21 ms·
Proton Pass end-to-end encrypted password manager is here and free for everyone
- ZeroCool2u 3y agoShould probably link directly to the announcement here: https://proton.me/blog/proton-pass-launch https://proton.me/blog/proton-pass-launch
- doodlesdev 3y agoAm I correct in believing that they haven't open-sourced Proton Pass yet? It seems like an ok password manager, but with no mention of open-source and an option for self-hosting, this already becomes completely unusable, especially considering so many great alternatives are already available. edit: Their official announcement post says it's now open source, however I haven't been able to find the repository. I also still see no mentions of self hosting.
- protonmail 3y agoHere's the repository: https://github.com/protonpass https://github.com/protonpass.
- beefee 3y agoPlease put your apps on F-Droid.
- doodlesdev 3y agoPSA: ProtonMail is available through IzzyOnDroid repo. ProtonVPN is available through FDroid repo. Proton Calendar and Proton Pass are missing though.
- psychphysic 3y agoCorrect me if this is no longer true. The fatal chink in the Proton model is that PGP keys must either be generated on the service or uploaded unencrypted? To me it seems trivial to make it possible to upload a locally generated appropriately formatted encrypted key. Glad if that now no longer true.
- upofadown 3y agoI don't know if that was ever true. That wouldn't make sense. ... and this is about the password manager ...
- psychphysic 3y agoDid you not realise the password manager uses PGP for the key storage? Same with Drive and Calender and of course the original Mail. Rather than just guessing and assuming it'd be useful if you actually knew about the ecosystem before commenting.
- protonmail 3y agoThis is incorrect. Encryption keys are generated client-side, and the private key is encrypted with the user password which the server never sees. This is also verifiable through Proton's open source code.
- dist-epoch 3y ago> But Proton Pass will also enable you to create a hide-my-email alias. An email alias is a randomly generated email address that sits between a third party (like Amazon, Facebook, or Netflix) and your real email account Is there some software I can install on my webserver to generate per service emails like Proton Pass here (amazon.44ot65@passmail.com, netflix.56ax12@passmail.com, ...)? And which forwards the mails to my main Gmail and allows replying to them.
- DotJr 3y agoYou can maybe try SimpleLogin. It's open source and can be self hosted (I have no idea how difficult or not this is). Proton acquired them and integrated the product into their own. https://simplelogin.io/ https://simplelogin.io/
- dist-epoch 3y agoThank you, looks perfect.
- FireInsight 3y agoAnonaddy, basically the exact same product made by different people, can also be selfhosted. https://anonaddy.com/ https://anonaddy.com/
- Mystery-Machine 3y agoBoth Google domains and Cloudflare Email routing have wildcard/catch-all email forwarding. You probably can't reply from those email addresses, but you can receive/have email forwarded to those addresses. I have had this setup with Google domains, I now have it setup with Cloudflare email routing. In both cases it's free, but you need to have the domain on Google domains for 1) or add site to Cloudflare (and use their name servers for 2).
- systems_glitch 3y agoCan't use the Firefox extension, FF 102 ESR is apparently too old :/
- protonmail 3y agoWe need support for manifest v3 for Proton Pass and it requires FF 109 at the minimum.
- Vaslo 3y agoI’ve been using since beta. It’s really smooth and pretty comparable to Bitwarden. It’s doesn’t have notes and such yet but it’s going to be a good competitor. I don’t think it’s open source so may not exactly be a good replacement for Bitwarden.
- doodlesdev 3y agoTheir original plan was to keep it closed source during the beta and make it open source upon release, according to https://proton.me/blog/proton-pass-launch https://proton.me/blog/proton-pass-launch it is now opensource, however I have not been able to find the repository anywhere. The biggest problem for me now would be the fact it cannot be self hosted, making lock in pretty extreme even though it's open source. The fact I can host my own instance is the main reason I stay with Bitwarden instead of migrating to an offline-first solution.
- protonmail 3y agoHere's the repository: https://github.com/protonpass https://github.com/protonpass.
- doodlesdev 3y agoAny specific reason not to put it in the ProtonMail GitHub organization? Anyway, thank you for taking the time to answer. :) Tangentially, I see the application is native (i.e. not using Xamarin like Bitwarden), you should definitely point this out if you ever make some technical post about Proton Pass, I'm sure HN folks will be interested to hear about it. Another thing, the client is not only open source but also free software, I think you should definitely point this out as well. I believe this is an important distinction for quite a lot of Proton users. I wonder however if this is OK to do for the iOS client, AFAIK GPL code could not be published on the app store without breaking the license [0]. Last but not least, I noticed that the issues tab does not appear on the Android repo but does on the iOS one, surely this is not intened? [0]: http://www.fsf.org/blogs/licensing/more-about-the-app-store-gpl-enforcement http://www.fsf.org/blogs/licensing/more-about-the-app-store-...
- pixxel 3y agoI guess most find it useful to have all these tools/services supplied by one company. Personally I think it’s awful for privacy.
