Full auto-logout after user-specified duration
The master password and 2FA method are used far too rarely to access Proton Pass.
Currently, you can set up a PIN or biometrics to access your Proton vault seemingly indefinitely. I believe this can make it harder to remember your master password, or spot issues with your 2FA method. I also believe this is a security risk for any devices that are left unattended for an extended time; a 6-digit code is more easily leaked than a strong master password!
I would like for Proton Pass to implement a feature in which the user can – but doesn't have to – specify a duration (like a week or a month), after which the current device is automatically logged out.
-
Mark C
commented
I want nothing to do with a pin and would much rather be logged out every 4 hours and on browser close. Plus MFA validation every 90 days on trusted systems (that I can name and revoke if needs be). Having to re-enter the master password more often is critical in my opinion as I need to make sure that I don't forget it!
I also liked the way that LastPass could be configured to re-prompt for the master password in order to fill in login details even while logged in, and would only allow bypassing the additional password requirement for a few minutes at a time afterwards. Being logged in just allowed you to view the list of sites (ex. vault) and if the current site has any logins associated.
-
Steven
commented
Require full re-login after a set period (e.g., 14 or 30 days, or never as in 1Password) on both iOS and OS. This adds a security layer and reinforces password recall.