Proton Pass is an open source, end-to-end encrypted password manager app. Create and store passwords, email aliases, 2FA codes, and notes on all your devices
It's horrible. I've had to hack together a shell script to switch between countries using a bunch of openvpn config files. The official app broke my Linux Mint network setup.
Same here. I'm fine using Proton for my mail & drive, but I also like keeping my passwords separate in bitwarden, and my 2fa separate in my raivo. A healthy separation is good.
I’m all for open source alternatives to bitwarden but this is non competitive with a mandatory subscription fee. Bitwarden is completely free for most users.
I thought the same thing but it actually does have a limited free plan. Seems like, similar to BW, it restricts 2FA behind the pass, but also with the pass you get unlimited hide-my-email aliases, multiple vaults to organize in (I don't know what this means), and eventually autofill credit cards.
This is quite a bit more expensive than BW's paid plan though. Not sure what all differences it has to BW otherwise.
Same. I'll continue to use Bitwarden. I think it's good to have other open-source options out there, though. Proton Pass is definitely prettier and will appeal to some people that care more about the aesthetics.
Proton is starting to loose focus in my opinion. I've been a costumer for 5 years only using email and I moved this year to fastmail and I couldn't be happier.
Unlimited emails alias, good apps, ability to use thunderbird without a self hosted bridge.
The promise of a encrypted email does not work if your contacts are not on proton too (for me was 100% of my contacts).
If you are really focused on privacy you would choose nextcloud for cloud for example and keypass or Bitwarden for password managers.
I would like them to focus on email client features and stop this side hustles.
@protonmail Proton claims to be a privacy oriented company and yet their email app doesn't show push notifications without Google Play Services means you will either have to use Google Play Services or live without push notifications (if you are using a degoogled phone). If Tutanota app could show push notifications without Google Play Services, it is definitely possible. What a joke!!
Probably none, if you're fine with KeePass. Personally I don't want to use anything that's hosted on someone else's server. It's a bit more inconvenient to use the local files of KeePass only, but I'd rather feel a bit safer with that, even if by all account BitWarden/Proton Pass would be fine.
I advice anyone against switching for now, especially if you're using KeePass or Bitwarden. Proton Pass has just been released, meaning it is not audited and it's immature.
I would not trust it with my passwords just yet.
They make good products, but they promise release dates over and over again, and miss them by 2+ years.
They also fuck people over by releasing apps to only their visionary memberships. Like okay. Guess my $150/month doesn't mean shit because I'm not visionary? Glad to wait 8 months for the beta to trickle down to me..
Still waiting on the ProtonMail Android app to be remade, and ProtonDrive Windows desktop app.
Edit: wait, I need a business plan to use this? What?
Ya, I'll stick to my $1.30 CAD per month for BitWarden over the $6 for this.
I was in the beta of it, didn't use it though as i am on 1password.
For me it's important that i have a desktop application. I don't want to open my fcking webbrowser anytime i need a password or want to edit some credentials.
And they simply don't have one. I gave it as feedback and they say it's on their roadmap. I said they should take 1passwords desktop as inspiration as it works so fcking good; I really love that floating quick search that you can summon with a keycombo.
If they're going to try to compete with Bitwarden they could at least offer 2FA for free instead of paywalling it as a feature. It was disappointing when Bitwarden did it, and it's even more disappointing with Proton - it's like failing an open book test.
It's mainly a difference in threat model. 2FA within a password manager is still 2FA for concerns of a website login being hacked by remote adversaries, which is the most important problem to solve.
If you use 2FA within your password manager, you should still lock that outer-most password vault with 2FA from a separate device (like you said), which solves your password vault being hacked by remote adversaries. Optionally, you can then use aggressive idle-locking of your vault on your personal devices, in case they're stolen physically.