- FireInsight 3y agoYou could also see it as reducing the amount of entities you have to trust. If everything is with Proton you only have to worry about their trustworthiness.
- omniglottal 3y agoIf there were more companies who went out of their way to handle only the metadata tied to my E2E content, I'd pay those companies, too! Using just one vendor isn't actually all that bad for privacy (anonymity being another matter), but requires lots of trust. As a US citizen, I trust the Swiss more than a US company, and can see that Proton's choices (including arbitration) are in support of my key requirements to have uncompromising privacy. I would like to see more companies competing for my trust, but these guys win so far so they get my money.
- lowbloodsugar 3y agoTime to ditch 1Password.
- xslvrxslwt 3y agoBitwarden was released years ago though?
- lowbloodsugar 3y agoI don't know them.
- firefoxkekw 3y agoProton, the company that still in 2023 doesn't allow to cancel the auto renewal without losing access to the services you have already paid, the most anti-consumer thing I have seen in my life. Here is how it works: 1. You pay for example for 2 years of access. 2. After a few months you decide to remove the auto renew and just use the remaining time of your subscription, your only option is to cancel your current subscription and lost access to any premium service you paid for, they give you credits for the remaining time of your subscription, that you can use if you contract other services. So you are force to cancel the subscription before the renewal time and hope you don't forget to cancel it. Run from this company.
- devmunchies 3y ago> your only option A calendar reminder to cancel the week before renewal is another option
- laeri 3y agoYes this is an option but a very annoying one.
- barbazoo 3y agoAnd also happen to have the time to switch email providers that same week. No, what they do is just shitty.
- devmunchies 3y agoI never said what they are doing isn't "shitty".
- Mystery-Machine 3y agoThank you, I believe that was obvious to everyone.
- pdpi 3y agoIt’s not “another option”. It’s a tool for dealing with the only option they give you.
- bobajeff 3y agoI don't think there is any good reason to store passwords on a remote machine that you don't own. When most passwords that anyone will ever have can be fit on one cheap thumb drive in a keepass database. For which there are many open source apps available.
- vlakreeh 3y agoEase of use is the biggest one. While you and I are capable of setting up and keeping up a remote machine with a self-hosted password manager, I'm incredibly confident my barely tech literate parents are. Realistically for people that aren't savvy enough to set up their own thing it's a e2ee password manager using that password manager's remote service or them using the same password for multiple websites and more of a lesser of two evils.
- bobajeff 3y agoThat makes sense. However, it's not that different from using the same password on all sites as an attacker only needs the master key for your online password manager.
- ghusto 3y agoIt's very different. Even if I gave you my master password, you wouldn't be able to get into my account. The password manager I use has MFA (and I don't mean 2FA).
- deleted 3y ago[deleted]
- devmunchies 3y agoI share a password manager with my spouse. There’s no way she would use it if it didn’t have a good mobile app.
- ravenstine 3y agoI generally agree, but it also depends on who you are. Although I don't have direct experience with this yet, I can imagine it's better for people who are not tech savvy or are prone to devices getting broken or lost. As a programmer, I've yet to have needed a password manager. My passwords are random word combos that are somewhat memorable and I have 2FA setup for most things. If I forget a password, I rely on the "forgot my password" flow, and just accept that as the occasional tradeoff for not having a password live anywhere specifically. For some sites that don't have 2FA, I rely solely on logging in via the "forgot my password" flow. Far as I can tell, I haven't been pwned.
- fortuna86 3y ago[dead]
- nyanpasu64 3y agoI also got an email from Proton saying that they're forcing mandatory arbitration and class action waiver on all users.
- protonmail 3y agoThis is also not true. -Proton's updated ToS does not change dispute resolution for users outside of the US. -Proton's legal jurisdiction is Switzerland. Swiss law does not permit class action lawsuits. -For US users, Proton's updated ToS also does not remove your existing right to bring a claim against Proton in Swiss court (so you are not forced into arbitration). -Recognizing that some US users might not want to bring a claim in Switzerland, our updated ToS adds the possibility to arbitrate in the US. -We are wary of US courts having jurisdiction over Proton as it gives the US govt leverage. We suspect many of you are too, which is why people care about Proton being Swiss. Therefore, while Proton agrees to permit arbitration in the US, we don't by default permit proceedings in US court.
- Mystery-Machine 3y agoI feel like it's not true that their services are end-to-end encrypted. I mean, they are, but they have the encryption keys so it's the same as if they are not. https://news.ycombinator.com/item?id=29103056 https://news.ycombinator.com/item?id=29103056 https://encryp.ch/blog/disturbing-facts-about-protonmail/ https://encryp.ch/blog/disturbing-facts-about-protonmail/ https://news.ycombinator.com/item?id=17775326 https://news.ycombinator.com/item?id=17775326 https://news.ycombinator.com/item?id=28057433 https://news.ycombinator.com/item?id=28057433
- jacooper 3y agoThe encryption keys are encrypted using your password. Its the same as your phone.
