Borgzilla,
@Borgzilla@lemmy.ca avatar

I’m pretty sure the app is great, but I am not a fan of putting all my eggs in the same basket. I will keep using Bitwarden for the time being.

Easy_Fox,
Easy_Fox avatar

Same for me. I use protonmail and used protonvpn for a while, but putting all my eggs in the same basket... I will keep using other providers for my other stuff.

TheZoltan,
TheZoltan avatar

Yeah I'm quite tempted to get on board with Proton as they could replace Tutanota, Bitwarden, Nord VPN and One Drive/Google Drive for me. Seems convenient and privacy focused but obviously all my eggs in one basket seems like something I might come to regret.

Borgzilla,
@Borgzilla@lemmy.ca avatar

At the end of the day, they may be the safest privacy-focused company out there, but they still own my data. Never trust anyone.

nehl,

Hey, a fellow tutanota user?

Jarmer,
Jarmer avatar

Same here. I'm fine using Proton for my mail & drive, but I also like keeping my passwords separate in bitwarden, and my 2fa separate in my raivo. A healthy separation is good.

Sebo,

I use keepassXC and Ive never had a problem with it, Is there anything different about Proton Pass?

confetti_8tVST5,

Didnt read anything about a security key or even a keyfile (poor mans security key w/o phishing protection). Im assuming its protected by totp which is fine but I do kinda prefer a security key

MarioBarisa,

I tried it and its pretty cool and polished, but Bitwarden is WAY better in every poseible way.

Raphael,

I agree with you there, KeePassXC is definitely the superior choice.

Harrison,

I’m all for open source alternatives to bitwarden but this is non competitive with a mandatory subscription fee. Bitwarden is completely free for most users.

ram,
@ram@lemmy.ca avatar

I thought the same thing but it actually does have a limited free plan. Seems like, similar to BW, it restricts 2FA behind the pass, but also with the pass you get unlimited hide-my-email aliases, multiple vaults to organize in (I don’t know what this means), and eventually autofill credit cards.

This is quite a bit more expensive than BW’s paid plan though. Not sure what all differences it has to BW otherwise.
https://lemmy.ca/pictrs/image/5ad9a6ce-eb03-4025-be61-6c90a9a12648.png

feral_hedgehog,
@feral_hedgehog@pawb.social avatar

Thought this was about Valve’s Wine fork and was very confused 😅

wounn,

Proton is starting to loose focus in my opinion. I’ve been a costumer for 5 years only using email and I moved this year to fastmail and I couldn’t be happier. Unlimited emails alias, good apps, ability to use thunderbird without a self hosted bridge.

The promise of a encrypted email does not work if your contacts are not on proton too (for me was 100% of my contacts).

If you are really focused on privacy you would choose nextcloud for cloud for example and keypass or Bitwarden for password managers.

I would like them to focus on email client features and stop this side hustles.

tate,

Proton’s whole reason to exist is to provide privacy, not email client features.

palebluedot,

I advice anyone against switching for now, especially if you’re using KeePass or Bitwarden. Proton Pass has just been released, meaning it is not audited and it’s immature. I would not trust it with my passwords just yet.

SoulKeeper,

@protonmail Proton claims to be a privacy oriented company and yet their email app doesn't show push notifications without Google Play Services means you will either have to use Google Play Services or live without push notifications (if you are using a degoogled phone). If Tutanota app could show push notifications without Google Play Services, it is definitely possible. What a joke!!

jjffnn,

I don't think that's true.
I get push notofications on my degoogled phone.

dwindling7373,

Wait what I have no google services and I get all the notifications. I do have microG of course…

protonmail,
@protonmail@mastodon.social avatar

@SoulKeeper While we rely on Google Play Store services for push notifications, they are end-to-end encrypted. To stay private when using Proton Mail on an Android phone, we recommend trying some of these tips: https://proton.me/blog/android-privacy .

We are also working on a complete rewrite of our Android app, which will allow for the improved functionalities and features to be added.

SoulKeeper,

@protonmail Thank you but I would sacrifice push notifications rather than using Google Play Services on my degoogled phone.

