Suggestion for improve clipboard
When copying a password, it should only be allowed to be pasted once, or automatically deleted from the clipboard after 20, 30, or 60 seconds (configurable time). If the user pastes the password somewhere, it should be immediately cleared from the clipboard to increase security and require a new copy if needed again.
This is now available with Proton Pass v1.33
-
Pierre Pierre Blais
commented
I am running Proton Pass v1.36.0 on Android. In my settings, I have "Clear clipboard" set to one minute. The clipboard entry is still not cleared after three minutes.
-
markoise
commented
Very good idea. This is sometimes very annoying, especially on Android.
-
Bill Walton
commented
LastPass has a "similar" feature. I find it endlessly annoying and would like to be able to disable it, or (better yet) manually control when to purge the clipboard. I sometimes paste first to a note or temporary text document just to keep from losing my new password before I get it pasted to the two places I want it.
-
Nicholas Maskell commented
I think it could be timed to a couple of minutes as when creating a login it's useful to have the password copied in case you need to repeat something
-
anon.amethyst
commented
Great suggestion and it should go hand-in-hand with what is called out in vroni's post:
Make text from ProtonPass web browser extension private
https://protonmail.uservoice.com/forums/953584-proton-pass-authenticator/suggestions/49231535-make-text-from-protonpass-web-browser-extension-pr -
Stu
commented
Valid idea but I think this option should be offered for those who want it - a toggle yes or no to activate. In some cases, this kind of requirement is unnecessary overkill and nuisance. The current clipboard expiration timer can already cover part or all of this risk
-
Gerard ONeill
commented
Security-wise, are programs allowed to read or test the clipboard? Even 10 seconds is a long time to wait to clear the clipboard and even then it might not be enough.
I'd suggest helping people clear the clipboard with a button would be better. That requires less systems permission, and works with all use cases. OTOH, perhaps if its an option it might be fine.
I just am averse to having programs step outside their bounds - I like to reason with as few rules as possible. The clipboard is a system resource, used by many programs, and may be used very quickly, or very slowly. I'd like to not worry about who's "security feature" might be testing the clipboard 10 seconds after a copy. Or even wonder if the copy didn't take vs it being arbitrarily blanked out.
-
DZFr
commented
A very interesting option to have !
-
TCS
commented
Some competitive product analysis may benefit Proton signifcantly. (KeePass is one that I had in mind.) I chose KeePass a long time ago because of the open file format (so have other developers)--REAL data control. Does PP have an open documented file format? Would I have to perusal the source code to extract that kind of information?
-
khwaj
commented
I'd suggest having this feature/ function as a selection option (On / Off) within the security section of the settings, because I like to retain certain clipboard items for use in other programs (eggs/ basket), & then manually delete from the clipboard when I'm finished.
Keep things open by design, & not forcing one decision upon users - m$ springs to mind! -
Douglas Silva
commented
KeePassDX (Android) has a "Magikeyboard", which bypasses the clipboard entirely and relies on that virtual keyboard for auto-type. It's a bit cumbersome, but I'm confident that Proton can design something better.
-
Pierre Pierre Blais
commented
It looks like if this is available but not working on Android. Perhaps consider a different approach, such as supporting a Proton Pass keyboard (check out Password Safe on Android).
-
Wojciech
commented
Would be nice to have.
-
Potato King
commented
Sounds a really great and important idea. But I wonder how will they like do they have access to clipboard ? idk. also I hope if they do , they keep linux users in mind who uses wl-clipboard.
-
Anonymous
commented
This feature is really important.
For example when using a shared device and other people have access to the clipboard. -
Per Eriksson commented
Important!
-
joe
commented
Yes, please.
-
DatGuy
commented
It would also be amazing if we could get some salt and hash into keyboard inputs like https://www.majorgeeks.com/files/details/keyscrambler.html this would really make the tool top tier in the industry. I'd gladly pay a little extra for it too. if paired with some monitering client side it might end up being better than roguekiller https://www.adlice.com/roguekiller-clipboard-protection/
-
Anonymous
commented
Also on Mac. After copying the password the clipboard should be automatically cleared.
-
Tyler Durden
commented
Yes ! Just like KeePass is deleting it automatically, Proton Pass should do this as well !