- protonmail 3y agoExactly. Your encryption key is stored encrypted so that we have no access to it. It is decrypted when you enter your password. We don't have access to your password, only an encrypted hash of it, so that our systems can recognize it. We cannot derive your password back from the hash.
- protonmail 3y agoIt's open source so the E2EE can be (and has been) independently verified. The crazy CIA/NSA conspiracy theories are also quite easily debunked, see here: https://www.reddit.com/r/ProtonMail/comments/14demhj/debunking_proton_and_ciansa_fake_news/ https://www.reddit.com/r/ProtonMail/comments/14demhj/debunki...
- butz 3y agoAnd still no native Linux client for Proton Drive.
- highwaylights 3y agoPossibly the worst experience I've had dealing with a software company. So bad in fact that I couldn't consider using any of their products ever again out of fear.
- latchkey 3y agoI was hesitant to even bother trying yet another open source password manager, but wow, the comments here are brutal. Thanks for confirming initial gut feeling. I'll stick with Bitwarden.
- Reisen 3y agoI am a current user of Proton about to search for a solution to move away from this company, I am quite disappointed in my experience with them in general. 1) Their mail import tool reports wrong email set count and sizes leading to low confidence the tool worked, in the end I mbsync'd from both fastmail and proton and compared the email set because the migration UX was so poor (this is reported by other users also). 2) Their alias address implementation is severely limited, on Fastmail I used *@domain to have infinite emails, on Proton you have to add every alias you want manually one by one, if you do not, you cannot reply from any address. This is not only limited in the UI, but everywhere, protonmail-bridge for example will reject sending any email that is not in your alias list, and as they limit it to 100 addresses you can't work around it programatically either. 3) Their bridge software is buggy, and poorly documented, it's better with the recent release but for a while it made heavy assumptions about your installation and would log you out sporadically, sometimes requiring gpg-agent to be restarted (for no reason I could figure out) before being able to re-auth. 4) Their Proton Drive offering is basically useless, it is not available on Linux so can't use it as a target for backup software like Kopia/restic etc, and desktop apps have been in development for as long as I can remember. The WebUI for it will break if you try and drop too many files at once. It has problems with file name limits which don't appear until you try and access the filesystem again; after uploading several documents with extremely long names I found they were straight up inaccessible on my phone or via the web, so as far as I can tell if I hadn't had a second backup I would have lost these files. All this would have been rough, but acceptible for me if I felt their client attention / support was good, but the support I received was terrible. Multi-day back and forths with support agents who did not seem to understand my questions, where with fastmail I would have a technical response to almost any question within an hour. Their uservoice page is full of basic requests that are unanswered after years: https://protonmail.uservoice.com/ https://protonmail.uservoice.com/ I've never regretted migrating to a company as much as I do Proton and I would not recommend switching to their applications, everything feels half baked or limited by poor focus on reaching feature parity with other competing services. The fact I can't do basic catch-all domain with their email service without being forced to reply via a limited alias list (if I can, their support was incapable of telling me how), was my last straw. It's a shame there's basically no other encrypted mail host that competes.
- 3y ago
- AnonC 3y agoPity it's only available on iOS and Android as apps and as browser extensions elsewhere. I would've been interested to check out a desktop password manager that's free/cheap and is not based on Electron* and follows native OS UX. [* As far as I know, Bitwarden is an Electron app. It shares the same kind of sluggishness and some weird navigation issues that are common in Electron apps. Though I wouldn't go back to 1Password for various reasons, I recall that it's also an Electron app ever since Agilebits got huge funding for the company.]
- hpb42 3y agoI Use KeePassXC[0] on the desktop and is really great. It is open-source; not an Electron app, it is written in C++[1]; there are browser plugins to auto-fill user/password/TOTP codes; it is local-first: not tied to any cloud vendors and you can easily sync the database file via any cloud system if you want; there is an Android app that can use the same database. [0] https://keepassxc.org/ https://keepassxc.org/ [1] https://github.com/keepassxreboot/keepassxc https://github.com/keepassxreboot/keepassxc
- varjolintu 3y agoThere's still nothing about the telemetry in the browser extension? I couldn't find any mention about it in the "Help us improve Proton apps" or from the privacy policy page. The privacy policy mentions "It details the data processing activities specifically related to the creation and activity of your Proton Account when you use Proton Pass." though, but it's a bit unclear. When looking at the extension's source code, telemetry data is anonymous, but it's always sent to the remote endpoint, and the only way to disable it is from your Proton account, not the extension itself.
- protonmail 3y agoThe telemetry option is shared between all products and can be accessed from account pages for each product, for https://account.proton.me/u/0/drive/security https://account.proton.me/u/0/drive/security for Drive, https://account.proton.me/u/0/pass/security https://account.proton.me/u/0/pass/security for Pass, etc.