individual 4-6 digit PIN codes added as option for high risk logins
Proton Pass already keeps your data safe with two-factor authentication, which is fantastic. But imagine if, when you need to quickly access important passwords—say for your bank or private email—you could just enter a simple 4-6 (or even 8) digit PIN. It’s a fast, extra layer of security that makes retrieving your most critical credentials both secure and super convenient.
-
J
commented
Yeah this sounds similar to BitWarden's extra password feature for the more secure logins - I would support this or a similar feature to keep the most secure logins protected.
-
Xavier
commented
This is critical to me, especially since Proton now has added support for crypto items.
This item normally never need to be accessed, so it doesn't make sense that proton would decrypt them with all the other password and have them vulnerable to a malware running on the laptop -
User commented
Just an additional password is not secure enough
-
Oliviero Talamo
commented
To preserve 2FA concept, the OTP data should be accessed at least with a different password.
If a user password is stolen, all his/her data are compromised because 2FA has become useless.
(See aòso CatatonicMan "Separate 2FA into it's own application" and Dembow "Dedicated 2FA screen") -
Anonymous
commented
Would love to see this feature implemented. Helps to add an additional layer of security based on sensitivity. i.e. forum sites, no additional PIN needed. Banking sites, additional PIN required. This should care through to shared vaults as well.
-
ajb12
commented
on a desktop computer a pin will unlock protonpass for all my accounts, from fast food rewards to bank accounts and retirement. I would like a separate password for more sensitive vaults and no password for non sensitive vaults (this is the current behavior). The requirement for additional verification is common for my bank account for example, even after I login I still need additional verification to get my card/account numbers
-
Antonio
commented
Master PIN would still search and find in all vaults, but if we tried to use from a vault with PIN, we would need to type the additional pin. Use case: frequently log into a browser game and type pin without paying too much attention. Log into online bank with more care. Without an extra PIN to the bank vault, some onlooker could obtain the pin that would give access to sensitive and not so so sensitive logins.
-
David
commented
I can't find any setting in the Proton Pass android app for adding a PIN or any other kind of security for the app. At a minimum, I'd prefer at least a 4 to 6 digit PIN to keep prying eyes away from my password app if someone gets ahold of my phone. As it stands, if someone is able to open my phone, they are able to get right into my Proton Pass app and see all my passwords.
-
alfredo
commented
Hello,
it would be good to see on Proton Pass the possibility of using an alphanumeric password instead of a PIN.
Android and iOS devices generally have encryption by default, whereas on PCs it is generally deactivated. For this reason, the Proton Pass database of the browser extension should be encrypted and possibly also the data loaded into RAM encrypted.
If the device is stolen without Proton Pass database encryption, anyone can access the database.
Thank you