated passinbox address already appears in Simplelogin.

When I look in SimpleLogin in the PGP settings it says: This feature is only available in premium plan.  
Despite the fact that I have Proton Plus.

---

## Post 48 by @jonah — 2023-06-30T17:00:40Z

> [@Mossturtlecoffee](#):
>
> I have Proton Plus

Proton _Mail_ Plus or Proton _Pass_ Plus? Mail Plus does not come with SimpleLogin. I’m trying to figure out if _Pass_ Plus unlocks SimpleLogin Premium features.

---

## Post 49 by @Mossturtlecoffee — 2023-06-30T17:26:21Z

Only Pass Plus.

I can manage the aliases in SimpleLogin that I generated in Proton Pass. But I do not have access to SimpleLogin Premium features.

---

## Post 50 by @whoami2 — 2023-07-01T13:04:41Z

Tried the Proton Pass app and extension as an Unlimited user. The extension version is nicer than Bitwarden for sure, it detects some website’s login field better, also offers a nice looking drop-down menu.

The app version however… is a bit lacking. One thing that always bugged me was the incomplete autofill implementation in password manager apps on android. Bitwarden got it right for both Firefox and Chrome(ium). For Proton Pass, it has some issues for usernames in Brave. Works for Firefox and Vivaldi though.

It is also mildly annoying the vault can only be managed from the extension and the app, visiting pass from the web just shows you the settings page.

---

## Post 51 by @Ouros — 2023-07-02T06:00:05Z

I’m not really sure if I want to use it, but I’m tempted to pay the promotional price of $12 per year for the premium service. I quite liked the aesthetics, but I don’t use Proton’s email service much, so I wouldn’t use the hide-my-email system as often.

Generally, I use Bitwarden, and I like that you can paste the API key for the DDG hide-email service, but I have my doubts about this Proton service.

---

## Post 52 by @in_the_city — 2023-07-02T23:13:29Z

> [@anon66296745](#):
>
> When Proton Pass comes out I don’t see a reason to list Bitwarden anymore and here are a few reasons why just out of the top of my head:  
> .
> 
> - FIDO2 WebAuthn being paywalled.

God forbid they make some money. It’s $10 a year. :roll_eyes:

---

## Post 53 by @V.R — 2023-07-06T09:42:25Z

Anybody know if the Proton Plus subscription would include family accounts and sharing when those features launch?

---

## Post 54 by @Mossturtlecoffee — 2023-07-11T07:47:31Z

Interesting. What do you think about it?

> **[Found all passwords, url's and usernames in memory - r/ProtonPass](https://reddit.adminforge.de/r/ProtonPass/comments/14uva6i/found_all_passwords_urls_and_usernames_in_memory/)**
>
> View on Redlib, an alternative private front-end to Reddit.

---

## Post 55 by @ph00lt0 — 2023-07-11T09:09:51Z

That is quite bad. I was also suprissed proton doesn’t let you use webauthn fido2 like bitwarden does.

But all proton apps that come out of beta are still beta for at least a year.

The calendar app they have for Android is pretty much broken for an entire month already.

---

## Post 56 by @Niek-de-Wilde — 2023-07-11T10:33:46Z

Oh, whats broken in calendar? Works perfectly fine here.

---

## Post 57 by @ph00lt0 — 2023-07-11T10:36:53Z

On my pixel 7 pro it constantly crashes when loading in start up of the app. Reinstall makes it work again for about half a day and then it’s crashing again. I assume it is something to do with the search feature and the local db being full but no way to asses that.

---

## Post 58 by @Niek-de-Wilde — 2023-07-11T11:16:01Z

Hmm, cannot reproduce on a pixel 6 pro with graphene OS.

---

## Post 59 by @ph00lt0 — 2023-07-11T11:20:47Z

I might have more appointments than you have that is not unlikely. But at least something is broken

---

## Post 60 by @Anonymous69 — 2023-07-11T14:15:15Z

I can confirm this is accurate. Unlimited aliases can only be generated from inside the password manager.

---

## Post 61 by @Dkama — 2023-07-11T23:39:52Z

GOS on P7P, Calendar also never crashed for me.

---

## Post 62 by @purplecactus — 2023-07-12T01:03:27Z

have a lot of appointments myself, using GOS on a Pixel 7A. No issues.

---

## Post 63 by @ph00lt0 — 2023-07-16T18:14:05Z

Issue has been confirmed by the proton team so you can all stop staying this. It has to do with the search feature and solution is been worked on.

---

## Post 64 by @Son — 2023-08-03T08:14:25Z

Hi, this is Son from SimpleLogin and now Proton Pass (PP).

I’m wondering if we can add PP to the password manager section? I think PP is qualified as it’s:

- open source\* and thoroughly audited
- has all features that a password manager provides (password generation, autofill, autosave, vaults, etc.)
- has email alias built in thanks to SimpleLogin
- support 2FA, credit card, custom field, etc
- has a free option which is enough for most users

More info on [Proton Pass: Free password manager with identity protection | Proton](https://proton.me/pass)

I see there’s also [Proton Pass (Password manager) - #63 by ph00lt0](https://discuss.privacyguides.net/t/proton-pass-protonmail-password-manager-service/12416/63), let me know if I should ask in this thread instead.

\*: the server code for PP isn’t open source for several reasons:

1. it’s based on the same backend as other proton services and isn’t designed to be self hosted (it has a lot of components)
2. open sourcing doesn’t add any benefit as data is always E2E encrypted & decrypted client side, meaning when data is always in the E2E encrypted form when it’s sent to the server. The server can be seen as a simple sync proxy to pass data from a device to another in a reliable way.
3. it has a lot of anti abuse logic and if public, will allow abusers to find workarounds. Anti abuse is an important topic when a service has a lot of users and some bad people can negatively affect everyone else.

---

## Post 65 by @Niek-de-Wilde — 2023-08-03T09:17:36Z

Well currently I still find Proton Pass to be rather lacking in certain areas. For example its still impossible to import or export your data on mobile, it just redirects you to the desktop browser extension.

---

## Post 66 by @CrypticHunter — 2023-08-03T11:39:24Z

> thoroughly audited

Could you please share the cryptography audit report?

I see a pen test report online in the Cure53 site, but nothing about your use of cryptographic principles which is especially important for a password manager.

Other than citing common best practices that might be implemented, as a user I would like to be assured that it is cryptographically secure.

---

## Post 67 by @Son — 2023-08-03T11:53:05Z

Hi we have prioritized the export on web first as most password managers only allow to import/export on their web versions. That being said, Proton Pass will allow to export from its mobile apps, should be available in Sep or Oct this year.

---

## Post 68 by @Son — 2023-08-03T11:57:20Z

Hey we have some info about the audit on [AMGAME168](https://shorturl.at/stOS6)

Proton Pass security model is on [The Proton Pass security model | Proton](https://shorturl.at/fkuxO) which dives into encryption details.

Sorry I need to use a URL shortener as I have this error with the final links:

 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/d/d0d68a55a9b396f74edf9ea7373d04c5776fb5f4.png)

---

## Post 69 by @CrypticHunter — 2023-08-03T15:14:53Z

Not sure if this gives me anymore confidence than before. I don’t quite understand why Cure53 was not commissioned to carry out a cryptographic audit especially since you mention it to be similar across all the Proton apps. Just declaring to use end-to-end encryption is not at all the same as to how it is actually implemented and the only way to have a peace of mind in this situation is to have a third party audit of the cryptographic implementation.

---

## Post 71 by @dngray — 2023-08-03T18:29:17Z

Please keep the thread professional, or we’ll have to start hiding posts.

