Auto-Lock Timers for Fill vs. View/Copy/Edit actions
Hi Proton Team,
Consider a user who has both a PIN/secondary password and auto-lock enabled for maximum security. The current workflow is often disruptive, as it forces re-authentication for every login attempt. This creates a dilemma: either the auto-lock timer is set too short, causing frequent interruptions for simple logins, or it is set too long, leaving the vault accessible longer than desired.
To resolve this, I propose adding a separate auto-lock timer specifically for credential filling as a new option in the settings.
Currently, a single timer governs both viewing/copying/editing and auto-filling. I suggest splitting this logic:
Fill Timer: The user can set a longer duration (or indefinite) since the risk is much lower.
View/Copy/Edit Timer: The user can set a shorter duration (or instant lock) since the vault itself requires much more security.
Setting a longer timer for filling would give away a little security for a lot of convenience. Each user could set their timers based on their own risk tolerance.
This approach eliminates the disruption of frequent re-authentication for logins while strictly protecting data visibility and configuration changes. It allows for a seamless login experience without compromising the security of the vault itself.
Thanks, Elias.