Recently I tried to figure out which service to use for a break-glass recovery scenario. Like if I lose all my devices, forget all my passwords, and need to recover everything: password manager database, access to accounts, my docs.
The weird thing for me is that no two well-known services share the same recovery approach. All services are pretty similar in terms of signing in but when it comes to account recovery, everyone invents their own thing.
Here’s a simplified comparison of services:
Whether the secret is short enough to write down matters for offline paper storage. Someone could try to write down Filen’s 640 random characters, but it was clearly not designed for that.
The option to rotate the recovery secret becomes important when the secret was compromised or entered on an untrusted device during recovery. This is where I see a hard trade-off Ente has made. When I asked the community why the recovery code can’t be changed, they said it would require full re-encryption of the entire Ente media library. Proton is in the same situation, but wrapping a permanent secret with a rotatable one solves this limitation in similar cases.*
Ente addresses this by encouraging people to use their SSS implementation, while it’s meant as a legacy route, it also works as a personal recovery solution. But it makes the secret non-writable in the current implementation. They also have recovery through trusted contact.
One more note on Ente: while I mentioned email as required in addition to the secret, users can actually bypass this by writing to support.
Proton’s approach is the most flexible: users can choose whether to store one passphrase that bypasses everything, or split data and account recovery (Filen-style). For data restore you need key files, and for account recovery a phone or email. The recovery passphrase is still the simplest approach and the one Proton itself recommends — and the only option where a single artifact requires nothing else.
Tuta’s approach is the strictest: they allow users to forget their password or lose their 2FA, but not both. I’d say if Proton wins in terms of chances of successful recovery, Tuta wins in terms of how hard it is to use the recovery route to steal an account.
More mainstream services like Google are less interesting to the crowd here. But broadly: Microsoft is closer to Proton’s approach, Apple closer to Tuta’s. Google is in its own league — as far as I know, with Advanced Protection enabled there’s no clear list of what a user has to provide if they lose their key. This looks intentional, and turning on APP is generally considered a good thing if you use Google. APP probably makes Google more secure, but a less predictable recovery option.
Personally I find Proton’s approach the most straightforward and reasonable, and do the same with a self-hosted solution. But I’m not sure if there’s a consensus in the community.
*Proton Drive also supports rotating the “permanent” secret if you ask them — but that requires removing all files from Proton Drive and a conversation with Proton support.