---

## Post 73 by @youdontneedtoknow22 — 2023-08-03T22:55:23Z

Proton Pass is out now and 2FA is also only a paid service, just like Bitwarden.  
It’s even gonna be more expsensive than Bitwarden, as their 75% offer costs $1 per month (vs $10 per year for Bitwarden), which won’t stay forever.  
If there’s a reason to list Proton Pass INSTEAD OF or BEFORE Bitwarden, this might be for the eco system integration (if you have a paid Proton Account, creating email alliases would be easier and depending on your account type you can use the 2FA), or better UX (I didn’t compare both but I heard people complaining about Bitwarden’s UX/UI).

---

## Post 74 by @Pragmatic — 2023-08-04T10:46:58Z

Do you think it’s worth taking the Proton Pass lifetime offer for €12/year instead of Bitwarden, for example?

---

## Post 76 by @Pragmatic — 2023-08-04T11:57:57Z

There’s something I don’t understand about Proton Pass.

I currently use Bitwarden to connect to Proton services (including Proton Pass) and I have to enter my email address, a complicated password and the 2FA (classic).

I would have liked to use a complicated, but easy to remember, password to access Proton Pass (like Bitwarden) and a different password for the other Proton services so as not to “weaken” the password for accessing my Proton emails, drive and calendar.

Is this possible?

Translated with [DeepL Translate: The world's most accurate translator](http://www.DeepL.com/Translator) (free version)

---

## Post 77 by @anon2844160 — 2023-08-04T13:00:35Z

> [@Pragmatic](#):
>
> I would have liked to use a complicated, but easy to remember, password to access Proton Pass (like Bitwarden) and a different password for the other Proton services so as not to “weaken” the password for accessing my Proton emails, drive and calendar.

At this time this is not possible. There was an explanation given my one of the Proton Pass people that they do not consider this a real risk, so I would not expect a fix in the near future. You could use a separate account just for Proton Pass.

---

## Post 78 by @Pragmatic — 2023-08-04T13:20:01Z

Can I delete my Proton Pass account (which is the same as the other Proton services) and use another e-mail address instead?

---

## Post 79 by @anon2844160 — 2023-08-04T15:46:25Z

It is possible to register a Proton Pass account using a non-Proton email. I don’t know if it is possible to remove the Proton Pass function from an existing account.

---

## Post 80 by @landordragen — 2023-08-05T08:45:57Z

It is. I have one Proton Pass account with an e-mail from a different provider.

---

## Post 81 by @mouldy — 2023-08-12T09:47:13Z

I’ve been on KeepassXC for many years now (I’ve also taken a look at Bitwarden) and in my opinion, it is inferior to both aside from the UI.

Here are deal breakers for me:

- **No folder support**. It has vaults but only up to 20 even for Unlimited users. I don’t know why this limitation is in place. I use folders a TON for work accounts (different folders per project).
- **No attachments**. KeepassXC and Bitwarden both come with this feature and it’s important to me to have all documents related to an account be in one place (scanned documents).
- **No full history for passwords and fields**. I can tolerate not having histories for other fields (KeepassXC has history for all fields) but the password history is only for generated passwords. And they ONLY last for a day. Proton deletes the password history after a day. I don’t understand why they would do this.

These three are so important for my workflow that I can’t use it.

Other disadvantages albeit a minor issue to me:

- No offline access to vault
- No desktop app
- No web app (only available as a browser extension)
- No tags

It is also 20% more expensive than Bitwarden and that’s for the discounted price ($12 for Proton Pass vs $10 for Bitwarden). They plan on charging $5/month ($60/year) for this service which is more than 5 times the price of Bitwarden when it has less features! I would’ve been fine with it if at least their service was 2 times better but it isn’t. What a joke of a service.

The only thing it has going for it is the better UI and the email alias feature but really, there’s nothing stopping you from using email alias services and putting the generated email in your already existing password manager.

I don’t recommend listing this product… at least not yet. Probably best to wait 6 months to a year.

---

## Post 82 by @Dkama — 2023-08-12T14:51:10Z

The lack of data breach monitoring is another big factor.

---

## Post 83 by @filen — 2023-11-09T19:38:33Z

Nope. Both paying

---

## Post 84 by @Son — 2024-02-17T21:33:39Z

Hi again, Proton Pass has quite some changes since last year and with our current development speed, there should be more coming soon.

Some notable changes since last year:

- vault sharing
- web app now available on [https://pass.proton.me](https://pass.proton.me)
- price for Pass Plus is now $1.99/m instead of $3.99/m
- item pinning/bookmarking
- edit/move/remove items in bulk
- sharing suggestion: useful for family or business
- offline mode for mobile
- item history: you can restore old versions of any item. Available now on iOS and in coming weeks on android & web.

Coming soon:

- desktop apps, start with windows, then Mac & Linux
- passkeys
- offline mode for desktop & web
- data breach monitoring
- Sync with SimpleLogin
- Identity autofill

As with any product in Proton, Pass is fully financed by users subscriptions. That pushes us to actively listen to your feedbacks (and not VC investors) and implement them as soon as we can. So far we have been able to implement the top feature requests on [Proton Pass: Hot (387 ideas) – The Voice of the Proton Community](https://protonmail.uservoice.com/forums/953584-proton-pass)

So I’d like you to reconsider listing Proton Pass on [The Best Password Managers to Protect Your Privacy and Security - Privacy Guides](https://www.privacyguides.org/en/passwords/)

Thanks,  
Son from SimpleLogin & Proton Pass.

---

## Post 85 by @ph00lt0 — 2024-02-17T22:42:53Z

I haven’t seen an _official_ statement anywhere, but I believe also [my concern about the vault limitation](https://discuss.privacyguides.net/t/bitwarden-or-proton-pass/14727/41) has been solved. I can create a lot more vaults at least for now, not sure what is the current limitation if any exists.

---

## Post 86 by @ph00lt0 — 2024-02-17T22:49:13Z

Furthermore, I have been using pass lately a lot to manage new aliases and already sort them in the _correct_ vaults. I would actually like to give some advice on that but not sure in what form yet. _Something in the lines of keep a segmentation between importance of accounts, so you know where to act first when shit hits the fan… but more on that later._

Now I was wondering how will SimpleLogin _migrate_ the existing aliases given I have a quite unman gable amount. Will they all just be _dropped_ in the default vault? That would be a sorting… and I would like to be able to in advance move the other stuff elsewhere to keep things manageable. Best case would be, and I hope you pass this along @Son, to _import/sync_ them to a separate vault, so people can start sorting from there.

---

## Post 87 by @anon28192316 — 2024-02-17T22:51:15Z

Personally, I’ll be happy to try protonpass the day security keys work on all platforms, and TOTP can be removed.

This is the feature I miss the most on proton today, and especially on protonpass since competitors already support security key on mobile.

---

## Post 88 by @moonwriting — 2024-02-17T22:59:51Z

Can you explain why you use Bcrypt to encrypt the user key when it is not meant to be used like that, as it isn’t a KDF but a password hashing function? There are better options available, such as Argon2.

---

## Post 90 by @privacycarrot — 2024-02-18T04:32:05Z

I moved to proton pass couple of months ago after using bitwarden for years, and I’m much more happy with the ux on web and android. Bitwarden was really painful to use. Automatic aliases is a killer feature for me too, and I’d be happy to see proton pass on PG (but don’t particulary care if they won’t). The only thing I’m not happy with is they don’t provide an f-droid build which is true for all their apps and I honestly hate it.

The common concern amont people is putting all eggs in one basket but personally I find it unconvincing as getting access to your password manager means getting access to everything anyway.