HorseFD,

Has anyone tried it yet? Two downsides for me:

  • there’s no desktop app
  • there’s no Safari desktop extension (I know most people don’t care about this)

It’s also more expensive than Bitwarden even at €1/mth

pabloscloud,

“no desktop app” One can use the iPad App on Mac with m1, tho sure not optimised for desktop.

“No safari extension” They announce it on their download page, so it should be available later.

Dalinar,

Goodbye LastPass (I’m aware I should have migrated already but I was holding out for this)

DanielPlainview,
@DanielPlainview@lemmy.world avatar

The most important step a man can take. It's not the first one, is it? It's the next one. Always the next step.

testingtesting123,
@testingtesting123@discuss.tchncs.de avatar

Th email protection is nice, but my one of my mails is already full of spam, so I don’t care any more and just use that when I don’t trust…

nimbool,
nimbool avatar

I don't think using the same credentials for an email service and a password manager is a good idea, regardless of how much I like Proton and what they stand for.

Snowfall,
Snowfall avatar

I like to see it! I’ll stay Bitwarden for now cause it works well (and I just went premium) but I’ll keep an eye on it.

moxival,

What does 2FA authenticator mean? Is it a vault to store your 2FA seeds?

noodlejetski,

yeah, although using a password manager as a 2FA provider sort of negates the "2F" part.

AgileBed,

Depends. I use 1Password and let it store all my 2FA, because my 1Password login is secured with another 2FA.

ShittyWizard,
ShittyWizard avatar

Yo dawg

AgileBed,

Now imagine I would use a third 2FA app to store the second 2FA.

!deleted95653, (edited )

deleted_by_author

  • Loading...
  • phoenixes,

    I think 2fa-in-your-password-manager is slightly better than not using it, since it requires that the attacker have access to your password vault, so it still protects against cases where just your password leaked somehow, but yeah, definitely not as good as full 2fa.

    Maestro,
    Maestro avatar

    I disagree. 2FA also protects against a breach/leak of the site. If your password is leaked or stored insecurely, then the 2FA still helps.

    Negative_Pair_5694,

    But to add to that as well: If the site has stored your password insecurely, they will probably have lost your 2FA secret too. Which even has to be stored in 'plain text' in contrast to your password.

    AlteredStateBlob,
    AlteredStateBlob avatar

    As per the video they released https://youtu.be/M8doASpFbuk it allows you to immediately enter the 2FA account.. oh man. as @noodlejetski said, this very much negates the whole point of 2FA.

    I really like protonmail and have been a paying user for years now. But nothing beyond calendar and mail has really made a lot of sense to me so far. I'll stick to my Keepass container, syncing that across my devices. It's easy to manage and I don't need to trust anyone else with that data ever in no way, shape or form.

    !deleted95653, (edited )

    deleted_by_author

  • Loading...
  • sudneo,

    Not fully accurate. The 2FA still prevents issues such as credential stuffing or bruteforcing, which might not depend on you. Of course, these risks are very limited if you use random unique passwords (as it makes sence since you are using a password manager).

    Also 2FA is anyway there for the password manager, and if you have a session on, chances are the same applies for the target app (for example, your email). So it's not completely useless.

    This said, I agree with the general principle. I personally use yubikeys where I can, including to store the TOTP codes (I never liked the phone to be 2FA device that much...)

  • All
  • Subscribed
  • Moderated
  • Favorites
  • privacyguides@lemmy.one
  • PowerRangers
  • DreamBathrooms
  • ngwrru68w68
  • magazineikmin
  • thenastyranch
  • InstantRegret
  • Youngstown
  • mdbf
  • slotface
  • rosin
  • GTA5RPClips
  • khanakhh
  • kavyap
  • Durango
  • provamag3
  • modclub
  • ethstaker
  • cubers
  • vwfavf
  • everett
  • cisconetworking
  • tacticalgear
  • tester
  • normalnudes
  • osvaldo12
  • anitta
  • Leos
  • megavids
  • All magazines