Log in to Proton Account with FIDO2 / WebAuthn ( Passkeys / Passwordless )
With the rise in account takeover, password breaches, and the complexity of managing hundreds if not thousands of account credentials and their MFA, a better solution is needed that simplifies and offer bullet-proof protection against phishing and account takeover attacks.
Many services like 1Password, Yubico/Yubikey, and Apple offer the ability to generate and securely store passkeys that can then be used to authenticate to services that support WebAuthn/FIDO2. I strongly recommend that ProtonMail, ProtonVPN, ProtonDrive, ProtonCalendar, etc. to support passwordless/passkeys in the near future to stay on top of security and ensure that its customers are properly protecting their accounts.
End-to-End Encryption is rendered useless if an attacker or governments can successfully takeover accounts due to weak or breached credentials. I believe the use of passkeys/passwordless supports and enhanced the mission and goals of Proton.me which is centered around security and privacy.
-
Ingemar
commented
Logging in with passkeys is becoming more and more established, which is great.
Proton should also support this as being a serious player. -
Arkamas
commented
There seems to be some misunderstanding about what FIDO2 actually is.
Proton does not currently support true FIDO2 functionality, it uses FIDO U2F. True FIDO2 eliminates the need and associated risks to input passwords altogether, whereas FIDO U2F only uses security keys as a second authentication factor in addition to a password - like TOTP - even if it is still more secure. However, Proton is still lacking in supporting the most secure and convenient authentication form, and not just for one platform but for all platforms, and I hope they are seriously looking to change this, especially where Proton Pass is concerned, having all the keys to one's kingdom. An extra password is great, but a password is still a password compared to what FIDO2 is.
Of any and all my accounts, Proton is the one I want most to have passwordless FIDO2 functionality. -
Nugroho Dewantoro commented
still waiting for this...
-
John Doe
commented
Other password managers that shall not be named provide the user with the option to sign in to their password manager with only a security key, which is a great idea. Can Proton Pass allow users to have passwordless sign in using a physical security key please? This would allow for interesting use-cases of the app and would also make Proton Pass more on par with existing products.
-
Pamela
commented
This feature has already been implemented on Outlook.com and is a must-have. That does not mean that we shouldn't have an alternative 2FA in case ************. Still, with Outlook.com, you can have two factors, none being the traditional password.
-
Damon
commented
How does Pass offer this capability for other domains, yet it isn't offered for their own?
-
Jay Freeb commented
Of all the Proton services, I'd like Proton Pass to require more than just my account password. I recently bought a YubiKey (security key), and I would like to be able to use it to unlock my Proton Pass app. I did setup this key with my proton account, but Proton Pass only kicks me out of the app (then requires my account password) when I am done using it, not my actual Proton account.
-
Anonymous
commented
It’s been fun to see Proton so excited about passkeys* and be so damning of other technology companies whose own passkey implementation has been lacklustre or platform locked.
*Proton Pass only, so it’d be nice to have a fully passwordless Proton account.
-
Sander commented
While having Passkey support is amazing, not every website supports it yet. There are however websites (like Discord) that do support Security Keys instead. With Bitwarden i have the ability to save these just like with Passkeys. Having this ability in Proton Pass as well would be a huge boost to my security with these kind of services without relying on a second password manager.
-
Jon
commented
For most people, there's a sweet spot between security and convenience. Being able to open Proton Pass with a physical credential like a (Yubi/Solo/Nitro/etc) USB key, or something like Apple keychain (unlock with a fingerprint, would be a big Improvement, and certainly over a PIN. Certainly more convenient than having to use the password used to secure the whole account whenever it logs out and not be able to store it in Proton Pass for that purpose (shall I write it on a post it note?). If it is possible to log in to Proton's website with a Passkey, surely it should be possible for Proton Pass too?
-
Arkamas
commented
FIDO2 authentication is exceptionally critical and by far the biggest thing Proton needs to prioritize on ALL platforms, and I'm honestly surprised they don't already have it. It's almost tragic to not be able to use the best part of my Yubikeys for something like Proton, especially with the advent of Pass. It's bad enough that most financial institutions and some major tech companies aren't employing it. I think Proton adopting it would help set the standard and be a major advertising point for them.
-
Kizu
commented
I love passkeys/security keys. Lots of other platforms that support those let you go passwordless. Proton is EXTREMELY important for every singular account I have and it being compromised would be a disaster.
Being able to go passwordless and make password attacks a non-issue would be helpful.
-
commented
Take my lsat three votes. Even though i'm doubtful it will happen, i'd speculate the password is used as part of the encryption key for the account.
-
YOW61
commented
I suggest supporting this idea, which already has many more votes...
https://protonmail.uservoice.com/forums/953584-proton-pass/suggestions/46723147-unlock-through-hardware-security-key-e-g-yubik -
auslegungssache commented
This is such an essential feature.
I find it quite funny, that Proton develops a password manager, while it doesn't even support passkey login.
-
TWOK commented
This is extremely important, and the only barrier to my recommendation to friends and family, as I cannot trust them to safely retain a master password of sufficient strength.
-
Federico Tonini commented
I support the idea of a Proton passkey.
hace verted a Google passkey and it seems to work great ... at least at the moment.
How do you feel about it ? -
tuesday074
commented
Then you could perhaps go one step further and use a PRF-capable passkey as an alternative encryption method for the account or the data.
Bitwarden already can do that for example: https://bitwarden.com/help/login-with-passkeys/
-
Mattias
commented
FIDO passkeys streamline authentication by merging login and multi-factor authentication (MFA) into one step, eliminating the need for a one-time password (OTP) afterwards. But some services when they implement passkeys, still requires you to enter an OTP. I'd prefer if Proton ensured that when passkeys are used, it's equal to a normal login plus MFA.
-
Martin
commented
We need FIDO login support on mobile and desktop app please. Not only web !
Thanks