> [@moonwriting](#):
>
> Can you explain why you use Bcrypt to encrypt the user key when it is not meant to be used like that, as it isn’t a KDF but a password hashing function?

From my understanding they use bcrypt to derive a key for to encrypt the user key using a symmetric cipher (possibly stretching it, given bcrypt is a password based kdf) so it’s used as designed. Bcrypt is also good enough (and much better than pbkdf2 used by bitwarden by default). Although argon2id is even better, depending on parameters it may be weaker than brcrypt, it also requires wasm to have acceptable derivation speed with good parameters which adds another attack vector (and is disabled in tor/mullvad browser and vanadium)

---

## Post 91 by @bee — 2024-02-18T06:41:31Z

+1 on the ux bit.

Proton Pass was an easy decision for me purely based on the ux/ui improvements over Bitwarden, and that’s coming from a non-Proton Unlimited subscriber, ie I’m willing to pay for it on its own.

I’m a strong believer in privacy not feeling like a chore or compromise, and Proton Pass finally brings password management up to a level where I feel that’s true for me here.

Once syncing from SL is implemented, it will also cut out my displeasure with using SL on mobile since I’ll just use Pass to manage it all, which effectively kills two birds with one stone for me.

---

## Post 92 by @Anonim4678 — 2024-02-18T08:51:43Z

> [@anon66296745](#):
>
> When Proton Pass comes out I don’t see a reason to list Bitwarden anymore

I agree. Fido paywall is horrible idea. But it is open source so it is trustworthy enough. People should have choice.

> [@matchboxbananasynergy](#):
>
> 1Password

It should be delisted.

- Not open source (we can’t check anything from their clarifications)
- They was [breached](https://www.digitaltrends.com/computing/1password-okta-breached-by-hackers/)

> [@Mossturtlecoffee](#):
>
> PGP settings

[Article](https://simplelogin.io/docs/mailbox/pgp-encryption/) (official)

---

## Post 93 by @moonwriting — 2024-02-18T11:20:34Z

> [@Anonim4678](#):
>
> Fido paywall is horrible idea.

This is not paywalled anymore.

> **[FIDO2 WebAuthn 2FA now in all Bitwarden plans including free! | Bitwarden](https://bitwarden.com/blog/fido2-webauthn-2fa-in-all-bitwarden-plans/)**
>
> Bitwarden envisions a world where nobody gets hacked and now includes FIDO2 WebAuthn two-factor authentication in all plans, including free. Everyone gets a security boost with FIDO2 WebAuthn credentials such as hardware security keys.

---

## Post 94 by @Bhaelros — 2024-02-18T12:01:35Z

1Password already made a statement regarding to Okta breach. No customer data was compramised.

> **[Okta Support System incident and 1Password | 1Password](https://1password.com/blog/okta-incident)**
>
> We detected suspicious activity on our Okta instance that we use to manage our employee-facing apps. We immediately terminated the activity, investigated, and found no compromise of user data or other sensitive systems, either employee-facing or...

Also, they are not open-source but they have regular security audits from reputable vendors.

> **[Security audits of 1Password | 1Password Support](https://support.1password.com/security-assessments/)**
>
> 1Password products have been reviewed by multiple independent security firms.

There is also a discussion in Reddit about this, and bried explanation on 1P forums.

> **[Reddit - The heart of the internet](https://www.reddit.com/r/1Password/comments/xks8ko/honest_question_why_isnt_1password_open_sourced/)**

[https://1password.community/discussion/comment/114870/#Comment\_114870](https://1password.community/discussion/comment/114870/#Comment_114870)

And, no. They shouldn’t be removed from the PG Recommendations.

#### 

As for Proton Pass, it still needs improvement. For me Windows desktop app is the most important part, then sharing logins with others, ability to select multiple items (not one by one clicking), more default categories and templates, ability to import custom fields and files from other password managers, like the software licenses, notes or attached files.

I won’t use a browser only password manager.

---

## Post 95 by @fury — 2024-02-18T15:40:53Z

> [@Anonim4678](#):
>
> Fido paywall is horrible idea

It is free now :smiley_cat:

> [@Anonim4678](#):
>
> It should be delisted

All proprietary software should be delisted or have huge warning labels that it is proprietary.

> [@moonwriting](#):
>
> This is not paywalled anymore

Oh you wrote before me :smile:

---

## Post 96 by @Son — 2024-02-18T20:53:29Z

> [@ph00lt0](#):
>
> Now I was wondering how will SimpleLogin _migrate_ the existing aliases given I have a quite unman gable amount. Will they all just be _dropped_ in the default vault?

Some details might change in the final implementation but basically we’re going to ask you to choose the vault in Pass where you want missing aliases, i.e. aliases that are on SL but not on Pass, to be synced to. After that, missing aliases will be automatically synced to this vault.

---

## Post 97 by @Son — 2024-02-18T20:54:33Z

> [@privacycarrot](#):
>
> The only thing I’m not happy with is they don’t provide an f-droid build which is true for all their apps and I honestly hate it.

Supporting for F-droid is in our todo list, I hope that it’ll be available in the coming weeks.

---

## Post 98 by @Son — 2024-02-18T20:58:42Z

> [@Bhaelros](#):
>
> As for Proton Pass, it still needs improvement. For me Windows desktop app is the most important part, then sharing logins with others, ability to select multiple items (not one by one clicking), more default categories and templates, ability to import custom fields and files from other password managers, like the software licenses, notes or attached files.

Vault sharing is now available.

Other requests are already listed on our feaure request forum on  
[Proton Pass: Hot (387 ideas) – The Voice of the Proton Community](https://protonmail.uservoice.com/forums/953584-proton-pass) , please feel free to upvote the ones you want to see coming so we can prioritize our todo list. We try to deliver as many features as we can but our team is relatively small compared to VC funded companies like 1password and the others.

---

## Post 99 by @Bhaelros — 2024-02-18T21:14:26Z

I don’t want to share whole vault but only several logins with outsiders.

Above were my suggestions because these features are already available in other password managers, and to be honest, I prefer to pay only one provider instead of many. If you can improve Proton Pass to the level of 1Password, I will gladly cancel my 1Pass subscription.

Edit. How many votes will be enough for a feature to be implemented, and how long will it take to implement? For example Bitwarden’s most wanted feature, autofill overlay took like 5 years to get implemented.

---

## Post 100 by @privacycarrot — 2024-02-19T00:26:31Z

That sounds encouraging, thanks! I just hope “coming weeks” really mean coming weeks and not “coming weeks ~~valve~~ proton time”

---

## Post 101 by @bee — 2024-02-19T07:20:53Z

Just to confirm, once aliases are migrated to a vault, they won’t require a premium SL subscription to remain activated? As a non-Unlimited subscriber I would have to pay for SimpleLogin and Pass separately, so it would be a shame if aliases were disabled for using SL domains (e.g. @slmail.me) without that subscription anymore.

---

## Post 102 by @sina — 2024-02-19T09:38:12Z

i didn’t read the whole Topic, i just want to say one thing about Proton:  
They closed my account without prior notice under the pretext of “anti-abuse” and i sent (many tickets and DMs in twitter) but nothing. i can never access my data again. i had a lot of important information, passwords and files in Proton that had a direct impact on my life and i don’t have the password of many platforms anymore.

my whole point is that if you have very important information, do not use Proton, because your account may be closed without prior notice and for any excuse, and you will never be able to access your information.  
just check what i said on reddit and you will see how many people have the same problem as me. i am sure bitwarden will never do this with your life.

---

## Post 103 by @Son — 2024-02-19T11:04:32Z

> [@Bhaelros](#):
>
> Edit. How many votes will be enough for a feature to be implemented, and how long will it take to implement? For example Bitwarden’s most wanted feature, autofill overlay took like 5 years to get implemented.

We rather look at the order of requests in terms of votes and not really the number of votes per se. About the ETA, this depends on the complexity of the feature. For info the features mentioned in [Proton Pass (Password manager) - #84 by Son](https://discuss.privacyguides.net/t/proton-pass-password-manager/12416/84) took us a couple of months to deliver.

---

## Post 104 by @Son — 2024-02-19T11:06:31Z

> once aliases are migrated to a vault, they won’t require a premium SL subscription to remain activated?

Aliases in SL remain active even after downgrade.

Please note that Pass Plus includes unlimited aliases but doesn’t include custom domains and other advanced features in SL.

---

## Post 105 by @Son — 2024-02-19T11:09:58Z

This doesn’t sound right, can you send me the number of customer support tickets that you have created so I can maybe take a look? An account can only be disabled if it violates the Proton terms and condition. Although the detection isn’t perfect and can sometimes be wrong, it will be reverted quickly after human verification. All services I know of have anti abuse system.

---

## Post 107 by @sina — 2024-02-19T12:32:09Z

Sir i have been sending the ticket number to Proton staff for 2 years, but nothing.  
Proton support told me on twitter that he can’t continue this conversation because of “security risks”!  
do you have any idea how much this hurts me? that i can’t access my files that are very important to me?  
i mean what is the worst thing a person can do with a account?  
if a person has done the worst possible thing, he should receive at least one warning. either disable the account for 24 hours or one week not forever!  
Proton didn’t even give me 24 hours to move my information from my account.  
that’s not really what i expect from a privacy-oriented provider.

---

## Post 108 by @Bhaelros — 2024-02-19T13:33:44Z

Did you contact them via this form? [Abuse appeals form | Proton](https://proton.me/support/appeal-abuse)

---

## Post 109 by @sina — 2024-02-19T17:58:32Z

yes a lot  
i even sent a DM to the CEO of Proton on twitter but i didn’t get any reply. of course they don’t care what happened to a user i’m just a simple man against a big company and i have no hope of getting my proton account back. is my fault because i was so dumb to believe proton advertising about privacy and user respect.  
after proton i went to skiff and you guys know what happened to skiff.  
now i’m in tuta because i have no choice. maybe i should give up about privacy in email.  
a few months ago i created a new account in proton but i was so stressed about it this account would be deactivated for any shitty reason too so i deleted the account.  
i know my message has nothing to do with the topic sorry Privacy Guides. i just wanted to say be careful with proton.

---

## Post 110 by @Bhaelros — 2024-02-19T18:03:57Z

Tuta is worse. They are actively censoring topics and posts in Reddit in which are criticizing them. Maybe you can try [mailbox.org](http://mailbox.org)?

Edit. Maybe go for business class emails like Microsoft 365?

---

## Post 111 by @Jasi — 2024-02-19T18:35:43Z

@Son i tested both of your services, both are great for me.

But for now I have issues with following:

- No Proton Pass (PP) to SimpleLogin (SL) syncing. This will cause errors if you for example remove created in PP alias directly in SL
- No separate AKA Master Password for PP. For now it uses same password (or passwords if 2 password mode enabled) as your account
- No free sending feature (only for new accounts). I think there should be another way to solve situation with abuse. You should have something that other services not provide :slight_smile:
- No E2EE in notes section in SL (but **with** E2EE in note section in PP)

For now :star: :star: :star: :star: service. It is definitely better than Addy (limited bandwidth) but have some issues that better to solve.

---

## Post 112 by @Nour — 2024-02-21T03:35:55Z

This only happens on the free plan (which is very prone to abuse), not for subscribers.

I’ve seen the reports on Reddit and they’re free accounts.

This is very worth mentioning because this does not affect subscribers.

Also, regardless, it’s always important to have backups, especially of your password vault.

---

## Post 113 by @Nour — 2024-02-21T03:42:05Z

> [@privacycarrot](#):
>
> The common concern amont people is putting all eggs in one basket but personally I find it unconvincing as getting access to your password manager means getting access to everything anyway.

If someone has access to your mail it’s the same thing as well because they can reset all passwords.

---

## Post 114 by @KeepItSimple — 2024-02-21T17:49:07Z

> [@privacycarrot](#):
>
> The common concern amont people is putting all eggs in one basket but personally I find it unconvincing as getting access to your password manager means getting access to everything anyway.

That is why 2FA exist. If I will tell you login/pass to my password manager and you still won’t be able to log in to twitter. You won’t be able to reset email either, 2FA is still needed. And password manager do not has 2fa codes or recovery codes.

> [@Nour](#):
>
> If someone has access to your mail it’s the same thing as well because they can reset all passwords.

I will give you my email login/pass, and you won’t be able to reset my twitter password. You still need 2FA code for reset. Also twitter do not knows my email. I myself do not know which email knows twitter, it is some forwarder service. How are you going to know that email to reset? Well, probably Twitter is not good example and they will allow to reset by username.

–  
Now We need some third guy who I give my 2fa phrase or recovery codes. He won’t be able to login without password though… He now needs 1 of you guys.

Or anyone of you both need that 3rd guy to login to twitter.

That is 3 different eggs in 3 different baskets.

---

## Post 115 by @HushedWave — 2024-02-21T18:00:59Z

At one point I recall seeing a post that said there’d be a feature coming that would allow you to use ProtonPass as a 2FA for your Proton account itself, is there any progress on that? Or, is there a recommended other method of securing your Proton account if you don’t want to use a separate 2FA service?

---

## Post 116 by @xe3 — 2024-02-21T23:45:21Z

> [@HushedWave](#):
>
> is there a recommended other method of securing your Proton account if you don’t want to use a separate 2FA service?

I guess it depends somewhat on what you mean by “don’t want to use a separate 2FA service.” When you say _service_ are you referring specifically and only to _hosted services_ or do you mean you don’t want to use a separate app, or hardware device. If so, what will you use as the second factor for Protonpass itself?

The only other option for a 2nd factor I can think of would be using an entirely different type of second factor (Typically, the norm is that the _first factor_ is “a secret you know” (e.g. a pin or password) and the second factor is normally “something you possess” (e.g. a phone or yubikey), however an alternative to using “something you possess” as the 2nd factor, would be using “something you uniquely are” (e.g. fingerprint or iris or voice print), but I’m not sure if this is possible with Proton.

If I’ve misunderstood what you are asking and you are open to an app or device, consider a TOTP app (like Aegis or 2fas) or a hardware device (like a pair of yubikeys). In my eyes the two most important accounts to protect with strong 2fa are your password manager and your primary e-mail.

Some links:

- [https://proton.me/support/two-factor-authentication-2fa](https://proton.me/support/two-factor-authentication-2fa)
- [https://proton.me/support/pass-2fa](https://proton.me/support/pass-2fa)
- What is the recommendation for folks that have 2FA setup with ProtonMail and want to use ProtonPass for 2FA? 
- [https://en.wikipedia.org/wiki/Multi-factor\_authentication](https://en.wikipedia.org/wiki/Multi-factor_authentication)

---

## Post 117 by @HushedWave — 2024-02-22T00:16:17Z

Ah so, I was referring to the post I saw here I believe:

> **[Reddit - The heart of the internet](https://www.reddit.com/r/ProtonPass/comments/14oj9ij/comment/jqhkge1/)**

"Currently, you cannot and should not use Proton Pass to store your Proton 2FA. In fact, in our Proton 2FA guides, we don’t recommend this for this reason.

**However, one of the upcoming features in Proton Pass will be a way to store Proton 2FA, and have Proton 2FA be accessible without requiring Proton 2FA.**"

Sounds nifty, as it seems a bit cumbersome to have a secondary 2FA tool installed exclusively for getting into Proton. (And my apologies, I probably should have said “tool” rather than service) But I don’t think this has been implemented, so I was wonderin’ if they had another workaround.

Using 2-password mode could work I suppose, but my understanding is that it isn’t as secure. But yeah I think you’re right, just have to bite the bullet for now.

---

## Post 118 by @xe3 — 2024-02-22T00:33:19Z

> [@Proton Team's comment on reddit](#):
>
> However, one of the upcoming features in Proton Pass will be a way to store Proton 2FA, and have Proton 2FA be accessible without requiring Proton 2FA."

Indeed this does sound interesting. But I don’t fully understand what it is that they are saying. I have a few guesses (involving the ways in which 2fa secrets could be stored in the protonpass mobile app), but it’d be better to get some clarification from someone with actual knowledge of what is planned. Hopefully @son or someone else can provide some context.

> [@HushedWave](#):
>
> Using 2-password mode could work I suppose, but my understanding is that it isn’t as secure. But yeah I think you’re right, just have to bite the bullet for now.

My understanding of Multi-factor authentication, is that the above is not 2fa, requiring two passwords is requiring the same factor 2 times, as opposed to 2 distinct factors that complement eachother. That said, it (might) still be a step in the right direction (I say might, because I can’t currently think of many scenarios where an adversary could attain one of the passwords but not the other, but that may just be due to my lack of imagination or lack of technical depth).

---

## Post 119 by @Son — 2024-02-22T10:01:39Z

> **However, one of the upcoming features in Proton Pass will be a way to store Proton 2FA, and have Proton 2FA be accessible without requiring Proton 2FA.**

Some final details might change but the way it will work is Pass will act as the 2FA authenticator for your Proton account on a “trusted” device that you choose. When you log in on another device, you can approve the login attempt from the trusted device. You can also add the new device to the list of trusted devices.

But please note that this doesn’t change our recommendation of storing the recovery code in a separate location, for ex on a paper that you leave in a safe box.

---

## Post 120 by @HushedWave — 2024-02-22T15:44:52Z

Thanks for the clarification. That would be excellent. :slight_smile:

---

## Post 121 by @mouldy — 2024-02-23T10:08:34Z

So I did a brief check on Proton Pass features again that were added since I last commented here 6 months ago.

There were lots of features but it still has no file attachment support which is a huge deal breaker for me. It is great that they increased the number of vaults to 50 from 20 recently. I still don’t like that they don’t have organizational features like nested folders or tags but I can tolerate it since they increased the vaults to 50 (dunno if this is a technical limitation). If they get file attachment support, I might swap over from Bitwarden just for the beautiful UI.

A browser app has been added a month ago too which is good. No desktop app yet but I don’t really mind it but some people here might.

Also keeping track of changes for Proton Pass is REALLY annoying. I made a suggestion about this on their subreddit to have a single place for their changelog but it looks like there still isn’t one. They previously wrote changelogs on their [Firefox browser extension page](https://addons.mozilla.org/en-US/firefox/addon/proton-pass/versions/) but they recently stopped doing that. I WANT Proton Pass to succeed but digging through Reddit posts and their social medias is a chore. @Son Can you please tell the higher ups about that? Even a plain text README.md file in a GitHub repository would be fine. Just something that I can quickly check if file attachments feature is added.

---

## Post 122 by @wojciechxtx — 2024-02-23T10:23:34Z

> [@mouldy](#):
>
> README.md file in a GitHub repository would be fine

No, it **will not** be fine. That would introduce huge mess. There are better places for changelogs. Like dedicated webpage that grabs changes from `CHANGELOG` file within repo.

---

## Post 123 by @ph00lt0 — 2024-02-23T10:42:27Z

Expensive lesson to not have all your data relying on one party it seems.  
Always have your own backups.

Anyway do share your support number. AFAIK @Son works at proton so actually might be able to help you out, obviously given you didn’t break their terms.

---

## Post 124 by @wojciechxtx — 2024-02-23T11:29:48Z

> [@ph00lt0](#):
>
> Always have your own backups.

:100:

---

## Post 125 by @Son — 2024-02-23T12:48:37Z

The changelogs for Pass can be found on

- [android-pass/CHANGELOG.md at a4e6552ab37ba3ad20e6cc4ea0d1f74046d4a650 · protonpass/android-pass · GitHub](https://github.com/protonpass/android-pass/blob/a4e6552ab37ba3ad20e6cc4ea0d1f74046d4a650/CHANGELOG.md) for Android

- [ios-pass/CHANGELOG.md at f4a6e1f601840b5e9c27ebb6bdbeb5c45d020401 · protonpass/ios-pass · GitHub](https://github.com/protonpass/ios-pass/blob/f4a6e1f601840b5e9c27ebb6bdbeb5c45d020401/CHANGELOG.md) for iOS

- [WebClients/applications/pass-extension/CHANGELOG.md at c3724631c15d5689852e9286ad6da63461f77af6 · ProtonMail/WebClients · GitHub](https://github.com/ProtonMail/WebClients/blob/c3724631c15d5689852e9286ad6da63461f77af6/applications/pass-extension/CHANGELOG.md) for browser extension

- [WebClients/applications/pass/CHANGELOG.md at c3724631c15d5689852e9286ad6da63461f77af6 · ProtonMail/WebClients · GitHub](https://github.com/ProtonMail/WebClients/blob/c3724631c15d5689852e9286ad6da63461f77af6/applications/pass/CHANGELOG.md) for web app

> It is great that they increased the number of vaults to 50 from 20 recently. I still don’t like that they don’t have organizational features like nested folders or tags but I can tolerate it since they increased the vaults to 50 (dunno if this is a technical limitation).

To sync data between devices, each vault is synced separately, so increasing the number of vault is synonym to adding more load on servers. We’ve optimized our code a lot recently to reduce the load and that allows us to increase the vault limit.

---

## Post 126 by @mouldy — 2024-02-23T15:04:19Z

Oh hey, thanks! Missed the CHANGELOG.md file when I went over that repo.

Thanks for the explanation on the vaults. Didn’t know the vaults were synced separately. And 50 is more than enough for me so I don’t really mind.

I just need the attachments feature before I can move. I currently have a lot of them per entry over at Bitwarden. I know I can technically just store them in Drive, but I want to have some association with the files with each entry (e.g. when I delete the entry, I want to delete the associated files). Plus it’s just way more convenient for the app to handle that.

After that, I don’t really have much complaints. I’ll primarily be using the web app anyways.

---

## Post 127 by @sina — 2024-02-24T11:38:00Z

i don’t need to pay for email right now even 500 MB is enough for me  
oh man this tuta UI made me crazy i really can’t stand it.  
for now i’m using skiff for sending email then maybe i go back to icloud

---

## Post 128 by @sina — 2024-02-24T11:39:47Z

true, but sometimes you forget and you don’t expect your account to be completely closed.

---

## Post 129 by @youdontneedtoknow22 — 2024-02-26T18:45:35Z

I just want to make a comment about a killer feature/bug that would make Proton Pass very unreliable for grandparents/old parents (if it’s true).  
I thought it was a bug on my side when I first tried Proton Pass and deleted it, but it really does seem to not save the suggested password on its own? It just gets copied and it’s your thing to save it then.  
The Admin replied there with no shown interest in fixing this.

> **[Save suggested passwords](https://protonmail.uservoice.com/forums/953584-proton-pass/suggestions/46938343-save-suggested-passwords)**
>
> Pass often suggests passwords but when I choose the password, it isn't saved anywhere or pass does not prompt to save it and create a login.
> 
> So essentially you end up creating an account with a password you will have to immediately reset.

---

## Post 130 by @Son — 2024-02-26T21:17:05Z

> [@youdontneedtoknow22](#):
>
> I thought it was a bug on my side when I first tried Proton Pass and deleted it, but it really does seem to not save the suggested password on its own? It just gets copied and it’s your thing to save it then.

The generated password is supposed to be saved during the autosave process after you sign up for an account. In case the autosave doesn’t work correctly, you can find the generated passwords in Menu \> Advanced \> Generated passwords.

Unfortunately a lot of websites don’t follow web standard and practices and hence sometimes the autosave doesn’t pop up - we keep improving it, it’s a never ending feature.

Autosave:

 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/4/418f102ebf27fdb6eb787c902e1bb90fd2438c71.png)

Generated passwords:

 ![CleanShot 2024-02-26 at 22.12.54@2x](//forum-uploads.privacyguidesusercontent.com/original/2X/d/dc3f9fbd3a0397223eb1a0dad7fd6c921875b3c5.png)

---

## Post 131 by @ph00lt0 — 2024-02-26T21:21:26Z

I actually didn’t know this, good info.

---

## Post 132 by @timo — 2024-02-26T21:25:47Z

@Son, can I ask you two questions?

1. If Proton Pass domains using simplelogin MX records, that means that it run on same infrastructure? Why when deleting alias created in Proton Pass through simplelogin I try to delete it in Proton Pass I get an error?
2. Why SimpleLogin still not using Proton Captcha?

---

## Post 133 by @Son — 2024-02-26T21:44:32Z

An alias actually exists in both Pass and SL. You can see SL as the alias backend for Pass. When you delete an alias in SL, the alias in Pass still exists but it points to nothing now, hence the error you see. We’ll fix this error in the next version.

> 1. Why SimpleLogin still not using Proton Captcha?

There are a couple of reasons:

a) It’s not that simple. Proton apps are SPA (single page applications) whereas most SL apps are classic web apps. Proton captcha is designed for Proton specific use case.

b) SL doesn’t have the same challenge as Proton when it comes to abusive signups. So far, the hcaptcha SL is using is enough to prevent that risk.

---

## Post 134 by @timo — 2024-02-26T22:01:32Z

> [@Son](#):
>
> abusive signups

But somewhere (maybe I am wrong?) I read that SL got a problem with abuse.

> [@Son](#):
>
> hcaptcha

If it is not evil reCAPTCHA I am ok, I was just curious :slight_smile:

> [@Son](#):
>
> SL as the alias backend for Pass

That was my question. Then why all alias domains from SL will have reverse alias simp\*elogin.\*o (hidden to avoid bots) but Pass domains have reverse alias domain the same as alias domain? Isn’t it better to separate domains?

---

## Post 135 by @youdontneedtoknow22 — 2024-02-26T23:42:31Z

I can totally understand how Websites not following standards could lead to this bug, but it’s been known for over 8 months with many reports on your subreddit for it. I tried Proton Pass for like 2-3 Websites I knew and it was very obvious from the beginning that some passwords were not saved.  
I didn’t have one such case while using the built-in Password manager in Firefox since 6-7 years. I don’t know how Bitwarden handles this, I hope other users could give us some info if they faced such thing.  
Of course it’s up to PG to decide this, but I would definitely not consider Proton Pass a password manager for the public at this point.

Here are some reddit posts about this:

> **[Reddit - The heart of the internet](https://www.reddit.com/r/ProtonPass/comments/1695b3l/proton_pass_doenst_detect_new_logins_new/)**

> **[Reddit - The heart of the internet](https://www.reddit.com/r/ProtonPass/comments/14z9tcq/proton_pass_does_not_save_changed_passwords/)**

> **[Reddit - The heart of the internet](https://www.reddit.com/r/ProtonPass/comments/1475tov/chrome_extension_for_proton_pass_not_saving/)**

> **[Reddit - The heart of the internet](https://www.reddit.com/r/ProtonPass/comments/17vcavs/not_saving_generated_passwords_as_new_login/)**

> **[Reddit - The heart of the internet](https://www.reddit.com/r/ProtonPass/comments/15zak4s/password_autosave_not_working/)**

Update:  
Bitwarden seems to have a very similar problem. Here’s a link for the bug report, it may help.

> <https://github.com/bitwarden/clients/issues/1620>
>
> ## Describe the Bug
> 
> We are aware of many sites' login forms where the Bitward…en browser extension either on a single platform/browser or multiple will not prompt the user to save a new password or update an existing password.
> 
> ## Expected Result
> 
> When you enter new credentials into a login form, or register for a new user account on a site, you should be automatically prompted to save those credentials upon submission by the Bitwarden browser extension. When you update your password on a site and you have a matching login in your vault, you should be automatically prompted to update those credentials upon form submission.
> 
> ## Actual Result
> 
> This works sometimes, but not always and it can depend on _many, many_ factors. Some sites simply don't work, some don't work consistently and others who knows. This is what we're aiming to fix!
> 
> ## Call to Action
> 
> Below is a link to a Google Form that we have created for capturing information that will help us track down all of these login pages and registration forms where Bitwarden has failed to prompt you to save those credentials. You may submit as many as you like, just please help us help you and the community by providing meaningful information and only those sites/pages where it legitimately doesn't work.
> 
> [Report failure of prompt to save credentials](https://forms.gle/tJXZSr4WwDqjq6vv5)
> 
> If you've been sent to this issue because another issue you had open was closed as a duplicate, thank you for taking the time to submit the issue to us, however we truly need to track this under a single item in aggregate fashion so we can manage it holistically and ensure we're taking broad measures that will improve this behavior with the maximum benefit to all. Please consider using the linked form above to submit the prior sites you had reported in the issue closed.

---

## Post 136 by @anon80779245 — 2024-02-27T04:37:02Z

One of the **issues** with Proton Pass, is that it uses the **same credential** as your **other Proton** accounts. This seems high-risk, plus the fact that this is only **web-based** (no desktop app),DOES IT ASK for password each times ? (barred //means that any open laptop (or hacked) will have all their passwords on the clear.//)

For recommendation, I think **there should be** :  
**1)Native apps** on Linux, Windows and MacOS,  
2)Require an **extra PIN** code by default, and option for a full password.  
3) **Guarantee** that you **wouldn’t be blocked** from accessing your **passwords** if there are abuse in other Proton products.\*

\*Imagine someone takes your phone, send in bulk email, and then you have lost all your passwords!

For those that use it, could you say if it is usable offline?

---

## Post 137 by @Mesk — 2024-02-27T19:54:01Z

Now the only issue is not having separate password from account (it will be even better if it will be _additional_ password)

---

## Post 138 by @anon80779245 — 2024-03-01T04:58:57Z

Well, they have a windows app that’s great, fix a lot of concerns. Two caveats : not for MacOS and Linux, the offline mode is only available with Premium. \*

This is ridiculous. For people with bad connectivity or behind a firewall, this is a “death” blow.

Furthermore, Bitwarden isn’t blocked by any government (AFAIK), while Proton domain is.

\*(See their blog post [Proton Pass Windows app is now available for everyone | Proton](http://proton.me/blog/proton-pass-windows-app))

---

## Post 139 by @Tech-Trooper — 2024-03-01T11:06:34Z

It’s frequently discussed like if putting eggs in the same basket or using same credentials are high risk or not. If you have 2FA and a good password, I don’t believe it’s a high risk using same credentials for proton pass. It’s mostly theoretical.

---

## Post 140 by @ansap — 2024-03-07T10:25:55Z

Bitwarden desktop app doesn’t even support offline mode either the last time I checked.

If you don’t close Proton Pass, then all data is there when there’s no internet.

---

## Post 141 by @ph00lt0 — 2024-03-07T11:25:50Z

> [@ansap](#):
>
> Bitwarden desktop app doesn’t even support offline mode either the last time I checked.

correct

---

## Post 142 by @paul — 2024-03-07T13:13:44Z

I just tested and Bitwarden on Windows works while offline. I can export my vault and copy psswd.  
What do you mean by offline mode here then ?

---

## Post 143 by @ph00lt0 — 2024-03-07T14:49:50Z

What we generally understand under offline mode is that you can use the application, access your data within the application without internet connection. An export is not considered offline mode.

---

## Post 144 by @anon80779245 — 2024-03-10T09:10:10Z

> [@ansap](#):
>
> Bitwarden desktop app doesn’t even support offline mod

As said by paul, you can visualise all your passwords offline. Even the password verification seems to be done offline, as when I change my password, it takes days to update on all my devices.

To be clear, I don’t know if you could use it weeks without internet, but it doesn’t requires a constant connection, like all Proton products do.

On a side not, **Proton Pass** webapp DO **NO** T require any **PIN** or password by default after the initial login. They do prompt you to enable a pin, but nothing mandatory. This is insecure. By contrast, Bitwarden ask you your vault password every 15 minutes.

---

## Post 145 by @youdontneedtoknow22 — 2024-03-16T14:17:18Z

> [@anon80779245](#):
>
> On a side not, **Proton Pass** webapp DO **NO** T require any **PIN** or password by default after the initial login. They do prompt you to enable a pin, but nothing mandatory.

So Bitwarden wants my main password every 15 mins if I want to login into a new website? Tbh sure this sounds more secure, but it’s way less convenient for normal joe users

---

## Post 146 by @Tech-Trooper — 2024-03-21T13:52:54Z

Today, I received an email stating that Proton Pass supports Passkeys.

 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/2/2a43d28cc68bb037f3d8971f93494dca102e2436.png)

---

## Post 147 by @anon39816623 — 2024-03-21T14:05:19Z

Yes, they just announced on their mastodon account that passkeys are available on all devices. Great news!

---

## Post 148 by @Jorgefreeman — 2024-03-21T23:52:07Z

@son can we also have separate passwords for Pass?

---

## Post 149 by @anon2600195 — 2024-03-22T01:15:16Z

I’m curious to know how free plan users are using Proton Pass. With Paid plan as far as I know they get a separate Mail ID/Username but for free users that’s not the case.

So if my Proton account ever gets compromised, the hackers could now access all my Passwords and thus gain access to each and every account of mine, that sure doesn’t sound right (considering none of them have 2FA - which I do have but this is just for the sake of example).

---

## Post 150 by @anon54480285 — 2024-03-23T09:42:22Z

I prefer to just have to worry about protecting 1 account instead of 2, but the request on User Voice is under review so there is that. The Proton Pass pin also logs out after 3 failed attempts.

Having said that, I am a subscriber with Proton Sentinel enabled (which gives additional security etc..)

---

## Post 151 by @ph00lt0 — 2024-03-23T10:28:15Z

I have seen this request before. But can you explain the use case? I am not really seeing any benefits

---

## Post 152 by @sgp — 2024-03-27T17:04:16Z

Proton Pass has matured into a compelling product that probably should be recommended on Privacy Guides.

It’s reasonable to recommend as a password manager: [The Best Password Managers to Protect Your Privacy and Security - Privacy Guides](https://www.privacyguides.org/en/passwords/)

It’s also reasonable to recommend as an email alias service: [Encrypted Private Email Recommendations - Privacy Guides](https://www.privacyguides.org/en/email/#email-aliasing-services)

A user can get unlimited aliases with Proton Pass Plus for $4.99/mo or $24/yr, or they can get unlimited aliases with Proton Unlimited (includes email, VPN, etc). A paid plan is required for TOTP (edit: unrestricted TOTP). SimpleLogin costs $30/yr.

---

## Post 153 by @Oti — 2024-03-27T20:18:37Z

> [@sgp](#):
>
> A paid plan is required for TOTP.

That’s not true. You have 3 free TOTP.

---

## Post 154 by @landordragen — 2024-03-27T20:56:39Z

Yeah but that’s not nearly enough, is it?

---

## Post 155 by @anon80779245 — 2024-03-28T04:44:04Z

What does it bring new compared to other password manager ?  
Also, it has significant security issues on the client side.

The **Desktop App do not ask for a password** or pin (by default) after first login. At the very least, a pin should be asked every session.

(A leak of your proton password will allow acess to not only your mail but also all your password and therefore your accounts. Although anyone with your mail can reset your passwords anyway.)

Can it be considered cross-platform ? Does it have a Linux app?

If we do recommend it, it should be cautionned that you should use a different account than for your Proton Mail account.

---

## Post 156 by @nihecof — 2024-03-28T16:13:26Z

> [@Son](#):
>
> Supporting for F-droid is in our todo list, I hope that it’ll be available in the coming weeks.

Hi, I saw you guys are working on making Proton Pass available on F-Droid. Could you guys go the reproducible build route? By default, F-Droid apps are built and signed by the F-Droid team, which requires a lot of trust, and a lot of people aren’t happy with this, even though F-Droid has a perfect track record.  
Reproducible builds are signed by the developers and not the F-Droid team, which eliminates the need to trust the F-Droid team.

I believe that this is especially important for a password manager.

> **[Reproducible Builds | F-Droid - Free and Open Source Android App Repository](https://f-droid.org/docs/Reproducible_Builds/)**
>
> F-Droid works to spread reproduciblebuilds across the freesoftware Android ecosystem. The goal is to enable software build processesthat anyone can run repe...

---

## Post 157 by @jonah — 2024-03-30T18:09:30Z

I think the concerns we had have been addressed now, anyone not ok with me marking this as #approved?

---

## Post 158 by @anon97654407 — 2024-03-30T19:23:32Z

I’m working on a PR right now :slight_smile:

Edit: Done!

> <https://github.com/privacyguides/privacyguides.org/pull/2459>
>
> Changes proposed in this PR:
> 
> - Update Password Management page: 
> 
> - Upda…te Recommendations cards of Bitwarden and 1Password to reflect new download platforms (e.g. Safari) and passkey management.
>    
> - Recommends Proton Pass (as the [relevant forum post](https://discuss.privacyguides.net/t/proton-pass-password-manager/12416) has been approved).
> 
> 
> 
> 
> - [x] I have disclosed any relevant conflicts of interest in my post.
> - [x] I agree to grant Privacy Guides a perpetual, worldwide, non-exclusive, transferable, royalty-free, irrevocable license with the right to sublicense such rights through multiple tiers of sublicensees, to reproduce, modify, display, perform, relicense, and distribute my contribution as part of this project.
> - [x] I am the sole author of this work. 
> - [x] I agree to the [Community Code of Conduct](https://www.privacyguides.org/coc).

---

## Post 159 by @jonah — 2024-03-30T22:19:58Z

![lD7BIQdYc9EFUB2W](//forum-uploads.privacyguidesusercontent.com/original/2X/8/81ba7ca86658811c247d5bbfa55d2e12de767937.png)

lol same time but you beat me to it

---

## Post 160 by @Tootieman — 2024-03-31T16:52:01Z

Hey guys and gals, just wanted to give you all a warning about an experience I’ve been struggling with for the past 2 weeks.

TL;DR: DO NOT USE PASS AS YOUR PROTON 2FA

This may be obvious to some folk, but I have been locked out from my account now for 2 weeks. All my 2FA for important accounts were in my pass so I’m sure everything is getting compromised while I sit locked out of my email, password manager, and my sanity.

Worst part is I had emailed proton immediately when my phone started acting funny. I didn’t change my password because I was worried that the biometrics was the only thing letting me sign in. I changed passwords within pass but the logs looked like it was all being viewed by the hacker anyways.

Well, after begging support to call or text me, it took a week before they shut down my account for security concerns. They then asked me to provide an insane amount of information to confirm it was me. Who I emailed recently, accounts and programs I used to sign in recently and my purchase date, amount and information. Luckily I used PayPal qne was able to find it from 2 years ago. When they respond, it’s been at 2-4am and it’s telling me more more more. I gave them everything they asked for and they have ghosted me for days now.

I literally gave you all the details and I even have the yubikey used for the account. That should be proof enough and I honestly have no idea how they even circumvented the yubikey?

I’m literally so disappointed with the quality of customer support from you guys and I am a premium subscriber for years. I practiced impeccable password hygiene with your app, making aliases for all accounts and strong passwords with 2FA. I didn’t store my password anywhere for my proton account, it’s in my head and password book. I could have been socially engineered but sentinel should have blocked my account and handled it when I reached out, not after a week and then longer because I still haven’t heard back.

If you claim to be all about security but don’t respond to security emergencies with any urgency then idk why I’m paying for your service. You don’t have any phone support which is insane to me. I understand my $200 helps pay for others, but I need help for me!

I am completely lost right now as my reliance on alias and strong passwords have all been placed on pass and now I know nothing. I can’t change passwords because I don’t know the email alias I used or the 2FA code.

Please please please let me back in with my security key which should be the cherry on top of the excessive information you already had me give you, 4 days ago.

How did they circumvent the yubikey anyways?

Please help me

---

## Post 161 by @Fibonacci — 2024-03-31T17:29:50Z

I’ve been silently reading this thread for many months and this is very concerning because it’s the second time someone reported this.

Did you contact the proton team ? Do you have any tickets numbers or case numbers ?

Did you use this form ? [Abuse appeals form | Proton](https://proton.me/support/appeal-abuse)

@Son Can you please check what’s wrong with their account ? They said they have their yubikey and all payments infos used 2 years ago.

I personally have all my passwords stored in protonpass and this makes me very scared, if I lose access to my protonpass account I’ll also lose access to everything else.

This is a good reminder for everyone to have backups.

---

## Post 162 by @anon73886004 — 2024-03-31T19:20:54Z

I believe even if your access to the account is restored you would not be able to decrypt previous emails, calendars, passwords, etc without your decryption key.

Does anyone know if the 2 password setup would have prevented an attacker from accessing both email and pass?

@Fibonacci , if this is a concern for you it could be remedied by keeping your proton credentials outside of Proton Pass which I’m sure many would advise regardless.

---

## Post 163 by @Fibonacci — 2024-03-31T19:37:21Z

I started having periodic backups of my protonpass account. I store them encrypted on my laptop.

@Tootieman still have their yubikey, so I guess they still can decrypt their data with it ?

---

## Post 164 by @anon73886004 — 2024-03-31T20:33:33Z

If support allows them back in, the recovery step would need to be performed. I wouldn’t expect the Yubikey would be sufficient unless the account password had been saved as the Yubikey’s static password (unlikely given the poster’s scenario).

My understanding is neither TOTP nor FIDO2 is used to encrypt the data on the account. Authentication only. Someone correct me if I’m wrong.

* * *

**Step 2.**  **Data recovery** : Recover your emails and other encrypted files using one of the following two options:

- **Recovery phrase** : If you’ve enabled your recovery phrase, you’ll be able to use it to restore your emails and other encrypted data.
- **Recovery file:** If you’ve downloaded a recovery file, you can upload it to restore your emails and data.

> **[Set account recovery methods in case you forget your Proton password | Proton](https://proton.me/support/set-account-recovery-methods#how-to-enable-a-recovery-phrase)**
>
> Set methods to recover your account if you forget your Proton password.

---

## Post 165 by @Fibonacci — 2024-03-31T21:04:47Z

I think @Tootieman has the correct password but don’t have 2FA which is stored in his proton pass. @Tootieman correct me if I’m wrong.

If support makes sure he’s the real owner of the account, they technically can disable 2FA and let him access and decrypt his data with his password, right ?

Now how support can make sure @Tootieman is the real owner ?

Apparently he has the yubikey, the password, payments info and maybe he can provide id for verification. Would that be sufficient ?

---

## Post 166 by @ph00lt0 — 2024-03-31T21:17:10Z

The tldr should be: have backups…

---

## Post 167 by @Tootieman — 2024-03-31T21:21:19Z

I actually have all my info, recovery keys for 2FA, my 12 digit recovery code, my yubikey, I just can’t get anyone from proton to unlock my account to access and start changing everything.

Problem is the alias’s while amazing at the time now makes me unable to do anything for accounts I need to change. Everything is in a password book after last hack I just want them to unlock it or tell me how my yubikey was circumvented or if my passwords have been exported

---

## Post 168 by @eqrlzo8t — 2024-04-01T04:10:24Z

@Tootieman You don’t have any backups of your database inside Proton?

---

## Post 169 by @ph00lt0 — 2024-04-01T10:09:13Z

That sounds strange. What are you seeing exactly? Because from what I know with that info you should be able to unlock it yourself.

---

## Post 170 by @Tootieman — 2024-04-01T16:12:16Z

I do I just am locked out by sentinel and no one is responding for days

---

## Post 171 by @Privasix — 2024-04-01T19:14:21Z

Tag @Son. Also try to write to `contact@proton.me`

---

## Post 172 by @Son — 2024-04-03T11:43:07Z

About the issue that you mentioned, can you please send me the ticket ID for the customer support ticket so I can check with the customer support team?

Currently we don’t recommend to use Proton Pass as the **only** place to store the 2FA code for your Proton account as you’ll need it to log into Pass. In the future, we plan to work on a way to use Pass as a “trusted device” so you don’t need another 2FA authenticator just for your Proton account.

---

## Post 173 by @Privasix — 2024-04-03T21:08:31Z

> [@Son](#):
>
> use Pass as a “trusted device” so you don’t need another 2FA authenticator just for your Proton account

So Proton Pass will become this authenticator? Am I right?

---

## Post 174 by @Son — 2024-04-04T10:15:00Z

Yes it can be used as a MFA for your Proton account so you don’t need a separate 2FA app just for your Proton account. In any case it’s still recommended to store your account recovery code somewhere safe.

---

## Post 175 by @jonah — 2024-04-15T19:19:32Z

2 posts were split to a new topic: [Proton Pass autofill does not save passwords automatically](/t/proton-pass-autofill-does-not-save-passwords-automatically/17888)

---

## Post 177 by @jonah — 2024-04-15T19:18:02Z

4 posts were split to a new topic: [Proton Pass vault limitation](/t/proton-pass-vault-limitation/17887)

---

## Post 178 by @jonah — 2024-04-15T19:18:08Z

#completed in [Release 2024.04.10 · privacyguides/privacyguides.org · GitHub](https://github.com/privacyguides/privacyguides.org/releases/tag/2024.04.10)
